The first note was found on 27 December 2016. Victor Gevers, a Dutch researcher who spends his holidays reporting exposed systems for the volunteer GDI Foundation, went looking for open MongoDB databases and found one that was no longer merely open: its contents were gone, replaced by a database named WARNING that held a single record. The record told the owner to send 0.2 bitcoin — about two hundred dollars that week — to an address and to email proof, and the data would come back. Within a week Gevers had counted nearly two hundred servers in the same state, and he spent the turn of the year notifying their owners one at a time.
Then came the pile-on. Gevers and a Norway-based colleague, Niall Merrigan, kept the tally in a public spreadsheet, and in the second week of January it stopped being countable by hand: about 2,000 hijacked databases on 3 January, more than 10,000 by the 6th, past 27,000 after a single weekend, and roughly 33,000 by 11 January — more than half of every MongoDB instance reachable from the open internet, by the estimates then in circulation. At least five groups were working the same territory within days, one demanding a full bitcoin, and they overwrote one another's ransom notes as they went. A victim reading a note could not know whether its author held their data, another gang did, or nobody at all.
The doors had been left open by default. Older MongoDB packages commonly started life listening on every network interface with authentication switched off, so the erased databases required no exploit — only an address, and Shodan had been indexing the addresses for years; its founder had counted about 30,000 exposed instances holding some 600 terabytes back in July 2015. Server logs told the uglier half of the story: most attackers never copied what they deleted. The kidnapping was a bluff; the destruction was real. Researchers counted just eleven payments to the first wave's bitcoin address by 3 January. By mid-month the same treatment had reached Elasticsearch clusters, then Hadoop and CouchDB installations, where some raiders skipped the ransom entirely and left behind a directory named NODATA4U_SECUREYOURSHIT.
MongoDB's makers noted, correctly, that authentication had been available all along, and published a hardening checklist in the first week of January; the durable fix arrived in December 2017, when version 3.6 shipped listening only to the machine it ran on unless deliberately opened. The month restated the lesson in a courtroom, too: on 5 January the US Federal Trade Commission sued D-Link in San Francisco over routers and cameras marketed as secure while shipping with hard-coded credentials, a case settled in 2019 with a decade of independent audits. The gangs returned to MongoDB that September and ransacked some 26,000 more. Nothing in January required brilliance — a port scanner, a list of addresses, and the patience to work through it.
The bank that fought in silence
For three days from 11 January 2017, customers of Lloyds, Halifax and Bank of Scotland found online banking intermittently unreachable — pages that loaded, then did not, then did. Cash machines and cards kept working; the group said almost nothing in public while its engineers fought the traffic, and confirmed only later that it had been resisting a denial-of-service attack rather than suffering an outage. No accounts were breached and no money was reported lost. Behind the scenes an emailed demand had arrived, offering to call off the attack and supply a list of the bank's weaknesses for roughly £75,000 in bitcoin; it went unpaid. The National Crime Agency later linked the attacks to Daniel Kaye, a Briton arrested at Luton airport that February on a German warrant for knocking about 900,000 Deutsche Telekom routers offline. Extradited back from Germany and charged over the bank attacks, he never stood trial for them — prosecutors dropped those charges — and in January 2019 he went to prison for 32 months for an older commission: being paid a retainer of up to $10,000 a month to flatten Liberia's largest mobile operator on behalf of a business rival.
The library that said no
On 19 January 2017 the St. Louis Public Library found roughly 700 computers across its central building and sixteen branches locked by ransomware, with a demand of about $35,000 in bitcoin to unlock them. The attack froze the circulation system — books could be neither borrowed nor returned — and darkened the public terminals, which in St. Louis mattered more than it sounds; a spokeswoman put it plainly to CNN: "For many of our patrons, we're their only access to the internet." The library said no reader or staff data had been taken — it stored no card numbers — called in the FBI, and declined to pay. Technicians wiped the affected servers and rebuilt them from backups; checkouts resumed within days, every branch was lending by that weekend, and the public machines followed as each was reimaged. As a parable it was the cover story inverted. The difference between a database you can restore and one you can only ransom back is a backup, and the library had one.
A New Year's defacement, and a gold rush
India's year opened with a defacement. In the first hours of 1 January 2017, the public website of the National Security Guard — the black-uniformed counter-terror force raised in the 1980s — stopped showing its own homepage and began showing an expletive-laden message aimed at the prime minister, "Free Kashmir" slogans and references to Pakistan's intelligence service. The intruders signed themselves Alone Injector; investigators pointed across the border, and nsg.gov.in was pulled offline the same morning while government technicians examined how its content had been swapped. A brochure site carries no operational secrets, and no NSG systems were reported touched, but the target was the point: someone had chosen the country's hostage-rescue force for a New Year's greeting, and the greeting stayed up long enough to be screenshotted.
