Microsoft published emergency patches for on-premises Exchange Server on 2 March 2021, a week ahead of its normal schedule, closing four previously undisclosed vulnerabilities that could be chained — beginning with nothing more than the server's address — into full remote control of the machine and every mailbox on it. The company attributed the espionage it had observed to a state-sponsored group operating from China, which it named Hafnium; Beijing denied involvement. The credits told the quieter story: the Taiwanese research firm DEVCORE had reported the flaws on 5 January, and analysts at Volexity had been watching them exploited in the wild since early January. The holes were at least two months old by patch day. The fix, it turned out, was also an announcement.
Something changed in the final days of February: the careful espionage became indiscriminate, and once the patches published, every unpatched server on the internet was a marked door. Automated scanning dropped web shells — small scripts that keep a way back in — faster than responders could count them. On 5 March, the journalist Brian Krebs reported, citing multiple sources briefed on the matter, that at least 30,000 organisations across the United States had been compromised, among them a significant number of small businesses, towns, cities and local governments; the same day, the White House press secretary described the campaign from the podium as an active threat. Global figures passed to reporters ran from 60,000 victims to a quarter of a million — estimates, and reported here as such.
The response was a study in triage. CISA ordered federal civilian agencies on 3 March to patch or disconnect. ESET counted more than 5,000 compromised email servers by 10 March and at least ten distinct state-aligned groups exploiting the holes — no longer one actor's operation. The European Banking Authority pulled its email systems offline on 7 March; Norway's parliament said on 10 March that data had been taken. Because the exposed population was precisely the one without security teams, Microsoft shipped a one-click mitigation tool on 15 March aimed at customers with no dedicated security staff, and said on 22 March that 92% of vulnerable servers had been patched or mitigated. The arithmetic carried a catch: a patch closes the door, but it does not remove a web shell already inside.
The criminal follow-through was quick. Samples of a new ransomware began arriving at the identification service ID Ransomware on 9 March, and on 11 March Microsoft confirmed that DearCry — a name that echoed WannaCry — was being installed by hand through the same four holes on servers that had not patched in time. The victim count stayed small; the sequence mattered more. In the space of nine days, a chain built for espionage had become a commodity for burglars, and the chain now carried the name DEVCORE gave it, the one that stuck: ProxyLogon.
The password to 150,000 cameras
On 9 March, Bloomberg revealed that a small hacktivist collective had spent roughly 36 hours inside Verkada, a Silicon Valley maker of cloud-managed security cameras, seeing what the cameras saw — access, the group claimed, to some 150,000 cameras: live feeds from a Tesla warehouse in Shanghai, from hospitals, schools, gyms and the county jail in Madison County, Alabama. Tillie Kottmann, the Swiss developer who spoke for the group, said the way in had been a super-admin credential found exposed on the public internet, and framed the intrusion as a protest against the reach of surveillance. Verkada disabled all internal administrator accounts after Bloomberg called, and later said the attackers had compromised a server used by its support team. Consequences arrived at two speeds: Swiss police raided Kottmann's Lucerne flat within days, and on 18 March a grand jury indictment was unsealed in Seattle — covering alleged leaks stretching back to 2019, none of them the cameras. Switzerland does not extradite its own citizens, and the case has never reached a US courtroom. The corporate ending came in August 2024, when Verkada agreed to pay $2.95 million and run a supervised security programme to settle Federal Trade Commission charges.
Forty million to make it stop
Phoenix Locker ransomware detonated inside CNA Financial, one of America's largest commercial insurers, on 21 March; the company disclosed what it called a sophisticated cybersecurity attack two days later, and for days its website was a static holding page. Contemporary reporting put around 15,000 devices encrypted, including the computers of employees logged in from home over VPN. On 20 May, Bloomberg reported that CNA had paid $40 million roughly two weeks after the attack — the largest ransom payment publicly reported anywhere to that point, and a figure CNA never confirmed. The company said it had consulted the FBI, followed US Treasury guidance, and determined the group calling itself Phoenix was not a sanctioned entity — a careful formulation, since researchers tied Phoenix Locker to Hades, malware associated with Evil Corp, sanctioned by Washington in 2019. In July the insurer told just over 75,000 people their data had been taken. The demand-side record had moved days earlier: REvil named Acer on its leak site with a $50 million demand, due 28 March and doubling after. Acer never confirmed paying, and researchers watching the gang saw it probing an Acer Exchange server — the month's headline holes, already earning.
MobiKwik: the breach that officially never happened
The claim surfaced in late February 2021, when the independent security researcher Rajshekhar Rajaharia reported that know-your-customer records from an Indian payments company — scanned Aadhaar and PAN documents among them — were being offered on a hacker forum. By the last week of March the listing had a name attached: MobiKwik, the Gurugram digital-wallet firm, with sellers claiming 8.2 terabytes of data covering roughly 10 crore users. A searchable portal appeared on the dark web, and users spent days finding their own card numbers, addresses and identity documents in it; TechCrunch, which reviewed the data, put the count at 99 million records. The French researcher Robert Baptiste amplified the find to a global audience and described it as possibly the largest KYC data leak seen to date.
