At 20:50 on Wednesday 8 April 2015 the sabotage of TV5Monde, the French-language international broadcaster, began; by 22:00, with its own engineers pulling the network down around them, the channels were off air together — eleven by the count its director-general gave that night, twelve in later reconstructions. Its website, its Facebook page and its Twitter account filled with banners signed CyberCaliphate, along with personal information said to belong to relatives of French soldiers and messages attacking President François Hollande. France was three months past the Charlie Hebdo killings, and the reading was immediate: jihadists had taken a television network off the air. The director-general, Yves Bigot, called the attack unprecedented. The rebuild began a little after 05:00 the following morning, by hand, by technicians who were in the building because a new channel had launched that day; normal programming did not come back until that evening.

It was not a defacement. France's national cyber-security agency, ANSSI, concluded that the object had been sabotage from the beginning. The intruders had first got inside on 23 January 2015 and spent eleven weeks mapping the place, entering at seven separate points — one of them the network of a Dutch firm that supplied remote-controlled studio cameras — before the destructive stage on the night of the eighth. The malware written for it was built to wipe the firmware of the encoders and network hardware that carried the signal, using credentials and configuration harvested from the broadcaster's own network equipment to find them. Bigot later said the station had come within a couple of hours of being gone for good, and credited an engineer who located the machine doing the damage and unplugged it.

The next day France 2's lunchtime bulletin, 13 Heures, sent a crew into the newsroom. The report went out with TV5Monde's reporter David Delos standing in front of a colleague's desk on which usernames and passwords had been written across index cards and sticky notes; one frame showed the YouTube password as lemotdepassedeyoutube — the password of YouTube — and a separate sequence caught azerty12345 on a note in front of a monitor. The network's explanation was practical and rather sad: with the antenna, the internal messaging and the email all down, access codes had gone up on the walls so journalists could still publish to the web. Commentators asked whether the broadcast had handed the attackers something. It had not needed to; they had been inside since January.

The reattribution came fast and stayed qualified. On 9 June 2015 FireEye's assessment was reported: the site hosting the CyberCaliphate material sat in an address block used by APT28 — the Russian military intelligence group later called Fancy Bear — on a server and registrar it had used before. ANSSI, which had the forensics, would not name a state in public, and France did not do so until 29 April 2025, when its foreign ministry said the GRU had used APT28 to sabotage the broadcaster. The Islamist claim was never disproved so much as outgrown; CyberCaliphate was a real name, which had hijacked US Central Command's Twitter account in January and Newsweek's in February. TV5Monde put the bill at about €5 million in the first year and €3 million a year afterwards. Bigot was left with two questions he said nobody could answer: why TV5Monde, and who gave the order and the money.

Also that month · 7–25 April

Reading the president's schedule

On 7 April 2015 CNN reported that hackers working for the Russian government had reached the unclassified network of the White House's executive office and had seen material including the president's non-public schedule. The route ran through the State Department: a phishing message sent from a State account had put malware on a White House machine, and the odd behaviour had first been noticed the previous October. The White House confirmed a breach of an unclassified system while stressing that nothing classified was involved — a distinction that wore thinner on 25 April, when the New York Times reported that the intruders had read some of the president's own unclassified email. Moscow rejected the accusation. The intrusion is generally associated with the group later called Cozy Bear, named at the Democratic National Committee in June 2016 — an association made afterwards, not in April. On 10 April Citizen Lab and its co-authors named the traffic-hijacking tool that had battered GitHub in March: the Great Cannon (March 2015). Baidu, whose traffic the tool borrowed, said its own systems had not been compromised, and Beijing denied any part in it. On 23 April, at Stanford, Defense Secretary Ashton Carter published a Pentagon cyber strategy that named China, Russia, Iran and North Korea in print.

Also that month · 14–15 April

A beacon and a tweet

Two discoveries share the date of 15 April 2015, and only one of them made the news. At the US Office of Personnel Management, staff found the second of two intrusions into the agency holding federal personnel and background files; the find has been credited both to the agency's own security staff and to a commercial tool being trialled there. Nothing was said publicly until June (June 2015), and the number given then — about 4.2 million personnel records — was only the first: 21.5 million background-investigation files were added on 9 July and 5.6 million fingerprint sets on 23 September, some 22.1 million people in all. The same day the researcher Chris Roberts was met by the FBI as he left a United flight at Syracuse, having tweeted in the air about the aircraft's crew-alerting system; agents seized his laptop, tablet and storage devices. A search-warrant affidavit by Special Agent Mark Hurley, reported on 15 May, said Roberts had told agents he once overwrote code on a thrust management computer and issued a climb command that moved a plane sideways. Roberts said the affidavit had compressed five years into a paragraph, and that any climb had been in a simulator; officials told reporters they had no credible evidence a cockpit had ever been reached from a seat, and he was never charged. Microsoft's 14 April patch round closed MS15-034, a critical HTTP.sys flaw that a single malformed request could use to crash a Windows server.

