The catastrophe never arrived. Election day, 3 November 2020, was the event American security planners had prepared four years for, ever since Russian operatives probed voter-registration systems in 2016. The Cybersecurity and Infrastructure Security Agency ran the day from a round-the-clock operations floor in Arlington, holding press briefings that grew steadily less eventful, and by the agency's own accounting about 95% of ballots cast carried a paper record that could be audited by hand. The feared scenarios — ransomware seizing registration databases, defaced results pages, a manipulated count — stayed theoretical. CISA's plain-text Rumor Control page, launched in the run-up to the vote to answer viral claims one at a time, turned out to be the busiest part of the whole operation.

What followed is the sentence the month is remembered for. On 12 November, the executive committees of the government and industry councils that coordinate election security — federal officials, state election directors and voting-system vendors together, CISA among them — issued a joint statement: "The November 3rd election was the most secure in American history." The line beneath it was bolded in the original: there was no evidence that any voting system had deleted, lost or changed votes, or been in any way compromised. The paper trail meant the claim could be tested, and it was — Georgia's hand tally of roughly five million paper ballots, completed on 19 November, confirmed the machine count.

On the evening of 17 November, President Trump announced by tweet that CISA's director, Chris Krebs, had been terminated effective immediately, calling the 12 November statement "highly inaccurate". Twitter fixed a disputed-claim label to the announcement. Krebs replied the same night from his personal account with seven words the security community has kept since: "Honored to serve. We did it right." His deputy, Matthew Travis, resigned hours later after being told he would not be permitted to serve as acting director; Brandon Wales, the agency's senior career official, took the role instead. In the weeks that followed, courts dismissed suit after suit alleging technical compromise of the vote, for the reason the statement had given: no evidence.

Nothing that has surfaced since has disturbed the substance of that statement, and this archive reports the episode the way it reports everything else in these pages — as what the evidence showed. The election infrastructure held in the year it was tested hardest: a pandemic election, record postal voting, adversaries watching. The director who said so plainly lost the job with nine weeks left in the administration, and left it with his composure intact. In an industry that measures itself by incidents, the defining security event of November 2020 was an absence — the breach that did not happen, defended in public at personal cost.

Also that month · Claims and confirmations

Capcom counts what Ragnar Locker took

Capcom's file and email servers began failing in the early hours of 2 November, and the Osaka games company behind Resident Evil and Street Fighter disclosed unauthorised access two days later. The Ragnar Locker ransomware group claimed it had taken a terabyte of data from networks in Japan, the United States and Canada, and a ransom note seen by researchers reportedly demanded $11 million in bitcoin; Capcom, after consulting law enforcement, did not engage. On 16 November the company confirmed that personal data had been compromised, with a potential maximum it then put at roughly 350,000 people. The final accounting took until April 2021 — 15,649 people confirmed affected, far below the early ceiling — with entry traced to an ageing backup VPN appliance kept alive at its North American subsidiary for pandemic remote working. No payment-card data was held. The gap between a gang's claimed terabyte and a company's audited count remains this archive's standing lesson in ransomware arithmetic.

Also that month · The archive of archives

23,000 stolen databases, free for a few hours

Around 4 November, someone posted the entire back catalogue of cit0day.in — a subscription service that had sold searchable access to stolen credentials — on a hacking forum, free. The cache ran to 23,618 separate archives: the accumulated breaches of roughly a decade of small websites, forums, shops and fan sites too minor to make the news and, in many cases, too minor to have ever disclosed at all. The download link survived only a few hours, long enough for researchers and criminals alike to copy everything. Cit0day itself had gone dark in September behind what appeared to be an FBI seizure notice, though researchers questioned whether the banner was genuine. Press aggregates spoke of billions of records; the defensible number came from Have I Been Pwned, which verified and indexed 226 million unique email addresses, many paired with passwords already cracked to plain text. For anyone who had reused a small site's password somewhere important, the risk stopped being theoretical that week — it was now indexed.

India desk · November 2020

BigBasket: the lockdown's grocer, up for sale

The year Indian households learned to buy groceries online ended with the country's biggest online grocer learning its customers were for sale. On 7 November 2020, researchers at the cybersecurity firm Cyble reported that a database of roughly 20 million BigBasket customer accounts was being offered on a cybercrime forum for about $40,000 — names, email addresses, phone numbers, hashed passwords, dates of birth, delivery addresses and the IP addresses used to log in. Cyble dated the intrusion itself to 14 October, said it had found the listing on 30 October, and informed the company on 1 November; the public learned a week after that. BigBasket confirmed a data breach, filed a first information report with Bengaluru's cybercrime cell, and said customers' financial details were safe because it does not store card data.

