Decembers in security have a rhythm: the incidents keep coming, but the mood turns retrospective. December 2025 obliged on both counts. In Seoul, e-commerce giant Coupang — the everything-app of South Korean life — spent the month watching its November breach disclosure grow until it covered tens of millions of customer accounts, roughly 33 million by the final tally, one of the largest consumer breaches in the country's history and an instant political event. In Britain, ransomware at DXC Technology, a supplier deep in the NHS's technology stack, revived the health service's least favourite memory: that WannaCry's true lesson was never about one worm, but about how much of a hospital lives on someone else's computers. France's interior ministry joined the month's casualty list, alongside a supporting cast — Freedom Mobile, 700Credit, SoundCloud, the University of Sydney — that would each have led a slow news week five years earlier.
Behind the incidents, the tallying began. 2025's ledger read like a genre anthology: the year had opened with a $1.5 billion crypto heist and India's draft data rules, detoured through a spring siege of British retail, a summer of exploited SharePoint servers and a sixteen-billion-credential compilation, an autumn in which Jaguar Land Rover's stopped production lines became Britain's costliest cyber event — and closed with an AI running most of an espionage campaign. The through-line wasn't any single technique. It was dependency: on shared platforms, borrowed tokens, single suppliers, single regions. In 2025 the industry didn't so much get breached as get reminded, monthly, of everything it had outsourced.
Aisuru's 29.7 terabit encore
Six weeks after its record-setting October blast against Azure, the Aisuru botnet broke its own mark: a DDoS attack peaking at 29.7 terabits per second, nearly doubling the previous record, from a swarm researchers estimated at up to four million compromised devices. The Mirai lineage that began in 2016 with baby monitors and DVRs closed 2025 commanding more firepower than most nations — still built, a decade on, from devices whose owners will never know they took part.
Crypto's calmest month of a violent year
The year's strangest statistic arrived from the sector that had started it all: December's crypto thefts totalled $76.2 million across 26 incidents — a 60% drop from November and pocket change beside February's Bybit catastrophe. Whether it was exchanges hardening, Lazarus regrouping, or thieves taking the holidays off, the year that began with the largest financial theft in history ended with its quietest month — a reminder that in security statistics, calm is a lagging indicator, not a forecast.
The year India's data rules got real
India closed 2025 having travelled, in eleven months, from draft rules (January) to a notified DPDP rulebook (November) — and December belonged to the scramble: compliance roadmaps, consent-manager questions, and the first board decks with "Significant Data Fiduciary" on a slide. Meanwhile the I4C's year-long crackdown on "digital arrest" call centres rolled on, even as holiday-season parcel scams and UPI fraud advisories filled the papers — the twin realities of Indian cyberspace: regulation maturing at the top, fraud industrialising at the street.
⏳ Time capsule — December 2025
- Prediction season crowned "agentic AI" the phrase of 2026 — on both the attack and defense slides, usually in the same deck.
- The first patch cycles quietly left behind Windows 10 machines whose owners never enrolled in extended updates — the long tail, beginning on schedule.
- Holiday scam advisories went out in every language: fake parcels, fake refunds, fake job offers — ClickFix's copy-paste trick now firmly mainstream.
- Security teams ended the year maintaining inventories of a new asset class: which AI tools hold which of their credentials.
History hands over
This is where 2025's archive closes — above it, The Vault climbs through 2026 toward the present. The dependencies December exposed became 2026's working agenda: third-party and SaaS-token audits went from novelty to norm, AI-agent security turned into the year's defining budget line, and India's DPDP runway made data protection the subcontinent's biggest corporate project. The story from January 2026 onward isn't history yet — it's the news, and it's being written in our current editions every week. The Vault will collect it when it's had time to become the past.