India desk · April 2015

A million emails to Mahanagar Doorsanchar Bhawan

TRAI published a consultation paper on over-the-top services on 27 March 2015 — twenty questions, comments due by 24 April — and in April the country answered. Airtel announced Airtel Zero on 6 April, a platform on which app makers would pay the operator so that their own customers' data was free; on 11 April the comedy group All India Bakchod posted a video called Save The Internet telling viewers exactly which address to write to; on 14 April, after days of public anger, Flipkart pulled out of the scheme. A loose coalition of engineers, entrepreneurs and free-software people ran savetheinternet.in, with a student-built netneutrality.in alongside it. By the deadline TRAI had taken more than a million emails, arriving at one point at about fifty a minute, and its website buckled; more than fifty academics from the country's technology institutes signed in support.

Then the regulator made the campaign's point for it. On 27 April TRAI published the submissions in full, including over a million email addresses, and a collective calling itself AnonOpsIndia said it had knocked trai.gov.in offline hours later; officials called the outage a technical glitch. A million citizens who had written to defend the open web had their addresses posted on a government site, eight years before the Digital Personal Data Protection Act attached statutory duties to such handling (what the DPDP Act requires). The rest went the campaigners' way. On 8 February 2016 TRAI's Prohibition of Discriminatory Tariffs for Data Services regulation banned differential pricing outright (February 2016), ending Airtel Zero and Facebook's Free Basics together; the Telecom Commission, the Department of Telecommunications' decision-making body, approved full net-neutrality rules on 11 July 2018.

AI Tech desk · April 2015

Four APIs and an age-guessing demo

Microsoft's Build conference ran from 29 April to 1 May 2015 at Moscone West in San Francisco, and on its second day it put machine learning behind a web address. Project Oxford arrived as a free public beta — face detection and recognition, speech-to-text and text-to-speech, computer vision with optical character recognition, and a language-understanding service — capped at five thousand calls a month. Two Microsoft engineers, Corom Thompson and Santosh Balasubramanian, had assembled a demonstration in about a day; they sent how-old.net to a couple of hundred people for feedback, and within hours tens of thousands of strangers were feeding it photographs, many of them to argue with the answers. The month had run that way twice already: Amazon announced its Machine Learning service at an AWS summit on 9 April, wizards in place of algorithms, and IBM opened a Watson Health unit on 13 April with Apple, Johnson & Johnson and Medtronic attached. Oxford became Cognitive Services in March 2016; Amazon's service was retired in favour of SageMaker, and IBM sold Watson Health's assets in 2022.

Digital Guard desk · April 2015

Signed, or it does not run

At the RSA Conference in San Francisco, held from 20 to 24 April 2015, Microsoft set out Device Guard for the still-unreleased Windows 10: an administrator could lock a machine to code signed by a vendor Microsoft vouched for, by the Windows Store or by the organisation itself, with the decision taken inside a hardware-isolated instance of Windows that applications could not reach. Scott Charney presented it on 21 April; seven hardware makers were named in support. The arithmetic behind the turn to whitelisting had appeared a week earlier: Symantec's twentieth Internet Security Threat Report, published on 14 April, counted more than 317 million new pieces of malware in 2014, close to a million a day, and crypto-ransomware attacks up more than 4,000 per cent. The week's money went elsewhere. On 20 April Raytheon agreed to buy Websense from Vista Equity Partners for about $1.9 billion, folding in its own Cyber Products unit and selling Vista back a fifth of the result; the company took the name Forcepoint in January 2016 and passed to private equity in 2021.

⏳ Time capsule — April 2015

  • On 2 April the P5+1 and Iran announced a framework agreement on Iran's nuclear programme at Lausanne, leaving the hard terms to a 30 June deadline.
  • SpaceX launched its sixth resupply run to the space station on 14 April; the first stage reached the drone ship but came down with too much sideways speed and tipped over, a failure Elon Musk put down to a stuck bipropellant valve.
  • The Apple Watch, open for pre-order from 10 April, began reaching buyers on 24 April; it did not reach India until November.
  • An earthquake of magnitude 7.8 struck Nepal at 11:56 local time on 25 April, about 85 km north-west of Kathmandu, killing 8,962 people across the region, 78 of them in India, which sent relief under the name Operation Maitri.
Where it stands today — 2026

The mask, and what it became

A decade on, April 2015 reads as the month the false flag stopped being a curiosity. TV5Monde was attacked behind a jihadist banner in a country still counting its dead from January, and the banner was wrong; the correction took two months, several firms and a national agency, and was hedged even when it arrived. The same technique came back in cleaner form at the Pyeongchang Olympics, where the malware carried borrowed code that pointed at North Korea (February 2018), and in the persona built to muddy the DNC attribution (June 2016). What has changed since is who does the correcting: attribution moved from research firms hedging in press reports to governments naming units and grand juries naming officers.

The other April stories all have endings. The intrusion found at the US personnel agency on 15 April became June's disclosure and the decade's most durable espionage haul (June 2015) — background files do not expire, and neither do fingerprints. The plane affair produced no charges and no evidence that a cockpit was ever reached from a seat, but it settled the etiquette of aviation research: not on a live flight, and not on Twitter. And the million emails India sent its regulator that April became a regulation in 2016 and rules in 2018, and then a habit — a public that expects to be consulted on how its network is priced and, since the Digital Personal Data Protection Act, on how its own address is handled (the DPDP Act, explained).