KrebsOnSecurity broke the story on 15 April 2019: Wipro — the Bengaluru-headquartered outsourcing giant whose roughly 170,000 employees run helpdesks, networks and back offices for many of the world's largest companies — had itself been breached, and its systems were being used as jumping-off points into its own customers. Krebs' sources, among them a forensic investigator working for one affected client, counted at least a dozen customer environments targeted from inside Wipro. The timeline that later emerged from Wipro's own forensic review was ordinary to the point of insult: one employee phished on 11 March, twenty-two more in a campaign the following week, and a legitimate remote-access tool, ScreenConnect, quietly seeded onto more than a hundred Wipro endpoints.

Wipro's handling became a story in its own right. Its first response to Krebs was a statement about the company's multilayer security that never addressed the question. Confirmation arrived the next day — on the quarterly earnings call, folded in among the fourth-quarter results. Chief operating officer Bhanu Ballapuram told analysts the incident was limited to a few phished employees, disputed that the intrusion had run for months rather than weeks, and described the attack as a "zero-day", offering nothing beyond the assurance that the relevant details had been shared with Wipro's antivirus vendor. Krebs' reply, published under the headline How Not to Acknowledge a Data Breach, catalogued the contradictions — including that the indicators of compromise Wipro circulated had, his sources said, originated with an affected customer.

In the first days the assumed explanation was espionage: a state actor mining a services firm for access to its clients. The truth was smaller and stranger. Investigators watched the intruders hunt customer systems for gift-card portals, and Krebs reported the access had already been used for gift-card fraud at a major retailer. In June, RiskIQ mapped the attackers' infrastructure and concluded the same crew had run at least five campaigns since 2016, possibly 2015, against the whole gift-card ecosystem — retailers, payment processors and the IT providers who serve them. Other outsourcers had been probed by the same operators, researchers said, while stressing that targeted did not mean breached; those companies reported finding no compromise.

The ending was quiet, which is itself the finding. Wipro was reported to be building itself a new, private email network — its existing corporate email system presumed compromised — circulated indicators of compromise, and said little more; no full public postmortem ever appeared, and no attribution was established beyond the criminals' commercial appetite. What endured was the shape of the thing. A company whose product is trusted access to other organisations' systems had that access turned around and pointed at the people paying for it — not by breaking the trust, but by riding it. This archive spends much of the next seven years watching the same manoeuvre executed at larger and larger scale.

Also that month · Two buckets, 540 million records

Facebook's data, on other people's servers

UpGuard researchers disclosed on 3 April that two third-party troves of Facebook user data had been sitting in publicly accessible Amazon S3 storage. The larger, assembled by Mexican media company Cultura Colectiva, ran to 146 gigabytes and more than 540 million records — Facebook IDs, account names, comments, likes and reactions. The second, a backup from a defunct California app called At the Pool, was smaller but sharper: records on some 22,000 users, including plaintext passwords that UpGuard judged were probably for the app itself rather than for Facebook. The disclosure timeline was the real indictment. UpGuard said it had emailed Cultura Colectiva on 10 and 14 January and heard nothing, then notified Amazon; the bucket was finally secured on the morning of publication, after a journalist put questions to Facebook. Facebook noted its policies prohibit storing user information in a public database — a policy the data had been violating, unnoticed, at rest. The platform was one year past Cambridge Analytica and three months from a five-billion-dollar FTC settlement.

Also that month · The helper's credentials

Three months inside the webmail support panel

Microsoft began notifying Outlook.com, Hotmail and MSN users on 13 April that a support agent's credentials had been compromised, and that intruders had used the support tooling between 1 January and 28 March to view information about their accounts. The first version of the disclosure was reassuring in a specific way: email addresses, folder names, subject lines and the addresses a user corresponded with had been exposed, but not the contents of messages. Within two days the company was confirming a second version to reporters — for roughly six per cent of affected accounts, message content had been accessible too, and those users were being notified separately. Microsoft described the total only as a limited subset of consumer accounts and never gave a number. It disabled the compromised credentials and said the scheme had been addressed. Both statements were true; the second was simply larger than the first, and this archive carries them side by side, because the gap between them is the story.

