The month opened with a confession. On 1 April 2020, with much of the world newly confined to its home, Zoom chief executive Eric Yuan announced that the platform's usage had outrun anything it was designed for: a maximum of roughly 10 million daily meeting participants in December had become more than 200 million in March. Cabinet meetings, funerals, weddings and entire school systems now ran on software built for corporate IT departments, and Yuan froze every new feature for 90 days, turning the company's engineers wholly to security and privacy. The FBI had warned about "Zoom-bombing" two days earlier, after intruders forced their way into online classrooms. April would be the month the audit happened in public.
The reckoning was quick. On 3 April, researchers at the University of Toronto's Citizen Lab reported that Zoom's advertised end-to-end encryption was nothing of the sort: meetings used a single AES-128 key in a mode that preserves patterns in what it scrambles, and in test calls between North American participants the key was sometimes issued by servers in Beijing. The lab judged the platform unsuited to governments worried about espionage or businesses fearing industrial spying; Zoom conceded meetings had at times been mistakenly routed through China. The same day, US federal prosecutors warned that meeting hijackers could face criminal charges. Within the week, Taiwan barred Zoom from government use, Google banned it from employee laptops, and New York City's education department told teachers to drop it.
Then came the logins. On 13 April the threat-intelligence firm Cyble reported buying roughly 530,000 Zoom credentials on criminal forums at $0.002 apiece — a fifth of a cent — with early batches given away free to build criminal reputation. This was not a breach of Zoom itself but credential stuffing: passwords reused from older leaks, tried at scale until they worked, among them accounts registered to major banks and universities. Each record carried an email address, password, personal meeting URL and host key. The technique claimed a second name before the month closed: Nintendo confirmed on 24 April that 160,000 accounts had been entered with credentials obtained elsewhere — a figure it would raise to 300,000 by June. Zoom had become critical infrastructure in three weeks; the keys were selling for a rounding error.
Repair came fast. Former Facebook security chief Alex Stamos signed on as an outside adviser, and on 22 April the company announced Zoom 5.0, moving meetings to AES-256 encryption in GCM mode, switched on across every account by 30 May. The same announcement claimed 300 million daily users; within days the phrase was quietly edited to 300 million daily meeting participants — a person counted afresh for every meeting joined — and on 30 April Zoom admitted the error. The endings are known now: end-to-end encryption arrived in October 2020; the Federal Trade Commission settled charges that November that Zoom had misled users about encryption — a mandated security programme, no fine; and an $85 million class settlement over privacy and Zoombombing followed in 2021. The verb survived the year better than the reputation did.
Maze hits the company that runs other companies
On Saturday 18 April, Cognizant — one of the world's largest IT services firms, with roughly 300,000 employees, most of them in India — confirmed that a security incident disrupting services for some clients was a Maze ransomware attack. The disclosure carried a strange coda: when reporters reached Maze, the gang denied responsibility — an attribution dispute this archive records as exactly that. Cognizant had already emailed clients lists of indicators of compromise, IP addresses and file hashes, so they could sever connections and hunt for infection; its customers learned the details from monitoring lists rather than a press release. The financial reckoning came on the May earnings call: a projected $50–70 million hit to second-quarter revenue plus remediation and legal costs — lost business, not a ransom figure, whatever later retellings claimed. The same week, the RagnarLocker gang hit Portugal's energy group EDP, demanding roughly $11 million and claiming 10 terabytes of stolen files — the criminals' figure, never confirmed by the company, which said power supply was never touched. Steal first, encrypt second, threaten always: the playbook this archive watched Maze invent in late 2019 was now everyone's.
Apple and Google, on the same side
On 10 April, Apple and Google announced something without precedent: a jointly built system, baked into both iOS and Android, to notify people exposed to COVID-19. The design was pointedly privacy-preserving. Phones would exchange rotating Bluetooth identifiers that changed every 15 to 20 minutes; matching happened on the device; location data was not collected at all. Even the language was corrected mid-stream — what launched as "contact tracing" was renamed an "exposure notification" service in late April, a truer description of what the technology could honestly promise. The API shipped to public-health authorities on 20 May, and national health apps on several continents were built on it. The hindsight verdict is mixed: adoption never reached the levels epidemiologists hoped for, and the apps were quietly retired as the pandemic ebbed. But as an artefact of April 2020 it stands — the fiercest rivalry in computing suspended, inside a fortnight, to argue about privacy engineering instead.
