The first sign was not a wiper but a flood. On 15 February 2022 the websites of Ukraine's defence ministry, its armed forces and two of its largest banks, PrivatBank and Oschadbank, were pushed offline by what the Ukrainian government described as the largest denial-of-service attack in the country's history; customers found they could not check a balance or move money. Three days later, on 18 February, the White House and the British government jointly attributed the attack to the GRU, Russia's military intelligence service — an unusually fast public attribution, made while the armour was still parked. Five days after that, the flooding stopped and the erasing began.
At 14:52 UTC on 23 February, hours before the first missiles, a wiper began running inside Ukrainian organisations — ESET counted at least five. It carried a valid code-signing certificate that DigiCert had issued in April 2021 to Hermetica Digital Ltd, a company registered in Cyprus; no legitimate software was ever found signed with it, and ESET's assessment was that the company had been impersonated rather than robbed. The certificate was revoked on 24 February, by which point it had done its work. The malware borrowed a driver from the EaseUS Partition Master utility to reach the disk directly, corrupted the master boot record, chewed through the file tables and rebooted the machine into nothing. A second and unrelated wiper, IsaacWiper, followed the next day against a Ukrainian government network.
The other operation began that same afternoon, in an Italian control room. Intruders reached a misconfigured VPN appliance at a KA-SAT ground management centre in Turin on 23 February, and in the small hours of the 24th, as the invasion opened, they issued legitimate management commands that overwrote key data in the flash memory of satellite modems across the network. Viasat put the figure at tens of thousands of terminals knocked offline and shipped nearly 30,000 replacement modems, while insisting the units were not permanently unusable and could be restored by a factory reset. Ukrainian military communications degraded. So did the connections of farms and households in countries with no part in the war — and 5,800 Enercon wind turbines in Germany, spread across roughly 11 gigawatts of capacity, lost remote monitoring and control. The turbines kept turning. Nobody could watch them.
Viasat published its own account on 30 March, describing the misconfigured VPN and the overwritten flash memory; SentinelOne named the modem-wiping malware AcidRain the following day. On 10 May 2022 the European Union, the United States and the United Kingdom formally attributed the KA-SAT operation to Russia, and the sanctions that followed were tied to the attribution rather than to the outage. At Black Hat in August 2023, Viasat and the NSA said publicly that what had looked like a single event was in fact two overlapping operations, one of them showing a deep understanding of how the network was built. Four years on, the lesson of the month is not the wipers, which stayed largely inside Ukraine. It is the modems, which did not.
Conti declared for Russia, and someone inside answered
On 25 February, the day after the invasion, the Conti ransomware operation posted a notice on its leak site announcing "a full support of Russian government" and threatening to strike back at the critical infrastructure of anyone who attacked Russia. Within hours the leadership had edited it into something more neutral, which tells you the reaction had been immediate and internal. Two days later the archives began appearing. From 27 February, and in files sent to journalists and researchers over the days that followed, came hundreds of daily logs from the gang's Jabber server — roughly 60,000 internal messages covering 21 January 2021 to 27 February 2022. They read like a company: salaries, hiring, sick leave, complaints about management, a physical office, working ties to the TrickBot and Emotet crews, ransom negotiations and bitcoin addresses. The leaker was described at the time both as a Ukrainian researcher with access to the server and as a disaffected member of the gang; the identity was never publicly established. Conti's brand did not survive the year.
The day Toyota could not build a car
Kojima Industries makes plastic interior parts and electronic components for Toyota, and on 26 February it found a server fault that had cut its communications with Toyota and disabled its production-tracking system. "This has never happened before," a Kojima spokesman told reporters. "We are not sure yet if it is a cyberattack, but we suspect it might be one." Toyota announced on 28 February that it would stop all 28 production lines at its 14 Japanese plants — every plant it operates in the country — at a cost of about 13,000 vehicles of output. The stoppage itself fell on 1 March; production resumed the following day, and Kojima's systems were largely restored within a month. Hino Motors and Daihatsu were caught in it too. Japan had joined Western sanctions on Russia days earlier, and Prime Minister Fumio Kishida was asked whether the two were connected: "It is difficult to say whether this has anything to do with Russia before making thorough checks." No public attribution was ever established.
Fifty-four apps, and no rule that a breach be reported
On 14 February 2022 the Ministry of Electronics and Information Technology blocked 54 apps under section 69A of the Information Technology Act, on a reference from the Home Ministry. The stated grounds were that the apps sought critical device permissions and collected sensitive user data being transmitted to servers outside the country; many were rebuilt or rebranded versions of apps already blocked in mid-2020, and several traced back to Tencent, Alibaba and NetEase. The list included Garena Free Fire, a battle-royale game with an enormous Indian player base and a competitive scene that simply stopped existing — published, awkwardly for the framing, by the Singapore-based, New York-listed Sea Ltd. The orders themselves were not published and the criteria were not disclosed, which the blocking rules provide for and which critics of the section have objected to for years.