The louder story was a gold rush. Seven weeks after the 8 November 2016 demonetisation of the ₹500 and ₹1,000 notes, the government was moving the country onto digital payments at speed: the BHIM app, launched by the prime minister on 30 December, was downloaded some three million times in its first few days and passed ten million downloads within its first fortnight. The fraud economy moved just as fast. Within days, reporters and researchers counted more than three dozen lookalike BHIM apps on Google's Play store, some downloaded thousands of times before removal, and the newspapers filled with warnings about phishing pages dressed as wallets and banks. Official figures said monthly digital transactions had risen by more than two-fifths between November and December 2016; nobody published a matching curve for the new fraud, but every later year of this archive records where that curve went.
The month the machines learned to bluff
For twenty days ending on 30 January 2017, four professional poker players sat at Rivers Casino in Pittsburgh and lost, slowly and then decisively, to Libratus, an artificial intelligence built by Carnegie Mellon's Tuomas Sandholm and his doctoral student Noam Brown. Across 120,000 hands of heads-up no-limit Texas hold'em against Dong Kim, Jimmy Chou, Daniel McAulay and Jason Les, the machine finished $1,766,250 ahead in chips, a margin its builders called statistically significant rather than luck. Chess and Go were games of perfect information; poker is hidden cards and bluff, and it fell anyway — nor did it fall alone, because on 6 January a University of Alberta team with Czech collaborators had posted the DeepStack paper, claiming victories over eleven professionals in matches played that winter, work Science published in March. The same week's CES wired Amazon's Alexa into Ford dashboards, an LG refrigerator and Huawei's Mate 9. Brown went on to crack six-handed poker, and later to help build the reasoning models of the mid-2020s.
A router from Norton, an arrest in Moscow
The industry's January had two faces. In Las Vegas on 3 January 2017, Norton announced its first hardware: the Norton Core, a geodesic dome of a Wi-Fi router that turned Symantec's threat intelligence on the home network itself, scanning traffic and quarantining compromised smart devices onto a separate network — attempted attacks on such devices had doubled during 2016, by the company's own count. Priced at $199.99 for early orders against a $279.99 list and due that summer, it never found its market: leaning on a subscription and selling poorly, the Core was discontinued on 31 January 2019, two years after its CES debut. In Moscow the month ended darker. On 25 January the newspaper Kommersant revealed that Ruslan Stoyanov, head of Kaspersky Lab's computer-incidents investigation team, had been quietly arrested weeks earlier on treason charges, alongside senior officers of the FSB's own cyber unit. Kaspersky said the case predated his employment; a closed military court later sentenced him to fourteen years, an early tremor of the geopolitics that would end with the company's software banned from American sale.
⏳ Time capsule — January 2017
- Donald Trump was sworn in as the 45th president of the United States on 20 January; the Women's March the next day drew crowds estimated in the millions across American cities and around the world.
- La La Land won all seven Golden Globes it was nominated for on 8 January — still the most by one film in a single night.
- Serena Williams beat her sister Venus in the Australian Open final on 28 January for a 23rd Grand Slam singles title, an Open-era record; a day later Roger Federer, 35 and six months out injured, beat Rafael Nadal in five sets for his 18th.
- Bitcoin began the year above $1,000 for the first time since 2013, then gave up nearly a third of its value within days when China's central bank began inspecting exchanges.
Closed by default
Nine years on, the January 2017 ransacking reads like the opening chapter of a book the industry is still writing. The immediate fix held: MongoDB has listened only to its own machine out of the box since the end of 2017, and secure-by-default became first a slogan, then a procurement requirement, and by the mid-2020s the explicit demand of Western cyber agencies. The pattern simply climbed a layer. The half-decade that followed belonged to the open S3 bucket and the unsecured Elasticsearch cluster — the same absent password, now holding other people's records by the hundred million, as the September 2019 edition records for very nearly an entire country.
The other stories aged just as legibly. St. Louis's refusal — backups, a wiped fleet, not a dollar paid — became the standard advice of the ransomware decade, easier to give than to follow at scale; four months after this edition's events, WannaCry made the point across 150 countries in three days. Daniel Kaye's rented firepower announced the Mirai era that runs through the botnet stories of 2018 and beyond, and the FTC's D-Link case closed in 2019 with a decade of audits, an early marker on the road to real device-security law. The Vault now reaches back past this edition into 2016 — the year of the Bangladesh Bank heist, the DNC intrusion and Mirai's attack on Dyn — and the archive runs forward from those pages, month by month, to the present.