The lockout began in the night of 18–19 March 2019. Across Norsk Hydro — a Norwegian aluminium producer with 35,000 employees in 40 countries and roughly 170 plants — screens froze one after another, replaced by a ransom note offering decryption in exchange for payment. The strain was LockerGoga, first observed only weeks earlier. By morning in Oslo, the company had done what almost no ransomware victim before it had dared: it told everyone. Hydro notified the market, briefed journalists the same day, and set out the three decisions its executives had already taken — pay no ransom, bring in Microsoft's incident responders, and communicate openly for as long as the crisis lasted.

What openness looked like on the ground is why the month is remembered. With order systems encrypted, plants fell back to pen and paper. Workers dug out old printed order forms; retired employees who still remembered the paper routines volunteered and came back through the gates to run them. Executives hand-wrote security warnings, photographed them, and texted the images to plant managers around the world. Local printing shops produced signs for entrances, stairwells and lifts reading "Please do not connect any devices to the Hydro network." Production degraded — the extrusion business was hit hardest — but metal kept moving, made for a while by people rather than software.

The communication was as deliberate as the recovery. Hydro held daily press conferences at its Oslo headquarters, ran daily webcasts that took questions, let journalists into its control rooms, and stood up a fresh website in the first week because the old one was down. Microsoft's Detection and Response Team rated the case maximum severity; one of its responders spent three weeks at a large Hungarian plant helping rebuild. NorCERT, Norway's national incident-response centre, said it was assisting. Investigators traced the intrusion back months, to an infected email that had arrived from a trusted customer around December 2018 — LockerGoga was not the break-in, only the detonation.

The numbers arrived in stages, and it matters to keep them straight. Hydro's first-week estimate was 300–350 million kroner, roughly $35–41 million; by July the figure had grown to NOK 550–650 million, up to about $71 million, among the costliest ransomware recoveries then on record. Insurance answered slowly: the first payment Hydro recognised, that autumn, was NOK 33 million — about $3.6 million, six per cent of the damage — with larger instalments following. The same strain had struck the American chemical makers Hexion and Momentive around 12 March, which surfaced publicly ten days later along with orders for hundreds of new computers. Refusing to pay was expensive. It also became the response every later victim would be measured against.

Also that month · The updater that turned

ShadowHammer came signed by ASUS

On 25 March, reporting by Motherboard and research from Kaspersky Lab revealed Operation ShadowHammer: for months in 2018 — roughly June to November — ASUS's Live Update utility, preinstalled on the company's computers, had delivered a backdoored version of itself, signed with legitimate ASUS certificates and served from ASUS's own update servers. Kaspersky found the poisoned build on more than 57,000 of its users' machines and estimated the true distribution could exceed a million; Symantec counted at least 13,000 among its own customers. The mass distribution was camouflage. The implant lay dormant unless a machine's MAC address matched a hard-coded list of around 600 targets, in which case it reached out for a second stage — surgery on a few hundred machines, performed through the one channel every user is told to trust. Kaspersky said it notified ASUS in January; on 26 March the company described a narrowly targeted attack by an advanced actor, shipped a fixed Live Update and released a diagnostic tool.

Also that month · Logged in the clear

Hundreds of millions of passwords, readable at work

On 21 March, Krebs on Security reported — citing a senior Facebook employee — that an internal review had found user passwords stored in plaintext on internal systems since as early as 2012, searchable by more than 20,000 Facebook employees. The insider's estimate ran from 200 million to 600 million accounts; access logs reportedly showed about 2,000 engineers making some nine million queries against data that contained plaintext passwords. Facebook confirmed the substance the same day, saying the passwords had never been visible outside the company and that its investigation had found no evidence of abuse — the company's own claim, worth labelling as such. It said it would notify hundreds of millions of Facebook Lite users, tens of millions of other Facebook users and tens of thousands of Instagram users; in April, the Instagram figure was quietly revised upward to millions. No intrusion, no attacker, no malware — just logging, left running for roughly seven years, at the company then holding the largest store of social credentials on earth.

India desk · March 2019

Nine hundred million voters, and the referee moves first

On 10 March 2019, Chief Election Commissioner Sunil Arora announced the general election to the 17th Lok Sabha: seven phases from 11 April, counting on 23 May, and an electorate of roughly 900 million — the largest election ever conducted anywhere. The Model Code of Conduct came into force at once, and for the first time it reached squarely into the online campaign. Candidates had to declare their social media accounts when filing nominations; political advertisements on social platforms required pre-certification, with the spending counted against expense limits; and the Commission's cVigil app let any citizen photograph a suspected violation and send it in. After Cambridge Analytica, and after two years of rumour-driven violence spread over messaging apps, nobody pretended the online campaign was a side issue.