MobiKwik's response is what fixed the case in memory. The company denied a breach categorically and repeatedly, suggested its users could themselves have uploaded the same information to multiple platforms, and in a 30 March statement dismissed the finder as "a media-crazed so-called security researcher". The Reserve Bank of India was reported at the end of the month to have ordered an immediate forensic audit by a CERT-In-empanelled auditor. The portal soon vanished; the audit's findings were never made public; no breach was ever officially confirmed. The stand-off simply outlasted the news cycle — the researcher stood by his claim, the company stood by its denial, and in December 2024 MobiKwik listed on Indian stock exchanges. What the episode exposed most clearly was the vacuum around the users, who had no legal right to be told anything at all — a gap these pages trace forward to the DPDP Act of 2023.
Four and a half billion words a day
Nine months after opening its API, OpenAI published usage figures on 25 March 2021: more than 300 applications were now running on GPT-3, built by tens of thousands of developers, and the model was generating an average of 4.5 billion words a day. The post read as a progress report; in hindsight it was the first hard evidence that renting a language model could be a business — the template every rival eventually copied. Days earlier the counterargument had shipped: EleutherAI, a volunteer collective organised on a Discord server, released GPT-Neo, open-source models of 1.3 and 2.7 billion parameters trained on its own dataset, The Pile — the start of the open-weights counterweight this archive traces forward. The month's consumer face was stranger and gentler: MyHeritage's Deep Nostalgia, launched in late February with animation technology licensed from the Israeli firm D-ID, had ancestors blinking in tens of millions of animated photographs by mid-March. Nobody yet had a collective name for any of it; Stanford would coin "foundation models" that August.
McAfee splits itself in two
The most famous name in antivirus chose to keep only half of itself. On 8 March 2021, McAfee announced the sale of its enterprise business — a division serving more than 86 per cent of the Fortune 100 — to a consortium led by Symphony Technology Group for $4.0 billion in cash, leaving the listed company a pure consumer brand. The deal closed that summer; in January 2022 STG fused its purchase with FireEye's products arm under a new name, Trellix, the desk where this archive picks the thread up. The week supplied a coda: on 5 March, federal prosecutors in Manhattan unsealed a cryptocurrency pump-and-dump indictment against John McAfee, gone from the company since 1994; he denied the charges, and died in Spanish custody that June with the case untried. And from 18 March, a security-intelligence update taught Microsoft Defender Antivirus to apply the ProxyLogon mitigation automatically on vulnerable Exchange servers — a step past the cover story's one-click tool: interim protection for owners who had done nothing at all, applied by the antivirus itself.
⏳ Time capsule — March 2021
- Oprah Winfrey's interview with Prince Harry and Meghan aired on CBS on 7 March, watched by about 17 million Americans on the night.
- Christie's sold Beeple's digital collage Everydays: The First 5,000 Days for $69.3 million on 11 March — the auction that made "NFT" a household word.
- A volcano began erupting at Fagradalsfjall in Iceland on 19 March, the Reykjanes peninsula's first eruption in about 800 years, and became a hiking destination within days.
- The container ship Ever Given wedged itself across the Suez Canal on 23 March; tugs freed it six days later, on 29 March, after a queue of hundreds of ships had formed.
The month the doors opened
Hindsight gives March 2021 a clean shape: it is the month "assume breach" stopped being a slogan for anyone running their own email. The sequel came fast. On 13 April 2021 the US Justice Department revealed that FBI agents, with a court order, had issued delete commands through criminals' own web shells on hundreds of American servers — owners told only afterwards, a first that this archive sees echoed in the LockBit infiltration of February 2024. In July 2021 the US, EU, UK and NATO formally blamed contractors working with China's Ministry of State Security. And the surface never really closed: ProxyShell reopened Exchange that August, Storm-0558's stolen signing key reached cloud mailboxes in July 2023, and on-premises SharePoint repeated the whole pattern in the summer of 2025 — each one an edition in these pages.
The month's other threads ran just as long. CNA's reported $40 million stood as the largest publicly reported payment for three years, until researchers disclosed a $75 million payment in 2024; the boom it marked is the one Conti's leaked chat logs laid bare in 2022, and Evil Corp — the sanctioned operation researchers saw behind Phoenix Locker — resurfaced in 2024 sanctions that tied one of its members to LockBit. MobiKwik's audit findings have still never been published, five years on. And the question March 2021 put to every small organisation — who patches the machines nobody thinks about? — has yet to find an answer worth printing. The Vault continues backwards from here.