On 3 April 2021, the security researcher Alon Gal noticed that a dataset he had been tracking for months had stopped being merchandise. Phone numbers and profile records for 533 million Facebook users — 32 million in the United States, 11 million in the United Kingdom, roughly six million in India, spread across 106 countries — had been posted on a low-level hacking forum for a few dollars' worth of forum credits, which is to say essentially free. The records held phone numbers, names, locations, birthdates and biographical details, with email addresses for a minority. None of it was new: versions had circulated for sale for months, and in January a Telegram bot had been offering lookups from the same trove for a fee. What changed in April was the price, and therefore who could afford it.
Facebook's response, in a blog post on 6 April, rested on a distinction: the data had been scraped, not hacked. Someone had fed enormous lists of phone numbers into the platform's contact-importer tools, which obligingly matched them to profiles — a capability the company said it had removed in 2019 once it understood the abuse. Because its systems had not been penetrated, this was not a breach; and because the data was already public and users could do nothing to fix it, the company decided against telling them. "We don't currently have plans to notify users individually," a spokesman told NPR. The same week, scraped records from 500 million LinkedIn profiles went up for sale on the same forum, and LinkedIn reached for the same construction: not a LinkedIn data breach, merely an aggregation of data from a number of websites.
The abstraction ended at the individual phone number. A number cannot be reset like a password; it follows its owner for years, which is why scraped datasets age so well and why smishing and SIM-swapping crews prize them. Within days, Troy Hunt's Have I Been Pwned service made phone numbers searchable for the first time, so that people could check the one thing about themselves the dataset was organised around. And browsing the files, the researcher Dave Walker found the entry for Facebook user ID 4 — Mark Zuckerberg, phone number included — and noted that the number was registered with Signal, the encrypted messenger his company did not own. The scraping had not spared the platform's founder.
Regulators noticed what users were never told. On 14 April, Ireland's Data Protection Commission — Facebook's lead supervisor in Europe — opened an inquiry into whether the contact-importer processing had complied with the GDPR's data-protection-by-design obligations. In 2026 the ending is known: the decision, announced on 28 November 2022 and covered in this archive's November 2022 edition, found infringements of Articles 25(1) and 25(2) and fined Meta €265 million. The fine quietly settled the month's argument. Whatever the correct word for what had happened, the design had let strangers pair half a billion names with half a billion phone numbers, and the numbers rang either way. The distinction mattered in law; to the person answering, it never did.
Codecov: two months of leaking secrets
Codecov's Bash Uploader was the sort of tool nobody reads twice: a script thousands of engineering teams pulled into their continuous-integration jobs to send code-coverage reports. On the morning of 1 April, a customer did what almost nobody does — compared the checksum of the script being served against the one published on GitHub — and found they did not match. Codecov's public disclosure on 15 April explained why: since 31 January, attackers had been serving a subtly altered version, a single added line quietly exporting the environment variables of every CI job that ran it — credentials, tokens, keys — to a server outside. Access had come from a credential the attackers extracted from an error in Codecov's public Docker images. The company, which counted roughly 29,000 customers, notified those affected as US federal investigators joined; HashiCorp revoked and rotated its code-signing key in the fallout. Two months of trusted execution, undone by one person checking a hash.
Spring Loaded, with schematics
On 20 April, while Apple streamed its Spring Loaded launch event, the REvil ransomware gang posted engineering schematics of MacBooks — including unreleased designs — to its leak site, announcing it had breached Quanta Computer, the Taiwanese manufacturer that assembles them. The gang demanded $50 million from Quanta by 27 April, threatened to double the figure, and said it would otherwise deal with Apple directly; every number in that sentence comes from the criminals' own countdown page, not from published forensics. Quanta confirmed an attack on a small number of its servers and said business operations were unaffected; Apple said essentially nothing, then or later. The drawings were genuine — independent repair technicians later described working from leaked schematics of exactly this kind to fix machines Apple would not document. Within weeks the Apple files had vanished from the leak site as quietly as they arrived, and no payment was ever confirmed.
Free downloads in a hard month
India spent April 2021 in the grip of its second COVID wave, which is part of why a run of data disclosures landed with so little force. On 11 April, the researcher Rajshekhar Rajaharia reported that customer data from Upstox, the country's second-largest stockbroker, was in criminal hands; the company acknowledged a compromise traced to a third-party data warehouse, warned that contact details and KYC documents had been exposed, and stressed that customers' funds and securities were safe. Then, on 26 April, the November 2020 BigBasket breach completed its arc: the ShinyHunters group posted a database of roughly 20 million of the grocer's customer records — email addresses, phone numbers, home addresses, dates of birth and hashed passwords — on a forum, free, the same distribution model the Facebook trove had demonstrated three weeks earlier.