India desk · April 2019

Justdial: the API that answered everyone

The report reached the press on 17 April: Rajshekhar Rajaharia, an independent security researcher, had found an old Justdial API endpoint — publicly reachable, unauthenticated, apparently forgotten — that returned user profile data to anyone who queried it. The fields were not trivial: name, mobile number, email address, home address, gender, date of birth, photo, occupation, company. Rajaharia estimated the exposure covered roughly 100 million users, a figure this archive carries as his claim rather than an audited count, and said the endpoint had been live since at least mid-2015. It was current, too: a fresh number used to ring Justdial's 88888 88888 hotline surfaced through the API almost immediately. The researcher added that he had been unable to find a working route for disclosing the problem to the company.

Justdial's response was a flat denial with an audit attached. The company said there had been no breach of 100 million users as claimed, that the vulnerability sat in an older version of its app and had already been fixed, that no financial data was exposed and that payment information was encrypted and separately audited — and that it had commissioned an independent technical review. Rajaharia publicly disputed the claim that the problem was fixed, and before the month was out a further exposed endpoint, this one leaking reviewer data, had been reported and closed within a day. What did not happen is the point this archive keeps returning to: no regulator intervened and no penalty followed, because none could. India in April 2019 had no data protection law. The statute that would change that was four years away.

AI Tech desk · April 2019

OpenAI Five beats the world champions

OpenAI Five, the Dota 2 system OpenAI had spent two years scaling, beat OG — the game's reigning world champions — two games to nil in San Francisco on 13 April 2019, the first time an AI system had defeated the world champions of an esport. The arithmetic behind it was the story: self-play reinforcement learning consuming roughly two million frames of gameplay every two seconds. Opened to the public for four days afterwards, the system won more than 99 per cent of its games. The rest of the month belonged to governance, attempted and abandoned. In Brussels, the EU's High-Level Expert Group of fifty-two specialists published its Ethics Guidelines for Trustworthy AI on 8 April — seven non-binding requirements, human oversight to accountability, that read in hindsight as the first draft of the AI Act that took force in 2024. Google, meanwhile, dissolved its external AI ethics council on 4 April, little more than a week after announcing it, once thousands of employees objected to its membership. Capability was compounding; governance was improvising.

Digital Guard desk · April 2019

Eighty modules, one identified victim

At its Security Analyst Summit in Singapore on 10 April 2019, Kaspersky Lab described TajMahal, a spying platform found the previous autumn that its researchers could tie to no known group. The framework ran to some eighty modules across two packages, Tokyo and Yokohama — among the largest plugin counts ever recorded for an APT toolset — with stealers for documents in printer queues and files on CDs, alongside keyloggers, audio recorders and webcam grabbers. Only one victim had been identified, a diplomatic body in Central Asia, which sharpened rather than settled the question of who had built so much for so few. The month's quieter arrival mattered more in the end. From 25 April, Cisco Talos watched attackers exploit a critical Oracle WebLogic flaw — patched out of cycle a day later — to install a previously unseen ransomware called Sodinokibi. The trade filed it as one more strain; under its later name, REvil, it reaches Travelex, JBS and Kaseya in these pages.

⏳ Time capsule — April 2019

  • The Event Horizon Telescope collaboration released the first image ever made of a black hole on 10 April — the supermassive object at the heart of galaxy M87.
  • Notre-Dame de Paris caught fire on 15 April; the spire and most of the roof were lost, and the cathedral would not reopen for more than five years.
  • Volodymyr Zelensky, a comedian who had played a president on television, won Ukraine's actual presidency on 21 April with about 73% of the runoff vote.
  • Avengers: Endgame opened on 26 April and became the first film to take more than a billion dollars in a single worldwide opening weekend.
Where it stands today — 2026

The trusted third party

April 2019's cover story is the earliest full statement in these pages of the idea that dominates the archive's later years: do not attack the target, attack the target's supplier. The gift-card crew that rode through Wipro wanted money; the operators who slipped an implant into SolarWinds' software updates — December 2020 in this archive — wanted governments; the affiliates who turned Kaseya's management tool into a ransomware distributor in July 2021 wanted everything in between. The technique aged better than any of the actors. Even the month's smaller stories rhyme forward: Microsoft's abused support account anticipates the help-desk social engineering that empties casinos in these pages in September 2023.

The India thread begins in earnest here too. Justdial's forgotten API was met with a denial, an audit and then silence, and in 2019 silence was legal: no notification duty, no data protection authority, no statute. The archive watches that vacuum fill — CERT-In's six-hour reporting mandate in 2022, the Digital Personal Data Protection Act in August 2023, its rules following slowly — and keeps relearning what this month taught. Wipro's breach mattered because of whose systems its systems touched; Justdial's mattered because nobody could make it matter. The Vault continues backwards from here, and both sentences keep being true.