Aegis SentryMagazine
πŸ— The Vault

Security history, retold with hindsight

The Vault is our retrospective archive: monthly editions covering two decades of digital security β€” the breaches, worms, laws, and characters people still remember β€” researched and written today, honestly dated, with the one advantage nobody had at the time: we know how each story ends. New batches are restored regularly until the archive reaches back twenty-one years.

2026

The runway to the relaunch Β· 7 of 7 restored βœ“ β€” plus the August 2026 back issueβ–Ύ

2025

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2025

The Reckoning Month

Coupang's 33 million, ransomware in the NHS supply chain, a 29.7 Tbps encore β€” and the year's bill, itemised.

November 2025

The Attacker Becomes an Algorithm

The first reported AI-run espionage campaign, the config file that silenced the web, and India's DPDP rulebook.

October 2025

The Funeral of Windows 10

An operating system retires with half the world aboard, F5's stolen blueprints, and a 15.72 Tbps record.

September 2025

The Month the Factories Stopped

Jaguar Land Rover goes dark for weeks, a Collins Aerospace attack strands travellers across Europe, and the Shai-Hulud worm loots npm.

August 2025

The Keys to Everyone's Kingdom

One chatbot's stolen OAuth tokens drain 700+ Salesforce customers β€” the month that wrote the whole year's playbook.

July 2025

The Weekend SharePoint Fell

The ToolShell zero-day chain rips through on-prem SharePoint and reaches the US nuclear agency; a Salesforce-social-engineering summer hits Qantas and Allianz.

June 2025

Sixteen Billion Passwords

The mega-compilation that scared the internet (with the nuance the headlines missed), and Predatory Sparrow burns $90M off an Iranian exchange.

May 2025

High Street Under Siege

M&S counts Β£300M, the Co-op confirms mass data theft, Coinbase reveals a bribed-insider breach β€” and 1.5M attacks shadow Operation Sindoor.

April 2025

The Long Easter

A hack empties M&S shelves and opens the retail siege, while the CVE catalog is saved from death by 24 hours.

March 2025

War Plans in the Group Chat

A journalist added to a US officials' Signal chat, 23andMe's bankruptcy puts 15M genomes on the block, and Tata Technologies lands on a leak site.

February 2025

The $1.5 Billion Blind Signature

North Korea drains Bybit in the largest crypto theft ever β€” by poisoning the tool it trusted to sign.

January 2025

The Report-Card Heist

One stolen password exposes a generation of students in the PowerSchool breach; India releases its DPDP draft rules.

2024

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2024

The Key to the Treasury

A stolen vendor key opens the US Treasury to Chinese state hackers, and browser extensions turn malicious over Christmas.

November 2024

The FBI Says Use Encryption

Washington confirms hackers inside the phone network β€” then tells citizens to route around it. Ransomware empties supermarket shelves.

October 2024

The Ghost in the Wiretap

Salt Typhoon is found inside US carriers and the lawful-intercept systems themselves; Star Health's records reach Telegram bots.

September 2024

The Supply Chain as a Weapon

Sabotaged devices detonate across Lebanon, redrawing hardware provenance risk; Transport for London is crippled.

August 2024

The Broker Who Lost Everyone

A background-check firm nobody chose leaks billions of records β€” then goes bankrupt, leaving victims with no counterparty.

July 2024

The Update That Grounded the World

8.5 million machines crash at once with no attacker involved; AT&T loses the call records of nearly everyone; WazirX loses $235M.

June 2024

The Month America Couldn't Buy a Car

15,000 dealerships go back to paper, the Snowflake campaign swells, and Indonesia admits it had no backups.

May 2024

The Passwords Were Already Gone

The year's biggest data theft begins with no exploit at all β€” just old credentials and missing MFA. Hospitals revert to handwriting.

April 2024

The Ransom That Bought Nothing

$22 million paid, the gang vanishes with it, and the data is extorted a second time. MITRE is breached through its own edge.

