The tills went quiet on New Year's Eve. Travelex — the world's largest retail foreign-exchange dealer, with some 1,200 branches and kiosks across more than 70 countries — pulled its websites offline in around 30 markets, replacing them with apologies for "planned maintenance". On 2 January the company said only that a "software virus" had been found and contained. Behind the holding pages, its network had been encrypted. At the airport counters the cash drawers still had money in them, so staff kept trading the old way — pen, paper, a calculator, receipts written out by hand — while every screen in the branch stayed dark.
The blast radius reached the high-street banks. Barclays, Lloyds, HSBC and Royal Bank of Scotland, along with Sainsbury's Bank, Tesco Bank and Virgin Money, all ran their travel-money services on Travelex's rails, and for weeks none of them could process an online currency order. On 7 January the company confirmed what the holding pages had concealed: ransomware, Sodinokibi, the strain also called REvil. The gang told journalists it had copied five gigabytes of customer data — dates of birth, card numbers, national-insurance numbers — and would sell it unless paid; the demand was reported at $3 million, doubling to $6 million when a deadline lapsed. Travelex maintained it had found no evidence that customer data had left its systems.
The ending arrived in instalments. Services crept back through late January and February, in-store first, online later. Then, on 9 April 2020, the Wall Street Journal reported — citing people familiar with the transaction — that Travelex had paid its extortionists 285 Bitcoin, about $2.3 million, to get its network back. The company has never confirmed or denied it. By that point the hack was the smaller of its problems: its parent, Finablr, was collapsing in an accounting scandal, and the pandemic had emptied the airports a currency trader lives on. Whatever the ransom bought, it bought a business whose customers were about to stop flying.
On 6 August 2020 Travelex entered administration. PwC's restructuring kept the brand alive under its lenders' ownership and cut more than 1,300 UK jobs; the collapse was attributed to the ransomware attack and Covid-19 together — one company felled by both kinds of virus in a single year. That is why this edition opens the archive's 2020: the decade of ransomware that runs through these pages — hospitals, pipelines, meatpackers, the Royal Mail — begins with a 44-year-old high-street name reduced to receipt books by people it never saw. The notice on the website said planned maintenance. It was neither planned nor maintenance.
The day the updates stopped
Microsoft's Patch Tuesday fell on 14 January, and it was two landmarks at once. Windows 7 received its final free security update that day, ten years after launch, with estimates of the machines still running it ranging from about 200 million to well over 400 million. The same day's patches fixed CVE-2020-0601, a certificate-validation flaw in the cryptographic core of Windows 10 and Windows Server that could make malicious code appear legitimately signed. The surprise was the reporter: the National Security Agency, publicly credited by Microsoft for the first time. On a press call, NSA cybersecurity director Anne Neuberger said the flaw "makes trust vulnerable" — and that handing it over, rather than quietly using it, marked a deliberate change of approach. Researchers published proof-of-concept exploits for the flaw, nicknamed CurveBall, within two days. The calendar's irony: the hundreds of millions of PCs leaving support that morning were not even affected; the fully patched ones were. And across the internet, unpatched Citrix gateways — under active exploitation since around 8 January, en masse once public exploit code appeared on the 10th — waited for fixes that only shipped between the 19th and the 24th.
The antivirus was watching
On 27 January a joint investigation by Motherboard and PCMag, built on leaked internal documents, revealed that Avast — free antivirus with around 435 million monthly users — had been packaging its users' browsing histories and selling them through a subsidiary called Jumpshot, which claimed data from 100 million devices. The offering included an "All Clicks Feed": every click, timestamped to the millisecond, from Google searches and Maps lookups to LinkedIn pages and porn sites. Documents named clients including Home Depot, Google, Microsoft, Pepsi and McKinsey. The data was stripped of names, but reporters showed how readily a device-level click trail could be re-identified; users had technically consented, and several told reporters they had no idea. On 30 January, chief executive Ondrej Vlcek announced Jumpshot would be wound down — three days from exposure to shutdown. The coda came four years later, when the US Federal Trade Commission fined Avast $16.5 million and banned it from selling browsing data. An antivirus asks to see everything on the promise that it looks for one thing only. Avast had found a second use for the view.
