The attack began overnight on Saturday 5 November 2016 — Bonfire Night — and the first that Tesco Bank's customers knew of it was a text message. Those who checked found the money already gone: card payments they had never made, most of them appearing to have happened in Brazil. Many spent the weekend on hold. By Sunday the bank was saying that about 40,000 current accounts had seen suspicious transactions and that money had actually left roughly half of them; on the Monday its chief executive, Benny Higgins, repeated those figures on BBC radio and confirmed that online transactions from current accounts had been frozen, while cards still worked in shops and cash machines. Andrew Bailey, then head of the Financial Conduct Authority, told MPs the attack looked unprecedented in Britain.

On Tuesday 8 November the numbers came down. Tesco Bank now said money had gone from 9,000 accounts, that £2.5 million had been refunded and that no customer would be left out of pocket; the block on online debit transactions was lifted within days. What it would not say was how. The bank held roughly 136,000 personal current accounts, and nothing it announced explained why some had been robbed and not the rest. The National Crime Agency and the month-old National Cyber Security Centre opened an investigation that has never, on the public record, produced an arrest. Speculation filled the space — a stolen customer database, a rogue insider, a flaw in the website — and the regulator's eventual account matched none of it.

That account arrived on 1 October 2018, in the FCA's final notice, and it began by removing the burglary: nobody had got inside Tesco Bank. The attackers had most likely run an algorithm producing genuine Tesco Bank debit card numbers, built virtual cards from them and pushed thousands of contactless magnetic-stripe transactions through a channel the bank never used and never thought to block — most of them coded to Brazil. Visa had warned its members about that exact pattern in Brazil and the United States; Tesco Bank blocked it on its credit cards and left its debit cards alone. When the alarm sounded, the financial crime team emailed a shared inbox instead of telephoning the on-call fraud analyst, as procedure required; 21 hours passed before the two teams spoke.

The rule eventually written to stop the payments carried the euro's currency code in the field where Brazil's country code belonged. The bank still blocked most of what was attempted, which is why the final figures were smaller than the first: £2.26 million taken from 8,261 accounts over 48 hours. The FCA fined it £16.4 million — about £33.5 million before credit for refunding customers and a settlement discount — and Mark Steward, its enforcement director, said the regulator had "no tolerance for banks that fail to protect customers from foreseeable risks". The thieves were never identified; nobody has been charged. The bank robbed that weekend no longer exists in the same form: mortgages to Lloyds in 2019, current accounts closed in 2021, cards and savings to Barclays on 1 November 2024.

Also that month · 25–29 November

Free rides on Market Street

On Friday 25 November the agent screens at San Francisco's Muni Metro stations stopped showing fares and showed a sentence instead — "You Hacked, ALL Data Encrypted" — with an address to write to. The Municipal Transportation Agency switched off its ticket machines and fare gates and left them off until nine on Sunday morning, so the light rail ran free across the Thanksgiving weekend; no train stopped and no signal failed. Writing to reporters as Andy Saolis, the attacker claimed 2,112 machines encrypted and demanded 100 bitcoin, about $73,000. The agency's own account, published on the Monday, was narrower: roughly 900 office computers locked — the agency never named the malware, and it was researchers who identified HDDCryptor, the full-disk encryptor also known as Mamba — payment systems untouched and no data taken from its servers; most machines restored from backups by Saturday morning; a ransom it said it had never considered paying. The next day Brian Krebs reported that a researcher had got into the attacker's mailbox. Inside were the receipts — roughly $140,000 in bitcoin since August, mostly from American manufacturing and construction firms whose Oracle servers he had found by scanning — and logins pointing to Iran.

Also that month · 27–28 November

The routers that crashed instead

At about five on the evening of Sunday 27 November, home routers across Germany began falling off the network, and because Deutsche Telekom's Speedport boxes carried the telephone and the television as well as the internet, some 900,000 households lost all three at once. The company told customers to pull the plug and restart, pushed new firmware, and watched the outage thin out through Monday. The cause was a Mirai variant knocking on port 7547 — the port the routers kept open so the operator could manage them from outside — with a request borrowed from the older TR-064 configuration protocol, its time-server field carrying a command telling the device to fetch and run a bot. The Speedports could not run it. Under the sheer volume of attempts they froze rather than enlisted, which is why Deutsche Telekom called the attack a failed one, and why an attempted takeover surfaced as an outage instead. Scans that week put roughly five million devices worldwide within reach of the same flaw — five weeks after Mirai had taken down Dyn from a different set of things nobody called computers.

India desk · November 2016

Cash to card, overnight

At a quarter past eight on the evening of 8 November the prime minister appeared on television unannounced to say that the ₹500 and ₹1,000 notes — about 86 per cent of the currency in circulation by value — would stop being legal tender at midnight. A cash economy went onto cards and phones in a single night. Cash machines closed for two days and reopened rationing ₹2,000 a day; the queues outside the branches became the image of that winter, and newspapers counted deaths among those standing in them, while the government later said it held no such record. Paytm's full-page advertisements the next morning carried the prime minister's photograph; the company claimed traffic up 435 per cent and downloads up 200 per cent — its own numbers, from its best fortnight.