Nothing then in force obliged the Bengaluru company to notify its 20 million customers directly, and the news arrived the way Indian breach news usually did in 2020 — through a researcher's blog and the next morning's papers. The seller was later identified in reporting as ShinyHunters, the group behind a string of that year's forum listings. Hindsight completes the arc: in April 2021 the database stopped being merchandise and became a free download, posted openly on a forum — the moment recorded in this archive's April 2021 edition. By then BigBasket was being folded into the Tata group, and a pandemic's worth of grocery customers' phone numbers and password hashes were permanently public. The law that would have required those customers to be told was still nearly three years from passage.

AI Tech desk · November 2020

AlphaFold and the fifty-year problem

The month saved its defining story for its final day. On 30 November 2020, the organisers of CASP14 — the biennial blind trial of protein-structure prediction — announced that DeepMind's AlphaFold 2 had achieved a median score of 92.4 out of 100 on the contest's accuracy measure, a level the assessors judged comparable with laboratory experiment. "Protein folding solved" led the front pages; the sober verdict — that a fifty-year grand challenge had substantially given way — has held up. The public database of predicted structures that followed in 2021 runs through this archive's 2021 and 2022 desks, and the work carried Demis Hassabis and John Jumper to a share of the 2024 Nobel Prize in Chemistry. The hardware kept pace: on 16 November Nvidia doubled the memory of its A100 accelerator to 80GB — the part on which much of the coming large-model boom would be trained — and on 17 November Apple's first M1 Macs went on sale, carrying a built-in neural engine that began making on-device machine learning unremarkable.

Digital Guard desk · November 2020

SentinelOne's $267 million November

Venture capital spent the month repricing the endpoint. On 11 November 2020, SentinelOne announced a $267 million Series F led by Tiger Global — a round that tripled the company's valuation inside nine months to just above $3 billion, and set up the record-setting flotation recorded on this archive's June 2021 desk. Six days later Microsoft announced Pluton, a security processor developed with AMD, Intel and Qualcomm to move the hardware root of trust off the motherboard and onto the CPU die itself, borrowing the design that had defended Xbox consoles; it reached shipping laptops in 2022 and has since worked its way quietly into the Windows hardware base. The month closed with a small lesson in humility: Sophos wrote to customers after learning on 24 November that a misconfigured internal tool had exposed names, email addresses and phone numbers of a subset of support customers — reported by an outside researcher, fixed promptly, and disclosed with the plainness the industry expects of everyone else.

⏳ Time capsule — November 2020

  • Pfizer and BioNTech announced on 9 November that interim trial results showed their COVID-19 vaccine to be more than 90% effective — the pandemic's first great piece of good news.
  • A new console generation launched into lockdown demand: Microsoft's Xbox Series X and S on 10 November, Sony's PlayStation 5 on 12 November.
  • Fifteen Asia-Pacific nations signed the Regional Comprehensive Economic Partnership on 15 November, creating the world's largest trading bloc.
  • Diego Maradona died on 25 November, aged 60; Argentina declared three days of national mourning.
Where it stands today — 2026

The words outlasted the job

Chris Krebs was back at work within two months: in January 2021 he and Alex Stamos founded a consultancy whose first public client was SolarWinds — the software firm at the centre of the espionage campaign disclosed in December 2020, the month after this one, which revealed that federal networks had spent that autumn quietly penetrated even as the voting infrastructure held. The agency itself endured and grew into the centre of American cyber defence this archive tracks across the decade. The firing kept echoing: in April 2025 a presidential memorandum ordered a review of Krebs's conduct and suspended security clearances around him, and he resigned his post at SentinelOne to contest it. The 2020 episode remains the reference case for what a true security statement can cost.

The month's criminal threads resolved at different speeds. Egregor — which announced itself that November by making the receipt printers of the Latin American retailer Cencosud spit out ransom notes at supermarket checkouts in Chile and Argentina — was broken within three months by a Franco-Ukrainian police operation in February 2021. Ragnar Locker's infrastructure was seized and a key suspect arrested in Paris in October 2023, closing the file Capcom opened. Cit0day's credentials fed years of the credential-stuffing attacks that run through every volume of this archive, and BigBasket's database completed its journey from merchandise to free download by the following spring. The Vault continues backwards from here — October 2020 and the months before it, restored with the one advantage the people living them lacked: knowing how it came out.