On the night of 13 January 2022, someone replaced the front pages of the Ukrainian state. Visitors to the foreign ministry, the Cabinet of Ministers, the State Emergency Service and the education ministry found the same block of text in Ukrainian, Russian and Polish, telling them their personal data had been made public and that they should be afraid and expect the worst. The closing line invoked Volhynia, Galicia and the OUN-UPA — the massacres that still sit between Poland and Ukraine — and the Polish read as though it had gone through a translation engine. The Security Service of Ukraine later said around seventy sites had been targeted and roughly ten actually altered. The cyber police said within hours that none of it was true.

The defacement was the part meant to be seen. On 15 January, Microsoft's Threat Intelligence Center published its analysis of destructive malware found on systems at Ukrainian government agencies, non-profits and IT firms, first appearing on victim machines on 13 January, the same night. The first stage overwrote the master boot record with a ransom note demanding $10,000 in bitcoin to a fixed wallet address, offering a Tox chat ID as the only channel. The second stage pulled a file corruptor from Discord and overwrote the contents of files carrying 189 different extensions with a repeating byte. Microsoft set out what was wrong with the note: the payload was identical for every victim, there was no per-victim key, no decryption identifier, and nothing had been encrypted at all.

How the attackers got in took longer to settle, and there was more than one route. Investigators examined an authentication-bypass flaw in the October CMS platform dating from August 2021, the Log4Shell fallout still washing through everything, and the compromise of Kitsoft, a Ukrainian IT contractor that managed websites for several government bodies — a supply-chain path into the state through the firm that had built its front door. On 16 January, Serhiy Demedyuk, deputy secretary of Ukraine's National Security and Defence Council, told Reuters the defacement had been a cover for more destructive work, and pointed at UNC1151, a group Mandiant had tied to Belarusian intelligence. That was Kyiv's assessment inside the first seventy-two hours, offered as such. The formal one took two and a half years.

In June 2024 the US Justice Department charged Amin Timovich Stigal, a Russian civilian, with conspiring to deploy WhisperGate against Ukrainian government systems; in September 2024 it added five officers of GRU Unit 29155, a colonel and four lieutenants, with a reward of up to $10 million offered for information leading to them. Microsoft, which had filed the activity under the placeholder DEV-0586, later renamed it Cadet Blizzard and attributed it to Russian military intelligence. None of the accused has been arrested. Six weeks after WhisperGate, HermeticWiper ran through Ukrainian systems on the eve of the invasion and the Viasat KA-SAT terminals went dark across Europe. January was the rehearsal, and the ransom note nobody could pay was the tell.

Also that month · Seventy days, 515,000 people

The Red Cross asked the attackers to be decent

On 19 January the International Committee of the Red Cross said data on more than 515,000 people had been taken from servers holding its Restoring Family Links records — the programme that reunites people separated by war, migration and disaster. The records came from at least sixty Red Cross and Red Crescent societies, covering missing people, their families, detainees and aid recipients. The ICRC shut the systems down, stopping the tracing work, and director-general Robert Mardini appealed to whoever held the files: "Please do the right thing. Do not share, sell, leak or otherwise use this data." The intrusion had begun on 9 November 2021 and was found only on 18 January, seventy days later, when the organisation installed endpoint detection agents during an upgrade. The way in was CVE-2021-40539, an unpatched flaw in Zoho ManageEngine ADSelfService Plus. The ICRC's fuller analysis a month later described code compiled to run only on the targeted servers, keyed to their MAC addresses. It said the tooling resembled that of advanced persistent threat groups, but declined to name anyone, and still has not. There is no public evidence, in 2026, that the data leaked.

Also that month · A raid with a short half-life

Russia arrested REvil, once

On 14 January, the same day Ukraine was putting its websites back up, Russia's Federal Security Service announced it had dismantled REvil, the group behind the Kaseya and JBS attacks of 2021. The FSB said it had searched twenty-five addresses linked to fourteen people across Moscow, St Petersburg, the Leningrad region and Lipetsk, seizing 426 million roubles, $600,000, €500,000, cryptocurrency wallets, computers and twenty cars — and said it had acted on a request from the United States and notified Washington of the results. Read on its own it looked like the first real Russian move against ransomware. Read against the calendar it lasted about six weeks, because on 24 February the invasion ended any cooperation. The prosecutions went ahead anyway, on Russian charges. In October 2024 a St Petersburg court convicted four of the accused — Artem Zayets, Aleksey Malozemov, Daniil Puzyrevsky and Ruslan Khansvyarov — on offences including illegal circulation of means of payment, with prison terms of more than four years. Four others were convicted in 2025 and released for time served. Nobody was extradited, and nobody was tried for the attacks that prompted the request.

