On 12 December 2023, Kyivstar — Ukraine's largest mobile operator, with roughly 24 million mobile subscribers — simply stopped. Voice, mobile data, and fixed-line services failed nationwide. Air-raid alert systems that depended on the network were affected, ATMs and payment terminals faltered, and a country at war lost a large share of its civilian communications in an instant.

Ukraine's Security Service attributed the attack to Sandworm, the unit of Russian military intelligence tracked by researchers as APT44. The detail that made the case a landmark came from Illia Vitiuk, head of the SBU's cyber department, who told Reuters it was probably the first example of a destructive cyberattack that "completely destroyed the core of a telecoms operator" — thousands of virtual servers and PCs wiped. Not encrypted for ransom. Wiped.

The dwell time is the part every defender should sit with. Vitiuk said the intruders had been inside Kyivstar's network since at least May 2023, with probable full access from November — roughly seven months of quiet residence before the destruction was triggered. Chief executive Oleksandr Komarov said the damage could not be contained virtually and the company was "physically disconnected" from the network to stop it spreading. Voice service returned nationwide by 14 December with more than 90% of base stations back on air, and Kyivstar declared full restoration on 20 December. The company denied that subscriber personal data had been exfiltrated, and reported losses in the billions of hryvnia.

A Telegram channel called Solntsepyok, which the SBU describes as Sandworm-affiliated, claimed responsibility — a claim, as ever, rather than proof. But the strategic meaning needed no attribution debate. In a war, a telecom operator is not a company; it is the nervous system through which a civilian population coordinates survival. December 2023 established that this nervous system can be deleted remotely, by an adversary who has been patiently watching from inside it since spring.

Also that month · The bill for October

Xfinity's 35.9 million, and the twelve-day window

On 18 December, Comcast notified 35,879,455 Xfinity customers that their data had been taken. The intrusion itself had run from 16 to 19 October and was found during a routine security exercise on 25 October — December was disclosure, not discovery. The route in was Citrix Bleed (CVE-2023-4966), the session-hijacking flaw Citrix had patched on 10 October; reporting says Xfinity applied the fix on 23 October, after the attackers were already inside. Exposed data included usernames, hashed passwords and, for some customers, the last four digits of Social Security numbers, dates of birth and security questions. A thirteen-day patch gap, thirty-six million people.

Also that month · The final tally

23andMe: 14,000 accounts, 6.9 million people

December brought the closing arithmetic on the year's most unsettling breach. 23andMe put the final scope at 6.9 million people — roughly 5.5 million DNA Relatives profiles and about 1.4 million Family Tree profiles. Only around 14,000 accounts were actually broken into, via credential stuffing with passwords reused from other breaches. The gap between those numbers is the entire lesson: an opt-in feature designed to connect genetic relatives meant that compromising one account exposed hundreds of people who were never hacked and never chose anything. The company also quietly changed its terms of service that month to push disputes into arbitration — a move widely read as pre-empting the class actions that came anyway.

India desk · December 2023

A BSNL listing, and a new telecom law

On 22 December, Business Standard reported that an actor using the handle "Perell" had listed a dataset belonging to state-owned BSNL for sale on BreachForums — a roughly 32,000-line sample, a claim of more than 2.9 million fibre and landline user records, and an asking price of about $5,000. Every one of those figures came from the seller; BSNL did not publicly confirm the breach at the time. (Readers should note that the "278 GB" figure widely attached to BSNL belongs to a separate 2024 incident, not this one.) The same fortnight brought a change of far greater consequence: Parliament passed the Telecommunications Bill on 20–21 December and it received presidential assent on 24 December, replacing the Indian Telegraph Act of 1885 after 138 years and rewriting the state's interception powers for the digital era. India ended 2023 with a data protection statute passed in August and a telecom statute passed in December — and neither yet operational.

⏳ Time capsule — December 2023

  • Google announced Gemini, its first natively multimodal model family, on 6 December, with the API opening to developers on 13 December.
  • Javier Milei was inaugurated as President of Argentina on 10 December.
  • COP28 closed in Dubai on 13 December with the "UAE Consensus" first global stocktake decision.
  • On 9 December, EU negotiators struck the provisional political deal that became the AI Act.
Where it stands today — 2026

The wiper's long shadow

Kyivstar remains the reference case for destructive attacks on civilian telecom infrastructure, and its seven-month dwell time is the number cited whenever someone argues that detection matters more than prevention. Its logic — infiltrate quietly, destroy decisively — runs directly to the wipers that erased a medtech company's screens in March 2026, and it sits behind every regulator who now treats telecom security as national security, from Washington's Salt Typhoon reckoning to Singapore's four-carrier disclosure. Citrix Bleed, meanwhile, went on to be the year's most consequential unpatched flaw, and 23andMe's 14,000-to-6.9-million ratio became the standard illustration of why interconnected features multiply breach blast radius. History, as this archive keeps finding, rarely ends in the month it happens.