The discovery that defined the month began with a second phone. A member of FireEye's security team noticed that an employee appeared to have two devices registered for network sign-in, and rang him to check. He had not registered the second one. Someone else, using his credentials, had. On 8 December 2020, the company other organisations call when they have been breached announced that it had been breached itself, by an attacker it assessed as a nation-state, and that its red-team tools — the software it uses to imitate adversaries on clients' networks — had been stolen. FireEye published detection countermeasures for all of them the same day, noting that none of the stolen tools contained zero-day exploits.
The harder question was how the intruders got in, and the answer, made public on 13 December, reached far beyond one security firm. Attackers had compromised the build system of SolarWinds, an Austin company with roughly 300,000 customers, and hidden a backdoor — nearly 4,000 lines of code FireEye named SUNBURST — inside legitimately signed updates for its Orion network-monitoring product, shipped between March and June 2020. Once installed, the implant waited up to two weeks before quietly calling home. SolarWinds told regulators that fewer than 18,000 customers may have installed a poisoned build. The operation had been rehearsed: an inert test snippet had ridden an Orion update as early as autumn 2019, proving the delivery route worked before anything hostile was sent down it.
Government moved with unusual speed. Late on 13 December, CISA issued Emergency Directive 21-01, ordering federal civilian agencies not to patch their SolarWinds Orion servers but to disconnect or power them down, and to treat every host they monitored as compromised. Reporting that week placed intruders inside the Treasury and Commerce departments first, then State, Homeland Security and the National Institutes of Health; on 17 December the Energy Department confirmed unusual activity, saying it was isolated to business networks and had not reached national-security functions, including the National Nuclear Security Administration. Microsoft, working the case alongside FireEye, said it had notified more than forty of its own customers whom the attackers had singled out for a second, hands-on stage of intrusion.
The month closed with a measured admission from Redmond. On 31 December, Microsoft said its investigation had found one internal account used to view source code in a number of repositories; the account could not modify anything, and the company argued that reading its code raised no fundamental risk, because it does not treat the secrecy of source code as a security boundary. It was a fitting end to a month in which the worst news kept arriving in careful corporate prose. What December established was the shape of the thing: a routine update as the way in, and a victim willing to investigate its own humiliation in public. What it could not yet establish — who, and to what end — belonged to January.
Papers for the most wanted product on earth
The same month the first doses went into arms, the infrastructure around the COVID-19 vaccine came under deliberate attack. On 3 December, IBM's X-Force warned of a precision phishing campaign, running since September, that impersonated an executive of a Chinese cold-chain company to harvest credentials from organisations across six countries involved in keeping vaccines frozen in transit — targeting IBM judged consistent with a state actor, though it made no attribution. Six days later the European Medicines Agency, then twelve days from ruling on the Pfizer/BioNTech vaccine, disclosed it had been hacked. Regulatory submission documents for the vaccine, held on an EMA server, had been accessed; BioNTech said its own systems and Pfizer's were not breached. The agency approved the vaccine on 21 December regardless. The ending came later, and was stranger: leaked documents surfaced online around the turn of the year, and in mid-January the EMA said some of the correspondence had been manipulated before publication in a way that could undermine trust in vaccines. Not theft for advantage — theft for disinformation.
Ticketmaster's $10 million password problem
Not every intrusion that month was the work of a foreign intelligence service. On 30 December, US federal prosecutors in Brooklyn announced that Ticketmaster would pay a $10 million criminal penalty, under a deferred prosecution agreement, over charges of computer intrusion and wire fraud for repeatedly accessing the systems of a rival ticketing startup between August 2013 and December 2015. The method was not sophisticated: a former employee of the rival, Songkick, joined Ticketmaster and brought his old passwords with him. Colleagues used the retained credentials to open the startup's draft ticketing pages and non-public data, the better to identify its clients and dissuade them from doing business with it. Ticketmaster had already paid $110 million in 2018 to settle Songkick's civil suit; the new agreement obliged it to maintain a compliance programme designed to detect and prevent computer-hacking violations — an obligation whose necessity was, by then, a matter of record.
Seven million cardholders, one open Google Drive link
On 8 December — a date the rest of this edition remembers for other reasons — the independent security researcher Rajshekhar Rajaharia reported a quieter Indian exposure: a roughly two-gigabyte database covering about seven million Indian credit and debit cardholders, hawked on the dark web yet sitting, in the end, on an ordinary public Google Drive link. The records, spanning 2010 to 2019, carried names, phone numbers, email addresses, employers and annual incomes, with account types and — for about five lakh people — PAN numbers attached. Card numbers themselves were absent, and that is precisely why the file mattered: everything in it was aimed at the human being rather than the card. Rajaharia checked dozens of the named entries against public LinkedIn profiles, and the details held up.
