On December 30, 2024 — with Washington already half-emptied for the holidays — the US Treasury Department told Congress it had suffered a "major incident." A Chinese state-sponsored actor had reached into departmental workstations and taken unclassified documents. The intruders had not battered down Treasury's defences. They had used a stolen API key belonging to BeyondTrust, the vendor whose remote-support software Treasury employees relied on for help with their computers.
That is the whole modern security problem in one sentence: the vendor you trust to fix your desktop holds a key to your desktop. Reporting through January would indicate the intruders had gone after the Office of Foreign Assets Control — the office that administers US sanctions — and the Committee on Foreign Investment in the United States, which screens foreign deals for national-security risk. If you wanted to know which entities Washington was about to sanction, or which acquisitions it was about to block, those two offices are precisely where you would look. The activity was attributed to the group tracked as Silk Typhoon, and by January 17 the Treasury's own sanctions office was sanctioning a hacker linked to the intrusion against it.
It was a fitting end to a year in which the perimeter had comprehensively stopped mattering. Whatever else 2024 taught, its clearest lesson was arithmetic: your attack surface is not your systems. It is your systems plus everyone holding a key to them — and nobody, including the US Treasury, had a complete list.
The browser extensions that turned
On Christmas Eve, security firm Cyberhaven discovered that its own Chrome extension had been published in a malicious version — an attacker had phished a developer's publishing credentials and pushed a poisoned update straight to users' browsers. Investigation found Cyberhaven was not alone: a cluster of other extensions had been compromised in the same campaign, quietly harvesting session data from anyone who had trusted them. Browser extensions run with sweeping access to everything you do on the web, update silently, and are almost never inventoried by security teams. Attacking them over the holidays, when nobody was watching the publishing dashboards, was the detail that made it professional.
Salt Typhoon's telecom tally grows
December brought no relief in the telecom-espionage story that had dominated the autumn: officials continued adding names to the list of US communications providers penetrated by the Chinese group tracked as Salt Typhoon, with a ninth carrier acknowledged as the year closed. Coming weeks after federal officials had publicly urged Americans to use encrypted messaging apps — an extraordinary thing for a government to advise about its own phone network — the running tally made December feel less like the end of an incident than the discovery of its true size.
Closing a year of firsts
India ended 2024 in a strange position: possessed of a data protection law with no operating rules. The DPDP Act had passed in August 2023, but the draft rules that would make it workable were still unpublished as the year closed — they would land three days into January. In the meantime, the year had delivered a brutal education in why they were needed: BSNL's reported intrusion in May, Hathway's leak of tens of millions of customer records in March, boAt's exposure in February, WazirX's $235 million theft in July, and Star Health's medical records circulating through Telegram bots in the autumn. A country that had digitised faster than almost anywhere on earth spent 2024 discovering the bill, and entered 2025 with the rulebook finally about to arrive.
Twelve days, and a quantum chip
OpenAI spent the month talking. From 5 to 20 December it ran a livestream a day under the title "12 Days of OpenAI", opening with the o1 reasoning model leaving preview alongside a ChatGPT Pro tier at $200 a month, releasing the Sora video model on 9 December to paying subscribers everywhere except the United Kingdom, Switzerland and the European Economic Area, where regulators had not yet been satisfied, and closing on 20 December with o3 — not shipped, but announced for external safety testing. Google counter-programmed throughout. On 9 December it presented Willow, a 105-qubit quantum processor it said had crossed the error-correction threshold at which adding qubits makes a machine more reliable rather than less; on 11 December it introduced Gemini 2.0 Flash, still experimental, with browser-driving research prototypes it grouped under the word "agentic". That word, worn to nothing by 2026, was novel enough in December 2024 that most of the coverage stopped to define it.
Cylance changes hands at a discount
On 16 December 2024 Arctic Wolf and BlackBerry announced that Arctic Wolf would buy Cylance's endpoint security business for $160 million in cash and roughly 5.5 million of its own shares. BlackBerry had paid $1.4 billion for Cylance six years earlier, in November 2018, when replacing signature files with a mathematical model was still a genuine differentiator; by 2024 every serious endpoint vendor made some version of that claim, and the premium had gone with it. The deal closed in February 2025, the technology folded into Arctic Wolf's platform under a new name; what had been a category in 2018 was, by 2026, simply how endpoint software is built. The month's other endpoint story measured the same crowded field: MITRE published the sixth Enterprise round of its ATT&CK Evaluations on 11 December, testing nineteen vendors — down from twenty-nine the round before — against emulated LockBit and Cl0p ransomware behaviour and, for the first time, North Korean malware on macOS. Also for the first time, it counted false positives, planting benign activity products were expected to ignore.
⏳ Time capsule — December 2024
- Bitcoin had crossed $100,000 for the first time in early December — a threshold that had seemed fantastical a year earlier.
- Security teams spent the holidays doing something new: auditing which browser extensions their staff had installed.
- "Salt Typhoon" and "Volt Typhoon" had entered the general-news vocabulary, a naming convention most people had never heard of twelve months before.
- Every 2025 prediction deck named the same top risk — third parties and identity — and, for once, the predictions turned out right.
The year of the borrowed key
December 2024's Treasury breach reads now as the overture to everything that followed. The BeyondTrust key was the same lesson the Salesloft Drift tokens would teach at scale eight months later, and the F5 and Klue compromises after that: attackers had permanently stopped attacking companies and started attacking the trust between companies. Silk Typhoon's operators drew sanctions in January 2025 and kept appearing in advisories through the year. The Cyberhaven campaign turned browser-extension governance from a niche worry into a standard enterprise control. And India's rulebook, three days away as the year ended, began the march that would end with the DPDP Rules notified in November 2025 — the subject of much of this archive's later coverage.