The month's largest Indian claim belonged to Domino's. In mid-April a seller on the same forum advertised 13 terabytes said to span 18 crore orders — names, numbers, addresses, order histories — alongside a claim of a million credit-card records. Jubilant FoodWorks, the chain's Indian franchise operator, acknowledged "an information security incident" — the intrusion itself dated to late March — while rejecting the card claim outright, saying it stores no financial data; the order records proved real enough. A month later the trove would resurface as a searchable portal, a story for May's edition. What April exposed most clearly was the absence of any duty to tell: no notification deadline, no data-protection law, nothing that obliged any of these companies to ring the customers whose numbers were now public. That law was still years away.
Brussels drafts the first AI rulebook
On 21 April, the European Commission published its proposal for the Artificial Intelligence Act, the first comprehensive attempt to regulate AI — a product-safety regime that sorted systems by risk, banned practices such as social scoring outright, and reserved its heaviest obligations for uses it deemed high-risk. It read then like regulation arriving ahead of its industry; from 2026 it reads as the founding text of the law that entered into force in August 2024 and is still phasing in. The commercial signals had come the week before, both on 12 April. Microsoft agreed to buy Nuance, the speech-recognition firm behind Dragon, for $19.7 billion including debt — then its largest acquisition since LinkedIn, aimed at the clinical documentation work ambient AI now does routinely. And Nvidia's GTC keynote, delivered from Jensen Huang's kitchen, announced Grace, the company's first data-centre CPU: an Arm design named for Grace Hopper, promised for 2023, with Swiss and Los Alamos supercomputers first in line. The chip that would underpin the AI build-out was, that month, a roadmap slide.
The state ships an uninstaller
On 25 April, at a deadline written into a module German federal police had pushed through Emotet's own update channel during January's takedown, infected machines worldwide quietly uninstalled the botnet: the file deleted Emotet's Windows services and its registry run key, then exited, touching nothing else on the machine. The takedown itself is January's cover story in this archive; what April supplied was the precedent — a state distributing code to private computers to remove software, which is what an antivirus vendor does, minus the licence agreement. Washington had already claimed the same ground on 13 April, when the Justice Department revealed that the FBI, under a Texas court order, had reached into hundreds of American Exchange servers still carrying web shells from the spring's Hafnium exploitation and commanded the shells to delete themselves, notifying owners afterwards. Both operations worked as designed, and both normalised something new: government code running remediation on private machines, uninvited. Emotet's operators, unimpressed, rebuilt the botnet before the year was out.
⏳ Time capsule — April 2021
- Prince Philip, Duke of Edinburgh, died on 9 April aged 99; pandemic rules capped his Windsor funeral at thirty mourners, the Queen seated alone.
- NASA's Ingenuity helicopter made the first powered, controlled flight on another planet on 19 April, rising about three metres above Mars's Jezero Crater.
- A jury convicted former Minneapolis police officer Derek Chauvin of the murder of George Floyd on 20 April.
- Twelve football clubs announced a breakaway European Super League on 18 April; within about 48 hours, fan and government fury had collapsed it.
The vocabulary stuck
April 2021's argument about the word breach was settled piecemeal. Ireland's regulator answered it with a design-failure fine in late 2022; platforms locked down the lookup features scrapers had feasted on; and the datasets themselves never went away — the Facebook numbers still surface in the smishing and impersonation economies of 2026, because phone numbers do not expire. Codecov, meanwhile, reads today like a rehearsal: the compromised build tool that siphoned secrets for two months prefigured the 3CX cascade this archive covered in March 2023 and the XZ Utils backdoor caught in March 2024 — by which point the industry had learned to say software supply chain, and to check its hashes.
The month's criminal cast met the decade unevenly. REvil reached its apex three months later with Kaseya, then broke apart under arrests on two continents; the affiliate behind Kaseya drew a thirteen-year American sentence in 2024. Babuk, which closed April extorting Washington DC's Metropolitan Police Department and leaked officers' files that May, dissolved within months — though its leaked builder seeded ransomware variants for years afterwards. And on 25 April, the uninstall command planted during January's Emotet takedown fired on schedule, deleting the botnet from infected machines worldwide — proof, filed quietly between the month's louder stories, that endings are possible. The Vault continues backwards from here.