At 23:53 on Saturday 17 December 2016, the remote terminal units that work the circuit breakers at Pivnichna — the 330-kilovolt transmission substation at Novi Petrivtsi, a village on the road north out of Kyiv — went off the network, and the breakers opened. The right bank of the capital lost power along with part of the surrounding region: about a fifth of Kyiv's consumption at that hour, the figure the acting head of the national transmission operator Ukrenergo, Vsevolod Kovalchuk, gave afterwards. Engineers drove out and brought the substation back by hand. Supply was restored in roughly an hour and a quarter, on a December night, in a country that had already lost its lights to malware the previous December. Nobody was hurt.

Ukrenergo said very little at first, and what it said was careful: hacker attack and equipment failure were both listed as possible causes, and equipment failure in mid-December cold was not a foolish theory. Kovalchuk did not stay neutral for long — he later told the American outlet Defense One that he was 99 per cent certain the outage had been deliberate — but that was one executive's confidence, not a company finding. The month around it made the confidence easy to share. On 6 December intruders had taken the finance ministry and the State Treasury offline for about two days and destroyed databases, holding up payments the government valued in hundreds of millions of hryvnia. This archive's January 2016 edition describes what the previous sequence, on 23 December 2015, had looked like.

Confirmation arrived slowly, and the dates are worth keeping apart. The outage was on 17 December; Ukrenergo's public statement that its workstations and SCADA servers had been disrupted by external influences, in what the investigation described as a planned and layered intrusion, came in the middle of January 2017, after outside investigators had been brought in and the forensics had run. What the intruders had actually used — malware that spoke the substation's own control protocols, so that opening a breaker needed no stolen operator session and no hand on any switch — was not published until ESET and Dragos released their analyses in June 2017, and the June 2017 edition carries that story. Through December, everyone outside the investigation had the same three facts: shorter than last time, quieter than last time, unexplained.

The ending is on the record. In October 2020 a federal grand jury in Pittsburgh indicted six officers of the Russian military intelligence unit numbered 74455 — the same six charged over NotPetya — and the government's narrative opened with destructive attacks on Ukraine's power grid, its Ministry of Finance and its State Treasury across December 2015 and December 2016 (October 2020). None of the six has been arrested; all remain on the FBI's wanted list. In April 2022, six weeks into the full-scale invasion, an updated build of the same malware was found on a Ukrainian energy company's network and stopped before it fired (April 2022). Kyiv has gone dark many times since. Almost none of it has been the work of code.

Also that month · Disclosed 14 December

A billion, and not the same billion

On 14 December Yahoo's security chief, Bob Lord, disclosed a second and older theft: in August 2013 an unauthorised third party had taken data associated with more than one billion accounts. It was separate from the 500 million admitted on 22 September (September 2016), and Yahoo had not found it — in November, law enforcement had handed it files an outside party claimed were Yahoo user data, which forensic experts confirmed. The records held names, email addresses, telephone numbers, dates of birth, passwords hashed with the obsolete MD5 algorithm and, in some cases, unencrypted security answers. Yahoo said it had never been able to identify the intrusion itself. The same notice carried a separate finding: someone had studied Yahoo's proprietary code and learned to forge the cookies that keep a browser signed in, entering accounts with no password at all. Verizon, which had agreed in July to buy the operating business for $4.83 billion, cut $350 million from it on 21 February 2017. Six days earlier, ThyssenKrupp had disclosed a theft of engineering know-how detected in April and traced to February, held back, it said, so the intruder would not learn he had been seen.

Also that month · 29–31 December

The laptop that was not the grid

On 29 December the Obama administration answered the year's election intrusions with thirty-five expulsions, two closed Russian-owned compounds and sanctions naming the GRU, the FSB, four GRU officers and three companies. DHS and the FBI published a joint analysis report under the codename GRIZZLY STEPPE. Moscow denied the intrusions throughout, and on 30 December Vladimir Putin declined to expel American diplomats in reply. Defenders who ran its indicators found many were Tor exit nodes and shared hosting, useful for finding nothing in particular, and said so within days. Utilities scanned anyway, and on the evening of 30 December The Washington Post reported that Russian hackers had penetrated the American grid through a Vermont utility. Burlington Electric answered within about ninety minutes: the code was on one laptop, not connected to grid systems. The paper rewrote the headline, appended an editor's note conceding that an earlier version had incorrectly said the grid was penetrated, and reported on 2 January that the alert had been tripped by an employee checking Yahoo mail, the software an ordinary criminal toolkit. The month's genuinely actionable warning drew a fraction of the attention: on 9 December CERT/CC had advised owners of two popular Netgear routers to stop using them until a fix existed. Checking a grid story before printing it is a lesson this archive returns to in October 2018.

India desk · December 2016

Legion's fortnight, and a lottery against cash

Legion's run carried on from November. On 9 December the group took Vijay Mallya's Twitter account and posted what it said were the businessman's financial details; on 11 December it took the accounts of the NDTV journalists Barkha Dutt and Ravish Kumar and put roughly a gigabyte of material said to be their email online. The interviews were larger than the dumps. Speaking to the Washington Post and to the site FactorDaily, Legion claimed access to Indian email servers, to Apollo Hospitals and to encryption keys used by Indian banks, and promised to publish the mail of sansad.nic.in, parliament's own domain. That dump never came, and none of the wider claims was substantiated. What the fortnight established was mundane: the accounts fell through reused and compromised email rather than through Twitter itself, and the Delhi Police inquiry that opened after the first hack traced logins across five countries without naming anyone that winter.

