Royal Mail's international export services failed on 10 January 2023, and the company publicly disclosed a "cyber incident" the following day, asking customers to stop posting items overseas altogether. The attack struck the Heathrow Worldwide Distribution Centre — the hub where export mail is processed and dispatched — which is why domestic post kept moving while everything bound abroad simply stopped. Small exporters, eBay sellers and anyone with family overseas discovered that a 500-year-old postal service had a single digital point of failure.
The first public clue to who was responsible came from the shop floor: staff at the Belfast distribution centre reported printers spontaneously producing ransom notes headed "LockBit Black Ransomware." Even the attribution turned into a farce. LockBit's spokesperson initially told reporters the group had not attacked Royal Mail, blaming other actors using its ransomware builder, which had leaked in September 2022 — before the gang confirmed on 7 February that one of its affiliates had deployed the payload after all. This archive reports that attribution as what it is: the criminals' own shifting claims, not published forensics.
What elevates the story is the negotiation transcript, which LockBit itself published. The gang demanded $80 million, framed as 0.5% of annual revenue, and later halved it to roughly $40 million. Royal Mail refused, telling the gang it would not hand over "the absurd amount of money you have demanded" and pointing out it was a smaller subsidiary than the attackers assumed. Limited international services resumed on 19 January, and Royal Mail said on 23 February that services had been restored for all customers — roughly six weeks of disruption. Its parent later booked £10 million in remediation and resilience costs, alongside a reported 5% drop in international parcel volumes.
It is one of the cleanest public examples in this archive of a large organisation absorbing six weeks of operational pain rather than paying — and publishing enough of the exchange for everyone else to learn from it.
T-Mobile, again
T-Mobile disclosed in an SEC filing on 19 January that a bad actor had obtained data on approximately 37 million current postpaid and prepaid customer accounts. The filing is precise in a way that repays reading: the attacker first retrieved data through the impacted API on or around 25 November 2022, T-Mobile identified the malicious activity on 5 January 2023, and the API was shut down within a day of detection. Exposed fields included names, billing addresses, emails, phone numbers, dates of birth and account details. The company framed it carefully — no evidence its systems or network had been breached, only that a single API had been abused. Contemporaneous reporting noted this was at least T-Mobile's eighth publicly disclosed security incident since 2018. Roughly six weeks of undetected extraction, through an interface working exactly as built.
The FBI had been reading Hive's mail since July
On 26 January, the US Justice Department announced it had disrupted the Hive ransomware group, seizing its leak site and negotiation portal alongside German and Dutch police and Europol. The revelation was the good part: the FBI said it had held covert access inside Hive's networks since late July 2022, quietly supplying more than 300 decryption keys to victims under active attack and over 1,000 keys to earlier victims — preventing an estimated $130 million in ransom demands from being paid. Hive had targeted more than 1,500 victims across over 80 countries, including hospitals and school districts. No arrests were announced; the operation was presented as disruption, with the investigation continuing. For six months, victims had been handed free decryptors by an agency that could not tell them why it had one.
DIKSHA: a national school platform, left open
On 23 January 2023, WIRED reported that a misconfigured cloud storage server used by DIKSHA — the Union Education Ministry's national school learning platform — had left student and teacher records reachable from the open internet, in some cases findable through an ordinary search engine. Exposed files included the full names, phone numbers and email addresses of more than one million teachers, plus a separate file covering about 600,000 students with names, course details and partially masked contact details. Human Rights Watch published its own findings on 27 January, saying the records covered children across every Indian state and included school, district and block-level location data and test scores, spanning roughly March 2020 to December 2022.
The researcher who found it said he had first spotted the exposure in June 2022 and received no reply after contacting DIKSHA's support address — seven months of an open door and an unanswered email. EkStep Foundation, which built the platform, said the Education Ministry implements DIKSHA's security and data-management policies; the ministry disputed HRW's characterisation of the location data collected. This was an exposure through misconfiguration rather than an intrusion, with no public evidence the data was exfiltrated or sold, and the links were removed after notification. It belongs in this archive because of who the data subjects were: schoolchildren, enrolled by their government, with no ability to consent, no way to know, and — in January 2023 — no data protection law to protect them.
⏳ Time capsule — January 2023
- Croatia adopted the euro and joined the Schengen area on 1 January.
- Supporters of Jair Bolsonaro stormed Brazil's Congress, Supreme Court and presidential palace on 8 January.
- Prince Harry's memoir Spare sold 1.43 million English-language copies on its first day — the fastest-selling non-fiction book ever.
- Microsoft announced a new multiyear, multibillion-dollar investment in OpenAI on 23 January; the widely reported $10 billion figure was never confirmed by either company.
The month the pattern set
January 2023 opens on themes the following three years never abandoned. Royal Mail's refusal to pay became a standard citation in the ransom-payment debate that runs through this archive to Britain's 2025 proposal to ban public-sector payments outright. T-Mobile's abused API prefigured a decade of breaches that involve no intrusion at all, only an interface answering too many questions. The Hive takedown established covert infiltration as a law-enforcement model, refined a year later against LockBit in Operation Cronos. And DIKSHA's open server is where India's story in these pages begins: a country digitising public services at extraordinary speed, with the law to govern it still seven months from passage and three years from force.
The Vault continues backwards from here. Every month restored adds another link in a chain this archive keeps discovering is unbroken.