On September 17, 2024, thousands of pagers carried by members of Hezbollah detonated near-simultaneously across Lebanon and parts of Syria. The following day, walkie-talkies did the same. Dozens of people were killed — including civilians and children — and thousands injured, in hospitals, streets, and homes. The operation was widely attributed to Israel, which did not claim it at the time; Lebanon's government and the UN condemned it, and the legality of an attack detonating devices in civilian spaces was immediately and sharply contested.
We cover it here because of what it established about hardware. The devices had been compromised long before they were used — explosives and triggering mechanisms reportedly built into the units during manufacture or distribution, through a supply chain that the eventual owners believed they had chosen carefully. Hezbollah had adopted pagers precisely as a security measure, deliberately retreating from smartphones to avoid electronic surveillance. The devices they chose to be safe were the vector.
The lesson generalises uncomfortably. Every organisation on earth buys hardware through chains it cannot fully see: white-label devices, contract manufacturers, distributors, resellers. Software supply-chain attacks — SolarWinds, XZ Utils, the npm worms — at least leave forensic artefacts that a defender can eventually find. A device altered before it ever reaches you offers no such courtesy. In the months afterward, procurement conversations in defence, telecoms, and critical infrastructure changed in a way that has not reversed: provenance, custody, and tamper-evidence moved from paperwork exercises to genuine requirements. September 2024 is why.
Transport for London, and the cost of caution
On September 1, Transport for London disclosed a cyberattack that would disrupt the capital's transport systems for weeks. Contactless journey histories and Oyster refunds were affected, staff lost access to systems, and TfL later confirmed that bank account details of a few thousand customers may have been accessed. A 17-year-old was arrested in connection with the incident. Two details stood out: the disruption came largely from TfL's own defensive shutdowns rather than the attacker's actions — the right call, taken at real public cost — and the arrest was another reminder that some of the year's most disruptive intrusions were the work of teenagers.
Kaspersky's American ending
September brought an unusual coda to a long geopolitical story: following the US ban on Kaspersky products, the company's American customers found their antivirus automatically removed and replaced with a different vendor's software — UltraAV — in some cases without clear warning. The transition, however defensible commercially, unsettled security professionals for a simple reason: it demonstrated that any security agent with update privileges can replace itself with something else entirely. The industry spent a fortnight arguing about the boundary between an update and a substitution — a debate that would look prescient ten months later, when a different vendor's update took down eight and a half million machines.
Star Health sues Telegram
India's largest health insurer spent September in an unfamiliar posture: as plaintiff. After customer data began circulating through Telegram chatbots that would return individual policyholders' records on request, Star Health went to court against the messaging platform itself, seeking to have the bots taken down — an Indian insurer suing a global messaging service over the distribution of its own stolen data. The move set up the far larger disclosure that followed weeks later, when the seller surfaced publicly claiming more than 31 million customers' records. It also posed a question Indian law was not yet equipped to answer cleanly: when stolen data is served through a platform, what is the platform's obligation — and who does a breached company sue first, the thief or the pipe?
⏳ Time capsule — September 2024
- Security conferences quietly rewrote their supply-chain tracks; "hardware provenance" became a session title everywhere.
- Apple shipped the iPhone 16 with an AI-first pitch, as the industry's attention turned decisively to on-device intelligence.
- Sales of pagers — a technology many assumed extinct — briefly became a subject of international news analysis.
- In India, festive-season shopping ramped up alongside the year's steepest wave of fraud advisories.
Provenance became a requirement
Two years on, September 2024's legacy is written into procurement policy rather than headlines. Hardware provenance, tamper-evident logistics, and custody documentation are now standard clauses in defence and critical-infrastructure contracts, and the phrase "trusted supplier" carries a weight it did not before. The month also completed a shift this archive keeps returning to: 2024 was the year attackers stopped targeting their victims directly and started targeting whatever their victims trusted — software updates, support vendors, cloud tenancies, and, that September, the physical devices themselves. Everything in these pages since has been a variation on that theme.