The long tail of 14 January
For India, Windows 7's retirement was less a deadline than the middle of a queue. The Reserve Bank had ordered banks off end-of-life Windows before — a June 2018 directive gave them until June 2019 to migrate ATMs from Windows XP, which still ran a large majority of the country's cash machines when it was issued — and by December 2019 the business press was reporting that banks had missed deadline after deadline under RBI and home-ministry circulars on ATM security. Much of what had been upgraded had been upgraded to Windows 7. On 14 January 2020 that replacement itself fell out of support, joining the small-business tills and government desktops that make India's installed base long-tailed by design: hardware is sweated here, and an operating system's funeral is observed years late. CERT-In, the national incident-response agency, logged 3,94,499 security incidents in 2019 — nearly double the previous year, the IT ministry later told Parliament.
January also held an Indian breach nobody knew about yet. When some 22 million Unacademy user records were found for sale on a dark-web forum in May 2020 — spotted by researchers at Cyble, priced at $2,000 — the newest account in the stolen database was dated 26 January 2020, placing the intrusion in or around this edition's month. The Bengaluru learning platform confirmed the breach; co-founder Hemesh Singh said about 11 million users were affected and passwords were strongly hashed. Usernames, names and email addresses travelled anyway. The Vault records it here, in the month the door most likely opened, with the month it became public stated plainly — reading the past with the dates straight is what this archive is for.
The company that scraped three billion faces
On 18 January the New York Times published Kashmir Hill's investigation of Clearview AI, a small New York firm that had scraped more than three billion face images from social networks and the open web and sold search access to police forces. The headline — "The Secretive Company That Might End Privacy as We Know It" — set the terms of the facial-recognition argument for years, through fines across Europe and a settlement that restricted whom Clearview could sell to in America. Eleven days later Facebook agreed to pay $550 million, then a record for a privacy suit, to settle Illinois claims over its own face-tagging database. And on 28 January, barely noticed beside the face wars, Google researchers unveiled Meena, a 2.6-billion-parameter chatbot trained on public social-media conversation and scored on whether its replies made sense; Google, citing safety, declined to release it. Refined into LaMDA, it became an ancestor of Bard and the Gemini era — the chatbot decade began this month, in a lab, behind a closed door.
The afterlife of Windows 7
When Microsoft shipped Windows 7's last free patches on 14 January, the antivirus industry stepped forward as the operating system's afterlife. Avast and AVG pledged to keep their products, business editions included, updated on Windows 7 for at least two more years; Bitdefender and Trend Micro gave similar assurances; Avira committed to November 2022; Sophos published end-dates of its own; and the German test lab AV-TEST kept a running list of who would still defend the abandoned machines. It was sound business — an enormous installed base was going nowhere, and a definitions update asks nothing of Microsoft — and many pledges were later extended rather than allowed to lapse, a rehearsal for the industry's role when Windows 10 followed in October 2025. The rest of the month's industry news was consolidation and contraction: on 7 January Accenture agreed to buy Symantec's Cyber Security Services business from Broadcom, and by 30 January Avast was winding down Jumpshot — the reckoning this edition's briefs record.
⏳ Time capsule — January 2020
- Chinese authorities sealed off Wuhan, a city of 11 million people, on 23 January; on 30 January the WHO declared the novel coronavirus a public-health emergency of international concern.
- The Duke and Duchess of Sussex announced on 8 January that they would step back as senior members of the Royal Family.
- Basketball great Kobe Bryant, his daughter Gianna and seven others died in a helicopter crash near Calabasas, California on 26 January.
- The United Kingdom formally left the European Union at 11pm on 31 January, after 47 years of membership.
The decade opens
REvil runs forward from Travelex through this archive like a fault line — the Kaseya long weekend of July 2021, the Moscow arrests of January 2022 — and the question Travelex answered quietly became the debate these pages return to most: pay in silence, or refuse in public, as Royal Mail did in January 2023 and as Britain proposed to make law for the public sector in 2025. Citrix's unpatched gateways set a template too. Exploited for a fortnight before fixes shipped, they were the first mass demonstration of the edge-appliance disaster, rehearsed again at Exchange in March 2021, at MOVEit in June 2023, and at the VPN gateways of January 2024 — an edition named for a government instruction: disconnect it now.
The quieter threads run just as far. Windows 7's funeral was a rehearsal for the one this archive records in October 2025, when Windows 10 followed with hundreds of millions of machines still aboard. Avast's Jumpshot, wound down three days after exposure, met its real ending in 2024: a $16.5 million Federal Trade Commission penalty and a ban on selling browsing data. Even the month's strangest story — UN experts alleging, on forensics other researchers disputed and Saudi Arabia dismissed as absurd, that Jeff Bezos's phone had been hacked via a WhatsApp account of the Saudi crown prince — prefigured the zero-click spyware era of this archive's September 2021. January 2020 believed its biggest story was a currency counter gone dark. Every restored year since has argued about which of its threads mattered more.