The criminal complaint unsealed in San Francisco on 6 November 2019 read less like a hacking case than a spy story with employee badge photos. The United States charged two former Twitter employees — Ahmad Abouammo, a media partnerships manager for the Middle East and North Africa, and Ali Alzabarah, a site reliability engineer — with acting as agents of Saudi Arabia, alongside Ahmed Almutairi, a Saudi marketing executive alleged to have served as the go-between. Their product was Twitter's own internal tooling: the email addresses, phone numbers, birth dates and IP addresses behind accounts that criticised the kingdom. Abouammo had been arrested in Seattle the day before. It was widely reported as the first time Saudi nationals had been charged with spying inside the United States.

The complaint's texture is what stays with the reader. In 2014, prosecutors said, Abouammo began meeting Bader Al-Asaker, who ran the charity and private office of a royal identified in court papers only as Royal Family Member-1 — and in reporting around the world as Mohammed bin Salman. Al-Asaker gave him a Hublot watch worth roughly $20,000 and at least $300,000, routed through a relative's bank account in Lebanon. In exchange, prosecutors said, Abouammo pulled up the account of Mujtahidd, an anonymous insider with more than a million followers sometimes described as a Saudi WikiLeaks, and passed along the email address and phone number behind it. When FBI agents finally knocked in 2018, he showed them a falsified invoice.

Alzabarah was the deeper breach. Through 2015 the engineer accessed the private data of more than 6,000 Twitter users, prosecutors alleged, feeding details on the kingdom's critics to his handlers. On 2 December 2015 Twitter confronted him about the access and placed him on administrative leave; he walked out of the San Francisco office, and by the next day he was on a flight to Riyadh with his wife and daughter, emailing his resignation as he went. He has never returned. The charges landed thirteen months after the murder of Jamal Khashoggi had put Riyadh's pursuit of its critics under global scrutiny — and they recast the platform insider, until then a fraud problem, as an instrument of foreign intelligence.

Because this is a retrospective, the ending is on record. Abouammo fought the case and lost: in August 2022 a San Francisco jury convicted him of acting as an unregistered foreign agent, money laundering, conspiracy to commit wire fraud and falsifying records, and that December a judge sentenced him to 42 months in prison and ordered him to hand over $242,000. Alzabarah and Almutairi appear on FBI wanted posters and are believed to be in Saudi Arabia, beyond the reach of US extradition. The espionage had required no malware and no breached perimeter — only two salaried men, and the access their jobs already gave them.

Also that month · The call sounded right

Trend Micro's insider

When customers of Trend Micro's home antivirus products began receiving support calls from fraudsters in the summer of 2019, the detail that unsettled the company was how much the callers knew. The scammers had names, email addresses and support-ticket numbers — information that lived in one place. On 5 November the firm disclosed why: an employee had used fraudulent means to reach a consumer support database and sold the contents of an estimated 68,000 customer records — under one per cent of its consumer base — to a third party running phone scams. Trend Micro said it became aware of the calls in early August, confirmed by late October that the source was internal rather than an intrusion, fired the employee, disabled the account and brought in law enforcement; payment-card data and enterprise customers, it said, were not involved. An antivirus vendor exists to keep attackers out. The week the Twitter charges dropped, the industry absorbed the same lesson twice: a database does not ask why a valid login wants what it wants.

Also that month · Ransom at the oil monopoly

Pemex bills by hand

On Sunday 10 November, ransom notes appeared on computers at Petróleos Mexicanos, Mexico's state oil company, pointing to a darknet payment portal associated with DoppelPaymer ransomware and demanding 565 bitcoin — about $4.9 million at the time, according to a note seen by Reuters. Pemex confirmed an attack but said it had touched less than five per cent of its computers, with production, supply and fuel stocks unaffected. The texture came from inside: Reuters, citing five employees and internal emails, described machines shut down across the country and payment systems frozen, staff in the refining arm cut off from email, workers in well-drilling services unable to reach the network — and billing, reports said, handled manually while systems were rebuilt. Mexico's government said the ransom would not be paid. The attackers told journalists the company had until the end of the month; three months later, when DoppelPaymer opened one of ransomware's first public leak sites, Pemex's name was on it.

India desk · November 2019

Pegasus reaches Parliament

WhatsApp's lawsuit against Israel's NSO Group, filed in California on 29 October 2019, had confirmed that Indian journalists, lawyers and activists were among roughly 1,400 users worldwide whose phones were targeted through a video-call flaw with NSO's Pegasus spyware. November was the month the affair reached Parliament. On 20 November the Standing Committee on Information Technology, chaired by Shashi Tharoor, took up citizens' data security and privacy; the IT Secretary told the panel that, officially, the government had no names of affected Indians, and governing-party members resisted putting Pegasus formally on the agenda. The same day, seventeen of the Indians notified by WhatsApp wrote to the committee demanding an investigation. The government pointed instead to WhatsApp's own correspondence — including a 5 September letter to CERT-In saying 121 Indian users may have been targeted.

