John Podesta was sixty-seven that spring, chairman of Hillary Clinton's presidential campaign after a career that had run through two White Houses. At 4:34 on the morning of 19 March 2016 his personal Gmail account received a message headed "Someone has your password". It greeted him by first name, reported that someone had just used his password to try to sign in, supplied a timestamp and an internet address in Ukraine, and offered a button to change the password. The typography was Google's. The link beneath it was a shortened Bitly address pointing somewhere else entirely. The message went to his chief of staff, Sara Latham, and from her to the campaign's technology helpdesk — which was exactly what was supposed to happen.

The reply came back from a helpdesk staffer named Charles Delavan. The email was legitimate, he wrote; John needed to change his password immediately and make sure two-factor authentication was switched on. He had meant to type illegitimate. Two letters, as he told the New York Times that December — a mistake he said he had not forgiven himself for. He had also pasted the genuine Google password-change address into his answer. Whoever acted on the advice used the link from the forged message instead, and entered the account's password on a page that belonged to nobody at Google. Ten years of correspondence went out the door.

Nothing visible followed, and the three dates that matter here are not the same date. The mailbox was emptied in the spring. Through the summer, researchers at SecureWorks mapped the link-shortening account behind the message — it had been left public, and it held thousands of similar links aimed at campaign staff, Russian journalists and defence figures. The campaign learned the extent of the loss only when other people began reading it, and that was 7 October 2016: roughly half an hour after the Washington Post published the Access Hollywood recording, and on the same day the Department of Homeland Security and the Director of National Intelligence jointly named Russia over the intrusions into political organisations, WikiLeaks put out the first tranche. Instalments followed almost daily until the election.

On 13 July 2018 a federal grand jury in Washington indicted twelve officers of Russia's military intelligence service, and the charge sheet recorded this month in flat prosecutorial prose: on or about 19 March 2016, officers of Unit 26165 sent a spearphishing email to the chairman of the Clinton campaign and took more than fifty thousand of his emails. Moscow denied it then and denies it now; none of the twelve has been arrested, and no court has tested the allegations. What the record leaves behind is smaller and harder than any of it. The advice in the helpdesk reply was correct — change the password, turn on two-factor authentication — and the second half of it was never done. The intrusion that mattered most in 2016 required no vulnerability at all.

Also that month · 18 and 28 March

The month the wards went back to paper

Methodist Hospital in Henderson, Kentucky, a not-for-profit community hospital on the Ohio river, spent the weekend of 18 March 2016 under a website notice declaring an internal state of emergency caused by a computer virus. The strain was Locky, identified by the hospital's information systems director, Jamie Reid; the family was then travelling behind invoice attachments. The demand was four bitcoin, about $1,600. Staff shut down every desktop, scanned them back one at a time, worked on paper for the best part of a week; the hospital said it paid nothing and lost no patient data. Ten days later the scale changed. On 28 March, MedStar Health — ten hospitals and some 250 outpatient centres across Maryland and Washington — took its email and clinical records offline and went to handwriting. Samas, or SamSam, needed nobody to click: it hunted out-of-date JBoss application servers and used the JexBoss tool to obtain a shell. A ransom note obtained by the Baltimore Sun asked three bitcoin a machine, or forty-five for the lot — about $18,500. MedStar said it paid nothing and rebuilt from backups, and rejected reporting that it had left a years-old patch unapplied. In November 2018 the Justice Department charged two Iranian men with running SamSam; both remain fugitives.

Also that month · 28 March

The case that ended without a ruling

Apple had been ordered in February to write software defeating its own passcode protections on the San Bernardino gunman's iPhone 5C, had refused publicly, and a hearing was set for 22 March in Riverside, California. The day before, the government asked for it to be vacated: an outside party had offered a possible method. On 28 March — the same Monday MedStar's screens went dark — prosecutors moved to withdraw the application, saying they had accessed the data without Apple's help. At a London event on 21 April the FBI director, James Comey, was asked what the method cost and said it was more than he would earn in the seven years and four months left to him — above $1.3 million, by public salary figures. It worked, he had said a fortnight earlier, only on the 5C and older handsets lacking a fingerprint sensor. Five years on, the Washington Post named the supplier: Azimuth Security, a small Australian firm. The Bureau never confirmed a price; the $900,000 in circulation came from Senator Dianne Feinstein, in 2017. The phone, once opened, held nothing of investigative value. The constitutional question — whether a statute from 1789 can compel a company to build a tool against its own product — went unanswered.

India desk · March 2016

A law for the register

On 3 March 2016 the finance minister, Arun Jaitley, introduced the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Bill and certified it a money bill. The Lok Sabha passed it by voice vote on 11 March. The Rajya Sabha, where the government lacked the numbers, returned it with five recommendations on 16 March; the lower house rejected all five that evening, which a money bill entitles it to do. Assent followed on 25 March. After six years of enrolment — ten fingerprints, two iris scans and a photograph, taken in school halls and panchayat offices — on the authority of a 2009 executive notification and nothing more, the largest biometric register ever built finally had a statute behind it.

