The Washington Post, Germany's ZDF and Swiss broadcaster SRF published a joint investigation on 11 February 2020 that settled one of the Cold War's oldest rumours. Crypto AG — the company in Zug whose cipher machines more than 120 countries, India and Pakistan among them, had bought to protect their most sensitive traffic — had been secretly owned since 1970 by the CIA and Germany's BND, under an operation code-named Thesaurus and later Rubicon. The machines were rigged. The agencies approved the hiring, shaped the algorithms and read the customers' messages for decades, while the customers paid full price for the equipment. A classified CIA history, leaked to the reporters, called it "the intelligence coup of the century".
The secret nearly surfaced more than once. In 1986, Ronald Reagan announced on television that intercepted traffic between Tripoli and its East Berlin embassy proved Libya's hand in the La Belle discotheque bombing — as close as a president could come to telling Crypto's customers what their machines really did. In March 1992, Iran arrested Hans Bühler, the company's star salesman, and held him for nine months; he knew nothing about the rigging, which is why he survived the interrogations. Crypto AG paid one million dollars to bring him home, dismissed him, then tried to recover the money from him personally. Bühler's public questions helped push a nervous BND to sell out in the early 1990s. The CIA simply carried on, alone, until it liquidated the company in 2018.
Switzerland's reckoning had, in fact, begun before the cameras arrived. The Federal Council appointed a former federal judge, Niklaus Oberholzer, to investigate on 15 January 2020 — nearly a month before publication — and parliament's intelligence oversight delegation opened a second inquiry on 13 February. That November, the delegation's report concluded the Swiss intelligence service had known of the foreign ownership since 1993 and had kept the knowledge from the government it served. Export controls fell on Crypto International, the successor firm that had bought the brand in 2018 and inherited none of the guilt. The machines' era was already over; what ended in February 2020 was the older Swiss product that had always sold them — neutrality.
No prosecution for the espionage itself ever followed, in Bern or anywhere else; the machines had done exactly what their true owners built them to do. That is why the story leads this edition. Nothing was hacked and nothing was breached. The compromise was manufactured on a production line, sold at full price, installed by its victims and maintained under service contract for half a century. Every later edition of the Vault that weighs whether a vendor, a router or an update server deserves trust is asking the question Zug answered on 11 February 2020 — and most of the engineers who spent careers building those machines learned what the work had been for the way everyone else did: from the news.
The Equifax breach gets faces
On 10 February, Attorney General William Barr announced a nine-count indictment against four officers of China's People's Liberation Army — Wu Zhiyong, Wang Qian, Xu Ke and Liu Lei, of the 54th Research Institute — for the 2017 Equifax breach, the theft of personal files on approximately 145 million Americans. Barr called it "an organized and remarkably brazen criminal heist"; the indictment, returned by a federal grand jury in Atlanta, alleged the four spent weeks inside the credit bureau's networks after entering through an unpatched web-application flaw, taking database designs along with the data. Two details gave the announcement its shape. First, officials noted the stolen records had never surfaced for sale — the signature of intelligence collection rather than fraud. Second, everyone in the room understood the defendants would never appear: Beijing rejected the accusation, and China does not extradite its soldiers. Six years on, the four faces remain where they were filed in February 2020 — on FBI wanted posters, unarrested, the formal answer to a question 145 million people never asked to be part of.
The guest list gets out
ZDNet reported on 19 February that the personal details of more than 10.6 million MGM Resorts guests had been posted to a hacking forum — names, home addresses, dates of birth, phone numbers and email addresses, free to anyone who found the thread. Reporters identified government officials, tech executives and celebrities among the rows, Justin Bieber and Twitter's Jack Dorsey included. MGM confirmed the data came from unauthorised access to a cloud server discovered in summer 2019, said it had notified affected guests that year as state laws required, and stressed that no payment-card or password data was involved; about 1,300 of the records held more sensitive detail, including passport numbers. The dates are the story: stolen in 2019, disclosed in 2019, the data became truly public in February 2020, when it stopped being a criminal's asset and became everyone's liability. In July, a dark-web seller claimed the real haul was 142 million records; MGM never confirmed that figure, and this archive records it as what it was — a sales pitch. The company's next appearance in these pages, in September 2023, would empty its casino floors instead.
