By the afternoon of Tuesday 3 October 2017, Washington already had its breach story: Richard Smith, the former chief executive of Equifax, sat before a House committee apologising for a theft whose count had been revised only the day before, upward again, to 145.5 million people — a figure that would climb once more, to 147.9 million, by March 2018. Then Yahoo supplied the day's second correction. Its new owner, Verizon, said in a statement from its Oath division that the intrusion of August 2013 — disclosed in December 2016 as an attack on more than one billion accounts — had in fact touched every Yahoo account that existed at the time: about three billion. The company had obtained what it called new intelligence during the integration, and outside forensic experts, whom it declined to name, had concluded the theft spared nothing.

The stolen copy held names, email addresses, telephone numbers, dates of birth, passwords hashed with the obsolete MD5 algorithm and, for many accounts, security questions and answers, some stored unencrypted. It did not, the company said, include clear-text passwords, payment-card data or bank details, which lived in other systems. Three dates frame the story, and they are far apart: the theft itself happened in August 2013; Yahoo learned of it in November 2016, when law enforcement handed over files a third party had been offering around; the full count arrived on 3 October 2017, more than four years after the intrusion. Researchers at InfoArmor had said in 2016 that copies of the database were sold at least three times, at around $300,000 each — a claim never proven, and never dislodged either.

Three billion was more accounts than the internet of 2013 had users, and the gap is the point: the figure counted mailboxes, not people. It took in accounts opened once and abandoned, Flickr logins, fantasy-league registrations and the co-branded addresses of partner telecoms whose customers had never typed yahoo.com into a browser. Verizon had already extracted its discount — $350 million off the purchase price, which closed in June 2017 at about $4.48 billion — and Yahoo had already, back in 2016, forced password changes on affected users and invalidated the unencrypted security questions. So October's announcement changed no defences; it changed the denominator. Oath emailed the additional two billion account holders, Verizon's chief information security officer promised accountability and transparency, and there was no new advice to give, because everything that could be reset had been reset a year earlier.

The endings are known now. Marissa Mayer, who had run Yahoo through both of its breaches, told a Senate committee on 8 November 2017 that the thefts had occurred during her tenure and that she wanted to apologise sincerely to every user. The Securities and Exchange Commission fined the company's remnant, renamed Altaba, $35 million in April 2018 — the first such penalty over an undisclosed breach, though it concerned the separate 2014 intrusion, kept from investors for nearly two years. A class action settled for $117.5 million, approved in 2020. For the 2014 breach, American prosecutors indicted two Russian intelligence officers and two hired hackers; for the August 2013 theft of everything, nobody has ever been publicly identified or charged. The number itself has never been surpassed.

Also that month · A flaw in the standard itself

The handshake that played twice

On Monday 16 October 2017, Mathy Vanhoef of the imec-DistriNet group at KU Leuven published what he called key reinstallation attacks — KRACK — against WPA2, the protocol that had secured effectively every protected wi-fi network for thirteen years. The trick was to replay the third message of the four-way handshake so that a device reinstalled a key it was already using, resetting counters and letting an attacker within radio range decrypt, and on some networks inject, traffic. Because the flaw sat in the standard rather than in any product, every correct implementation was affected; the worst case was Android 6.0 and Linux devices whose wi-fi software could be tricked into installing an all-zero key — about 41 per cent of Android devices, by Vanhoef's estimate at disclosure. Vendors had been warned from July, and Microsoft had quietly patched a week early, on 10 October. No exploitation in the wild was ever confirmed. The same Monday, researchers at Masaryk University disclosed ROCA, an Infineon key-generation flaw that weakened millions of smartcards; within three weeks Estonia froze the certificates on some 760,000 national ID cards. WPA3 was certified the following June.

Also that month · NotPetya's quieter cousin

The rabbit in the Flash update

On the morning of 24 October 2017, visitors to several compromised Russian news sites were offered an Adobe Flash update. Those who ran the installer got Bad Rabbit: disks encrypted, a black-and-red demand for 0.05 bitcoin — then about $280 — and a timer counting down forty hours until the price rose. The Interfax news agency went dark, as did Fontanka in St Petersburg; in Ukraine, card payments failed in the Kyiv metro and Odessa's airport processed passengers by hand. ESET catalogued the malware as Diskcoder.D and, with Kaspersky's researchers, traced its code to June's NotPetya; inside, its scheduled tasks were named drogon, rhaegal and viserion, after the dragons in Game of Thrones. Early analysis reported, with some relief, that no stolen NSA exploit was involved; Cisco Talos then found EternalRomance in its lateral movement, and the relief was withdrawn. Detections sat mostly in Russia, with Ukraine around an eighth of the total, and the campaign's infrastructure went offline within hours. A year later, in October 2018, the British government attributed Bad Rabbit to the GRU.

