Cryptographers have made the same argument since the 1990s, patiently, to anyone who would listen: a surveillance back door cannot be built that only the intended party can walk through. Build the mechanism, and you have built it for whoever finds it. It is an argument that has always had the disadvantage of being hypothetical.

In late October 2024 it stopped being hypothetical. Reporting revealed that a Chinese state-linked group — later publicly tracked as Salt Typhoon — had penetrated the networks of major US broadband and telecommunications providers, among them AT&T, Verizon, and Lumen. And the detail that turned a serious espionage story into a landmark was this: the intruders had accessed systems the carriers use to comply with lawful-intercept requests — the apparatus of court-authorised wiretapping itself. The interception capability that US law requires carriers to maintain had been, in effect, borrowed.

The scope emerged over following weeks: call records at scale, and for a smaller number of individuals in politics and government, the content of communications. But the conceptual damage was done immediately. Every future government proposal for exceptional access to encrypted systems would now be met with a single word — Salt Typhoon — and there is no good answer to it. October 2024 is the month the theoretical objection acquired a case number, and the reason the following month produced the strangest official advice of the decade: use encrypted apps instead.

Also that month · The library goes dark

Someone attacked the Internet Archive

On October 9, visitors to the Internet Archive were greeted by a JavaScript pop-up informing them the site had been breached — roughly 31 million user records, including email addresses and bcrypt-hashed passwords, later surfacing in Have I Been Pwned. The defacement was compounded by DDoS attacks that knocked the service offline repeatedly over following days, and by a second intrusion later in the month through unrotated access tokens. Of all 2024's victims, this one produced the most universal reaction: a non-profit that archives the web for everyone, running on a shoestring, attacked for no discernible gain. It was a reminder that the internet's public infrastructure is often maintained by people with no budget for a security team.

Also that month · The other typhoon

Campaign phones in the crosshairs

Weeks before the US presidential election, reporting indicated the same telecom intrusions had been used to target the phone communications of figures in both major campaigns. Nothing suggested vote-counting systems were affected — the election-security machinery held — but the episode reframed what "election interference" could mean. You do not need to touch a ballot if you can listen to the strategy conversations of the people running the campaign.

India desk · October 2024

Star Health, and the chatbot that handed out medical records

India's biggest breach story of the year turned on a distribution method as troubling as the theft itself. A hacker using the handle "xenZen" claimed to hold 7.24 TB of data belonging to more than 31 million Star Health customers — names, phone numbers, addresses, medical reports, insurance claims — and offered the trove for around $150,000. Rather than simply listing it on a forum, the seller built Telegram chatbots that let anyone query and download individual customers' records on demand. Star Health confirmed it had received a ransom demand of about $68,000, refused to pay, and took the extraordinary step of suing Telegram in an Indian court to force the bots offline. For a country whose data protection rules were still in draft, October 2024 supplied the argument in one story: the most sensitive category of personal information — a person's medical history — reduced to a self-service lookup in a messaging app.

⏳ Time capsule — October 2024

  • "Typhoon" became the year's defining threat-actor naming convention in mainstream news coverage.
  • The Internet Archive's outage produced a rare thing online: near-universal sympathy for the victim.
  • Cybersecurity Awareness Month advisories collided awkwardly with the news that the phone network was compromised.
  • In India, festive-season fraud advisories ran alongside the Star Health story — a month of unusually well-informed caution.
Where it stands today — 2026

The argument that ended

Salt Typhoon is now the permanent counter-example in every encryption-policy debate, and the reason telecom security became a national-security portfolio rather than an industry concern — a shift that runs directly to Singapore's four-carrier disclosure in February 2026. The Internet Archive survived, hardened, and kept archiving. And Star Health's Telegram bots became the case study Indian regulators reach for when explaining why the DPDP framework needed teeth: it is one thing for data to be stolen, and another for it to be productised. Our India edition's coverage of breach-notification duties exists because of months like this one.