The servers stopped answering at about seven in the morning on Wednesday 23 November 2022. At the All India Institute of Medical Sciences in New Delhi — the hospital patients travel across state lines to reach, because it is where the treatment they cannot get at home is free or nearly free — the eHospital application built and operated by the National Informatics Centre had been encrypted. Outpatient registration, admissions, discharges, billing, appointment scheduling and laboratory report generation all ran on it. What failed first in practice was the least glamorous piece of the system: the barcodes printed for every specimen sent to the laboratory, without which nobody could reliably say whose blood was whose.
AIIMS put out a notice saying that services would continue in manual mode, which turned out to be an accurate description of the following fortnight. A standard operating procedure was circulated for admitting, transferring and discharging patients on paper. Clerks wrote by hand at counters designed for scanners, and the patients hardest to process were those without a unique health identification number, because there was no longer a system in which to look them up. Delhi Police registered a first information report against unknown persons on 25 November, and the case passed to the force's Intelligence Fusion and Strategic Operations unit, which treated it as extortion and cyber terrorism. CERT-In assessed the incident; a DRDO team joined the technical work; the Ministry of Home Affairs was involved throughout.
On 28 November, with the hospital in its sixth day of paper, Indian newspapers reported that the attackers had demanded roughly ₹200 crore in cryptocurrency. It travelled around the world within hours, and was disputed from the beginning by everyone with access to the investigation. Delhi Police issued a statement saying no ransom demand of the kind quoted in sections of the media had been brought to its notice by AIIMS authorities. India's national cyber security coordinator said separately that no ransom had been demanded. When the government answered in the Lok Sabha on 16 December, the Minister of State for Health, Bharati Pravin Pawar, told the House that no specific amount of ransom had been demanded, though a message had been found on the server indicating a cyber attack.
What was eventually established is narrower than what was reported. Five physical servers hosting the eHospital application were affected and roughly 1.3 terabytes of data encrypted; the government blamed improper network segmentation for the spread. One backup server had not been touched. The data was recovered from it onto new hardware — AIIMS said so on 29 November, and online outpatient registration resumed on 6 December, two weeks after the machines went quiet. The widely repeated claim that records of three to four crore patients, including former prime ministers and judges, had been compromised was a fear expressed in reporting, not a finding published by anyone. No group has ever publicly claimed the attack, no AIIMS patient records have surfaced on a leak site, and no arrest has been announced.
Medibank's customers read about themselves
Medibank had detected the intrusion in October and told the Australian market on 7 November 2022 that data belonging to 9.7 million current and former customers had been taken, and that it would not pay. The attackers began publishing on 9 November, on a dark-web blog associated with the REvil ransomware operation, and they did not publish alphabetically. They released curated batches sorted by diagnosis — drug and alcohol treatment on one day, a file they labelled "abortions" on 10 November, others covering HIV and sexually transmitted infections — and described their selections as good and naughty lists. The ransom figures that circulated, first around US$10 million and then US$9.7 million, came from the attackers' own posts; Medibank has never confirmed them. On 11 November the Australian Federal Police said publicly that the offenders were in Russia. The dumping continued in batches until 1 December, when the attackers posted what they called the remainder and declared the case closed.
LastPass wrote to its customers again
On 30 November 2022, LastPass told customers it had detected unusual activity in a third-party cloud storage service shared with its affiliate GoTo, and that an unauthorised party, using information obtained in the August 2022 incident, had gained access to certain elements of customer information. The August incident had been presented as contained: source code and technical information taken from a development environment over four days, with no customer data and no encrypted vaults touched. The November notice was the first public indication that the two were joined. LastPass added that customer passwords remained safely encrypted under its zero-knowledge architecture, which was accurate and beside the point. On 22 December the company disclosed the rest — the attacker had copied backup customer account information including names, company names, billing addresses, email addresses, telephone numbers and IP addresses, together with a backup of customer vault data held in a proprietary binary format that carried unencrypted website URLs alongside fields encrypted with a key derived from each user's master password. Whoever held that copy could take as long as they liked.
A data protection bill, five days early
The Ministry of Electronics and Information Technology published the draft Digital Personal Data Protection Bill, 2022 for public consultation on 18 November — five days before AIIMS went to paper. It replaced the Personal Data Protection Bill, 2019, which had been withdrawn in the Lok Sabha on 3 August 2022 after years in a joint parliamentary committee, and what replaced it was deliberately slimmer: fewer clauses, plainer drafting, no separate statutory category for sensitive personal data, and a schedule of penalties that included up to ₹250 crore for a data fiduciary failing to take reasonable security safeguards against a breach. The drafting used feminine pronouns throughout, a small choice that drew wide comment. Feedback was invited by 17 December, later extended into the new year.