On 26 November CERT-In, the national incident-response agency, sent a notice to NSO Group itself, seeking details of the exploitation and its effect on Indian users. Two days later the IT minister, Ravi Shankar Prasad, told the Rajya Sabha that to the best of his knowledge no unauthorised interception had occurred — and, pressed by at least five MPs, declined to say whether any arm of government had bought Pegasus. The question was never answered. The Pegasus Project reporting of July 2021 forced it back into the open; a Supreme Court-appointed committee later found malware on five of the 29 phones it examined without conclusively naming Pegasus, and recorded that the government had not cooperated. WhatsApp's suit ended in 2025: NSO held liable, a jury's $167 million punitive award cut by the judge to about $4 million, and a permanent injunction keeping NSO off WhatsApp for good.

AI Tech desk · November 2019

GPT-2, no longer too dangerous

On 5 November 2019 OpenAI released the full 1.5-billion-parameter GPT-2, the language model it had declared too dangerous to publish when our February desk opened this story — closing that arc in nine months, with the lab saying it had seen no strong evidence of misuse and publishing a detection model alongside the weights. The staged release drew mockery at the time; from 2026 it reads instead as the first draft of every frontier-release argument since, conducted over a model that now counts as small. The rest of the month sketched the decade ahead. At its AI Summit on 12 November, Intel demonstrated Nervana neural-network processors for training and inference, its first chips purpose-built for deep learning — then bought rival Habana Labs within weeks and wound Nervana down early the next year. And on 29 November China's cyberspace regulator published rules requiring AI-generated video and audio online to be prominently labelled from 1 January 2020, among the first attempts anywhere to make synthetic media announce itself — aimed at precisely the fabrications GPT-2's minders had feared.

Digital Guard desk · November 2019

The birth of NortonLifeLock

The industry's oldest name changed hands on 4 November 2019, when Broadcom completed its $10.7 billion purchase of Symantec's enterprise security business, taking the Symantec brand with it. The remainder — the consumer arm built around Norton and LifeLock — renamed itself NortonLifeLock and began trading on Nasdaq as NLOK the following day. It was the quiet end of the company that had anchored commercial antivirus for nearly three decades, and the start of one this archive tracks forward: the Avast merger and the Gen Digital rename run through our 2021 and 2022 desks. Enterprise Symantec, by most accounts, began a long retreat under its new owner. The month supplied a smaller lesson in glass houses. Check Point confirmed in mid-November that the forum of ZoneAlarm, its consumer brand, had been breached through an outdated vBulletin installation carrying a flaw patched in September, exposing names, email addresses, hashed passwords and dates of birth of roughly 4,500 users — those affected, it said, contacted within a day.

⏳ Time capsule — November 2019

  • Germany marked 30 years since the fall of the Berlin Wall on 9 November.
  • An exceptional 187 cm tide flooded Venice on 12 November — the city's worst water since 1966.
  • Tesla unveiled the Cybertruck on 21 November; its supposedly shatterproof windows cracked live on stage.
  • Hong Kong's district council elections on 24 November drew record turnout and a sweeping pro-democracy result.
Where it stands today — 2026

The threat was already inside

November 2019 gave this archive its cleanest statement of a theme that never left: the credential problem is a people problem. Abouammo's 2022 conviction made the Twitter case the standing reference for platform-insider risk — invoked again when a Twitter whistleblower told the US Congress in September 2022 that far too many employees still held access to core systems, and every time since that a trusted staffer has turned up at the centre of a breach. Trend Micro's rogue employee, meanwhile, fed an industry that outlived him: the fake support call armed with real customer data runs through the following years of these pages, all the way to the digital-arrest scams India's desk tracks in 2026.

The month's other thread ran through refusal. Pemex would not pay; neither would Louisiana, whose state government spent 18 November fighting a Ryuk infection under its second cyber emergency of the year, nor a Wisconsin provider whose ransomed servers held the records of more than a hundred nursing homes. Eleven days after Pemex's note, the Maze gang answered the refusals by publishing a victim's stolen files — the turn December's edition, Steal, Encrypt, Publish, follows into the leak-site decade. DoppelPaymer itself lasted until 2023, when German and Ukrainian police, with Europol and the FBI, moved against its suspected core members. The Vault continues backwards from here, and the chain holds.