March 2024

Half a Second from Catastrophe

The XZ Utils backdoor is caught weeks before it reaches the world's servers β€” by one engineer noticing a timing anomaly.

February 2024

The Month Healthcare Stopped Getting Paid

Change Healthcare freezes a nation's medical claims and reaches 190 million people; police seize LockBit and troll it.

January 2024

Disconnect It Now

Agencies are ordered to rip out their own VPN appliances; Russian intelligence reads Microsoft's executive email.

2023

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2023

Signal Lost

Sandworm wipes the core of Ukraine's largest mobile operator and 24 million people lose service; Xfinity discloses 35.9 million records.

November 2023

Sneakernet on Wall Street

Ransomware cuts the world's biggest bank out of Treasury clearing β€” and settlement data reportedly travels by USB stick.

October 2023

Trust, Archived

Okta's support system is breached for the session tokens inside it; 815 million Indian records are offered for $80,000.

September 2023

Vegas Goes Analog

Nine days of dead room keys and dark slot machines on the Strip β€” and the way in, the attackers claimed, was a phone call.

August 2023

The Help Desk Said Yes

A password reset granted over the phone empties American shelves; a spreadsheet exposes every police officer in Northern Ireland.

July 2023

The Key Microsoft Couldn't Explain

A stolen signing key forges tokens into US government mailboxes β€” and a customer, not Microsoft, catches it.

June 2023

Cl0p's Harvest

MOVEit engulfs the BBC, British Airways, federal agencies and two state DMVs; Barracuda says replace the box, don't patch it.

May 2023

The Long Weekend

Attackers pick a US holiday to start the year's biggest breach; Toyota admits a decade-long exposure.

April 2023

The Supply Chain Eats Itself

The 3CX compromise turns out to have begun with another supply-chain attack β€” the first documented cascade.

March 2023

Someone Else's Conversation

ChatGPT users see strangers' chat titles, and Italy pulls the product from an entire country.

February 2023

The Two-Year-Old Door

Thousands of hypervisors encrypted through a flaw patched two years earlier β€” and a free recovery script that lasted a day.

January 2023

Return to Sender

Ransomware stops Britain's international post for six weeks; an abused API drains 37 million T-Mobile accounts.

2022

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2022

Zero Knowledge

LastPass admits the vaults were copied, Rackspace's Hosted Exchange dies of Play ransomware, a FortiOS flaw opens the edge-device era β€” and AIIMS comes back.

November 2022

Manual Mode

Ransomware puts AIIMS Delhi on paper for a fortnight, Medibank's customers find their diagnoses dumped online, and ChatGPT quietly launches.

October 2022

The Fortnight of No Evidence

Medibank spends a fortnight saying there is no evidence, then concedes every customer; CommonSpirit goes back to paper; Hive publishes Tata Power's files.

September 2022

Accept the Prompt

An MFA-fatigue attack walks into Uber and out through Rockstar's unreleased GTA, an unauthenticated API drains Optus, and LA schools refuse to pay.

August 2022

The Key That Held

A smishing campaign called 0ktapus phishes more than 130 organisations through Twilio and Signal β€” and breaks against Cloudflare's hardware security keys.

July 2022

A Billion, Then Silence

A seller offers 23TB of Shanghai police records on a claimed billion citizens, Albania's e-government is wiped offline, and Uber admits its 2016 cover-up.

June 2022

A Headstone in Gyeongju

Internet Explorer retires to a granite headstone in South Korea, a record HTTPS DDoS comes from 5,067 hijacked servers, and VPN providers pull out of India.

May 2022

The Loudest Exit

Costa Rica declares a national emergency over Conti's ransomware β€” then the gang goes dark mid-siege; Follina breaks Word; SpiceJet strands passengers overnight.

April 2022

Back to Paper

Conti takes Costa Rica's tax and customs systems offline, stolen OAuth tokens open private repos at dozens of firms, and India starts a six-hour breach clock.