His reading of the likely source was mundane and, for that reason, damning: not a bank's core systems but the third-party sellers banks use to push cards — one of the quiet data-sharing arrangements Indian finance runs on. No company confirmed ownership of the file, and no further attacker needed to exist for the harm to be real; a phishing caller armed with a target's employer, income band and phone number does not need the card number too. It capped a bruising year for Indian data, after Unacademy in May and BigBasket in November, and weeks later the same researcher would surface the JusPay card leak, disclosed in the new year. All of it landed in a country whose data protection bill was still sitting with a parliamentary committee — the wait for the DPDP Act had nearly three more years to run.
The paper Google would not publish
On the evening of 2 December 2020, Timnit Gebru, co-lead of Google's Ethical AI team, announced that the company had pushed her out in a dispute over a research paper — "On the Dangers of Stochastic Parrots", written with the linguist Emily Bender and others — questioning the costs and biases of ever-larger language models. Google maintained it had accepted her resignation and that the paper had not met its bar for publication; Gebru said she had resigned nothing and been fired. A protest letter drew thousands of signatures from inside and outside the company, and engineers resigned over it. The rupture ran for years: her co-lead Margaret Mitchell was dismissed in February 2021, as that month's desk records, while the paper, published the following March, became one of the most-cited critiques of large language models — its title the standard shorthand once chatbots arrived. Quieter but durable, DeepMind's MuZero appeared in Nature on 23 December: an agent that mastered Go, chess, shogi and Atari without being told their rules, planning with a model it learned itself.
Turning a beacon into a killswitch
While the cover story unfolded, the trade mounted its fastest collective response to date. The countermeasures FireEye released on 8 December for its stolen red-team tools took the form of machine-readable rules — Snort, Yara and ClamAV signatures posted to a public repository — which rival vendors folded into their own products within days. Once SUNBURST was identified on 13 December, detections followed the same path; Microsoft, tracking the backdoor as Solorigate, added it to Defender, then on 16 December escalated from merely alerting on the trojanised Orion binaries to quarantining them outright, accepting that stopping a network-monitoring tool mid-run was now the lesser harm. The odder stroke came the same week: with GoDaddy, the domain's registrar, FireEye and Microsoft turned avsvmcloud[.]com — the address every SUNBURST implant called home to — into a killswitch, serving replies that caused the backdoor to disable itself, though FireEye cautioned this would not evict intruders already dug in elsewhere. The fortnight became the template for coordinated vendor response; FireEye itself would be split within two years, its Mandiant half bought by Google.
⏳ Time capsule — December 2020
- Mass COVID-19 vaccination began on 8 December: 90-year-old Margaret Keenan received the first Pfizer-BioNTech dose given outside clinical trials, at University Hospital Coventry.
- Cyberpunk 2077 launched on 10 December so broken on older consoles that Sony later pulled it from the PlayStation Store entirely and offered full refunds.
- A software developer, a mathematician and a Belgian codebreaker solved the Zodiac Killer's 340-character cipher after 51 years; the FBI confirmed the solution on 11 December.
- The United Kingdom and the European Union reached their post-Brexit Trade and Cooperation Agreement on 24 December — a Christmas Eve deal, seven days before the transition period ended.
What December seeded
Nothing in this archive radiates further than December 2020. The following month — covered in the next edition — brought the US intelligence community's first formal word, "likely Russian in origin", and the discovery that the same actor had reached Malwarebytes and Mimecast, not always through SolarWinds at all; April 2021 brought sanctions and the formal naming of Russia's SVR. Investigators eventually put the deep intrusions at nine federal agencies and roughly a hundred companies. The lesson outlived the incident: Washington's 2021 executive order made software bills of materials procurement language, and when Log4j shook every dependency tree in December 2021, and 3CX and XZ Utils followed in later years of these pages, each was read by the light SUNBURST had lit.
December's quieter items ran long threads too. NortonLifeLock's 7 December agreement to buy Avira for $360 million — a company Investcorp had bought for half that eight months earlier — closed in the new year, as our January 2021 desk records; by late 2022 the buyer had merged with Avast and renamed itself Gen Digital, the consolidation Digital Guard traces today. The EMA leak's manipulated documents previewed the breach-to-disinformation play these pages meet again and again. And India's seven million cardholders were an early sighting of a pattern — researcher finds file, companies stay silent, law lags — that runs through JusPay and MobiKwik to CERT-In's six-hour rule and the DPDP Act. The Vault continues backwards from here; 2020 still has eleven months to give up.