Fraud followed the money. A WhatsApp message insisted the new ₹2,000 note held a nano-GPS chip trackable by satellite, and the Reserve Bank had to say no such technology existed. Then came the calls: strangers offering to exchange old notes or fix a wallet, asking for card numbers and one-time passcodes — a pattern that would acquire the name KYC fraud only after the wallet rules of 2017. On the evening of 30 November the Twitter account of Rahul Gandhi, the Congress vice-president, began posting abuse about demonetisation and his family, its display name altered to an insult; a group calling itself Legion claimed it and promised the party's emails next. The Congress account followed the next morning; December's edition carries the rest. Years later a Bengaluru chargesheet in an unrelated bitcoin case named a hacker, Srikrishna Ramesh, as the man who reset the password — an allegation, never tested at trial.

AI Tech desk · November 2016

Amazon puts deep learning on the price list

On 30 November, at re:Invent in Las Vegas, Andy Jassy announced Amazon's first three machine-learning services: Rekognition, which labelled objects, scenes and faces in photographs; Polly, which read text aloud in 47 voices and 24 languages and was priced by the character; and Lex, Alexa's speech-recognition and language-understanding layer, in preview for building bots. Deep learning had become a utility, ordered like storage. Rekognition stayed in the news: in July 2018 the ACLU ran Congress's portraits against a mugshot database and it matched 28 members — a test Amazon said used too low a confidence threshold — and in June 2020 the company suspended police use of it for a year. Two weeks earlier, on 15 November, Microsoft's Harry Shum had announced that OpenAI, then a small non-profit, would make Azure its main cloud — little noticed then, the decade's defining AI alliance since. The same day Google moved Translate onto neural networks for eight languages, and on the 22nd its researchers showed a single model translating Korean into Japanese without ever having been trained on the pair.

Digital Guard desk · November 2016

Kaspersky takes Windows Defender to the regulator

On 10 November Eugene Kaspersky published a post titled "That's It. I've Had Enough!", and the same day Russia's Federal Antimonopoly Service opened a case against Microsoft on his company's complaint. The grievance was that Windows 10 pushed users off third-party anti-virus: an upgrade could switch it off and enable Windows Defender instead, lapsed-licence warnings were buried among Windows notifications, and — the regulator's own emphasis — developers once given two months to make a product compatible with a new build now got six days. Microsoft said it kept within competition law and had yet to see the papers. Kaspersky repeated the complaint to the European Commission and Germany's Federal Cartel Office on 6 June 2017, and on 10 August announced it was withdrawing all three once Microsoft had promised vendors more testing time and their own expiry notices in the Fall Creators Update. On 20 November Symantec agreed to buy LifeLock for $24 a share, a $2.3 billion enterprise value: the identity-protection turn that became the company's name, NortonLifeLock, once Broadcom had taken its enterprise business in November 2019.

⏳ Time capsule — November 2016

  • On the night of 2 November, in a Game 7 that ended after midnight, the Chicago Cubs won the World Series for the first time since 1908, beating Cleveland 8–7 in ten innings interrupted by a seventeen-minute rain delay — having trailed the series 3–1.
  • Donald Trump was elected the 45th president of the United States on 8 November, carrying the Electoral College while trailing Hillary Clinton by about 2.9 million votes nationally; the result was called in the early hours of the 9th.
  • Leonard Cohen's death was announced on 10 November; he had died on the 7th, aged 82, seventeen days after releasing You Want It Darker.
  • India beat England by 246 runs at Visakhapatnam on 21 November, Virat Kohli making 167 and 81 — the first win of a series India would take 4–0 by the end of the year.
Where it stands today — 2026

Foreseeable risks

Ten years on, the Tesco Bank weekend is the reference case for theft by arithmetic: a bank emptied through its own card design, nobody inside the walls. The 2018 notice — a warning acted on for credit cards and not debit, a rule typed into the wrong field, a response that ran on a mis-sent email — is now a set text in operational resilience. Britain's other November case was the ordinary kind: the Three UK upgrade database, confirmed on the 18th, was opened with an employee's credentials, first reports of millions at risk narrowing to the 133,827 accounts Three named that day — a count it raised by a further 76,373 in March 2017, to about 210,000 — and three arrests. The month's largest number, 412 million FriendFinder Networks accounts counted by LeakedSource on 13 November, held the year's record barely a month, until Yahoo disclosed a billion in December.

The routers are the longest thread. Earlier that month the man behind the German outage had aimed Mirai at Liberia's Lonestar Cell MTN, and the took-a-country-offline headlines of 3 and 4 November were contested by Dyn's Doug Madory and Liberia's cable consortium, neither of whom could find a national outage in their data; Daniel Kaye's arrest at Luton airport the following February is told in the January 2017 edition, and port 7547 fed the case for the device-security laws Britain and the EU completed in 2024. San Francisco's free weekend was the mildest preview of what ransomware would do to public bodies; Atlanta in 2018 and Baltimore in 2019 lost months, not a holiday. India's migration onto phones runs on, and the winter's polite calls asking for a passcode are the ancestors of today's digital arrest.