The criticism that mattered concerned what the bill did not constrain. Central government agencies could be exempted from its provisions by notification; the members of the proposed Data Protection Board were to be appointed by the government the Board would sometimes have to rule against; and the consultation itself was run on terms under which submissions were held in a fiduciary capacity and not published, so no one could read what anyone else had argued. For a sense of what enforcement looks like where a law already exists: ten days later, on 28 November, Ireland's Data Protection Commission announced a €265 million fine against Meta Platforms Ireland for infringing the data-protection-by-design obligations in Articles 25(1) and 25(2) of the GDPR, in an inquiry opened after Facebook profile records were scraped through contact-importer tools. That decision had been adopted three days before it was announced. India, that month, had a hospital running on paper and a bill out for comment.
The launch was a blog post
OpenAI released ChatGPT on 30 November 2022 as a free research preview: a conversational interface over its GPT-3.5 series, tuned with reinforcement learning from human feedback to follow instructions and decline some requests. The launch was a blog post, not a paper. Sam Altman said the service crossed one million users within about five days — his figure, and nobody had a better one. Read from 2026, the date needs no annotation: within months the preview was being described as the fastest-growing consumer application to that point, and everything else in this archive's later volumes runs downstream of it.
Meta had already had its month. Galactica, a model trained on scientific literature and posted as a public demo on 15 November, came down after roughly three days once researchers showed it inventing authoritative-sounding citations — the failure the industry would spend the following years learning to name. Cicero, published in Science on 22 November, reached human level at Diplomacy by joining a language model to strategic planning, scoring more than double the human average in an online league whose players learned only afterwards what they had been negotiating with. Stability AI shipped Stable Diffusion 2.0 on 24 November, swapping OpenAI's text encoder for an openly trained replacement and tightening its training-data filters, to immediate complaint from users who found familiar styles harder to reproduce.
NortonLifeLock becomes Gen Digital
On 7 November 2022, NortonLifeLock announced that the company formed by its merger with Avast, completed that September, would be called Gen Digital; the NLOK ticker gave way to GEN on the Nasdaq the following day. The new name sat over much of the consumer anti-virus shelf — Norton, Avast, LifeLock, Avira, AVG, CCleaner and ReputationDefender — run from dual headquarters in Tempe, Arizona, and Prague, and pitched not as anti-virus at all but as "Cyber Safety", with a stated purpose of powering "Digital Freedom". Both the name and the consolidation have held. The enterprise side of the industry had a rougher month: CrowdStrike's results on 29 November showed annual recurring revenue up 54 per cent to US$2.34 billion, slightly short of what analysts had expected, and George Kurtz told investors that smaller customers were delaying purchases in a tightening economy. The shares fell sharply the next day — a company this archive meets again in July 2024, for reasons that had nothing to do with revenue.
⏳ Time capsule — November 2022
- FTX filed for Chapter 11 bankruptcy on 11 November and Sam Bankman-Fried resigned as chief executive the same day.
- NASA launched Artemis I towards the Moon on 16 November, the first integrated flight of the Space Launch System and Orion.
- The FIFA World Cup opened in Qatar on 20 November; two days later Saudi Arabia beat Argentina 2–1 at Lusail, ending a 36-match unbeaten run.
- OpenAI released ChatGPT as a free research preview on 30 November.
What the fortnight was worth
AIIMS came back, and India's legislative answer to what had happened to it took three more years to arrive. The draft published five days before the attack became the Digital Personal Data Protection Act in August 2023; the rules that make it operable were notified on 13 November 2025, on a phased runway that does not reach full compliance until 13 May 2027. CERT-In's six-hour incident reporting direction, in force since June 2022, was the only binding obligation on the hospital at the time, and it says nothing about network segmentation — the specific failing the government itself named in Parliament. AIIMS reported and repelled a further attempt in 2023. The 2022 case has produced no arrest and no formal attribution beyond official accounts, reported in December 2022, tracing the intrusion to IP addresses in China and Hong Kong.
The other two stories are still being counted. Medibank's refusal has held: Australia, the United States and the United Kingdom sanctioned a Russian national over the breach in January 2024 — Australia's first use of its cyber sanctions powers — the information commissioner filed civil penalty proceedings that June, and the class actions were still before the courts in 2026. LastPass's November letter opened the longest-running theft in this archive: US federal agents linked a $150 million cryptocurrency heist in January 2024 to master passwords cracked from those vaults, prosecutors moved to seize about $23.6 million of it, and in December 2025 the analysis firm TRM Labs said it had traced more than $35 million in thefts to the same backup. Encrypted, in that architecture, only ever meant not yet.