The year began at the school gate. On December 28, 2024, an intruder used a single compromised support credential to log into PowerSchool's customer support portal and export data from its Student Information System — the software that, for a vast share of North American schools, simply is the record of a child's education. PowerSchool began notifying affected districts on January 7, 2025. The forensic investigation placed the unauthorized access between December 19 and 28, and the scale was staggering: the attacker's extortion demand claimed data on roughly 62.4 million students and 9.5 million teachers — figures PowerSchool never confirmed as a precise count, but which went unchallenged as the incident came to be widely described as the largest breach of children's data in US history.

For a subset of those affected, the stolen fields went beyond names and grades to Social Security numbers, medical alerts, and home addresses — the kind of data a child cannot change and will carry for decades. PowerSchool paid the attacker's ransom (court documents later put the demand around $2.85 million in Bitcoin) in exchange for a promise the data would be deleted. It was, predictably, a promise made by a criminal: in May, individual districts including the Toronto District School Board began receiving fresh extortion emails built on the same stolen data. Paying had bought nothing but a receipt.

The through-line of the whole affair — one stolen password, one over-trusted support portal, tens of millions of the most vulnerable data subjects imaginable — was the year's opening thesis statement. 2025 would be a year about the fragility of the systems everyone depends on and no one quite owns, and it started with the one that holds our children's report cards.

Also that month · The Treasury reckoning

Silk Typhoon named, sanctions land

January carried the fallout from the US Treasury's December 30 disclosure that a Chinese state actor had reached departmental workstations by abusing a stolen BeyondTrust remote-support API key. Reporting indicated the intruders had targeted the Office of Foreign Assets Control and the Committee on Foreign Investment in the US — the offices that run sanctions and screen foreign deals. The activity was attributed to the group tracked as Silk Typhoon, and on January 17, Treasury's OFAC sanctioned a Shanghai-based hacker linked to the intrusion, alongside a firm tied to the separate Salt Typhoon telecom-espionage campaign. A stolen vendor key had opened the US Treasury: the borrowed-credential problem, at the highest possible stakes.

Also that month · The payment question

Britain moves to ban ransoms

On January 14, the UK Home Office opened a consultation proposing to ban ransomware payments by public-sector bodies and critical national infrastructure operators, alongside a regime requiring other victims to notify authorities before paying, plus mandatory incident reporting. It made the UK one of the first major economies to formally float a targeted ransom-payment ban — an attempt to attack ransomware's business model at the source, by drying up the revenue. The debate it opened, over whether banning payment protects victims or punishes them, is one the world is still having.

India desk · January 2025

The rulebook arrives (in draft)

On January 3, 2025, India's Ministry of Electronics and IT released the draft Digital Personal Data Protection Rules, 2025 for public consultation — the long-awaited operational machinery under the DPDP Act, 2023, covering consent notices, breach notification, obligations for significant data fiduciaries, and verifiable parental consent for children's data, with feedback open until February 18. It was the first concrete step in a year-long march that would end, in November, with the rules notified in force. The same month brought a cautionary counterpoint: the BASHE ransomware group claimed on its leak site to have breached ICICI Bank customer data, setting a January 24 ransom deadline. ICICI never confirmed a breach, and OSINT analysts found inconsistencies in the posted samples — so the claim stayed exactly that, a claim. Two Indian data stories to open the year: one a landmark of regulation, the other a reminder of how much noise surrounds every real signal.

AI Tech desk · January 2025

DeepSeek opens the weights, markets flinch

DeepSeek released R1 on 20 January 2025, publishing the model's weights, and a set of smaller distilled versions, under an MIT licence — at a moment when frontier reasoning was assumed to be a closed and capital-intensive business. On 27 January the DeepSeek assistant reached the top of the US App Store's free chart and American technology stocks fell sharply; Nvidia shed about 17 per cent in a session, its worst day since March 2020. The figure driving the panic — a training run costing roughly $5.6 million — described the final pre-training pass of the earlier V3 model rather than the whole programme, and SemiAnalysis later estimated DeepSeek's total server spending far higher, in the region of $1.6 billion. The month also ran in the opposite direction, towards scale: Stargate, a US data-centre venture announced at the White House on 21 January, and Operator, OpenAI's browser-driving agent, released on 23 January as a research preview for Pro subscribers — absorbed into ChatGPT's agent mode by July and retired as a standalone product.

Digital Guard desk · January 2025

The industry inspects DeepSeek's app

January's endpoint story was a consumer app. After DeepSeek's assistant topped the download charts, security firms and regulators pulled it apart: in the closing days of the month Wiz reported a DeepSeek-linked ClickHouse database sitting publicly reachable without authentication, exposing over a million log lines including plaintext chat history and API keys, and on 30 January Italy's Garante ordered an immediate block on the processing of Italian users' data, calling the company's answers insufficient. The US Navy had already told personnel on 24 January to avoid the model; Texas barred it from state devices on 31 January. Endpoint teams spent the week writing blocking policy for software nobody had procured — the first run of a drill that became routine through the year. Quieter, and more telling of the trade's own condition: AV-Comparatives published its 2024 consumer summary on 29 January, naming ESET HOME Security Essential product of the year across sixteen tested Windows products, with Avast, AVG, Bitdefender and Kaspersky taking top-rated awards — Kaspersky's arriving months after US law had cut off its sales and updates in that market.

⏳ Time capsule — January 2025

  • TikTok went dark for US users for about 14 hours on January 18–19 as a divest-or-ban law took effect, returning after a pledged enforcement delay.
  • On January 27, Chinese startup DeepSeek's R1 app topped the US App Store and Nvidia shed roughly $589 billion in value — the largest single-day market-cap loss in history at the time.
  • On January 21, OpenAI, SoftBank, and Oracle announced Stargate, a US AI-infrastructure venture pitched at up to $500 billion.
  • On January 16, Blue Origin's New Glenn reached orbit on its first flight, while SpaceX's Starship Flight 7 upper stage broke apart over the Caribbean.
Where it stands today — 2026

Everything was already visible

January 2025 was the start of a year whose every theme was present in its first month. The PowerSchool breach set the template for 2025's education and identity disasters, and its pay-and-get-re-extorted ending became the standard argument against ever trusting a criminal's promise. Silk Typhoon's stolen key foreshadowed a year defined by borrowed credentials. Britain's ransom-ban proposal opened a policy debate that only widened. And India's DPDP draft began the runway that would land in November's rulebook and 2026's compliance scramble. Below this month the archive now reaches back through 2024 and twelve further years, to January 2012 — because the story didn't start here either. It never does.