Delhi declares Zoom unsafe — and ships its own app
India's work-from-home migration ran head-first into the Zoom question. CERT-In, the national incident-response agency, had issued advisories on 6 February and 30 March about the platform's weaknesses and safe configuration. On 16 April the Ministry of Home Affairs went further: an advisory from its Cyber Coordination Centre declared that Zoom "is not a safe platform" and barred its use by government officers for official meetings. Private citizens were not forbidden it; instead the ministry published survival rules for those who stayed: fresh meeting IDs and passwords for every call, waiting rooms switched on, screen-sharing restricted to the host, entry locked once a meeting began. The country under the world's largest lockdown would keep meeting on Zoom — but the Indian state, formally, would not.
The same fortnight, the government shipped its own pandemic software. Aarogya Setu, a contact-tracing app built by the National Informatics Centre, launched on 2 April and reached 50 million installs in 13 days — by the government's telling, faster than any app before it, Pokémon Go included. Its design ran opposite to the Apple–Google model announced the same month: alongside Bluetooth it collected GPS location, and name, number, gender and travel history flowed to government servers under terms that disclaimed liability — in a country that had no data protection statute. By 29 April, central government employees were directed to use it. The sharper technical scrutiny — a French researcher pulling the app apart finding by finding — arrived in early May, and belongs to next month's edition.
Facebook's chatbot, OpenAI's jukebox
The laboratories, working from home like everyone else, closed the month with a flourish. On 29 April Facebook AI released Blender, an open-domain chatbot open-sourced at 9.4 billion parameters — then a record — pre-trained on 1.5 billion Reddit conversations and fine-tuned to blend personality, knowledge and empathy in a single model; human evaluators preferred it to Google's Meena, though Facebook conceded it would contradict itself and invent facts if pressed for long. A day later OpenAI published Jukebox, a neural network that generated music as raw audio, rudimentary singing included, conditioned on genre, artist and lyrics — at a cost of roughly nine hours of computation for one minute of sound. Even the field's gatherings migrated: ICLR, planned for Addis Ababa, ran entirely online from 26 April. From 2026 the signposts are legible — Facebook's habit of releasing models openly ran through BlenderBot to the Llama family, and Jukebox's raw-audio ambition anticipated the commercial music generators, and the licensing arguments, of the mid-decade.
Eighteen million lures a day
For the defence industry, April was the month the pandemic became the threat model. On 1 April Microsoft sent what it called a first-of-its-kind targeted notification to several dozen hospitals running vulnerable VPN and gateway appliances — equipment the REvil ransomware gang was actively probing just as remote work made it indispensable. Its follow-up on 28 April was bleaker: multiple ransomware crews had launched dozens of attacks in the first two weeks of the month, many from footholds established long before and held until downtime hurt most. Google, on 16 April, measured the lure: Gmail was blocking 18 million coronavirus-themed malware and phishing messages a day, on top of more than 240 million pandemic-related spam messages. The strangest item came from the criminals themselves: the operators of Shade ransomware announced their retirement on 26 April, apologised to victims, and published roughly 750,000 decryption keys, which Kaspersky confirmed were genuine and folded into a free decryptor. Six years on, hospitals never left the target list; retirements with an apology stayed rare.
⏳ Time capsule — April 2020
- US oil prices went negative for the first time in history on 20 April, with West Texas Intermediate futures settling at −$37.63 a barrel.
- Captain Tom Moore, 99, completed 100 laps of his Bedfordshire garden on 16 April; his NHS charities appeal closed on his 100th birthday having raised £32.8 million.
- ESPN premiered The Last Dance, its Michael Jordan documentary, on 19 April — to a locked-down audience with no live sport to watch.
- The Pentagon officially released three US Navy videos of "unidentified aerial phenomena" on 27 April.
The month the world logged on
April 2020 is the hinge on which this archive's next six years turn. The overnight dependence on remote-access software — videoconferencing, VPNs, remote desktops — created the attack surface that ransomware crews spent the following two years mining, and Maze's tactic of stealing data before encrypting it became the standard playbook of the gangs that stopped fuel pipelines and meat plants in the May and June 2021 editions. Cognizant's $50–70 million was an early lesson this archive relearns yearly: the cost of ransomware is mostly the absence of business, not the ransom. And half a million stuffed Zoom logins previewed a truth that never expired — a password reused in 2012 was a working key in 2020, and somewhere it still is in 2026.
The Indian threads run just as long. Aarogya Setu's April — a state app, 50 million downloads in 13 days, governed by terms and conditions rather than a statute — is the opening scene of the privacy story that runs through these pages to the DPDP Act's passage in August 2023 and its slow grind into force. The Home Ministry's Zoom advisory marked the moment videoconferencing became a question of sovereignty, and CERT-In, the agency behind those February and March advisories, returns in 2022 with a six-hour reporting rule. The Apple–Google handshake expired with the pandemic; the argument it started, about engineering privacy into surveillance, never did. The Vault continues backwards from here.