By December 2019, ransomware could already stop physical things. A United States Coast Guard advisory dated 16 December described a Ryuk infection at a maritime facility that began with one phishing email and ended with cameras, door controls and cargo-transfer monitoring encrypted — primary operations down for more than thirty hours. On 21 December, RavnAir cancelled a half-dozen Alaska flights at the peak of holiday travel, roughly 260 passengers grounded, after an attack the previous day forced it to disconnect its Dash 8 maintenance system and the system's backup. Against all of it, the defender's orthodoxy stayed the same: keep good backups, restore, refuse to pay. That month, a crew called Maze finished building the answer to backups.
The proof of concept had arrived in November. When the security-staffing firm Allied Universal missed a payment deadline, Maze did what ransomware gangs had always threatened and never done — on 21 November it published roughly 700 megabytes of the company's files, then pointed reporters to the evidence. On 7 December it went after the city of Pensacola, Florida, a city already in mourning after the previous morning's shooting at its naval air station. Municipal email, phone lines and online payments failed; the Maze crew itself claimed the attack in emails to reporters; the demand was $1 million. The city did not pay, and before the year ended the gang released two gigabytes of what it claimed were thirty-two — proof, it said, for the journalists.
Two days after Pensacola, Maze was inside Southwire, the Carrollton, Georgia wire and cable maker, demanding 850 bitcoin — roughly $6 million — against a claim of 120 gigabytes taken. Southwire shut down its own network and refused. On 16 December the security writer Brian Krebs documented the gang's newest infrastructure: a public website listing eight victims that had declined to pay, with infection dates, volumes of stolen data and the machine names of encrypted servers. When a portion of Southwire's files appeared on that site, the company did something almost unheard of — on 31 December it sued its extortionists in a Georgia federal court and pursued the Irish company hosting the files. These attacks, BleepingComputer's Lawrence Abrams had already warned, "should now be considered data breaches."
The lawsuit worked, briefly. The site came down in early January after Southwire pressed its case against the Irish host; within weeks it was back on infrastructure in Singapore, and fourteen more gigabytes of Southwire's data went up. The method acquired a name — double extortion — and then an industry. Maze announced its retirement in November 2020, but by then every serious crew kept a wall of the unwilling, and REvil's blog, LockBit's wall and Cl0p's 2023 lists of MOVEit victims all descend from the eight names Krebs found in December. The first imitation was already under way as the decade closed: on New Year's Eve, REvil's affiliates were inside the currency exchange Travelex. That story opens the January 2020 edition.
A stranger's voice in a child's bedroom
In the second week of December, American local news filled with the same story told from different houses: Ring security cameras, installed for safety, speaking with strangers' voices. The case that carried furthest came from DeSoto County, Mississippi, where a camera had been mounted in a children's bedroom for four days before a man's voice began talking to an eight-year-old girl through it. Reporters found forums openly trading account-cracking tools for exactly this purpose. Ring said its own systems had not been compromised and that attackers were reusing usernames and passwords spilled in other companies' breaches — credential stuffing, meeting the smart home. The first class action was filed before the month ended. In February 2020 Ring made two-factor authentication mandatory, and in 2023 the US Federal Trade Commission ordered it to pay $5.8 million in customer refunds over camera-access failures. The same month, camera maker Wyze confirmed that a database holding details of 2.4 million users had sat exposed online for most of December.
Eighty thousand open doors for Christmas
On 17 December, Citrix published security bulletin CTX267027: a directory-traversal flaw in its Application Delivery Controller and Gateway appliances — the boxes that sit at the front of corporate networks and let staff in from outside — allowed unauthenticated remote code execution. What the bulletin did not contain was a patch. Citrix offered configuration mitigations and a promise of fixes to come; Positive Technologies, whose researcher Mikhail Klyuchnikov had found the flaw, estimated that 80,000 companies in 158 countries were running exposed appliances. Administrators, contemplating a critical hole in the corporate front door across the holidays, gave the CVE a rude nickname that stuck. The gap between disclosure and repair became one of the defining races of early 2020: working exploits were published on 10 and 11 January, mass scanning followed within hours, and Citrix shipped its patches between 19 and 24 January. What came through the unpatched doors in between is the January 2020 edition's story.
