The charges had been sitting under seal in a Dallas courthouse since August, waiting for their subject to make a mistake. On 8 October 2021, Yaroslav Vasinskyi, a 22-year-old Ukrainian, made it, crossing the border into Poland, where he was detained at Washington's request. A month later, on 8 November, the US Justice Department unsealed the indictment: Vasinskyi, it alleged, was the REvil affiliate who pushed ransomware through Kaseya's VSA software on 2 July 2021 — the supply-chain attack that reached as many as 1,500 businesses through their IT providers and forced Sweden's Coop to close most of its roughly 800 supermarkets because the tills would not open. Ransomware prosecutions usually name ghosts. This one named a man already in custody.
The rest of the day widened the frame. The department announced the seizure of $6.1 million in funds traceable to ransom payments received by Yevgeniy Polyanin, a 28-year-old Russian charged over REvil attacks on Texas local governments in 2019, who remained — and remains — at large; the FBI's wanted notice placed him in Russia, possibly Barnaul. The State Department offered up to $10 million for REvil's leadership and $5 million for its affiliates. The Treasury sanctioned Chatex, a cryptocurrency exchange it said had processed ransom money. And Europol revealed Operation GoldDust: on 4 November, Romanian police had arrested two suspects linked to some 5,000 REvil infections and roughly €500,000 in collected ransoms, with a GandCrab affiliate held in Kuwait the same day — seven arrests across the two ransomware families since February 2021, in an investigation spanning seventeen countries.
Six days later came the answer. On Sunday 14 November, researchers at the German security firm G DATA, watching machines infected with TrickBot, saw the botnet fetch a new component their analysts assessed, with deliberate care, as looking like Emotet. Emotet — the spam botnet that had been the internet's principal malware delivery service until January 2021, when police in eight countries seized its servers in Operation Ladybird and later uninstalled it from victim machines — was being rebuilt on top of TrickBot's surviving infections, a manoeuvre the volunteer trackers of Cryptolaemus christened Operation Reacharound. Within days its spam runs resumed. By early 2022, researchers were counting freshly compromised machines in the six figures.
Hindsight scores the month both ways. Vasinskyi was extradited to Texas in March 2022 and sentenced in May 2024 to thirteen years and seven months, with $16 million in restitution; prosecutors said he had a hand in more than 2,500 attacks that demanded over $700 million. Polyanin has never seen a courtroom. Russia staged its own REvil raid in January 2022, then invaded Ukraine; the Russian prosecutions shrank to carding and malware charges, and in 2025 four of the accused walked free on time served. Emotet's revival ran through 2022 before fading as Microsoft finally blocked by default the Office macros it lived on. The handcuffs were real. So was the reboot.
The bureau's mail server, borrowed for the evening
Late on the night of 12 November, spam filters across the United States met a hard case: waves of emails warning of a fabricated cyberattack, falsely naming the security researcher Vinny Troia as its author, sent from eims@ic.fbi.gov — a real FBI address, on real FBI infrastructure, passing every authentication check. Spamhaus counted at least 100,000 recipient addresses, harvested from the public ARIN internet registry. The flaw sat in the bureau's Law Enforcement Enterprise Portal: the sign-up confirmation email's one-time passcode leaked in the page's own HTML, and the message's subject and body were generated client-side in the browser's request, where anyone could rewrite them. A prankster using the handle Pompompurin walked the journalist Brian Krebs through the trick while the emails were still landing; the FBI called it a software misconfiguration and said no data or personal information had been accessed. The name matters later in this archive: Pompompurin was Conor Fitzpatrick, founder in 2022 of the stolen-data market BreachForums, arrested in March 2023 — and, after an appeals court threw out his first sentence as too lenient, resentenced in 2025 to three years.
The help desk picks up
By Robinhood's own account, its intrusion began with a telephone call on 3 November: someone rang a customer-support employee and talked their way into the firm's support systems — no vulnerability exploited, just a voice persuading a person. The trading platform disclosed the result on 8 November: email addresses for about five million customers, full names for a different group of roughly two million, and, for around 310 people, names with dates of birth and ZIP codes — about ten of them with more extensive account details exposed. No Social Security, bank account or card numbers were taken, the company said, and no customer lost money. After the intrusion was contained, the caller demanded payment to keep the data off the market; Robinhood instead notified law enforcement, retained Mandiant, and published the details itself. The technique deserved the most attention and got the least. The patient, scripted phone call aimed at a help desk spent the next four years becoming the era's defining intrusion method — a thread this archive picks up in September 2023, when it took the casinos of Las Vegas offline.
