It started with the small stuff. Over the Easter weekend, Marks & Spencer shoppers found contactless payments failing and click-and-collect broken; by Monday, April 21, the disruption was too widespread to ignore. On Tuesday, April 22, M&S formally disclosed a "cyber incident" to the London Stock Exchange, apologising to customers while keeping its stores open. According to later BBC reporting, attackers using the DragonForce name had emailed CEO Stuart Machin from a compromised employee account around April 23, claiming to have encrypted the company's servers — and the DragonForce encryptor was reportedly deployed on M&S's VMware ESXi hosts on April 24, two days after the public disclosure. On Friday, April 25, M&S suspended all online orders, a pause on internet clothing sales that would not lift until June 10.
The intrusion was linked by researchers and press to the Scattered Spider (UNC3944) community, who reportedly got in through social engineering of third-party IT support — no zero-day, just a convincing phone call to someone with the power to reset access. It was the template for the whole spring: attackers who understood that the softest part of a hardened company is the human at the help desk. And M&S was only the first domino — the Co-op disclosed its own intrusion on April 30, Harrods on May 1, and the British high street settled in for a siege whose full cost, £300 million to M&S alone, would only become clear the following month.
What made April feel precarious wasn't just the retail hack. It was that, the same week, the invisible scaffolding the entire security industry stands on nearly collapsed.
24 hours from losing the CVE program
Every security tool on earth speaks a common language of vulnerability IDs — CVE-2025-53770 and its millions of siblings — maintained for 25 years by the non-profit MITRE under US government contract. On April 15, a leaked MITRE letter warned that the funding contract would expire the next day. For 24 hours, the industry stared at the prospect of its shared reference catalog going unmaintained. On the morning of April 16, CISA executed an 11-month option period on MITRE's expiring contract — a contract reported at $57.8 million — averting the lapse — and, chastened, a group of CVE Board members announced the CVE Foundation to move the catalog off dependence on a single government sponsor. The vulnerability everyone had ignored was the funding model itself.
The breach ledger fills with patients
April's quieter carnage was medical. Yale New Haven Health began notifying 5,556,702 patients that their data was stolen in a March network attack — then 2025's largest US healthcare breach. Blue Shield of California disclosed that a Google Analytics misconfiguration had been quietly sharing member health data with Google Ads from 2021 to 2024, affecting up to 4.7 million people — a breach with no hacker at all. Dialysis provider DaVita found ransomware in its network on April 12 (roughly 2.7 million eventually affected), and Hertz confirmed customer data stolen via zero-days in Cleo's file-transfer software. Healthcare: data-rich, security-poor, and perennially top of the victim list.
Nippon Life India's twelve dark days
Late on April 9, 2025, Nippon Life India Asset Management — the country's fourth-largest fund house, with roughly 20 million unique investors — reported a cyberattack on its IT infrastructure and notified the exchanges the next day. The company shut down affected systems, leaving its website, investor portal, and mobile app offline for about 12 days before service was restored around April 21. Crucially, transactions stayed available through exchanges and partner platforms throughout, and no customer-data breach was reported. It was, in a sense, a model disclosure — prompt, contained, honest about the outage — but the twelve-day downtime of a major asset manager's public face was its own quiet lesson for an Indian financial sector racing to digitise faster than it hardens.
Four launches and a benchmark dispute
OpenAI shipped twice in three days. GPT-4.1, with mini and nano variants beneath it, arrived in the API on 14 April 2025 with a million tokens of context and a clear bias towards coding; two days later came o3 and o4-mini, the first OpenAI reasoning models able to reach for every ChatGPT tool unprompted — searching, running code, cropping and zooming an image inside the chain of thought. Google answered on 17 April with Gemini 2.5 Flash in preview, whose "thinking budget" let developers dial reasoning up for hard problems or off altogether for cheap ones. The month had opened less happily: Meta released Llama 4 Scout and Maverick on 5 April, then spent the following week explaining that the Maverick placed second on the LMArena leaderboard was an unreleased, chat-tuned variant, its VP of generative AI denying that Meta had trained on test sets and saying the company would never do so. Sixteen months on, the tool-using reasoner is simply what a frontier model is, and the thinking budget a standard dial rather than a novelty.
The log file that reached SYSTEM
On 8 April 2025 Microsoft's monthly release closed well over a hundred flaws, one already in use: CVE-2025-29824, a use-after-free in the Windows Common Log File System driver that let an intruder with a foothold climb to SYSTEM. Microsoft tied the exploitation to a group it tracks as Storm-2460, which planted the PipeMagic backdoor first and ransomware after, against a handful of targets from American IT firms to Saudi retail. Six days earlier, hotpatching had reached general availability on Intel and AMD Windows 11 Enterprise machines, letting fixes take hold in running memory without a restart — the reboot, long the reason patches went unapplied, at last optional. Verizon's Data Breach Investigations Report, published on 23 April to an industry still rattled by the CVE near-lapse, found ransomware present in 44 per cent of breaches and third-party involvement doubled to 30 per cent. At RSA Conference, opening on 28 April, Palo Alto Networks moved to buy the AI-security startup Protect AI, an early sign of the turn that has since redrawn what the endpoint industry believes it protects.
⏳ Time capsule — April 2025
- April 2 — "Liberation Day" — brought the sweeping US tariffs, with a universal 10% import levy from April 5 and weeks of market convulsions.
- Spot gold broke $3,500 an ounce for the first time ever on April 22, as trade-war fear drove a flight to safe havens.
- On April 14, Blue Origin's NS-31 flew Katy Perry, Gayle King, and Lauren Sánchez on the first all-female spaceflight since 1963.
- Pope Francis died on April 21 at 88, a day after a final Easter Sunday appearance in St Peter's Square.
The people were the perimeter
April 2025 opened the retail siege that defined Britain's cyber year, and its through-line — Scattered Spider talking past the help desk — became the single most-studied attack pattern of the era, cited in every 2026 identity-verification mandate. The CVE near-death, meanwhile, jolted the industry into treating its shared infrastructure as something that needs deliberate stewardship rather than assumed permanence, a debate still live as the CVE Foundation matures. And the month's healthcare bloodletting set a floor the sector never rose above. The lesson April taught — that the softest attack surface is a human with administrative rights, and the most fragile system is often the one everyone assumes someone else is funding — is the one our current editions keep re-proving.