March 2022

Twenty-Five Minutes in January

Lapsus$ walks through Nvidia, Samsung, Microsoft and Okta; $620m leaves the Ronin bridge unnoticed for six days; Viasat explains the wiped modems.

February 2022

Hours Before the Tanks

Wipers erase Ukrainian systems hours before the invasion, a satellite hack silences 5,800 German wind turbines, Conti's chats leak, and India blocks 54 apps.

January 2022

Expect the Worst

Ukraine's government sites are defaced and WhisperGate wipes what it touches, the Red Cross loses data on 515,000 vulnerable people, and Russia raids REvil.

2021

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2021

A Fire in the Library

Log4Shell turns one logged string into code execution everywhere, Kronos payroll goes dark through Christmas, and Modi's account briefly "adopts" Bitcoin.

November 2021

Names, Faces, Handcuffs

The US unseals Kaseya charges and seizes $6.1M as REvil affiliates are arrested, Emotet reboots six days later, and a prankster mails hoaxes from the FBI itself.

October 2021

Part One

A 4chan torrent spills Twitch's code and payouts, governments hijack REvil via its backups, Iran's pumps read "cyberattack 64411", and Acer India confirms a breach.

September 2021

Forced Entry

Citizen Lab hands Apple a captured zero-click exploit and the patch ships in six days; REvil returns from poisoned backups; BlackMatter squeezes an Iowa grain co-op.

August 2021

Generating Noise

A 21-year-old walks through T-Mobile's unlocked router and 54 million records follow; Poly Network's $611m thief hands it all back.

July 2021

The Long Weekend

REvil rides a Kaseya update into 1,500 firms and shuts Coop Sweden's tills; the FBI quietly holds the key; the Pegasus list reaches India's Parliament.

June 2021

The Price of Meat

Ransomware idles a fifth of US beef capacity and JBS pays $11m; the FBI claws back Colonial's ransom; a $10 cookie opens EA; India's CoWIN "leak" is a hoax.

May 2021

Running on Empty

DarkSide shuts the Colonial Pipeline and America queues for petrol; Conti switches off Ireland's health service; Air India discloses a decade of data.

April 2021

Not a Breach

533 million Facebook records go up for free, Codecov leaks CI secrets for two months, REvil demands $50m for Apple's schematics.

March 2021

Thirty Thousand Doors

Exchange zero-days hit 30,000 US organisations in a week; hackers browse 150,000 Verkada cameras; MobiKwik denies everything.

February 2021

The Cursor Moved

A cursor moves on its own at Oldsmar's water plant and the lye setpoint jumps 111-fold; Cl0p shakes down Accellion users; CD Projekt refuses to pay.

January 2021

The State as Antivirus

Eight countries seize Emotet and push an uninstaller through its own botnet; SolarWinds fallout hits Mimecast and Malwarebytes; JusPay's breach surfaces.

2020

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2020

The Second Phone

A second phone unmasks FireEye's breach, SUNBURST rides SolarWinds updates into US federal networks, and 7 million Indian cardholders surface on Google Drive.

November 2020

The Most Secure Election

Officials call the vote the most secure in American history, Krebs is fired by tweet, Ragnar Locker breaches Capcom, and 20 million BigBasket records go on sale.

October 2020

Two Hundred Euros

Vastaamo's stolen therapy notes become the mass extortion of Finnish patients, Ryuk hits US hospitals as agencies warn, and six GRU officers are indicted for NotPetya.

September 2020

Patch by Monday

Zerologon hands over Windows domains for a string of zeroes, Ryuk darkens 400 UHS hospitals, and DΓΌsseldorf's ransomware death gets its honest answer.

August 2020

The Employee Said No

A Tesla insider wears an FBI wire to sink a $1m malware bribe, DDoS extortion halts New Zealand's exchange four times, and Uber's ex-security chief is charged.

July 2020

The Blue Ticks Went Quiet

A phone call hands teenagers Twitter's admin console, WastedLocker grounds Garmin's services, Blackbaud pays for a promise, and India bans 47 clone apps.