Four crore investors, one open API
In the first week of November, a young Indian security consultancy called CyberX9 went public with what it had found a fortnight earlier inside CDSL Ventures Limited — the KYC registration agency owned by Central Depository Services Limited, one of the two depositories holding the country's demat accounts. A flaw in a public-facing API, the researchers said, let a requester walk past authorisation checks and read the know-your-customer records the agency holds on roughly 4.39 crore investors: names, PAN numbers, dates of birth, residential addresses, phone numbers, email addresses, marital status, father's or spouse's name, income ranges and demat account details. CyberX9 reported the flaw on 19 October to CDSL, CERT-In and NCIIPC; the fix took about seven days to arrive — and on 29 October the researchers found it could be trivially bypassed, and reported it again.
CDSL's response carried a distinction worth preserving: it said there had been no security issue or data vulnerability at CDSL itself, while confirming that its subsidiary had received a vulnerability alert "which has since been mitigated". The 4.39 crore figure is CyberX9's inference from CVL's own published count of investors whose KYC it has processed — a measure of the exposure window, not a confirmed tally of records taken — and no public forensics established whether anyone found the door before the researchers did. The episode read as a warning about where India concentrates its financial identity: one SEBI-registered subsidiary, one API, and the PAN details of four crore market participants behind it. A year later, almost to the week, CDSL itself detected malware on internal machines and market settlements were delayed — a different incident, at the same address.
A billion faceprints, deleted
On 2 November 2021, Meta announced it was switching off Facebook's face-recognition system — the feature that for a decade had put names to faces in users' photos — and deleting the individual faceprints of more than a billion people, one of the largest voluntary retreats from a deployed AI system on record. The retreat came with fine print: Meta kept the underlying technology and reserved narrower future uses, a caveat that looked like caution at the time and like the whole point by mid-decade, when face-matching crept back into its products for scam-advert screening and account recovery. The rest of the month ran the other way. At Ignite the same day, Microsoft unveiled the invitation-only Azure OpenAI Service, wrapping GPT-3 in enterprise compliance for corporate customers; and on 18 November OpenAI removed the GPT-3 API waitlist altogether, letting any developer in supported countries sign up and build. The queue vanished a year and twelve days before ChatGPT made the world rejoin it.
Shareholders wave the Norton–Avast merger through
The consumer antivirus business spent November 2021 voting itself into a new shape. On 4 November, NortonLifeLock's shareholders approved, all but unanimously, the share issuance behind its merger with Avast — a deal valued at up to $8.6 billion — and on 18 November Avast's investors passed the scheme at the court and general meetings it required. What remained was regulatory: Britain's competition authority took the tie-up into a full inquiry before clearing it, the deal closed the following September, and by the end of 2022 the combined firm had renamed itself Gen Digital, with Norton, Avast, AVG and Avira under one roof. The month also showed why the incumbents were consolidating: at Ignite on 2 November, Microsoft announced Defender for Business, folding endpoint detection and response into Microsoft 365 for firms of up to 300 employees — enterprise protection sliding into the small-business tier antivirus vendors had long called home. And on 1 November, the BlackMatter ransomware gang, successor to the DarkSide operation behind Colonial Pipeline, told affiliates it was closing, citing pressure from the authorities.
⏳ Time capsule — November 2021
- COP26 closed in Glasgow on 13 November with the Glasgow Climate Pact, after a late intervention by India and China softened its coal language from phase-out to phase-down.
- Adele released 30 on 19 November; it went on to become the world's best-selling album of 2021.
- On 26 November, the WHO designated the new coronavirus variant Omicron a variant of concern; within days, much of the world had restricted travel from southern Africa.
- Barbados became a republic at midnight on 30 November, swearing in Sandra Mason as its first president and declaring Rihanna a national hero.
The tide that didn't turn
November 2021 built the template the rest of this archive keeps reusing: name the man, seize the wallet, price the tip-off. The FBI's covert months inside Hive in January 2023, the trolling seizure of LockBit's leak site in February 2024, the sanctions that trailed Conti's collapse through 2022 and beyond — all of it descends from the week Washington decided ransomware prosecutions should have faces and press conferences. Vasinskyi sits in an American prison into the mid-2030s. Polyanin's wanted poster has not changed. And the $10 million bounty became standard practice, repriced and reissued so often that by mid-decade it was simply how the United States opened bidding on any sufficiently damaging adversary.
The counterweight held too. Emotet's second life burned through 2022 and guttered out the following year, ended less by police work than by Microsoft blocking the macros it lived on — the arrests-are-slow lesson of November 2021 running in reverse. The phone call that opened Robinhood matured into the era's signature technique, from the casino floors of September 2023 to the British retail outages of 2025. Pompompurin's joke aged strangely as well: the man who once made the FBI's own servers smear a researcher went from prank to marketplace to prison inside four years, his forum seized and its successors seized again. The Vault continues backwards from here; the chain, as ever, holds in both directions.