The ransomware began encrypting systems at Brno University Hospital at around two o'clock in the morning of Friday 13 March 2020 — hours after the Czech Republic, its coronavirus cases climbing past a hundred, had declared a state of emergency. At five, the hospital's public-address system began repeating an instruction across the country's second-largest hospital: shut down your computers, immediately. By eight the network was off and scheduled surgeries were cancelled. Acute patients were moved to St Anne's, the city's other big hospital; the affiliated Children's Hospital was caught in the blast radius too. In the first week of Europe's pandemic, doctors and nurses fell back to paper and pen.

The timing was the injury. Brno ran one of the country's principal COVID-19 testing laboratories, and taking its systems offline delayed the analysis of samples at the moment throughput mattered most, while NÚKIB, the national cyber agency, worked the wards alongside clinicians. Nor was it an isolated grudge: the institutions fighting the virus were being probed everywhere that fortnight. From 13 March, a phishing site imitating the World Health Organization's internal email system tried to harvest staff credentials — spotted by a New York lawyer and security researcher, Alexander Urbelis, and reported by Reuters on 23 March; the WHO said the attempt failed. In Washington on 15 March, the US health department logged a surge of suspicious traffic amid fake quarantine rumours spreading by text message. Officials said its systems were never breached.

Five days after Brno, the criminal economy staged a gesture. Canvassed by the news site BleepingComputer on 18 March, the operators of Maze pledged to stop "all activity versus all kinds of medical organizations" until the situation with the virus stabilised, and DoppelPaymer promised free decryption for any hospital hit by mistake. The pledge was already hollow. On 14 March, Maze had attacked Hammersmith Medicines Research, a London drug-trials firm that had tested the Ebola vaccine and stood ready to run trials for COVID-19 candidates. HMR halted the attack the same day — its managing director, Malcolm Boyce, said he would rather go out of business than pay — but data had been stolen, and on 21 March, three days into the truce, records of former trial volunteers appeared on Maze's leak site.

Brno rebuilt over the following weeks with NÚKIB alongside it, and the episode closed the way most of the era's hospital attacks would: no ransomware strain officially named in public, no attacker identified, no one charged. In April the agency warned that a wider campaign against Czech health institutions was coming; the attempts that followed were repelled. The truce fared no better. Read from 2026, the month's verdict is exact — the gangs' word was worth three days, and the restraint they advertised never arrived. Within six months German prosecutors were examining, and ultimately could not prove, whether a patient's death after an ambulance was diverted from a ransomed Düsseldorf hospital belonged to the attackers. Hospitals had become targets, and stayed targets.

Also that month · The perimeter dissolves

The office emptied in a fortnight

In the second half of March, most of the world's desk work left the building, and remote access was thrown open faster than it could be secured. Shodan, the search engine for internet-connected devices, measured the exposure: machines answering Remote Desktop Protocol on its standard port rose roughly 41 per cent over the month, with a similar climb on the non-standard ports administrators hoped would hide them. Barracuda counted the lure that followed the workers home — 137 coronavirus-themed spear-phishing detections in January, 1,188 in February, 9,116 in the first three weeks of March, a 667 per cent surge. Even Patch Tuesday misfired: vendor advisories on 10 March briefly described an unpatched, wormable flaw in Windows file-sharing — CVE-2020-0796, promptly nicknamed SMBGhost — forcing Microsoft into an out-of-band fix two days later. A public exploit arrived by June; the feared WannaCry sequel never did. And on 30 March, the FBI's Boston office made the month's newest intrusion official, warning of "Zoom-bombing" after strangers joined Massachusetts online classrooms — one shouting a teacher's home address.

Also that month · Two logins, 5.2 million guests

Marriott, sixteen months later

On 31 March, Marriott International disclosed its second major breach in sixteen months: information on approximately 5.2 million guests, taken through a guest-services application used at franchise properties. The dates repay attention. The activity began in mid-January 2020, using the login credentials of two employees at a franchise property; Marriott noticed the unexpected access at the end of February; guests learned of it a month after that. Exposed details included names, contact information, loyalty-account numbers, linked airline programmes, birth dates and stay preferences — though the company said it had no reason to believe passwords, payment cards, passports or national identity numbers were involved. Hindsight adds a precision the headlines blurred: the £18.4 million fine the UK regulator levied on Marriott that October punished the earlier Starwood breach, disclosed in 2018, not this one. This one simply confirmed the pattern — credentials, again, at the seam between a hotel chain and its franchisees.

