On 12 December 2023, Kyivstar — Ukraine's largest mobile operator, with roughly 24 million mobile subscribers — simply stopped. Voice, mobile data, and fixed-line services failed nationwide. Air-raid alert systems that depended on the network were affected, ATMs and payment terminals faltered, and a country at war lost a large share of its civilian communications in an instant.
Ukraine's Security Service attributed the attack to Sandworm, the unit of Russian military intelligence tracked by researchers as APT44. The detail that made the case a landmark came from Illia Vitiuk, head of the SBU's cyber department, who told Reuters it was probably the first example of a destructive cyberattack that "completely destroyed the core of a telecoms operator" — thousands of virtual servers and PCs wiped. Not encrypted for ransom. Wiped.
The dwell time is the part every defender should sit with. Vitiuk said the intruders had been inside Kyivstar's network since at least May 2023, with probable full access from November — roughly seven months of quiet residence before the destruction was triggered. Chief executive Oleksandr Komarov said the damage could not be contained virtually and the company was "physically disconnected" from the network to stop it spreading. Voice service returned nationwide by 14 December with more than 90% of base stations back on air, and Kyivstar declared full restoration on 20 December. The company denied that subscriber personal data had been exfiltrated, and reported losses in the billions of hryvnia.
A Telegram channel called Solntsepyok, which the SBU describes as Sandworm-affiliated, claimed responsibility — a claim, as ever, rather than proof. But the strategic meaning needed no attribution debate. In a war, a telecom operator is not a company; it is the nervous system through which a civilian population coordinates survival. December 2023 established that this nervous system can be deleted remotely, by an adversary who has been patiently watching from inside it since spring.
Xfinity's 35.9 million, and the twelve-day window
On 18 December, Comcast notified 35,879,455 Xfinity customers that their data had been taken. The intrusion itself had run from 16 to 19 October and was found during a routine security exercise on 25 October — December was disclosure, not discovery. The route in was Citrix Bleed (CVE-2023-4966), the session-hijacking flaw Citrix had patched on 10 October; reporting says Xfinity applied the fix on 23 October, after the attackers were already inside. Exposed data included usernames, hashed passwords and, for some customers, the last four digits of Social Security numbers, dates of birth and security questions. A thirteen-day patch gap, thirty-six million people.
23andMe: 14,000 accounts, 6.9 million people
December brought the closing arithmetic on the year's most unsettling breach. 23andMe put the final scope at 6.9 million people — roughly 5.5 million DNA Relatives profiles and about 1.4 million Family Tree profiles. Only around 14,000 accounts were actually broken into, via credential stuffing with passwords reused from other breaches. The gap between those numbers is the entire lesson: an opt-in feature designed to connect genetic relatives meant that compromising one account exposed hundreds of people who were never hacked and never chose anything. The company also quietly changed its terms of service that month to push disputes into arbitration — a move widely read as pre-empting the class actions that came anyway.
A BSNL listing, and a new telecom law
On 22 December, Business Standard reported that an actor using the handle "Perell" had listed a dataset belonging to state-owned BSNL for sale on BreachForums — a roughly 32,000-line sample, a claim of more than 2.9 million fibre and landline user records, and an asking price of about $5,000. Every one of those figures came from the seller; BSNL did not publicly confirm the breach at the time. (Readers should note that the "278 GB" figure widely attached to BSNL belongs to a separate 2024 incident, not this one.) The same fortnight brought a change of far greater consequence: Parliament passed the Telecommunications Bill on 20–21 December and it received presidential assent on 24 December, replacing the Indian Telegraph Act of 1885 after 138 years and rewriting the state's interception powers for the digital era. India ended 2023 with a data protection statute passed in August and a telecom statute passed in December — and neither yet operational.
Gemini's launch, and an edited demo
Google announced Gemini 1.0 on 6 December 2023 in three sizes — Nano, Pro and Ultra — and put Bard with Gemini Pro live the same day in English across 170 countries and territories, though not in the European Union or the United Kingdom, where it said it was still working with regulators. Ultra, claimed as the first model to pass the human-expert baseline on MMLU, did not reach users until February 2024. Within a day the launch was overshadowed by "Hands-on with Gemini", a video built from still frames and typed prompts rather than the real-time spoken exchange it appeared to show; Google maintained that the prompts and outputs were real, shortened for brevity. EU negotiators announced the provisional AI Act deal on 9 December after thirty-six hours of talks; Mistral posted a magnet link on 8 December and introduced Mixtral 8x7B, an Apache-licensed mixture-of-experts model, on 11 December; and on 27 December The New York Times sued OpenAI and Microsoft over training data, a claim OpenAI disputes as fair use and one that in 2026 still frames the argument.
500 decryption keys, and an unseized site
On 19 December 2023 the United States Justice Department announced a disruption of ALPHV/BlackCat, by then the second most prolific ransomware-as-a-service operation. The FBI had spent months inside the gang's infrastructure and came away with decryption keys for around 500 victims, sparing them roughly $68 million in ransom demands; the seizure of the leak site was coordinated with Europol and partners across Europe and Australia. Within hours BlackCat reposted the site under its own control with the words "THIS WEBSITE HAS BEEN UNSEIZED", loosened its rules on affiliate targeting and raised affiliate revenue shares to 90%; the seizure was real, the shutdown was not. Two quieter defensive notes closed the month: Kaspersky used a 37C3 talk on 27 December to explain how Operation Triangulation's iPhone chain had abused an undocumented hardware feature, and on 28 December Microsoft disabled the ms-appinstaller protocol handler by default after signed MSIX packages were used to walk malware past SmartScreen. The survival mattered — an affiliate breached Change Healthcare in February 2024, and BlackCat exit-scammed that March behind a fake seizure notice of its own.
⏳ Time capsule — December 2023
- Google announced Gemini, its first natively multimodal model family, on 6 December, with the API opening to developers on 13 December.
- Javier Milei was inaugurated as President of Argentina on 10 December.
- COP28 closed in Dubai on 13 December with the "UAE Consensus" first global stocktake decision.
- On 9 December, EU negotiators struck the provisional political deal that became the AI Act.
The wiper's long shadow
Kyivstar remains the reference case for destructive attacks on civilian telecom infrastructure, and its seven-month dwell time is the number cited whenever someone argues that detection matters more than prevention. Its logic — infiltrate quietly, destroy decisively — runs directly to the wipers that erased a medtech company's screens in March 2026, and it sits behind every regulator who now treats telecom security as national security, from Washington's Salt Typhoon reckoning to Singapore's four-carrier disclosure. Citrix Bleed, meanwhile, went on to be the year's most consequential unpatched flaw, and 23andMe's 14,000-to-6.9-million ratio became the standard illustration of why interconnected features multiply breach blast radius. History, as this archive keeps finding, rarely ends in the month it happens.