At lunchtime on Wednesday 21 October 2015 TalkTalk took its websites down. The next day the company told its four million customers that it had suffered a significant and sustained attack, that it was working with the Metropolitan Police, and that names, addresses, dates of birth, phone numbers, email addresses, account details and bank or card information might have been taken. Its chief executive, Dido Harding, then gave a run of interviews in which she was asked, repeatedly, whether the data had been encrypted, and could not say; more than one interviewer pointed out that she had had hours to find out. She could not say how many customers were affected either, so the number that travelled was the whole base. Up to four million, the headlines said.
The mechanism, as the Information Commissioner's Office later reconstructed it, was old. The intrusion ran from 15 to 21 October through three web pages inherited with Tiscali's British business in 2009, whose database software carried a bug for which a fix had been available for three and a half years, and never applied. The same pages had been opened the same way on 17 July and again on 2 and 3 September; nobody acted, because nobody was monitoring them. A demand for about £80,000 in bitcoin reached the company. On the AlphaBay market a seller advertised what he said was the customer database — a claim TalkTalk never confirmed. On 6 November it published its count: 156,959 customers, 15,656 bank account numbers with sort codes, and about 28,000 card numbers obscured, it said, beyond use.
Arrests began within the week. On 26 October a boy of 15 was arrested; on 29 October a 16-year-old in west London; on 31 October a 20-year-old in Staffordshire; on 3 November a 16-year-old in Norwich; on 24 November Daniel Kelley. A company that could not say whether it encrypted had been opened by young men and boys using a technique older than some of them. At the Old Bailey on 19 November 2018, Judge Anuja Dhir jailed Matthew Hanley, 23, and Connor Allsopp, 21, both of Tamworth, for twelve months and eight; neither, she accepted, had exposed the vulnerability — others started it, and they joined in at different times. Kelley, who admitted eleven offences, was sentenced to four years on 10 June 2019.
In November Harding put the cost at £30 million to £35 million. On 2 February 2016 the company reported £60 million and 101,000 customers gone in the quarter, though nearly half a million had taken the free upgrade offered as an apology; £77 million is the figure read out at the Old Bailey three years later. On 5 October 2016 the ICO fined TalkTalk £400,000, the largest it had ever imposed against a ceiling of £500,000, and found that its failure to implement the most basic cyber security measures had let hackers in with ease. Elizabeth Denham called the fine a warning that cyber security was "not an IT issue, it is a boardroom issue". The number that mattered was never 156,959. It was four million, the one said first.
The channel to America, closed
On 6 October 2015 the Court of Justice of the European Union declared invalid the Commission's Safe Harbour decision of 2000, under which American companies self-certified that European data was adequately protected. The case, C-362/14, had begun with an Austrian law student. After the Snowden disclosures, Max Schrems complained to Ireland's Data Protection Commissioner that Facebook Ireland was sending his data to a country whose agencies could read it; the Commissioner rejected the complaint as frivolous and vexatious, with no case to answer. Mr Justice Hogan of the Irish High Court held on 18 June 2014 that the question had to go to Luxembourg, and the reference was lodged that July. The court's answer was that legislation giving public authorities generalised access to the content of communications compromised the essence of the right to private life, that Europeans had no judicial remedy in America, and that no Commission decision could stop a national regulator examining a complaint. It took effect at once. Privacy Shield replaced the arrangement on 12 July 2016 and fell to the same complainant in Schrems II on 16 July 2020.
The people layer
On 1 October Experian disclosed a breach of a server holding two years of T-Mobile US credit applications: about 15 million names, addresses, dates of birth, Social Security and driving-licence numbers, though no payment data and, Experian said, nothing from its credit database. It had detected the intrusion on 15 September, just over two weeks before it went public; T-Mobile's John Legere said he was incredibly angry about it. On 13 October the FBI and Britain's National Crime Agency said they had sinkholed the command servers of the Dridex banking trojan, blamed for at least £20 million of British losses, and unsealed an indictment naming Andrey Ghinkul, a 30-year-old Moldovan arrested in Cyprus on 28 August. On 21 October WikiLeaks published the contents of CIA director John Brennan's personal AOL account, including his draft security-clearance form; the intruder, a self-described teenager, told the New York Post he had talked Verizon into disclosing account details and AOL into resetting the password. On 27 October the Senate passed the Cybersecurity Information Sharing Act, 74–21, over objections that it would pipe user data to the NSA; it became law inside December's spending bill.
Voluntary, and spreading
On Thursday 15 October 2015 a five-judge bench of the Supreme Court widened the uses of Aadhaar it would allow. On 11 August a three-judge bench had confined it to two schemes, subsidised grain and cooking gas. Now the rural employment guarantee, the National Social Assistance Programme's pensions for the old, widowed and disabled, the Jan Dhan bank accounts and the Employees' Provident Fund could use it too — on the condition, repeated from the order of 23 September 2013, that Aadhaar stay purely voluntary and nobody be refused a benefit for lacking it, until the constitutional challenge before the court was decided. The next morning the same court struck down the National Judicial Appointments Commission, four to one: a bench that would not let Parliament near the appointment of judges was content to let the world's largest identity database spread, provided it was called optional.