June 2020

The Snake Knew Honda

Ransomware that knows Honda by name stops its plants, Australia announces an attacker it won't name, UCSF pays $1.14m β€” and India bans 59 Chinese apps.

May 2020

The Going Rate

ShinyHunters stocks a dark-web supermarket past 180 million records, REvil demands $42m from Lady Gaga's lawyers, and Europe's pandemic supercomputers mine Monero.

April 2020

The Accidental Utility

Half a million Zoom logins sell for a fifth of a cent, Maze ransomware hits Cognizant, and India's Home Ministry declares Zoom not safe for government use.

March 2020

Shut Down Your Computers

Ransomware silences Brno's COVID-testing hospital, lockdowns empty the world's offices, and the gangs' pledge to spare medicine collapses in three days.

February 2020

Made in Switzerland

A leaked CIA history reveals the agency and Germany's BND secretly owned Crypto AG; four PLA officers are indicted for Equifax; MGM's 10.6m guest list leaks.

January 2020

Planned Maintenance

Travelex trades by pen and paper under REvil ransomware, Windows 7 leaves the patch train, the NSA hands Microsoft CurveBall, and Avast sells what it guards.

2019

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2019

The Second Ransom

Maze attacks Pensacola, publishes Southwire's files and opens ransomware's first leak site; strangers speak through Ring cameras; Airtel shuts a 300M-user flaw.

November 2019

Spies on the Payroll

US charges two Twitter employees as Saudi spies, a Trend Micro insider sells 68,000 customers, Pemex refuses DoppelPaymer, and Pegasus reaches India's Parliament.

October 2019

Not Possible

India's largest nuclear plant calls a cyberattack "not possible", then confirms it; WhatsApp sues NSO over Pegasus; Sandworm defaces Georgia in an afternoon.

September 2019

A Nation on One Server

An unsecured Miami server leaks nearly every Ecuadorian's record, checkm8 makes iPhones forever exploitable, and a Wyoming hospital falls back to paper.

August 2019

Simply Visiting Was Enough

Google reveals websites that hacked visiting iPhones for years, one breached MSP downs 22 Texas towns at once, and BioStar 2 leaks a million fingerprints.

July 2019

Shared Responsibility

Capital One loses 106 million credit applications to one misconfigured firewall, the ICO proposes Β£282m in GDPR fines, and Bulgaria's tax files hit every newsroom.

June 2019

Final Notice

The AMCA breach bankrupts a medical debt collector in 14 days, Riviera Beach and Lake City vote to pay ransoms, and the US answers Iran's downed drone in code.

May 2019

The Missed Call

A WhatsApp call nobody answers plants NSO's Pegasus spyware, Baltimore refuses a 13-bitcoin ransom, and 885 million title documents sit one digit from anyone.

April 2019

The Jumping-Off Point

Phished Wipro systems become corridors into a dozen customer networks, 540 million Facebook records sit in open buckets, and Justdial's old API leaks India.

March 2019

Pen and Paper

Norsk Hydro runs its plants by hand rather than pay LockerGoga, ASUS's updater ships a backdoor, and Facebook admits storing passwords in plaintext.

February 2019

Attack and Destroy

An attacker erases every US server and backup VFEmail owns β€” no ransom asked β€” while 617 million stolen accounts go on sale and QuadrigaCX's wallets turn up empty.

January 2019

Collection #1

773 million stolen logins surface free as Collection #1, a student doxxes Germany's politicians, a teen catches FaceTime listening, and SBI's SMS server sits open.

2018

12 of 12 editions restored βœ“ β€” a complete yearβ–Ύ
December 2018

In Through the Provider

The US and five allies name China over Cloud Hopper, a second bug kills Google+, Shamoon wipes Saipem, and Delhi lists ten agencies that may read any computer.

November 2018

Do Not Disturb

Marriott discloses four years of undetected access to Starwood's guest database, a Postal Service API answers questions it was never asked, and CISA gets a name.

