Governments do not usually advise citizens to route around national infrastructure. In November 2024 the United States did exactly that. On November 13, US agencies publicly confirmed that hackers affiliated with the People's Republic of China — the group tracked as Salt Typhoon — had compromised multiple American telecommunications providers, stealing call records and, in cases involving a limited number of individuals in government and politics, the actual content of communications. Then came the advice that made the story land with the general public: senior FBI and CISA officials urged Americans to use end-to-end encrypted messaging and calling apps rather than ordinary phone calls and SMS.

Read that again as a security proposition. The state was telling its citizens that the plain old telephone system — the network built, regulated, and lawfully wiretapped by that same state — should be assumed compromised, and that commercial encryption was now the safer option. It was an admission with no modern precedent, and it inverted a decade of official argument. Western governments had spent years pressing technology companies to weaken or provide access around end-to-end encryption. In November 2024 their own security agencies pointed at those same encrypted apps and said: use these.

The reason for the reversal was the most uncomfortable detail of the whole affair, revealed the previous month: among the systems the intruders had reached were those American carriers use to service court-authorised wiretap requests. The lawful-access machinery built for legitimate surveillance had itself become a target — the precise scenario cryptographers had warned about for thirty years, arriving in the news exactly as described. A back door, however lawful, is a door.

Also that month · Empty shelves

One vendor, and the supermarkets wobble

On November 21, ransomware struck Blue Yonder, a supply-chain management provider most shoppers had never heard of — and the effects surfaced immediately in places they had. Starbucks reverted to manual processes for scheduling and paying staff; in the UK, major grocers reported disruption to warehouse and distribution systems in the run-up to Christmas. It was the year's clearest domestic demonstration of concentration risk: one software company, chosen by procurement teams for its efficiency, sitting silently behind the logistics of coffee shops and supermarkets across two continents. Nobody votes on these dependencies, and almost nobody maps them, until a leak site does it for them.

Also that month · Fintech's turn

Finastra, and the file-transfer problem again

November also brought a breach at Finastra, a financial-software provider whose products sit inside a large share of the world's banks, after an attacker was reported to have obtained data from an internally hosted file-transfer platform. The specifics were narrower than the headlines suggested, but the shape was wearily familiar: file-transfer systems, the plumbing that moves bulk data between institutions, had been the industry's softest target since the MOVEit catastrophe of 2023 — and were still holding, in one place, precisely the data an attacker most wants.

India desk · November 2024

The nation notices "digital arrest"

By late 2024, a scam that had been quietly ruining Indian families for months finally became a national conversation. In his Mann Ki Baat radio address at the end of October, the Prime Minister devoted a segment to "digital arrest" fraud — the impersonation of police and agency officials over video call to terrify victims into transferring their savings — walking listeners through the three-step response of stop, think, and act, and stating plainly that no investigative agency conducts arrests or interrogations by video call. Through November the machinery followed: I4C advisories, helpline publicity, and the blocking of large numbers of fraudulent SIMs and accounts. When a scam requires a head-of-government broadcast to counter it, it has stopped being a cybercrime statistic and become a public-health problem — which is why this magazine's India edition still runs Fraud Watch as a standing column.

AI Tech desk · November 2024

Anthropic's protocol, and China's reasoning models

On 25 November 2024 Anthropic open-sourced the Model Context Protocol, a specification for connecting assistants to the systems where data actually lives — content repositories, business tools, development environments — released with Python and TypeScript software development kits and a short list of early adopters including Block and Apollo. It drew modest coverage; a data-plumbing standard is not a product launch. Read from 2026, it was the month the agent era quietly acquired its wiring — the reason later editions of this archive describe tool-using agents rather than chatbots. The rest of November belonged to reasoning. DeepSeek published R1-Lite-Preview on 20 November, showing users its chain of thought through its web chat, and Alibaba's Qwen team followed on 28 November with QwQ-32B-Preview, an openly licensed reasoning model of 32 billion parameters. In nine days, two Chinese laboratories established that inference-time reasoning would not remain a Western advantage. Governments were watching: on 20 and 21 November, nine countries and the European Union convened the International Network of AI Safety Institutes in San Francisco for the first time.

Digital Guard desk · November 2024

Microsoft moves antivirus out of the kernel

Four months after a faulty content update from CrowdStrike sent Windows machines worldwide into boot loops, the industry's structural answer arrived at Microsoft Ignite in Chicago. On 19 November 2024 Microsoft set out its Windows Resiliency Initiative, and with it the commitment that mattered most to endpoint vendors: new Windows capabilities allowing security products to be built outside kernel mode, running in user space as ordinary applications do. Members of the Microsoft Virus Initiative also agreed to adopt safe deployment practices — gradual rollouts, deployment rings, monitoring — whose absence had defined July. A companion feature, Quick Machine Recovery, promised administrators a route to fix machines that would no longer boot. The commercial reckoning came on 26 November, when CrowdStrike reported quarterly revenue of $1.01 billion, up 29 per cent, and annual recurring revenue of $4.02 billion, while acknowledging extended sales cycles and one-time customer commitment packages. Gross retention stayed above 97 per cent: customers were negotiating harder, not leaving. The kernel exit proved the slower promise — its private preview reached hand-picked partners only in July 2025.

⏳ Time capsule — November 2024

  • The US presidential election dominated the month; the feared election-day cyber catastrophe did not materialise, which was itself the story.
  • Bitcoin surged past $90,000 in the post-election weeks, on its way to six figures by December.
  • "Signal" trended as a consumer download recommendation — endorsed, remarkably, by federal law enforcement.
  • Black Friday brought the usual flood of fake-retailer domains, now generated at industrial scale.
Where it stands today — 2026

The month encryption won the argument

November 2024 permanently changed the politics of encryption. The FBI's own advice became the standard rebuttal to every subsequent proposal for lawful-access back doors, and the Salt Typhoon intrusions pushed telecom security up the regulatory agenda in Washington and beyond — a shift still visible in February 2026, when Singapore disclosed that a related actor had reached all four of its major carriers. Blue Yonder's ransomware, meanwhile, joined the small library of incidents that boards actually remember, because it emptied shelves they had personally shopped at. And in India, "digital arrest" moved from an emerging scam to a permanent fixture of national cyber-awareness — a fixture our current editions still cover, month after month, because it never stopped working.