The scans were on the open internet
In the first week of February, Indian newsrooms picked up a report by the German security firm Greenbone Networks with a number that resisted comprehension: 121 million medical images belonging to Indian patients — X-rays, CT and MRI scans — reachable on the open internet, alongside records of more than a million patients. This was not an intrusion. Radiology departments store images on picture archiving and communication systems, PACS, and Greenbone counted 97 such systems in India answering to anyone who asked, no password required. The files carried names, dates of birth, national identifiers, medical histories and physicians' names. Coverage named institutions from Mumbai's Breach Candy Hospital to the imaging provider Utkarsh Scans, and reported Maharashtra the worst-affected state, with Karnataka second. Greenbone had first warned about exposed medical archives the previous autumn; when it looked again, the global count had grown by 60 per cent, to 1.19 billion images.
Nobody had to tell the patients: India in February 2020 had no data protection law, the health-data bill drafted two years earlier had gone nowhere, and the Personal Data Protection Bill sat with a parliamentary committee, where it would eventually be withdrawn. Nothing here was shown to have been stolen — the exposure was the injury, and it fell on people at their most vulnerable, photographed from the inside. The archive's later editions record how the story continued: ransomware inside AIIMS in November 2022, and a privacy law finally passed in August 2023, its rules arriving years after the scans went online. The patients of 2020 remain the cautionary tale a decade of policy was written around.
The largest model ever published, briefly
Microsoft's research division announced Turing-NLG on 10 February — a language model of 17 billion parameters, the largest yet published and roughly twice the size of the Nvidia model whose record it took. It wrote direct answers to questions and abstractive summaries of documents, and Microsoft open-sourced DeepSpeed, the training library that made it feasible, the same day. The record lasted a season — OpenAI's GPT-3, ten times larger, arrived in May — and the library outlived the model it was built to carry. The month's other lesson was colder. On 26 February, Clearview AI, the facial-recognition firm that had scraped three billion photos from the public web, notified customers that an intruder had stolen its entire client list. The company said its servers were not breached and the flaw had been fixed; the roster of agencies surfaced in the press anyway, and regulators on three continents spent the following years ordering the firm to delete their citizens' faces. A company built on collecting other people's data had failed to keep hold of its own.
Security's last full house before the lockdown
RSA Conference 2020 opened at San Francisco's Moscone Center on 24 February under the theme "Human Element", and the industry supplied it: 36,000 attendees by the organisers' count, at what would prove the last full-scale security gathering before the pandemic. The virus was already on the programme's margins — IBM, a platinum sponsor, had pulled out on 14 February, AT&T Cybersecurity and Verizon followed within the week, fourteen sponsors and exhibitors stayed away in all — and on the conference's second day the host city declared a precautionary state of emergency. Within three weeks San Francisco ordered its residents home, and the next RSA Conference would be held on screens. The month's quieter change came at McAfee, where Peter Leav, lately of BMC Software, took over as chief executive from Chris Young on 3 February. He inherited the industry's most recognisable brand, and the hindsight is brisk: a return to the stock market within the year, the enterprise business sold the year after, and the company private again by the time he left in 2022.
⏳ Time capsule — February 2020
- Parasite won Best Picture at the Academy Awards on 9 February — the first film not in the English language to take the top prize.
- The World Health Organization announced "COVID-19" as the name of the new coronavirus disease on 11 February.
- Global stock markets recorded their worst week since the 2008 financial crisis in the final week of February, as the outbreak spread beyond China.
- The United States and the Taliban signed the Doha agreement on 29 February — a leap-day signature setting the terms of the American withdrawal from Afghanistan.
The oldest story in the archive
Rubicon reaches further back than anything else in the Vault — to 1970 — and further forward than most of it. The question it left, whether the equipment itself can be trusted, is the spine of this archive's next six years: SolarWinds arrives ten months later in the December 2020 edition; the 2021 restorations trace the supply-chain year that followed; and the 2024 and 2025 editions record state operators living inside telecom infrastructure itself, reading traffic at the switch the way Langley once read it at the rotor. The Equifax indictment set a durable template too — named officers, formal charges, no realistic trial — one the archive's later years reach for again and again.
India's thread begins here in earnest as well: scanners answering the open internet in February 2020, ransomware inside AIIMS in the November 2022 edition, CERT-In's six-hour reporting rule that same year, and a data protection Act in August 2023 whose operating rules arrived only at the end of 2025. And hanging over every page of this edition is what its readers could not know: within weeks the offices would empty, the perimeter would dissolve, and the decade of remote everything would begin — the March 2020 edition sits next door. The Vault continues backwards from here. Every month restored is another month the present turns out to have been rehearsing.