At about eight o'clock on the morning of Friday 5 February 2021, an operator at the City of Oldsmar's water treatment plant noticed someone else inside his computer. Oldsmar treats water for around 15,000 people on the north-western edge of Tampa Bay, fifteen miles from the stadium that would host the Super Bowl two days later. The morning visit barely registered: supervisors used the plant's TeamViewer software to check in remotely all the time. At about half past one the connection returned, and this time the operator watched his mouse cursor move on its own, open the treatment controls, and raise the setpoint for sodium hydroxide — the lye dosed to manage the water's acidity — from 100 parts per million to 11,100. Minutes later, the session ended.

The operator returned the setpoint to normal at once, and officials said other safeguards would have caught the change long before treated water reached a tap — the water itself would have taken more than a day to enter the system. On Monday 8 February, Pinellas County Sheriff Bob Gualtieri stood beside Oldsmar's mayor and announced an attempted poisoning of the city's water supply, and by evening a five-minute event in a small Florida city was a global story about critical infrastructure. The advisories that followed were less dramatic and more damning: state and federal notices described a plant whose computers ran Windows 7, shared a single TeamViewer password, and sat exposed to the internet without a firewall. Utilities across the world spent that week discovering what their own operators could reach from home.

What never arrived was a culprit. The FBI and Secret Service joined the investigation; no suspect was named, no arrest made, no forensic account published. Then, in March 2023, Oldsmar's former city manager Al Braithwaite told a public-administration conference that the great water hack had been an employee mistakenly clicking through the software — a "non-event", in his words, resolved in minutes, likely caused by the same operator "banging on his keyboard". He said the FBI's investigation had reached the same conclusion, finding no evidence of access from outside. Asked about it, the bureau would say only that it had not been able to confirm the incident was initiated by a targeted cyber intrusion. The sheriff's office said the case remained open.

Five years on, this archive cannot tell its readers whether anyone was ever on the other end of that cursor. What it can say is what was true either way: a plant supplying drinking water to a town was reachable from the open internet, through remote-control software protected by one shared password, on an operating system Microsoft had stopped supporting a year earlier. The scare did what a confirmed attack would have done — remote access was stripped out or locked down across the sector, and who could touch the treatment controls became a standing question. Oldsmar is now taught two ways: as the intrusion that nearly poisoned a town, and as a caution about how far a story can travel ahead of its evidence.

Also that month · The file-transfer harvest

Cl0p and the twenty-year-old appliance

The month's quieter disaster ran through Accellion's File Transfer Appliance, a roughly twenty-year-old product its maker had spent years urging customers to retire. Attackers had been chaining zero-day flaws in it since mid-December 2020, planting a web shell Mandiant named DEWMODE and pulling files from the organisations still running it. There was no ransomware and nothing encrypted — only theft, followed by extortion emails threatening publication on the Cl0p leak site. February was the month the bill came due in public: Singtel disclosed on 11 February and within the week counted about 129,000 customers exposed, national identity numbers among the fields; the grocer Kroger followed on 19 February; Bombardier on 23 February, extracts of aircraft data appearing on the leak site. Files taken from the law firm Jones Day surfaced too — the firm insisted its own network was never breached, only the vendor's appliance it used. Accellion, citing Mandiant, put the toll at fewer than 100 of some 300 remaining FTA customers, fewer than 25 with significant data loss. The same crew ran the same play through GoAnywhere and MOVEit in 2023 — the harvest in this archive's June 2023 edition.

Also that month · No negotiation

CD Projekt publishes the ransom note

On 9 February, CD Projekt Red — the Polish studio behind Cyberpunk 2077 and The Witcher, weeks past Cyberpunk's troubled launch — announced it had discovered a breach the previous day: devices encrypted, internal data taken. Rather than negotiate quietly, it published the full ransom note, which gave the studio 48 hours and claimed source code for Cyberpunk 2077, The Witcher 3, Gwent and an unreleased Witcher 3 build, plus legal, HR and investor documents. CD Projekt said it would "not give in to the demands nor negotiate", and restored from backups. Researchers at Emsisoft judged the malware almost certainly HelloKitty, then a niche operation. Within days an auction opened on the Russian-language forum Exploit — one million dollars to start, seven million to buy outright — and closed with the sellers claiming a satisfactory offer from outside the forum; every figure in that sentence comes from the criminals. The coda arrived in April 2024, when the gang's rebrand published keys to the stolen archives and modders reported compiling working Witcher 3 builds from the code. Refusing to pay denied the attackers their payday. It did not keep the source private.