The invasion arrived ten days later, and India's direct exposure was slight; what mattered was the timing. In February 2022 India had no data protection statute in force and no general obligation on a company to say it had been breached. CERT-In's directions under section 70B — the six-hour reporting clock, 180 days of log retention, the KYC duties on VPN and cloud providers — were still ten weeks away, issued on 28 April 2022. The scale came from the government: Rajeev Chandrasekhar, the Minister of State for Electronics and IT, told the Lok Sabha in a written reply on 16 March 2022 that CERT-In had handled more than 2.12 lakh cyber security incidents to the end of February 2022, against 14.02 lakh for the whole of 2021. Nothing that month compelled any of those organisations to tell the people whose data was inside them.
AlphaCode finishes mid-table, and Arm stays unsold
DeepMind opened the month on 2 February 2022 with AlphaCode, a code-writing system that, entered into simulations of ten recent Codeforces programming contests, finished around the middle of the human field — roughly the level of the median competitor, as the lab carefully put it. Dismissed by some at the time as a laboratory exercise, it has aged into plain description: machine-written code at that standard is now simply how much software gets made. A week later the collective EleutherAI published the full weights of GPT-NeoX-20B, a 20-billion-parameter model trained on its own Pile dataset and released under an Apache licence on 9 February — then the largest language model anyone could freely download, and an early landmark of the open-weights movement Meta's Llama would turn into an industry a year later. The month's biggest number belonged to a deal that died: on 8 February Nvidia and SoftBank abandoned the $40 billion sale of Arm after a year and a half of regulatory resistance, SoftBank keeping the deposit and steering Arm towards the listing it completed in September 2023.
Mandiant courted, Avast kept waiting
Industry news led with a courtship that failed and a merger that crawled. On 8 February 2022 Bloomberg reported that Microsoft was in talks to buy Mandiant, the incident-response firm whose name runs through a decade of breach investigations; both companies declined to comment, Mandiant's shares jumped by almost a fifth, and the deal announced on 8 March belonged to Google — $5.4 billion, with Mandiant inside Google Cloud still. NortonLifeLock's purchase of Avast, meanwhile, spent the month in the regulatory queue: Germany's competition authority had cleared it, Britain's and Spain's had not, and in mid-February the companies moved their expected completion date to early April. The Competition and Markets Authority instead sent the deal to an in-depth inquiry in March, cleared it in September 2022, and the combined company trades today as Gen Digital. In the month's final days the industry mobilised around the invasion: Microsoft wrote detection signatures for the new wiper within hours, and the first offers of free protection for Ukrainian organisations appeared — a trickle that widened through the first days of March.
⏳ Time capsule — February 2022
- The Beijing Winter Olympics opened on 4 February and closed on 20 February.
- Meta's shares fell about 26% on 3 February, erasing roughly $230 billion of market value — the largest single-day loss in US stock market history at the time.
- Lata Mangeshkar died in Mumbai on 6 February, aged 92; India observed two days of national mourning.
- The Los Angeles Rams beat the Cincinnati Bengals 23–20 in Super Bowl LVI on 13 February.
The month the blast radius stopped being local
Four years on, February 2022 is the month the argument about whether cyber operations would accompany a conventional war stopped being theoretical. What the forecasts got wrong was the shape of it. The strike on Western power and water that officials had spent weeks warning about never arrived; what arrived instead was collateral, and it arrived through a commercial satellite operator's customer list. German wind farms lost their monitoring because they happened to share a network with a Ukrainian army. The KA-SAT incident is now the standing citation in every argument about space systems as critical infrastructure, and in the insurance industry's long quarrel over what the word "war" means inside a policy.
The rest of the month runs straight into this archive. Conti's brand did not survive 2022 — the United States posted a reward of up to $10 million for information on its leadership in May, and its people scattered into smaller crews, leaving the affiliate market LockBit would dominate when it stopped Royal Mail's international post eleven months later. Kojima Industries is the earliest clean instance of the pattern that would freeze American healthcare payments in February 2024: one supplier, one set of systems, no slack left anywhere. Lapsus$ was inside Nvidia on 23 February and the company confirmed an intrusion on the 25th; the demands, leaks and arrests belong to March. In India, the ten weeks to the CERT-In directions were the last quiet stretch before the clock started.