The question the order deferred took three more years. Parliament gave Aadhaar a statute in March 2016, as a money bill the upper house could not block; a nine-judge bench found a fundamental right to privacy on 24 August 2017; and on 26 September 2018 the court upheld the scheme for welfare and tax while striking out Section 57, which had let banks, schools and telecoms demand the number. What the bench did not examine that October was how the data would be held. CERT-In counted 49,455 security incidents across India in 2015, and the information technology ministry's later tally put close to 1,500 government websites hacked between January 2010 and December 2015. The law that would govern all this data waited until 2023.
Autopilot arrives, marked beta
Tesla began pushing software version 7.0 to Model S owners on the evening of 14 October 2015, and by the following morning the fleet had Autosteer, Auto Lane Change and Autopark. Elon Musk called the package a beta and advised drivers to keep their hands on the wheel; the cameras and radar it used had been fitted to every car built since October 2014. No driver-assistance system had been handed to an entire fleet overnight before, and the name survived the Florida crash of May 2016, which American regulators disclosed on 30 June 2016. Bloomberg reported on 26 October that a machine-learning system called RankBrain had been ranking a share of Google's searches since the spring, unannounced, and that the company placed it third among its signals, behind links and content. Apple bought VocalIQ of Cambridge and the image-recognition startup Perceptio in the first week, disclosing no terms. And from 5 to 9 October DeepMind's AlphaGo beat the European champion Fan Hui five games to nil, a result held back until Nature published it in January.
TippingPoint sold, Symantec put on notice
On 21 October 2015 Trend Micro agreed to pay about $300 million for TippingPoint, the intrusion-prevention business Hewlett-Packard had inherited from 3Com and was shedding eleven days before it split itself in two; the Zero Day Initiative went with it, and the sale closed in March 2016. A week later, on 28 October, Google set out what Symantec's certificate authority had to do to stay trusted in Chrome: a full account of the test certificates its Thawte unit issued for google.com, independent third-party audits, and Certificate Transparency logging on every certificate it issued from 1 June 2016, or Chrome would reject them. Google's reading of Symantec's own audit put the tally at 164 certificates over 76 domains and 2,458 for domains that had never been registered; Symantec said it was already accelerating its logging. Symantec sold it to DigiCert in August 2017. And on 29 October Fortinet, Intel Security, Palo Alto Networks and Symantec published together, as the Cyber Threat Alliance, an analysis associating CryptoWall 3.0 with more than $325 million in payments.
⏳ Time capsule — October 2015
- On 19 October Canada's Liberals under Justin Trudeau won 184 of the 338 seats in the House of Commons, ending Stephen Harper's nine years in office; Trudeau was sworn in on 4 November.
- On 21 October the world marked Back to the Future Day, the date Marty McFly reaches in the 1989 sequel: Nike unveiled self-lacing Mags, Pepsi's run of 6,500 Pepsi Perfect bottles sold out within minutes, more than 1,700 cinemas screened the trilogy back to back, and Reston, Virginia, renamed itself Hill Valley for the occasion.
- On 24 October India's Ministry of Defence announced that it had approved the induction of women into the fighter stream of the Indian Air Force, on an experimental basis; the first three were commissioned as fighter pilots in June 2016.
- On 31 October New Zealand beat Australia 34–17 at Twickenham before 80,125 people to win the Rugby World Cup — the first team to retain the Webb Ellis Cup and the first to win it three times; Dan Carter was man of the match and Richie McCaw lifted the trophy.
Four numbers, a decade on
A decade on, October 2015 reads as the month the cost of a breach was itemised in public. TalkTalk's numbers — four million, then 156,959; £35 million, then £60 million, then £77 million; 101,000 customers; a £400,000 fine — became the template, and the £500,000 ceiling it pressed against became four per cent of turnover when GDPR arrived in May 2018. The men who opened the door were jailed in November 2018 and June 2019. The teenager in the CIA director's inbox turned out to be Kane Gamble of Leicestershire, 15 when the campaign began that summer, given two years' youth detention in April 2018; two American accomplices got five years and two. The help-desk trick they used has never stopped working, from Las Vegas to the British high street.
The Luxembourg ruling has been re-argued ever since. Privacy Shield was adopted on 12 July 2016 and annulled on 16 July 2020; the Data Privacy Framework of 10 July 2023 rests on an executive order and a review court, and after the Supreme Court held this June in Trump v. Slaughter that the trade regulator's removal protections were unconstitutional, Schrems's group noyb called for it to be repealed too. Equifax followed Experian in September 2017; Dridex's operators, named as Evil Corp, were sanctioned in December 2019. And the number that was voluntary in October 2015 is the one Indians are asked for first: the 2018 verdict drew the line at private compulsion, and the DPDP Act wrote the rules for the data it unlocks.