October 2018

The Chip Nobody Found

Bloomberg alleges a rice-grain spy chip inside American data centres, every named company denies it flatly, and nobody ever produces the hardware.

September 2018

Twenty-Two Lines

Twenty-two lines of JavaScript skim British Airways cards as customers type them, Facebook loses 30 million tokens, and India's Supreme Court draws Aadhaar's line.

August 2018

The Tool Nobody Scanned

A year-old worm rides an unscanned tool into the world's largest chip fab, Reddit's SMS second factor is intercepted, and Cosmos Bank loses β‚Ή94 crore in two days.

July 2018

The Prime Minister's Prescriptions

Singapore discloses the theft of 1.5 million patient records and its Prime Minister's medicine list, while Washington names twelve GRU officers it cannot arrest.

June 2018

The Bank Rang First

A London bank spots the skimmer on Ticketmaster's checkout in April and is told nothing is wrong; the page keeps working perfectly until 23 June.

May 2018

Dear Valued Customer

The GDPR takes effect and four complaints land at midnight, Talos finds half a million routers running VPNFilter, and India's Supreme Court reserves judgment on Aadhaar.

April 2018

A Flag on the Console

Someone wipes thousands of Cisco switches in Iran and Russia, and ten days later the US and UK jointly warn that Russia already lives in the world's routers.

March 2018

The Friends of Friends

A quiz installed by 270,000 people hands Cambridge Analytica the profiles of tens of millions, SamSam puts Atlanta back on paper, and UIDAI denies a leak.

February 2018

Someone Else's Fingerprints

Wiper malware blacks out the Pyeongchang opening ceremony behind forged fingerprints, memcached floods GitHub at 1.35 Tbps, and India's banks lose money two ways.

January 2018

The Cost of Guessing

Meltdown and Spectre expose twenty years of processors, $530 million leaves a Tokyo exchange in one morning, and India files a police case against a reporter.

2017

12 of 12 editions restored βœ“ β€” plus the WannaCry specialβ–Ύ
December 2017

The Last Line

FireEye names Triton, malware that reprograms plant safety controllers; Mirai's authors plead guilty; Airtel loses its Aadhaar licence over silent accounts.

November 2017

A Bounty for Silence

Uber admits a year-old theft of 57 million records and the $100,000 that bought silence; Intel patches the computer below the computer; Imgur answers in a day.

October 2017

All of Them

Yahoo's 2013 breach count triples to all three billion accounts, KRACK breaks WPA2 itself, and Bad Rabbit rides a fake Flash update into Kyiv's metro.

September 2017

Forty Days of Silence

Equifax breaks forty days of silence over 143 million credit files, a signed CCleaner update picks its forty targets, and the SEC admits EDGAR was hacked.

August 2017

The Hero in Handcuffs

The man who stopped WannaCry is arrested leaving Las Vegas, Maersk counts NotPetya's cost, and nine judges make privacy a fundamental right in India.

July 2017

Nobody Had to Break In

Millions of Verizon, Dow Jones and WWE records sit in cloud buckets anyone can read, HBO admits a breach, and a staged car crash ends AlphaBay.

June 2017

Dressed as Ransomware

A poisoned tax-software update wears a ransomware mask over a wiper, bills the world billions β€” and India's busiest container port goes manual overnight.

May 2017

The Other Twenty-Eight Days

WannaCry fills the month's middle while a fake Google Docs asks for real permissions, OneLogin admits its worst case, and 17 million Zomato accounts go on sale.

April 2017

Lost in Translation

The Shadow Brokers give the NSA's Windows arsenal away free, all 156 Dallas sirens sing to a clear sky, and a four-week clock starts that nobody can hear.

March 2017

Year Zero at Langley

WikiLeaks opens the CIA's toolbox, Microsoft ships the patch WannaCry will punish, Struts burns before Equifax β€” and 2.2 million McDelivery records sit exposed.