Fifteen minutes to find, one statement to close
In the first week of December, a Bengaluru security researcher named Ehraz Ahmed demonstrated a flaw in an API used by Airtel's mobile app: fed any subscriber's phone number, it returned that person's name, email address, date of birth, residential address and device IMEI. Ahmed said finding it took him about fifteen minutes. The potential exposure ran to the scale of Airtel's subscriber base — upwards of 300 million people, the country's third-largest network — though potential is the operative word: no evidence emerged that anyone malicious had used it. The BBC and Indian outlets reported the flaw in the first days of December, and Airtel's account was brief — the problem lay in a testing API, it was addressed as soon as it was brought to the company's notice, and no customer data had been breached. A door found unlocked and shut, this time by the person who found it.
Days later, on 11 December, the Personal Data Protection Bill was introduced in the Lok Sabha — India's first full attempt at a general data-protection law, drafted in the long wake of the Supreme Court's privacy judgment, and promptly referred to a Joint Parliamentary Committee. Read together, the week's two events framed the country's predicament exactly: subscriber data at hundreds-of-millions scale, guarded by whatever each company chose to build, with the law that might compel better still a draft. Hindsight is unkind. The committee deliberated for two years, the bill was withdrawn in August 2022, and the statute India finally passed — the DPDP Act — arrived in August 2023, its rules later still. The unlocked doors of 2019 stayed legal for years yet.
Thirteen thousand researchers, two billion dollars
The field's annual gathering filled the Vancouver Convention Centre from 8 to 14 December: NeurIPS 2019 drew roughly 13,000 registered attendees and 6,743 paper submissions, 1,428 of them accepted — the largest edition yet of what had become machine learning's census. Facebook used the week to launch its Deepfake Detection Challenge in earnest, releasing a dataset of more than 100,000 clips filmed with paid actors and inviting Kaggle competitors to learn to spot the forgeries; the sobering results the following summer showed how far detection trailed generation, a gap 2026 has not closed. The month's decisive move came two days after the conference ended: on 16 December Intel paid roughly $2 billion for Habana Labs, the Israeli designer of the Gaudi training and Goya inference chips, reckoning the AI silicon market would exceed $25 billion by 2024. The market guess proved timid; the belief that Gaudi could take serious ground from Nvidia was not one the intervening years honoured.
Counting the year ransomware became a crisis
On 12 December, Emsisoft released its State of Ransomware in the US report three weeks early, hurried out by an incident in which, the firm said, a municipal government's data may have reached criminal hands. Its count gave the year its shape: at least 948 American government agencies, schools and healthcare providers hit in 2019 — later revised to 966 — including 113 state and municipal bodies and 764 healthcare providers, at a potential cost put above $7.5 billion, with emergency patients redirected and 911 dispatchers working from paper maps. The month also embarrassed the defenders directly. On 9 December Sophos documented Snatch ransomware rebooting Windows into Safe Mode, where most security software never loads, before encrypting. And on 3 December Mozilla pulled Avast's and AVG's extensions for harvesting detailed browsing histories; Avast said the collection served the tools' protective function and stored no user identification, but its data-selling subsidiary Jumpshot closed within two months, and in February 2024 the US Federal Trade Commission settled the matter for $16.5 million and a ban on selling browsing data for advertising.
⏳ Time capsule — December 2019
- Boris Johnson's Conservatives won an 80-seat majority in the UK general election on 12 December, clearing the way for Brexit the following month.
- The US House of Representatives voted on 18 December to impeach President Donald Trump — the third presidential impeachment in American history.
- The United States Space Force was established on 20 December, the first new branch of the American military in more than seventy years.
- On 31 December, Wuhan's municipal health commission publicly reported a cluster of pneumonia cases of unknown cause — the first official notice of what became COVID-19.
What December invented
Within a year the method had a name — double extortion — and a market. Maze announced its retirement in November 2020 with the satisfaction of a firm that had changed its industry, and the leak wall outlived it everywhere: by 2021, the question for a breached company was less whether its files were encrypted than whether they were already published. The quieter road taken that December aged just as revealingly. LifeLabs, which told fifteen million Canadians on 17 December that it had paid its attackers to retrieve their health data, then spent four years in court keeping the privacy commissioners' report on the breach unpublished. It finally appeared in November 2024; affected customers were offered up to C$150 each.
For India, December closed a year of firsts: from SBI's unsecured server and Indane's leaking dealer portal, through Justdial's open APIs, Wipro's compromised employees, Kudankulam's infected administrative network and the Pegasus calls on WhatsApp, to Airtel's fifteen-minute flaw. Nearly every episode was an unlocked door rather than a heist — and the bill meant to compel locks entered Parliament the same week the year's last door was found, a thread this archive follows through the DPDP Act's passage and its long wait for rules. The Vault's 2019 shelf closes here. The next morning belongs to Travelex, and to January 2020.