Cisco's Talos group published a warning on 5 April 2018 about a feature almost nobody had chosen to run and almost nobody had chosen to switch off. Smart Install is a provisioning protocol: it lets a new switch collect its configuration and its operating system image from a central server without an engineer touching it. Left listening on the network, as it was on a great many devices, it will also let an unauthenticated stranger download the running configuration, rewrite it, replace the image and execute commands. Talos counted more than 168,000 systems exposed to the open internet, down from the roughly 251,000 Tenable had counted in 2016, said the misuse should be mitigated immediately, and noted that some incidents it had seen were believed to involve nation-state actors.

On the night of Friday 6 April, into the Saturday, somebody used it at scale. Network engineers in Iran and Russia found switches rebooted with the startup configuration erased and replaced by an ASCII drawing of the American flag above the line "Don't mess with our elections" and a contact address. Iran's minister for information and communications technology, Mohammad Javad Azari Jahromi, said roughly 3,500 switches in the country had been affected and that most were back in service the following day. Whoever was behind it, using the initials JHT, told Motherboard they were retaliating against governments they believed had interfered in elections, and said they had patched rather than wiped devices found in the United States and Britain — an anonymous claim, never corroborated.

Ten days later the context arrived. On 16 April the US Department of Homeland Security, the FBI and Britain's National Cyber Security Centre jointly published technical alert TA18-106A, on Russian state-sponsored targeting of network infrastructure devices worldwide. The byline was itself the news: the first time the NCSC had appeared as co-author on a joint DHS and FBI product. The alert said the US government had been receiving reporting since 2015 that actors were exploiting large numbers of enterprise-class and residential routers and switches; that the targets were governments, private-sector organisations, critical infrastructure providers and the ISPs serving them; and that compromised devices were being used for spoofing and man-in-the-middle attacks to support espionage, extract intellectual property, hold persistent access and potentially lay a foundation for future offensive operations.

What should have carried further was how ordinary the methods were. The alert named Telnet, the first and second versions of SNMP, TFTP and Smart Install itself: management protocols decades old, with authentication that is either absent or sent in clear text, left enabled because turning them off requires first knowing they are on. Routers and switches carry no antivirus, rarely any endpoint detection, no logging anyone reads, and are patched on a vendor's schedule rather than a Tuesday. The two events of that month shared a layer and nothing else. One was a wipe built to be noticed within hours, on hardware whose owners could see exactly what had happened. The other, on the account of two governments, had been running quietly for at least three years.

Also that month · Two days in Washington

The line nobody noticed

Facebook put its own number on the Cambridge Analytica harvest on 4 April — up to 87 million people, well above the 50 million first reported in March, and a count Cambridge Analytica disputed the same day, saying it had licensed data on no more than 30 million — and the same post carried a second admission that drew far less attention. Until that day anyone could type a phone number or email address into Facebook's search box to find who it belonged to. Its chief technology officer, Mike Schroepfer, said it was being switched off because "we believe most people on Facebook could have had their public profile scraped in this way" — a company telling two billion users their profiles had probably already been taken, by parties it could not name. Mark Zuckerberg testified for close to five hours on 10 April before the Senate Judiciary and Commerce committees sitting jointly, putting more than forty senators in a queue with five minutes apiece. Senator Orrin Hatch asked how a service its users did not pay for sustained itself. "Senator, we run ads," Zuckerberg replied. The House Energy and Commerce Committee had him for another five hours on 11 April, where he confirmed to Representative Anna Eshoo that his own data was among that improperly shared. The full account is in the March 2018 edition.

Also that month · Eight months of nothing

Panera's website was the leak

KrebsOnSecurity reported on 2 April that panerabread.com had been serving customer records in plain text to anyone willing to change a number in a URL: names, email and postal addresses, birthdays and the last four digits of payment cards, for anyone with an online ordering account. The researcher Dylan Houlihan said he reported it on 2 August 2017, received a one-line acknowledgement — "Thank you for the information we are working on a resolution" — then heard nothing for eight months. Panera took the site down that day, said the problem was fixed within two hours of being told, put the affected consumers at fewer than 10,000 and said there was no evidence card data was taken. Krebs first estimated more than seven million records, then carried an update citing the firm Hold Security that put the figure above 37 million once the commercial division was found exposed too. The two figures were never publicly reconciled, and this archive keeps them apart: a researcher's estimate against a company's assertion. Separately, on 20 April, SunTrust said a former employee might have taken contact-list information on about 1.5 million clients; chairman and chief executive William Rogers told the bank's earnings call the employee "may have attempted to print information on approximately 1.5 million clients and share this information with a criminal third party", and the bank said it had seen no indication the data left it.

