The story began at the end of March, when security vendors published near-simultaneous advisories that 3CX's DesktopApp softphone had been trojanised and was shipping a backdoor to customers. CrowdStrike's warning came first on 29 March; 3CX's own alert and a CISA advisory followed on the 30th. Users had actually been reporting endpoint-security detections on 3CX's forums since around 22 March — and had largely been told they were false positives. 3CX says more than 600,000 organisations and over 12 million daily users run its platform, which gave a compromised, validly signed installer one of the largest blast radiuses since SolarWinds.
Then, on 20 April, Mandiant published the finding that made April 2023 a landmark. The intrusion into 3CX had itself begun with a separate supply-chain compromise: a 3CX employee had downloaded a trojanised installer for X_TRADER, a financial trading application, in April 2022. Attackers used the resulting backdoor to move laterally into 3CX's network and from there to poison 3CX's own product. Mandiant called it "the first we are aware of which has led to a cascading software supply chain compromise" — the company's own careful hedge, worth preserving rather than flattening into a flat claim of firstness.
The details of the first link are the ones that should keep procurement teams awake. Trading Technologies had discontinued X_TRADER in 2020. The malicious installer was nevertheless still downloadable from the company's website in 2022, and it carried a valid code-signing certificate that remained valid until October 2022. A dead product, still hosted, still signed, still trusted — and through it, an attacker reached a communications vendor used by 600,000 organisations. Trading Technologies said it had not verified Mandiant's findings and reiterated that it stopped supporting the software in 2020.
Attribution stayed deliberately messy, and this archive keeps it that way. CrowdStrike attributed the 3CX compromise with high confidence to Labyrinth Chollima, a DPRK-nexus cluster commonly folded into "Lazarus". Mandiant declined to adopt that label, tracking the operator as UNC4736 and linking it only with moderate confidence to previously reported North Korean cryptocurrency-theft activity. Two of the world's best incident-response firms, looking at the same intrusion, published different names with different confidence levels — a useful reminder of how provisional attribution is, even when everyone agrees on the general direction.
Western Digital pulls the plug on itself
Western Digital said it identified a network security incident on 26 March, in which an unauthorised third party accessed a number of its systems, and issued its public statement on 3 April. It then proactively disconnected services from the internet: My Cloud, My Cloud Home, SanDisk ibi and others went dark from 2 April, with service reported restored on 13 April — roughly twelve days during which customers could not reach their own files on their own devices. The attackers told reporters anonymously that they had taken about 10 TB including a code-signing certificate, and were reported to have demanded a "minimum 8 figures"; Western Digital never confirmed either. What it did confirm, on 5 May, was narrower: a copy of an online-store database with customer names, addresses, hashed passwords and partial card numbers.
Capita: from "no evidence" to 6.6 million people
The intrusion at UK outsourcer Capita began on 22 March at 07:52, when a malicious script pulled down Qakbot and Cobalt Strike. Roughly 973 GB was exfiltrated on 29–30 March, and ransomware landed on more than 1,000 hosts on 31 March, forcing a password reset across all 59,359 system accounts. Capita notified the ICO on 31 March and went public on 3 April, initially saying it had found no evidence that customer, supplier or colleague data had been compromised. Black Basta listed the company around 8 April with sample files. On 20 April, Capita conceded data had been exfiltrated from roughly 4% of its server estate. The final toll reached around 6.6 million people — including approximately 470,000 pension scheme members, with special-category health and criminal-record data among the material — £25 million in recovery costs, and a combined £14 million ICO fine in October 2025.
RentoMojo's misconfiguration, and a hacktivist target list
On 20 April 2023, Bengaluru rental startup RentoMojo emailed customers to disclose that attackers had gained unauthorised access to one of its databases, attributing the breach to a cloud misconfiguration. Have I Been Pwned later catalogued 2.2 million unique email addresses exposed alongside names, phone numbers, dates of birth, password hashes, purchase records — and government-issued IDs including passport and Aadhaar numbers. (Various secondary write-ups cite wildly different victim counts; the HIBP figure is the one with provenance.) RentoMojo said no financial data was exposed because it never stores card or UPI details, though users reported receiving emails from a group claiming otherwise — an unsubstantiated claim.
Separately, on 13–14 April, I4C and CERT-In circulated an "Urgent – High Alert" after a group calling itself Hacktivist Indonesia published a list of roughly 12,000 central, state and private Indian websites it said it would target with denial-of-service attacks. Officials said Indian government sites were updated and capable of handling the threat. The alert is a useful marker of where India's cyber posture stood in early 2023: capable of issuing rapid national advisories, and simultaneously host to consumer startups leaving Aadhaar numbers in misconfigured databases.
⏳ Time capsule — April 2023
- Finland formally joined NATO on 4 April, becoming the alliance's 31st member.
- The Super Mario Bros. Movie opened on 5 April and went on to gross more than $1 billion.
- Netflix announced on 18 April that it would ship its final DVDs in September, ending the 25-year mail business it was built on.
- SpaceX flew the first integrated Starship test on 20 April; the vehicle was destroyed less than four minutes after liftoff.
Compounding trust
The 3CX cascade proved that supply-chain compromises multiply: a single poisoned installer can be the seed of a second, larger one, and the chain of trust an organisation depends on extends further than any vendor questionnaire reaches. Everything in this archive's later years — the npm worms of 2025, the AI-toolchain compromise of July 2026 — is a variation on the lesson April 2023 taught first. The X_TRADER detail, a discontinued product still hosted and still signed, made certificate lifecycle and software decommissioning genuine security disciplines. And Capita's arc from "no evidence" to 6.6 million people remains the standard warning about the cost of premature reassurance: the denial is always quoted back to you.