At half past three in the morning UTC on 22 March 2022, a Cloudflare employee emailed the company's incident response team a link to a tweet about screenshots that had gone up minutes earlier, and an incident room was open eight minutes later. The images had been posted on Telegram by Lapsus$, a loose extortion crew whose members would turn out to be teenagers, and they showed the internal support tooling of Okta — the identity provider that thousands of organisations rely on to decide who may log in to everything else. One image carried a Cloudflare employee's email address; Cloudflare suspended that account by 05:03 UTC and forced password resets on the 144 employees who had changed a password or an authentication factor since 1 December. The screenshots themselves were dated 21 January. They were two months old.
Okta's own published timeline explains why. On 20 January at 23:18 UTC its security team received an alert that a new multi-factor authentication factor had been added, from a new location, to the Okta account of a support engineer working for Sitel — an outsourced customer-support provider whose Sykes subsidiary handled some Okta cases. The account was suspended just after midnight. Forensics later placed the intruder inside the Sitel environment between 16 and 21 January. Okta asked Sitel for the findings and received a summary report on 17 March; the complete report arrived at 12:27 on 22 March, roughly nine hours after the screenshots had already been published. The attack was January. The disclosure was March.
What followed was a case study in how a company sizes a breach in public. On 22 March, Okta's chief security officer, David Bradbury, put the maximum potential impact at 366 customers, about 2.5 per cent of the customer base — a number derived not from evidence of access but from every Okta tenant any Sitel engineer could have touched during the five-day window. On 20 April, with the investigation finished, Bradbury said the intruder had actively controlled a single Sitel workstation for twenty-five consecutive minutes on 21 January, and that two customers had been impacted. Both figures came from Okta. The company conceded it "should have more actively and forcefully compelled information from Sitel," and later ended the relationship.
The Okta episode closed a month in which the same crew had walked through much of the industry. Nvidia confirmed on 1 March that employee credentials and proprietary information had been taken. Samsung confirmed on 7 March that source code relating to Galaxy devices had been stolen, after roughly 190GB appeared in a torrent, and said no customer or employee personal data was involved. Ubisoft disclosed an incident on 10 March. Microsoft confirmed on 22 March that a single account had been compromised, after the gang published what it claimed was 37GB of source code. Microsoft's write-up described methods rather than exploits: SIM swaps, paid insiders, repeated authentication prompts, and sitting in on victims' own crisis calls. On 24 March, City of London Police announced it had arrested seven people aged 16 to 21, all released under investigation.
The bridge nobody was watching
On 23 March 2022 an attacker used compromised validator keys to sign two withdrawals that emptied the Ronin bridge, the crossing between Ethereum and the sidechain built for the game Axie Infinity: 173,600 ETH and 25.5 million USDC, worth roughly $620 million at that day's prices and the largest cryptocurrency theft recorded to that point. Nobody noticed for six days. It surfaced on 29 March, when a user could not complete a withdrawal and Sky Mavis, the studio behind the game, went looking. Five of nine validator keys had been compromised — four belonging to Sky Mavis, the fifth to the Axie DAO, which had let Sky Mavis sign on its behalf during a traffic surge in November 2021 and never withdrawn the permission. Sky Mavis said in a post-mortem on 27 April that its staff were under constant advanced spear-phishing attacks and that one employee had been compromised; later reporting described a fake job offer delivered as a PDF, after rounds of interviews for a company that did not exist. The US Treasury tied the receiving address to North Korea's Lazarus Group on 14 April. Sky Mavis raised $150 million, reimbursed users, and reopened the bridge in June.
What happened to the modems
Tens of thousands of satellite modems across Ukraine and Europe had stopped working on 24 February, in the hour Russian forces crossed the border; on 30 March, Viasat published its first account of why. The company said an attacker had exploited a misconfiguration in a VPN appliance to reach the trusted management segment of the KA-SAT ground network, then issued commands to the terminals that overwrote key data in their flash memory, leaving them unable to connect. The next day SentinelOne published an analysis of a wiper it named AcidRain and reported developmental overlaps with a component of VPNFilter, malware previously attributed to Russian military intelligence. Viasat said the description was consistent with what it had observed; it did not itself name an attacker. The detail that stuck was collateral and industrial: roughly 5,800 Enercon wind turbines in Germany lost remote monitoring, because they happened to depend on the same satellite link. The European Union, the United Kingdom and the United States formally attributed the attack to Russia on 10 May 2022.
Counting incidents, collecting biometrics
On 11 March 2022 the Reserve Bank of India ordered Paytm Payments Bank to stop onboarding new customers with immediate effect, and to appoint an IT audit firm to carry out a comprehensive system audit of its IT systems. The order was issued under Section 35A of the Banking Regulation Act, 1949, and the public reasoning ran to three words: material supervisory concerns. New customers would resume only after the regulator had reviewed the auditors' report. Five days later, on 16 March, the Minister of State for Electronics and IT, Rajeev Chandrasekhar, told the Lok Sabha in a written reply that CERT-In had recorded more than 2.12 lakh cybersecurity incidents in the first two months of 2022 — against 14.02 lakh across the whole of 2021.