Ten days later the platforms came to the referee. On 20 March, industry body IAMAI presented the Election Commission with a Voluntary Code of Ethics signed by Facebook, WhatsApp, Twitter, Google, ShareChat and TikTok, effective immediately: a dedicated high-priority channel for the Commission, trained teams for the election period, and a commitment to act within three hours on violations of Section 126 — the 48-hour pre-poll silence. There was no breach to report from India this month; this was the quieter story of a state negotiating terms with platforms it could not compel. The code outlived its election — extended in September 2019 to every future Indian poll — and its three-hour clock reads, from 2026, like a first draft of the harder deadlines that came later.

AI Tech desk · March 2019

Deep learning collects its Turing Award

The citations arrived before the consequences. On 27 March, the ACM announced that the 2018 Turing Award — computing's highest honour, its $1 million prize funded, fittingly, by Google — would go to Geoffrey Hinton, Yoshua Bengio and Yann LeCun, for the neural-network research they had kept faith with through the field's lean decades. Hinton accepted as a Google vice-president, LeCun as Facebook's chief AI scientist; only Bengio had remained wholly academic, a fair census of where the field now lived. The structures moved the same month. On 11 March, OpenAI recast itself as OpenAI LP, a "capped-profit" company limiting first-round investors' returns to one hundred times their stake — the vehicle that took Microsoft's first billion dollars that July, and whose cap was dismantled in the restructuring of 2025. The same day, Nvidia agreed to buy the networking firm Mellanox for $6.9 billion: read then as a datacentre deal, in hindsight the purchase of the fabric that every large model since has trained across.

Digital Guard desk · March 2019

Two hundred and fifty scanners, mostly ornamental

The month's biggest story began not with a tip-off or a subpoena but inside an antivirus vendor's telemetry: Kaspersky Lab researchers spotted the poisoned ASUS updater at the end of January, and the 25 March disclosure — covered above — made the strongest case in years for the unglamorous business of watching endpoints at scale. The industry's own products fared less well under inspection. In mid-March the Austrian laboratory AV-Comparatives published the largest Android antivirus test then attempted, setting 250 security apps from Google Play against 2,000 malicious samples: barely one in three provided protection worth the name, over two-thirds failed to block even 30 per cent, and fewer than one in ten caught everything — a market, the testers concluded, padded with apps built by advertisers rather than security firms. Analysts did receive one gift. At the RSA Conference on 5 March, the NSA's Rob Joyce released Ghidra, the agency's in-house reverse-engineering suite, free — known publicly only from the Vault 7 leaks two years earlier, and by 2026 as much a fixture of malware analysis as the commercial suites it undercut.

⏳ Time capsule — March 2019

  • Ethiopian Airlines Flight 302 crashed minutes after take-off from Addis Ababa on 10 March, killing all 157 aboard; regulators worldwide grounded the Boeing 737 MAX within days.
  • US prosecutors unveiled Operation Varsity Blues on 12 March, charging some 50 people — including actresses Felicity Huffman and Lori Loughlin — over bribery in elite college admissions.
  • Nursultan Nazarbayev resigned on 19 March after nearly three decades leading Kazakhstan; parliament voted the next day to rename the capital Astana as Nur-Sultan.
  • Brexit day came and went: Britain was due to leave the EU on 29 March, but Parliament rejected the withdrawal agreement a third time that day, by 344 votes to 286.
Where it stands today — 2026

Three kinds of trust

March 2019 reads, from here, like a curriculum. Norsk Hydro's refusal-plus-transparency became the citation every incident-response plan reached for — the standard against which Colonial Pipeline's quiet payment in 2021 and Royal Mail's published defiance in 2023 would both be measured in these pages. The criminal side resolved slowly: in October 2021, twelve suspects linked to the operation behind LockerGoga and MegaCortex were arrested in Ukraine and Switzerland, and in September 2022 Bitdefender and Europol released a free decryptor built from seized keys — three and a half years too late for Hydro, which had already rebuilt by hand and never asked for its files back.

ShadowHammer's lesson took longer to land. A signed update from a real vendor, poisoned at the source and aimed at a few hundred machines, was treated in 2019 as an exotic curiosity; December 2020 brought SolarWinds, March 2023 brought 3CX, and March 2024 brought XZ Utils, each making it look less like a curiosity and more like a template — a thread this archive follows through those editions. Facebook's plaintext logs found their ending in September 2024, when Ireland's regulator fined Meta €91 million over the storage it had admitted in March 2019. And India's three-hour code still shadows its elections. The Vault continues backwards from here, restoring the months where these habits began.