India desk · January 2022

Bulli Bai: a fake auction, hosted for free

On 1 January 2022 a page appeared at bullibai.github.io presenting more than a hundred Indian Muslim women as lots in a mock auction. The photographs came from the women's own public social media accounts, some doctored; the targets were journalists, activists, students and academics. Ismat Ara, a Delhi journalist who found herself listed, filed a complaint describing the page as designed to create fear and shame in Muslim women generally. It was the second time: in July 2021 a near-identical page called Sulli Deals had listed around eighty women and produced no arrests. GitHub removed the page and blocked the account; India's IT minister Ashwini Vaishnaw said the platform had confirmed as much. Nothing here was hacked, and nothing taken that the women had not already published themselves.

The arrests came quickly this time. Mumbai Police held Vishal Kumar Jha, a twenty-one-year-old student, in Bengaluru on 4 January, and Shweta Singh, eighteen, and Mayank Rawal, twenty-one, both from Uttarakhand, the next day. On 6 January the Delhi Police cyber cell arrested Niraj Bishnoi, a twenty-one-year-old engineering student from Jorhat in Assam, naming him the page's author; on 9 January the same unit arrested the man behind Sulli Deals in Indore, six months after that case went cold. Charges ran under the Indian Penal Code and the IT Act; most of the accused were bailed during 2022. The case marked the shape of a gap rather than a breach. India then had no data protection statute at all; the CERT-In directions were three months away and the DPDP Act nineteen, and neither would have reached this. The women's remedy was a police complaint and a foreign platform's willingness to press delete.

AI Tech desk · January 2022

OpenAI teaches GPT-3 to follow instructions

On 27 January, OpenAI made InstructGPT the default for the text models on its API — GPT-3 fine-tuned with reinforcement learning from human feedback, so that it would do what it was asked rather than continue whatever it was given. The announcement was modest and the numbers were not: the firm's human labellers preferred the output of a 1.3-billion-parameter InstructGPT to that of the 175-billion-parameter GPT-3, evidence that alignment could beat two orders of magnitude of scale. Read from 2026 it is the month's most consequential release, because the same recipe, scaled up and given a chat window, became ChatGPT ten months later. Three days earlier, on 24 January, Mark Zuckerberg had announced Meta's AI Research SuperCluster, which the company said would be the fastest AI supercomputer in the world once its full sixteen thousand GPUs were in place by mid-2022. It was pitched at the metaverse; it is remembered as part of the build-out that went on to train the Llama models.

Digital Guard desk · January 2022

The antivirus that mined Ethereum

Norton 360 began January explaining a feature many of its customers had not noticed: an Ethereum miner, bundled since the previous summer, that put idle machines to work and kept 15 per cent of the proceeds. The backlash arrived on 4 January, after a thread by the writer Cory Doctorow spread widely; the company's own removal instructions had users switch off the product's tamper protection before deleting NCrypt.exe by hand, and Krebs on Security reported that Avira — under the same parent, NortonLifeLock, and claiming half a billion users — carried a near-identical feature. NortonLifeLock's defence, maintained throughout, was that the miner was strictly opt-in and never ran without permission. Ethereum abandoned proof-of-work mining later that year and took the premise with it. On 19 January, Symphony Technology Group named the company it had assembled from McAfee Enterprise and FireEye: Trellix, an XDR vendor. Two of the industry's oldest brands became a garden lattice; Mandiant, the piece STG had not bought, went to Google soon after.

⏳ Time capsule — January 2022

  • The Hunga Tonga–Hunga Haʻapai volcano erupted on 15 January, sending tsunami warnings around the Pacific rim.
  • Novak Djokovic was deported from Australia on 16 January after a court upheld the cancellation of his visa, ruling him out of the Australian Open.
  • Microsoft announced on 18 January that it would buy Activision Blizzard for $68.7 billion, the largest acquisition the games industry had seen.
  • The James Webb Space Telescope reached its orbit around the L2 point on 24 January, roughly a million miles from Earth.
Where it stands today — 2026

The month the archive now starts

January 2022 is, for now, the oldest edition in The Vault, and a fair place to begin: almost everything that follows is visible in it. WhisperGate opens a line that runs through HermeticWiper and Viasat in February 2022 and reaches, in these pages, a March 2026 of wipers destroying workstations at a medtech company while staff watched. The ICRC breach set the pattern for humanitarian data as a target, and for intrusions found by accident. The FSB's REvil raids read now as the last cooperative gesture before the door shut. The smaller stories held: Crypto.com's two-factor bypass on 17 January, described first as an incident in which the company insisted no customer funds were lost, then as 483 accounts and $34 million; and DeadBolt's campaign against exposed QNAP drives, which ended with a vendor force-pushing firmware onto hardware customers owned.

The Vault continues backwards from here. December 2021 and the months behind it — Log4Shell, Kaseya, Colonial Pipeline, and further back still to the WannaCry edition already sitting in this archive — are future restorations. The India desk's thread starts here too, in a month when the country's whole answer to a page full of women's faces was a police station and an email to a company in San Francisco. Each edition added tends to confirm the same unwelcome thing: the chain does not begin anywhere in particular. It only gets longer at both ends, and the month that looks like an opening is usually somebody's middle.