India desk · October 2017

Fifteen bitcoins for the registry

On 3 October 2017 — the same Tuesday as Yahoo's arithmetic — researchers at Seqrite, the enterprise arm of Pune's Quick Heal, published what they had found on a darknet forum: an advertisement offering data connected with more than 6,000 Indian organisations, priced at 15 bitcoins, then a little over $60,000. Posing as buyers, the researchers obtained a sample and concluded the material came from the Indian Registry for Internet Names and Numbers, IRINN, the body under the National Internet Exchange of India that allocates the country's IP addresses. The sample list of email addresses reached across the institutions that run Indian infrastructure — reports named the Reserve Bank of India, the Bombay Stock Exchange, ISRO, UIDAI, telecom operators and state government portals — and the seller offered, for a further fee, to take a chosen network down. The most alarming claim of all was that access to the registry could be used to tamper with the allocation of IP addresses itself.

Every part of that was a claim, and the registry's answer came quickly. NIXI said there had been no serious breach: the intruder, it said, had collected only basic profile information, lacked any capacity to damage the system or mount a denial of service, and its security had since been strengthened. Seqrite said it had alerted the government and APNIC, the regional internet registry for the Asia-Pacific. No disruption to India's IP allocation ever materialised, and no arrest was ever reported; the episode simply faded, unresolved, the way such stories did in a country that then had no law requiring anyone to report an intrusion at all. The reporting clock India eventually built — six hours, under CERT-In's 2022 directions — belongs to a later edition of this archive.

AI Tech desk · October 2017

Three days from an empty board

On 18 October 2017, DeepMind published AlphaGo Zero in Nature: a Go program given nothing but the rules, which learned entirely by playing itself and, after three days, beat the version that had defeated Lee Sedol by a hundred games to nil. Within forty days it had passed every previous version, and the point was the discarded ingredient — no human games at all, where the original had studied hundreds of thousands. Self-play generalised into AlphaZero within weeks, and became the result the field reached for, years later, when reasoning models began learning from their own generated experience. The following week Geoffrey Hinton, with Sara Sabour and Nicholas Frosst, posted capsule networks, his proposed successor to the convolutional nets he had helped establish — a road the field, already turning toward the transformer published that June, mostly declined to take. And on 25 October, Saudi Arabia announced citizenship for the animatronic Sophia from a Riyadh conference stage — a stunt that said less about the science than about the appetite for AI theatre to come.

Digital Guard desk · October 2017

Source code on the table

Kaspersky Lab spent October on the front pages: American reports alleged Russian state hackers had used its antivirus to find National Security Agency tools on a contractor's home computer, weeks after Washington ordered the software off federal networks. Its institutional answer came on 23 October 2017 — a Global Transparency Initiative offering its source code, updates included, for independent review, outside assessment of its engineering practices, three transparency centres by 2020 and a $100,000 top bug bounty. The company denied, then and since, helping any government spy; its own inquiry, published two days later, confirmed the antivirus had in 2014 retrieved an archive of Equation Group source code from a machine whose owner had switched it off to run pirated software — files deleted, it said, on Eugene Kaspersky's orders. Data processing moved to Zurich a year later — the 2018 shelf of this archive carries it. The quieter endpoint story aged best: the Fall Creators Update of 17 October shipped Exploit Guard and Controlled Folder Access, the start of Windows Defender's climb from afterthought toward the centre of the endpoint market.

⏳ Time capsule — October 2017

  • The Nobel Prize in Physics went on 3 October to Rainer Weiss, Barry Barish and Kip Thorne for the LIGO detector and the observation of gravitational waves, two years after the first signal was recorded.
  • The New York Times published its Harvey Weinstein investigation on 5 October; ten days later Alyssa Milano asked anyone who had been harassed or assaulted to reply "me too", and the phrase was used half a million times on Twitter within twenty-four hours.
  • On 19 October the astronomer Robert Weryk, working with the Pan-STARRS1 telescope in Hawaii, spotted a fast-moving object later named 'Oumuamua — the first visitor from another star system ever observed.
  • Bitcoin, which had begun the year below $1,000, crossed $5,000 on 12 October and $6,000 eight days later.
Where it stands today — 2026

The number that held

Nine years on, three billion remains the ceiling. Larger row counts have circulated since — the credential compilations of the mid-2020s stacked old leaks into files with more records — but no single organisation has ever disclosed a bigger breach, and the business lesson was priced in early: Verizon, which paid roughly $9 billion for Yahoo and AOL together, sold the combination to Apollo in 2021 at a valuation near $5 billion. What October 2017 changed most was the telling. The SEC's $35 million penalty against Altaba became the template for treating silence as the offence, and since December 2023 an American public company has had four business days to disclose a material intrusion — a rule that runs in a straight line from the afternoon the count tripled.

The other stories matured on their own schedules. KRACK pushed the Wi-Fi Alliance to certify WPA3 in June 2018, and Vanhoef kept auditing his own fix — Dragonblood in 2019, FragAttacks in 2021 — so that wi-fi security improved the way infrastructure usually does: quietly, version by version. Bad Rabbit closed the year of worms that had opened with three days of WannaCry in May, and in October 2018 Britain put the GRU's name on it. And the darknet listing that rattled India's registry ended in denial and silence — an ending the country later legislated against, with a six-hour reporting clock in 2022 and a data protection act in 2023, both waiting in the later years of this archive.