India desk · March 2020

Four hours' notice, one letter of fraud

India's March compressed years of digitisation into a fortnight. The Janata Curfew emptied the streets on Sunday 22 March; two evenings later, the Prime Minister gave 1.3 billion people roughly four hours' notice of a 21-day nationwide lockdown beginning at midnight on 25 March. Work, school and worship moved onto phones overnight, and CERT-In marked the shift with a high-severity advisory on 26 March — "Cyber security during covid-19 outbreak" — urging hardened VPNs and warning of pandemic-themed phishing. On 28 March the government created PM CARES, a relief fund accepting donations over UPI — and within 48 hours, Delhi Police's cybercrime unit had flagged a counterfeit collection handle in circulation: pmcare@sbi, a single letter short of the genuine pmcares@sbi. The State Bank of India blocked the fake, a case was registered, and police asked donors to check the registered name before giving.

The scam needed no malware — only a lookalike name and the country's trust in a payment rail that had crossed a billion transactions a month the previous autumn. More counterfeit handles imitating the fund surfaced across several banks' UPI namespaces in the weeks that followed, and CERT-In issued alerts as the pattern spread. Read from 2026, this is the archive's first sighting of the fraud economy that shadows India's digital decade: social engineering running at UPI speed, from the KYC and utility-bill scams of the lockdown years to the organised "digital arrest" calls documented on this magazine's India desk. There was no data-protection statute then, and no six-hour reporting rule — only a police warning, a blocked handle, and the advice to read carefully before you pay.

AI Tech desk · March 2020

The White House Asks the Machines to Read

On 16 March the White House Office of Science and Technology Policy issued a call to action to America's AI researchers, and handed them the material to work on: CORD-19, the COVID-19 Open Research Dataset, assembled at speed by the Allen Institute for AI with Microsoft, the National Library of Medicine, Georgetown's CSET and the Chan Zuckerberg Initiative. It opened with some 29,000 scholarly articles on the coronavirus family — machine-readable, free, and posted to Kaggle alongside the scientific questions most urgently in need of answers. The mobilisation ran wider than text. Early in the month DeepMind released AlphaFold's predicted structures for several understudied proteins of the new virus, unreviewed and free; and in the last week of March, Folding@home — its volunteer ranks swollen by locked-down PC owners — crossed an exaflop of donated compute simulating the virus's proteins. CORD-19 grew past a million papers and fed a generation of scientific-search systems; the month's pattern, machine learning thrown at biology in an emergency, outlasted the emergency.

Digital Guard desk · March 2020

Sophos Goes Private as the Endpoint Goes Home

The month's biggest corporate news arrived on its second day: on 2 March, Thoma Bravo completed its take-private purchase of Sophos at approximately $3.9 billion — $7.40 a share, in cash — and took the British firm off the London Stock Exchange it had joined in 2015. The buyer's appetite outlasted the pandemic: private equity spent the following years consolidating the sector, and Sophos itself would later absorb a rival, Secureworks. The rest of the industry spent March giving product away. As offices emptied, SentinelOne made its core endpoint product free from 16 March to mid-May; CrowdStrike opened Falcon Prevent to employees' home computers at no extra cost and let customers temporarily surge licences for the machines being handed to remote workers; Kaspersky gave healthcare organisations its products free for six months. The gestures were generosity and marketing in equal measure — the offers expired within months, but the home laptop never came back inside the perimeter, and securing it became the endpoint industry's business for the decade.

⏳ Time capsule — March 2020

  • The World Health Organization declared COVID-19 a pandemic on 11 March, with about 118,000 cases then confirmed worldwide.
  • The NBA suspended its season on 11 March after a player's positive test arrived minutes before tip-off; other leagues followed within days.
  • The Dow Jones Industrial Average fell 2,997 points on 16 March — the largest one-day point drop in its history to that date — despite an emergency US rate cut to near zero.
  • Japan and the International Olympic Committee postponed the Tokyo Olympics on 24 March, the first postponement in the modern Games' history.
Where it stands today — 2026

The perimeter never came back

Nothing about March 2020 proved temporary. The exposed remote desktops Shodan counted became the standard way in for the ransomware wave that dominates this archive's 2020 and 2021 editions, and hybrid work made the dissolved perimeter permanent — identity, not geography, became the thing attackers stole. The healthcare truce is remembered as a curiosity: May 2021 put Ireland's health service back onto paper, and February 2024's edition records the month American healthcare stopped getting paid. The counter-example was set the same week as Brno: Finastra, whose software runs in most of the world's biggest banks, pulled its own servers offline on 20 March to choke a ransomware intrusion and recovered — reportedly without paying — the choice Royal Mail would make, at length, in this archive's January 2023 edition.

In India, one counterfeit letter in a UPI handle was the small beginning of this archive's longest-running story: fraud at payment-rail speed, maturing through the lockdown-era scams into the organised "digital arrest" industry of 2024 and 2025. The Zoom classrooms the FBI warned about in March became permanent infrastructure, and so did their abuse. And the phishing site aimed at the WHO opened a year in which vaccine research became the most contested intelligence target on earth. The Vault continues backwards from here into 2019 — the last months in which any of this would have sounded unimaginable.