February 2017

Other People's Memory

Cloudbleed sprays strangers' secrets across the cached web, two PDFs break SHA-1, and one mistyped command switches off a chunk of the internet for four hours.

January 2017

The Password Was Nothing

Ransom notes replace 33,000 passwordless MongoDB databases, Lloyds rides out three days of DDoS, and a St. Louis library rebuilds from backups rather than pay.

May 2017 Β· Special

Three Days in May: The WannaCry Outbreak

The weekend ransomware became a household word β€” the archive's long-read companion to the May 2017 edition.

2016

12 of 12 editions restored βœ“β–Ύ
December 2016

Seventy-Five Minutes

A Kyiv substation trips at 23:53 and automates what took hands a year earlier, Yahoo discloses a different billion accounts, and Legion works through December.

November 2016

No One Broke In

Money leaves 8,261 Tesco Bank accounts with no intrusion at all, San Francisco's Muni opens its fare gates, and demonetisation moves India onto cards overnight.

October 2016

Things Nobody Called Computers

Cameras and video recorders take down Dyn and much of the American web, three stories break within one hour on 7 October, and India reissues 3.2 million cards.

September 2016

The Two-Year Silence

Yahoo admits a two-year-old theft of 500 million accounts, a camera botnet buries a reporter's site under 620 Gbps, and Jio makes India's data the world's cheapest.

August 2016

The Arsenal on Pastebin

An auction of the NSA's firewall exploits opens on Pastebin, three zero-days land on a dissident's iPhone, and 22,400 pages of submarine documents surface.

July 2016

Three Days Before Philadelphia

WikiLeaks publishes 19,252 DNC emails three days before the convention, PokΓ©mon Go asks for the whole Google account, and Ethereum rewrites its ledger by vote.

June 2016

The Call Nobody Returned

An FBI call to the DNC help desk goes unreturned for months, a re-entrancy bug drains 3.6 million ether from The DAO, and the RBI sets its banks a six-hour clock.

May 2016

The Half-Life of a Password

LinkedIn's four-year-old breach turns out to be 167 million accounts, more banks find the Bangladesh malware, and IRCTC denies losing a crore of records.

April 2016

Interested in Data?

Eleven and a half million files leave a Panamanian law firm, an entire electorate is dumped online in Manila, and WhatsApp encrypts a billion conversations.

March 2016

Someone Has Your Password

A fake Google warning reaches a campaign chairman and the reply comes two letters short, ten hospitals go back to paper, and Aadhaar finally gets its law.

February 2016

The Silent Printer

A jammed printer hides $81 million leaving Bangladesh Bank, a judge orders Apple to break its own lock, and India's regulator says no to Free Basics.

January 2016

Someone Else's Cursor

Analyses confirm the first blackout caused by a cyber-attack, hard-coded credentials surface in two firewall brands, and defacements follow Pathankot.

2015

12 of 12 editions restored βœ“β–Ύ
December 2015

Six Hours by Hand

Breakers open by remote hand across three Ukrainian utilities and 225,000 customers lose power, Juniper finds code nobody there wrote, and 191 million voter records sit exposed.

November 2015

What the Toymaker Kept

A toymaker loses 4.8 million parent accounts and 6.4 million children's profiles and learns of it from a reporter, and Paris reopens the encryption argument.

October 2015

Four Million, Then Fewer

TalkTalk's chief executive cannot say whether the data was encrypted and four million shrinks to 156,959, while Safe Harbour falls in Luxembourg.

September 2015

The Slow Download

A counterfeit Xcode, shared because the real one downloaded too slowly, writes spyware into WeChat and thousands of App Store apps β€” and India's encryption policy lasts a day.

August 2015

The Delete That Wasn't

Ashley Madison's database is published and a nineteen-dollar delete button turns out to be a bookkeeping entry; impersonated executives move $46.7 million out of Hong Kong.

July 2015

Nothing to Hide

A Milan spyware vendor's own archive is published from its hijacked Twitter account, two researchers work a Jeep remotely, and Android learns it can be attacked by text message.

