The year opened with a pair of zero-days in Ivanti Connect Secure — the VPN appliance that thousands of organisations, including government agencies, use to let remote staff reach internal systems. Disclosed on January 10, the flaws were chained to give unauthenticated attackers control of the device. Exploitation was immediate and indiscriminate: what began as a state-linked espionage campaign was, within days, a free-for-all as criminal groups picked up the technique. Thousands of appliances were compromised worldwide.

Then the guidance began to fail. Mitigations were published and bypassed. Fresh vulnerabilities in the same product line kept surfacing. Organisations that had diligently applied every instruction discovered attackers were already inside — and, worse, that persistence could survive the vendor's own reset procedures. By the end of January, the US cyber agency issued an emergency directive with a striking instruction: federal agencies were not merely to patch, but to disconnect Ivanti Connect Secure products from their networks entirely, then rebuild before reconnecting them.

Consider what that instruction concedes. The recommended response to a security product was to remove it from the network. It was the bluntest official acknowledgement yet of a structural problem this archive returns to repeatedly: the appliances sold to defend the perimeter sit at the perimeter, run opaque proprietary firmware that customers cannot inspect, are rarely covered by endpoint monitoring, and hold the credentials to everything behind them. They are, in short, the ideal target — and January 2024 is when that stopped being a researcher's argument and became a federal order.

Also that month · The test account nobody retired

Russian intelligence reads Microsoft's email

On January 19, Microsoft disclosed that Midnight Blizzard — the Russian state group behind SolarWinds — had accessed a small number of corporate email accounts, including those of senior leadership and staff in cybersecurity and legal functions. The entry point was almost embarrassing in its ordinariness: a password-spray attack against a legacy, non-production test tenant that had no multi-factor authentication enabled, from which the attackers pivoted using an OAuth application with elevated permissions. The world's largest security vendor was compromised through a forgotten test account and an over-permissioned app — the precise combination that would define breach after breach through the following two years.

Also that month · The voice on the phone

A deepfaked president calls New Hampshire

In late January, voters in New Hampshire received robocalls carrying an AI-cloned voice of the sitting US president, urging them not to vote in the state's primary. The audio was crude by later standards and the perpetrator was eventually identified, fined, and prosecuted — but the significance was the date. In the first month of a year in which more than half the world's population would vote, synthetic media had moved from conference demo to deployed election interference, cheaply, against real voters. Every subsequent election-security programme of 2024 was written in the shadow of that call.

India desk · January 2024

The world's largest election, and an untested rulebook

India entered 2024 preparing for a general election of unprecedented scale — nearly a billion eligible voters — with a data protection law on the statute books and no rules to operate it. The combination shaped the year that followed. Electoral rolls, voter-outreach databases, and campaign messaging systems held vast quantities of personal data with no enforceable framework governing their handling, while the country's threat landscape was already among the world's most active by volume. What January established, and the rest of 2024 confirmed through Hathway, boAt, BSNL, WazirX, and Star Health, was a simple mismatch: India was generating digital infrastructure at world-leading speed and governing it with a statute that could not yet be enforced.

⏳ Time capsule — January 2024

  • A compilation dubbed the "mother of all breaches" — roughly 26 billion aggregated records — briefly panicked the internet, in a preview of June 2025's sixteen-billion scare.
  • Security teams spent the month physically unplugging VPN appliances, an activity nobody had budgeted for.
  • "Deepfake" entered election-security planning documents as a line item rather than a footnote.
  • 2024's "year of elections" framing was everywhere — more than 60 countries, and every one of them a target.
Where it stands today — 2026

Where the edge crisis began

January 2024 opened a chapter that has not closed. The Ivanti emergency established the template — mass exploitation of a security appliance, mitigations that don't hold, persistence that survives remediation — and the same story ran through Cisco's ArcaneDoor in April, MITRE's own breach, Fortinet through 2025, and F5's stolen source code in October 2025, each time with defenders a little more willing to assume their edge devices were already compromised. Microsoft's forgotten test tenant became the standard illustration of why identity hygiene beats perimeter spending. And the New Hampshire robocall marked the start of synthetic media as an operational election threat — a problem that has since grown far cheaper and considerably more convincing.