The objection was procedural, and that was the point. Article 110 confines a money bill to taxation and the public purse, and the certification removed the upper house from a law about identity, welfare and who may be refused a ration. Jairam Ramesh challenged it in court within weeks; the answer took until 26 September 2018, when the Act survived four to one — the section letting private companies demand the number struck down, the national-security disclosure power struck down as it stood, the money bill route upheld over a dissent calling the certification a fraud on the Constitution. Privacy had become a fundamental right the year before. The month's quieter Indian entry came on 1 March, when Proofpoint published Operation Transparent Tribe: spearphishing of Indian embassies in Riyadh and Astana on 11 February, watering holes aimed at military personnel, and a remote-access trojan named MSIL/Crimson, on infrastructure resolving to Pakistani addresses — the researchers' finding, not a government's, and answered publicly by neither.

AI Tech desk · March 2016

Sixteen Hours of Tay

On 23 March 2016 Microsoft's research and Bing teams put a chatbot named Tay on Twitter, aimed at Americans aged eighteen to twenty-four and built to learn from whoever talked to it. Users taught it to repeat abuse; within sixteen hours and more than 96,000 tweets it was suspended. Peter Lee, a corporate vice-president, apologised on 25 March: a coordinated attack had exploited a vulnerability, a "critical oversight" that stress-testing had not caught, while XiaoIce, its Chinese predecessor, had some forty million users. Tay woke by accident on 30 March; at Build that day Satya Nadella told developers it was "not up to this mark" and Microsoft was back to the drawing board, then announced the Bot Framework, Cognitive Services and "conversation as a platform". Google had put Cloud Machine Learning into alpha at GCP NEXT the day Tay launched, eight days after AlphaGo beat Lee Sedol four games to one. Ten years on, Tay reads as the first mass lesson that a deployed model's inputs are an attack surface — the ancestor of every prompt-injection story in this archive.

Digital Guard desk · March 2016

Defender Goes Post-Breach

On 1 March 2016 Terry Myerson, who ran Windows at Microsoft, announced Windows Defender Advanced Threat Protection: a "post-breach" service to detect, investigate and respond to attacks already inside, built from behavioural sensors in Windows 10, cloud analytics and what Microsoft called its intelligent security graph, fed by more than a billion Windows devices. It was already running on half a million endpoints with early adopters, was promised more broadly later in the year, and went on sale from 1 October inside the new Windows 10 Enterprise E5 subscription. The operating-system maker had entered endpoint detection and response — renamed since, it is now Microsoft Defender for Endpoint. On 9 March Trend Micro closed its $300 million purchase of TippingPoint from Hewlett Packard Enterprise, agreed the previous October, taking the Zero Day Initiative with it. On 4 March Palo Alto Networks found KeRanger, the first working Mac ransomware, inside a signed Transmission installer that waited three days before asking one bitcoin; Apple revoked the certificate. Cisco's Talos unit published SamSam's JBoss method on 23 March, five days before MedStar.

⏳ Time capsule — March 2016

  • Scott Kelly and Mikhail Kornienko landed in Kazakhstan on 2 March after 340 days aboard the International Space Station, then the longest single spaceflight by an American.
  • Barack Obama arrived in Havana on 20 March, the first sitting American president to set foot in Cuba in eighty-eight years — the last had been Calvin Coolidge, in 1928.
  • India beat Pakistan by six wickets at Eden Gardens on 19 March in the World Twenty20, Virat Kohli unbeaten on 55 on a pitch nobody else could score on.
  • Zaha Hadid died in Miami on 31 March, aged sixty-five, of a heart attack while being treated for bronchitis; she was the first woman to win the Pritzker Prize, in 2004, and had received the Royal Gold Medal in her own right that February.
Where it stands today — 2026

Two Letters

Ten years on, the March 2016 mailbox is the reference case for how cheap a decisive intrusion can be. There was no exploit, no zero-day, no poisoned update: a forged notice, a shortened link and a helpdesk answer typed in a hurry. Nearly every phishing-awareness deck written since runs on this story, and the instruction buried in the reply — turn on two-factor authentication — became the industry's most repeated sentence, then hardware keys, then passkeys, none of which existed as defaults at the time. Twelve officers stand named and none has stood trial. Few typos have been read as closely as Charles Delavan's, and he has never claimed it was anything other than his.

The other threads all ran. What began at Methodist and MedStar became the permanent condition of healthcare: SamSam's operators shut down a major American city's government in March 2018, and by the time crews took an Irish health service and an American fuel pipeline in the same month of 2021, hospitals had stopped calling it unprecedented. The Apple question was never answered: the government bought its way past it and left the law untouched, and it has been re-argued in every encryption fight since. The register India gave a statute that March grew into the identity layer beneath payments, welfare and phone connections, upheld with pieces cut out of it in 2018 and joined seven years later by a general data protection law. The mailbox surfaced that October.