LastPass updated its incident notice on 22 December 2022 to say that the attacker behind the August intrusion had copied a backup of customer vault data. The container, the company explained, was held in a proprietary binary format carrying both unencrypted fields — website URLs among them — and fully encrypted ones: site usernames and passwords, secure notes, form-filled data. A separate backup taken by the same actor held basic account information: company names, end-user names, billing addresses, email addresses, telephone numbers and the IP addresses from which customers had reached the service. The copying was part of a second intrusion that LastPass later dated from 12 August to 26 October 2022. The disclosure arrived two months after it ended, three days before Christmas.

The value of the December notice lies in what preceded it. On 25 August LastPass had said an unauthorised party took portions of source code and technical information from its development environment, with no evidence of access to customer data or encrypted vaults. On 15 September it reported that the investigation with Mandiant was complete and the intruder's activity had been contained to a four-day window. On 30 November it said that an unauthorised party, using information obtained in August, had reached certain elements of customer information held at a third-party cloud storage service. Each notice was accurate as far as it went, and each was narrower than the one that followed it. The company never contradicted itself; it simply kept finding more.

LastPass rested its reassurance on its zero-knowledge architecture: the encrypted fields were protected with 256-bit AES and could be opened only with a key derived from each customer's master password, and a twelve-character minimum with 100,100 PBKDF2 iterations had been the default since 2018. The researcher Wladimir Palant published an analysis on 28 December setting out what the notice omitted — that the default had once been a single iteration, then 500 from 2012 and 5,000 from 2013, and that LastPass had never migrated existing accounts, leaving long-standing users on settings a decade old. He costed the offline cracking of a strong master password at each level: roughly $1.5 million at 100,100 iterations, about $75,000 at 5,000, and fifteen dollars at one.

The unencrypted fields mattered on their own: a list of every site a customer had saved is a targeting list needing no decryption. LastPass told consumers on default settings that no action was required; much of the security profession, including people who had recommended it for years, said the opposite — treat the vault as taken and change what is inside it. The timing was its own argument. Okta had published its own notice on 21 December, confirming that its source-code repositories had been copied after GitHub flagged suspicious access, and on 23 December a forum seller advertised what he called 400 million Twitter records — a number researchers deflated once they found the duplicates, and which the platform later put down to earlier scraping, not a fresh intrusion.

Also that month · Thirty thousand mailboxes

The email that never came back

Rackspace's Hosted Exchange service failed on Friday 2 December 2022. Its customers were mostly small and mid-sized businesses — accountants, clinics, recruiters, single-office law firms — and they lost not only new mail but years of archived mail, in the month when invoices go out. Rackspace confirmed on 6 December that the outage was a ransomware incident, and began moving customers onto Microsoft 365 at no extra cost. CrowdStrike published on 20 December the exploit chain it named OWASSRF, which strung CVE-2022-41080 and CVE-2022-41082 together to reach remote code execution through Outlook Web Access, stepping around Microsoft's ProxyNotShell mitigations. Rackspace named the Play ransomware group at the end of the month; the completed forensic investigation, reported in early January 2023, found the attacker had reached the personal storage files of 27 of nearly 30,000 Hosted Exchange customers, with no evidence the contents were viewed or distributed. Class actions followed within days, the share price fell roughly 40% across December, and the platform was never restored: Rackspace retired Hosted Exchange altogether. Costs reported to the SEC reached about $11 million, roughly half recoverable from insurance — remediation spending, not lost revenue.

Also that month · The appliance at the edge

A heap overflow in the SSL-VPN

Fortinet published its advisory on 12 December 2022 for CVE-2022-42475, a heap-based buffer overflow in the SSL-VPN component of FortiOS that let an unauthenticated attacker run code on the device from the internet. The company said it was aware of an instance of the flaw being exploited in the wild; CISA added it to the Known Exploited Vulnerabilities catalogue the following day. Fortinet's follow-up analysis, published in January 2023, described what the intruders had installed: a modified copy of the appliance's own IPS engine, altered to suppress logging, delivered by an exploit whose complexity the company said pointed to an advanced actor and a campaign highly targeted at governmental or government-related organisations. Fortinet named no state, and this archive does not either. What began here is the pattern of the three years that followed — the box bought to keep intruders out becoming the way in. In April 2025 Fortinet warned that attackers who had exploited this flaw and two later FortiOS vulnerabilities had left symbolic links behind that survived patching, preserving read-only access to the device's files. Patching closed the hole. It did not always close the account.