India desk · February 2021

Two and a half million records, and a denial

India's story that month was an argument. In the first days of February, the security researcher Rajshekhar Rajaharia flagged a website run by a group calling itself Red Rabbit Team, displaying what it said were records of about 2.5 million Bharti Airtel subscribers — names, addresses, dates of birth, phone numbers and, in some samples, Aadhaar numbers — with claims of many more held back. Reports said the group had first approached Airtel in December 2020, demanding a few thousand dollars in bitcoin to stay quiet. On 3 February the company issued a flat denial: there had been no breach of Airtel's systems, the samples contained "glaring inaccuracies", and subscriber data in India passes through many hands beyond the operator under regulatory requirements. It said it had alerted the authorities.

It was never resolved. Rajaharia's own hypothesis pointed at the machinery rather than the company: the records resembled data from the subscriber-lookup systems operators must expose to law enforcement — a researcher's reading, not a finding. The pages came down, no regulator published a conclusion, and the claim was never substantiated at the scale advertised; nor was it conclusively disproved. The episode is preserved here less for what it proved than for what it showed. In February 2021 an Indian subscriber whose details surfaced on an extortion site had no notification coming, because none was required, and no arbiter to decide between claim and denial. The six-hour reporting mandate came the following year, the data-protection law two and a half years on — both stories these pages have already told.

AI Tech desk · February 2021

Google fires its other AI ethics lead

On 19 February 2021, Google fired Margaret Mitchell, founder and surviving co-lead of its Ethical AI team, two and a half months after the contested exit of her fellow lead Timnit Gebru. The company said its review had found code-of-conduct and security violations, including moving confidential documents outside the firm; Mitchell had spent the preceding weeks locked out of her accounts after searching them for evidence of how Gebru had been treated, and the wider group had just been reorganised under a new head, Marian Croak. The team that had questioned ever-larger language models had, in effect, been managed out — an argument that stopped being internal to Google once such models were in everyone's hands. The month's gentler AI story went viral in its final days: MyHeritage's Deep Nostalgia, built on video-reenactment technology licensed from the Israeli firm D-ID, animated old family photographs so the dead could blink and smile, generating millions of clips within days and giving consumer deepfakery its first sentimental face.

Digital Guard desk · February 2021

The month antivirus became a data business

The endpoint trade spent the month turning itself into a data business. On 9 February, SentinelOne paid 155 million dollars in cash and equity for Scalyr, a log-analytics firm founded by former Google engineers, buying the machinery to search everything an enterprise emits rather than merely its endpoints; the company floated in New York that summer, and Scalyr's engine became the data layer beneath its platform. McAfee moved the opposite way: its 23 February results showed a fourth quarter carried by consumer subscriptions, with enterprise growth far behind, and a fortnight later it agreed to sell the entire enterprise business to Symphony Technology Group for four billion dollars — the half that re-emerged in 2022, fused with FireEye, as Trellix. The field supplied its own omen. Researchers at Red Canary disclosed Silver Sparrow, macOS malware resident on nearly thirty thousand Macs across more than 150 countries, shipping a binary compiled natively for Apple's months-old M1 silicon and never observed delivering a payload — the platforms were changing faster than the defences watching them.

⏳ Time capsule — February 2021

  • Myanmar's military seized power in a coup on 1 February, detaining Aung San Suu Kyi on the morning the new parliament was due to convene.
  • A mid-February arctic outbreak collapsed the Texas power grid; more than four million customers lost electricity and much of the state spent days under boil-water notices.
  • NASA's Perseverance rover landed in Jezero Crater on Mars on 18 February — the third arrival at Mars in ten days, after orbiters from the UAE and China.
  • Daft Punk announced their split on 22 February with an eight-minute video titled "Epilogue", twenty-eight years after they formed.
Where it stands today — 2026

The alarm that outlived its cause

February 2021's biggest story is the strangest kind of consequential: five years on, there is still no public evidence that anyone attacked Oldsmar at all. Yet the response was real, and it held. Remote access to treatment controls was rethought across the water sector, the advisories became doctrine, and when confirmed intrusions at utilities arrived in later years, the playbook existed because a Friday afternoon in Florida had frightened an industry into writing it. The month's Indian scare aged differently: the Airtel claim simply evaporated, unproven and undisproved — a reminder that the stories which cannot be settled shape policy as surely as the ones which can.

The Accellion campaign reads in 2026 like a rehearsal: the same Cl0p-linked crew ran the same play through GoAnywhere and then MOVEit — the 2023 harvest this archive has already restored — and file-transfer software is now understood as the soft border of every large organisation. February's SolarWinds business set patterns of its own: Microsoft closed its review on 18 February, conceding the intruders had viewed and downloaded portions of Azure, Exchange and Intune component source code, and executives faced the Senate on the 23rd, beginning the argument over mandatory disclosure that produced a federal incident-reporting law the following year. The Vault continues backwards from here. Some months teach by what happened; February 2021 teaches by what could never quite be proved.