The louder story was money: a month into demonetisation, the state had begun paying people to stop using cash. On 8 December the finance minister, Arun Jaitley, announced discounts for paying digitally — 0.75 per cent off fuel at public-sector pumps, half a per cent off suburban railway season tickets, ten per cent off electronic highway tolls. On 15 December NITI Aayog announced two lotteries, Lucky Grahak Yojana and Digi-Dhan Vyapar Yojana: ₹1,000 each to 15,000 consumers a day for a hundred days, prizes for merchants, the first draw on Christmas Day. Electronic transaction volumes rose by something over two-fifths between November and December on the Reserve Bank's provisional figures, then fell back in the new year. Banks and police cyber cells spent the same weeks warning about phishing dressed as wallet alerts and fake customer-care numbers.

AI Tech desk · December 2016

Universe, Amazon Go and sixteen revoked registrations

OpenAI released Universe on 5 December 2016, letting a learning agent use a computer as a person does, from screen pixels, across Atari titles, a thousand Flash games and browser tasks; it was deprecated within eighteen months. The same day Amazon unveiled Amazon Go, a Seattle grocery where cameras and deep learning replaced the checkout, staff-only and promised to the public for early 2017; it admitted them in January 2018, the system left Amazon's supermarkets in 2024 amid disputed reports that reviewers in India checked many transactions, and in January 2026 Amazon said the Go shops would close. Uber began self-driving pickups in San Francisco on 14 December without a state permit; a car ran a red light that day, Uber blamed the safety driver — its documents later said otherwise — and on 21 December the DMV revoked sixteen registrations, so the cars went to Arizona, where one killed a pedestrian in March 2018. Apple's first AI paper, on refining synthetic images with adversarial training, appeared on 22 December and won a best-paper award at CVPR in July.

Digital Guard desk · December 2016

Malwarebytes 3.0, and Alice at the cash machine

Malwarebytes shipped version 3.0 on 8 December 2016, folding its anti-malware, anti-exploit and anti-ransomware engines and web protection into one $39.99-a-year product, and its chief executive, Marcin Kleczynski, said customers could finally replace their traditional antivirus; more than half, by his count, already ran nothing else. It still promised to coexist with third-party antivirus, and the first build was rough enough — false warnings that protection was off — to need fixes before Christmas and in January. On 20 December Trend Micro described Alice, ATM malware found in November with Europol's EC3: one stripped-down component, loaded through a USB or CD-ROM port and unlocked with a code, that did nothing but empty the cassettes — a cruder route to the money than the switch-side compromise behind India's card recall in October 2016 — and dating from 2014. On 15 December Bitdefender, Check Point, Emsisoft and Trend Micro joined No More Ransom, adding decryptors to the eight already free. The replacement pitch became the industry's standard framing within a few years; Alice-style jackpotting reached American cash machines in January 2018.

⏳ Time capsule — December 2016

  • J. Jayalalithaa, chief minister of Tamil Nadu, died in Chennai on 5 December after a cardiac arrest, having been in hospital since 22 September; she was buried on Marina Beach the following day.
  • Bob Dylan stayed away from the Nobel ceremony in Stockholm on 10 December; Patti Smith sang A Hard Rain's A-Gonna Fall in his place, lost the words in the second verse, apologised for her nerves and began the passage again.
  • Rogue One: A Star Wars Story opened in American cinemas on 16 December, the first live-action Star Wars film outside the numbered saga, and went on to take more than a billion dollars worldwide.
  • India declared on 759 for 7 at Chennai on 19 December with Karun Nair unbeaten on 303 — his third Test, and only the second triple century by an Indian — and won by an innings the next day to take the series 4–0.
Where it stands today — 2026

What the hour was for

A decade on, the seventy-five minutes at Pivnichna are read as a rehearsal, and the reading has hardened since. In August 2019 Joe Slowik of Dragos reassessed the event and argued that the blackout had not been the objective at all: the malware also carried a component aimed at Siemens protective relays, and on his account the intent was to leave those relays deaf, so that restoring power would break the equipment rather than save it. That is Dragos's assessment, offered three years after the fact and not an established finding, but it changed how the industry reads a short outage. On that reading the attempt failed on details: packets sent to addresses that did not answer, and operators who had the substation back faster than anyone planned for.

The other threads ran out to their ends. The names came in October 2020; the sequel in April 2022, weeks after the same service put wipers into Ukrainian networks in the hours before the tanks — and then artillery made the argument about code academic. Yahoo's billion became all three billion of its accounts in October 2017, and then a $35 million penalty from American regulators for the years of silence; the August 2013 intrusion has never been publicly pinned on anyone. In India, Legion's fortnight did more for two-factor authentication among the famous than any advisory, and December's incentives opened a payments-fraud economy the India desk still covers. The archive's 2017 opens in January, with unlocked databases and a new payments app.