India desk · April 2018

Where the money's data lives

The Reserve Bank of India issued circular RBI/2017-18/153 on 6 April 2018, headed "Storage of Payment System Data", and its operative requirement was one sentence: all system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India. The data was drawn widely: end-to-end transaction details, and any information relating to a payment or settlement transaction gathered, transmitted or processed as part of a payment message. The scope was everyone authorised under the Payment and Settlement Systems Act, 2007, and the banks. The stated reason was unfettered supervisory access. Providers had six months, were to report compliance by 15 October 2018, and to file a board-approved system audit report by a CERT-In empanelled auditor by 31 December 2018.

The objections were immediate and lasted years. The card networks and American technology firms argued that pulling data into one country would fragment fraud models that work because they are global, and that the cost would fall hardest on the smallest players; the RBI clarified later that processing abroad was not prohibited, provided the data was deleted from foreign systems and returned within the prescribed period. Enforcement, when it came, was blunt rather than financial. In July 2021 the regulator barred Mastercard from taking on new domestic customers for continued non-compliance with the same direction, lifting the restriction only in June 2022. None of this was an incident, which is why it belongs in an archive of them. April 2018 is the month two capitals asked different questions about the same data — Washington asking who held it, Mumbai deciding where it had to sit — and Mumbai's has travelled furthest.

AI Tech desk · April 2018

Brussels puts a figure on AI

The European Commission published a Communication headed "Artificial Intelligence for Europe" on 25 April 2018, the Union's first strategy for the technology. It committed €1.5 billion of Horizon 2020 research funding across 2018 to 2020, set a target of at least €20 billion in combined public and private investment by the end of 2020, and promised ethics guidelines grounded in the Charter of Fundamental Rights before 2018 was out. The ground had been prepared on 10 April, when twenty-five European countries — twenty-four member states and Norway — signed a declaration of cooperation on AI. Britain's House of Lords published its inquiry "AI in the UK: ready, willing and able?" on 16 April, arguing the country should lead on ethics rather than scale. Earlier in the month more than 3,100 Google employees had signed a letter asking Sundar Pichai to cancel the company's Project Maven work for the Pentagon; Google said in June it would not renew the contract. The guidelines Brussels ordered arrived in April 2019; their requirements are recognisable in the AI Act.

Digital Guard desk · April 2018

The endpoint business goes to market

Three companies put a price on endpoint protection inside four days. Carbon Black filed its registration statement on 9 April 2018 for a Nasdaq listing under CBLK. Palo Alto Networks said on 10 April that it would buy Secdo, an Israeli endpoint detection and response firm, and closed on 24 April — $82.7 million in cash by its own later filings, against the $100 million reported in the Israeli press — with the technology promised to its Traps agent, which became the Cortex XDR agent the following year. On 12 April the Czech antivirus company Avast announced its intention to float in London, in what was expected to be the exchange's largest technology listing. RSA Conference opened at Moscone Center that same week, and on 17 April Microsoft and thirty-three other firms, Symantec, Trend Micro, Avast and F-Secure among them, signed the Cybersecurity Tech Accord, undertaking to help no government attack innocent citizens or enterprises. VMware bought Carbon Black for $2.1 billion in 2019; Avast is now part of Gen Digital.

⏳ Time capsule — April 2018

  • The Commonwealth Games ran on Australia's Gold Coast from 4 to 15 April, with some 6,600 athletes and team officials from 71 nations and territories.
  • Prince Louis was born at St Mary's Hospital in Paddington on 23 April; the name Louis Arthur Charles was announced four days later.
  • Joseph James DeAngelo was arrested in California on 24 April and identified as the Golden State Killer, in the case that made genetic genealogy — matching crime-scene DNA to distant relatives on a public ancestry database — a mainstream investigative tool.
  • Kim Jong-un crossed the demarcation line at Panmunjom on 27 April to meet Moon Jae-in, the first North Korean leader to set foot in the South since 1953, and the two signed the Panmunjom Declaration.
Where it stands today — 2026

The month the plumbing got its warning

Five weeks after TA18-106A, on 23 May 2018, Cisco Talos disclosed VPNFilter: at least 500,000 routers and network storage devices in no fewer than 54 countries, mostly consumer and small-office hardware, with a sharp spike of new victims in Ukraine. That story belongs to the May 2018 edition, but it is April's argument with numbers. Everything since has confirmed it. The edge of the network — routers, firewalls, VPN concentrators, the telecommunications equipment underneath all of it — has become the preferred foothold for state intrusion, because it sits outside the tooling built to watch endpoints; the long, patient occupations this archive covers from the December 2020 edition onward begin somewhere in that layer. In 2024 America's cyber-security agency was still publishing advisories asking organisations to turn Smart Install off.

The remediation advice has not changed either, which is the uncomfortable part: eleven months after WannaCry had made the same case about unpatched endpoints, two governments were reduced to asking the world to disable Telnet. The slower thread out of April 2018 is the legal one. The Reserve Bank's circular is the first link in a chain that runs through India's long data-protection argument to the DPDP Act and the six-hour reporting rule, and localisation, exotic in 2018, is now simply how the payments industry is built. The two days of testimony in Washington produced penalties rather than statute. The Vault continues backwards from here.