On 28 March the Criminal Procedure (Identification) Bill was introduced in the Lok Sabha. It would allow police to record finger and palm impressions, footprints, photographs, and iris and retina scans from anyone convicted, arrested or held in preventive detention, with biological samples compellable only for offences against women and children or those carrying seven years or more, and the National Crime Records Bureau holding the records for seventy-five years. Opposition members objected at introduction on privacy grounds, citing the Supreme Court's Puttaswamy judgment; the Bill cleared both Houses within ten days and received assent on 18 April. What makes the pairing worth recording is what India did not have that month: no data protection statute in force — the 2019 Bill was still pending, and would be withdrawn that August — and CERT-In's six-hour reporting regime still six weeks away.
The transformer gets its own engine
At its GTC conference on 22 March 2022, Nvidia announced the Hopper architecture and the H100, an 80-billion-transistor GPU with a Transformer Engine built to accelerate the model family behind GPT-3 — received at the time as a data-centre roadmap item, and in hindsight the workhorse silicon of the frontier-model build-out that followed. The month's software news reads the same way: small print, large consequences. On 15 March OpenAI gave GPT-3 and Codex the ability to edit and insert text rather than only append to it, one quiet step in the conversion of an autocomplete engine into a working assistant. On 29 March DeepMind posted the Chinchilla paper, which showed a 70-billion-parameter model trained on more data outperforming its own 280-billion-parameter Gopher at the same compute cost, and reset how the industry sized its models. Earlier in the month, on 8 March, DeepMind co-founder Mustafa Suleyman had surfaced with a new venture, Inflection AI; two years later Microsoft hired him, and most of the company's staff, to run its consumer AI work.
Warned in Berlin, listed in Washington
The Russian question stopped being hypothetical. On 15 March 2022 Germany's Federal Office for Information Security, the BSI, formally warned against Kaspersky's products, advising that they be replaced — a Russian manufacturer, it reasoned, could be forced to attack its own customers or be misused without its knowledge. On 25 March the US Federal Communications Commission added AO Kaspersky Lab to its covered list of national-security threats, the first Russian company on a register previously occupied by Chinese firms such as Huawei and ZTE. Kaspersky called both decisions political rather than technical, a defence it maintained all the way to the outright American ban of 2024. The month's other business was consolidation: on 1 March an investor group led by Advent International and Permira completed its take-private of McAfee, an all-cash deal valued at over $14 billion; and on 16 March the UK's Competition and Markets Authority announced competition concerns that sent the NortonLifeLock–Avast merger into an in-depth Phase 2 investigation. Clearance came only in September; by year's end the combined company had been renamed Gen Digital.
⏳ Time capsule — March 2022
- The UN General Assembly voted 141 to 5 on 2 March, with 35 abstentions including India, to demand Russia withdraw from Ukraine.
- Apple's "Peek Performance" event on 8 March introduced the Mac Studio and the M1 Ultra chip, a third-generation iPhone SE and a 27-inch Studio Display.
- The IPL returned on 26 March with ten teams for the first time since 2011, the entire league phase played in Mumbai and Pune.
- At the Academy Awards on 27 March, CODA became the first film from a streaming service to win Best Picture — and Will Smith walked on stage and struck Chris Rock.
The playbook outlived the crew
Lapsus$ did not last. A jury at Southwark Crown Court found two teenagers responsible in August 2023, and on 21 December 2023 Arion Kurtaj, then eighteen and assessed as unfit to stand trial, was given an indefinite hospital order; the younger defendant received a youth rehabilitation order. The method outlived them. Help-desk social engineering, SIM swaps and authentication-prompt fatigue became the opening move for the English-speaking crews that followed, and the identity provider became the obvious place to aim. Okta was breached through its support systems again in October 2023, and again a customer noticed first. What was startling in March 2022 — that no zero-day appeared anywhere in the chain — is now the baseline assumption.
The other threads ran on. Ronin's $620 million stood as the largest cryptocurrency theft on record until February 2025, and the North Korean revenue pipeline it belonged to only widened. Viasat's wiped modems drew formal state attribution on 10 May 2022 and pulled commercial satellite operators inside the critical-infrastructure conversation for good. In India, the Reserve Bank's March 2022 order against Paytm Payments Bank was the first visible step on a road that ended in early 2024 with the regulator winding the bank's operations down. The Criminal Procedure (Identification) Act became law three weeks after it was introduced; the data protection statute that might have governed the database it authorised did not pass until August 2023, and its rules took longer still.