India desk · December 2022

AIIMS comes back, one server at a time

Delhi's All India Institute of Medical Sciences had been running on paper since 23 November 2022, when ransomware took down the eHospital system handling registration, admission, discharge and laboratory reporting. December was the month of coming back. Records were written by hand at the counters, doctors saw patients without their histories, and the queues outside the outpatient block were the visible part. Through the first week of December services returned in stages, rebuilt on four new servers by the National Informatics Centre from a backup the attackers had not reached, the network sanitised before anything was reconnected. On 16 December the government told the Rajya Sabha that the servers had been compromised because of improper network segmentation, that no specific ransom sum had been demanded despite the message left behind, and that CERT-In had advised remediation. Reports in Indian media attributing the attack to Chinese actors were never confirmed by government.

AIIMS was not alone. On 30 November the website of the Indian Council of Medical Research absorbed roughly 6,000 attempts within 24 hours from an address traced to Hong Kong, which the National Informatics Centre firewall held; Safdarjung Hospital reported an incident its medical superintendent said was not ransomware, and which NIC restored within a day. The law was still being drafted around them. MeitY had released the draft Digital Personal Data Protection Bill on 18 November with comments due by 17 December, and on that date extended the deadline to 2 January 2023. So the month India's largest public hospital rebuilt its patient database ended with no data protection statute in force — only CERT-In's six-hour reporting direction, effective since mid-2022, standing between a breach and the people in it.

AI Tech desk · December 2022

A million users in five days

Five days after its quiet 30 November launch, ChatGPT crossed one million users — Sam Altman announced the milestone on 5 December 2022, the same day Stack Overflow temporarily banned ChatGPT-generated answers because they were plausible, prolific and too often wrong. The month's other obsession was Lensa, whose "magic avatars" briefly made it the most-downloaded app in the world while artists and privacy advocates argued over what it had been trained on and what its users had signed away. Two hobbyists released Riffusion on 15 December, coaxing music out of Stable Diffusion by teaching it to draw spectrograms, and OpenAI followed with Point-E on 20 December, generating rough 3D point clouds from a text prompt in minutes. By 21 December The New York Times was reporting that Google had declared a "code red". Written from 2026, the ironies are tidy: the code red became Bard and then Gemini, and the site that banned ChatGPT's answers signed a data deal with OpenAI within eighteen months.

Digital Guard desk · December 2022

The malware came with Microsoft's signature

On 13 December 2022, its December Patch Tuesday, Microsoft confirmed what Mandiant, SentinelOne and Sophos had reported to it in October: drivers signed through its own Windows Hardware Developer Program were being used in attacks. The toolkit the researchers described — a loader called STONESTOP and a kernel-mode driver called POORTRY — existed to kill antivirus and EDR processes from the kernel, carrying a signature that told the operating system the code could be trusted. Sophos tied the drivers to Cuba ransomware deployments, Mandiant to a crew it tracked as UNC3944, later better known as Scattered Spider. Microsoft suspended the partner accounts, revoked the certificates and shipped detections. The same week, on 12 December, Gen Digital noticed an unusually large volume of failed logins at Norton — a credential-stuffing run against nearly a million accounts, begun around 1 December with password pairs bought elsewhere and disclosed the following January. The company said its own systems were not compromised. From 2026 the episode reads as an opening chapter: the EDR killer became a standard, traded item in the ransomware toolkit.

⏳ Time capsule — December 2022

  • Argentina beat France on penalties in the World Cup final at Lusail on 18 December, after a 3–3 draw.
  • The US Department of Energy announced on 13 December that the National Ignition Facility had achieved fusion ignition — an experiment run on 5 December in which 2.05 megajoules of laser energy produced 3.15 megajoules of fusion energy.
  • Volodymyr Zelenskyy addressed a joint meeting of the US Congress on 21 December, on his first journey outside Ukraine since the invasion.
  • Pelé died in São Paulo on 29 December, aged 82.
Where it stands today — 2026

The vaults are still being opened

The LastPass data did not stay theoretical. In September 2023 Brian Krebs reported that researchers had traced a run of cryptocurrency thefts — more than 150 victims and around $35 million at that point — to seed phrases held in vaults copied in 2022 and cracked offline at the attackers' leisure. Larger thefts were attributed to the same source in the years that followed. The regulatory reckoning took longer: the UK Information Commissioner's Office issued a penalty notice to LastPass UK Limited in November 2025 for a little over £1.2 million, citing among other failures that senior staff could reach Employee Business accounts from personal devices. A US class action settled for $24.5 million, with final approval scheduled for July 2026.

The month's other stories aged in their own directions. Rackspace never brought Hosted Exchange back; the incident ended a product line rather than a company, and its customers finished on Microsoft 365 the migration the attack had started for them. CVE-2022-42475 opened the run of edge-device flaws this archive follows through the three years after it, each one arriving at a firewall or a VPN concentrator rather than a laptop. And AIIMS became the case that every subsequent Indian argument about critical information infrastructure returns to — invoked when the DPDP Act was passed in August 2023, and again when its rules were finally notified. December's lesson is the one the month keeps restating: the disclosure is not the incident. It is the last part of the incident to arrive.