June 2015

Everyone They Had Ever Known

Washington admits losing four million personnel files, then the security-clearance questionnaires themselves β€” and Kaspersky finds a nation-state inside its own laboratory.

May 2015

An Email About Ukraine

A spoofed UN message puts a trojan inside the German Bundestag and sixteen gigabytes leave the building; the IRS finds its security questions already answered.

April 2015

The Caliphate That Wasn't

TV5Monde goes dark behind a jihadist banner that investigators later trace to Russian military intelligence, and a million Indians email their telecom regulator.

March 2015

The Cannon Beside the Wall

China turns ordinary browsers into a five-day flood against GitHub, FREAK and Rowhammer surface β€” and India's Supreme Court strikes down Section 66A.

February 2015

Under His Own Credentials

Anthem tells 78.8 million people their Social Security numbers are gone after an administrator spots a query running as himself, and the world's SIM keys turn out to be copies.

January 2015

The First Aspect

Washington answers the Sony Pictures attack with sanctions on arms dealers who never touched a keyboard, and London asks whether any message may be unreadable.

2014

12 of 12 editions restored βœ“β–Ύ
December 2014

A Furnace Left Undefined

Germany's security office describes a steel mill intrusion that leaves a blast furnace unable to shut down β€” and names neither the plant, the attacker nor the date.

November 2014

Paper Cheques in Culver City

A skeleton appears on the screens at Sony Pictures, a studio falls back to fax machines and paper cheques, and Regin surfaces after six years in the dark.

October 2014

Names, Not Numbers

JPMorgan Chase tells the SEC it has lost the contact details of 76 million households β€” and that there is nothing for any of them to change.

September 2014

The Lanes That Were Labelled

Home Depot confirms 56 million cards taken from the self-checkout lanes its own systems labelled as payment terminals, and a 25-year-old Bash flaw breaks loose.

August 2014

A Crime Called a Leak

Photographs stolen from a hundred private accounts are called a leak, a hospital chain becomes Heartbleed's first big casualty, and India opens 18 million accounts.

July 2014

What Came With the Update

Symantec and Kaspersky publish rival accounts of a group that hides a remote-access tool inside three European industrial vendors' own software downloads.

June 2014

The Two-Week Window

A court order pulls GameOver Zeus onto a substitute server, giving the world's infected computers a fortnight's grace β€” the archive's first ransomware takedown.

May 2014

Wanted Posters in Pittsburgh

The US names five serving Chinese soldiers as hackers and prints their faces, eBay resets 145 million passwords, and TrueCrypt quits without ever explaining why.

April 2014

Sixty-Four Kilobytes at a Time

A missing bounds check in OpenSSL is disclosed with a name, a logo and a website of its own, and the web spends a decade failing to finish the cleanup.

March 2014

The Mailbox It Owned

Microsoft opens a blogger's Hotmail inbox to trace a Windows leak, then swears off the practice eight days later; Full Disclosure closes and reopens in six.

February 2014

The Coins Were Already Gone

Mt. Gox halts withdrawals, goes dark and files in Tokyo with about 850,000 bitcoin missing β€” coins researchers later find had been leaving since 2011.

January 2014

Seventy Million More

Target's card breach widens into a story about seventy million address books, and a refrigeration contractor's stolen credentials turn out to be the way in.

2013

12 of 12 editions restored βœ“β–Ύ
December 2013

Forty Million Cards

A breach of an American retailer's card readers becomes a consumer event in the week before Christmas, while two judges read the same surveillance programme in opposite directions.

November 2013

An Alarm, Then Nothing

The Target intrusion runs unseen through November, the detection software fires on the thirtieth, the alert reaches Bangalore β€” and Minneapolis does nothing.

October 2013

Encrypted, Not Hashed

Adobe's breach turns 150 million passwords into a public puzzle: encrypted rather than hashed, one key for every account, and each user's hint beside it in plain text.

September 2013

The Standard They Wrote

Three newspapers publish together on the deliberate weakening of commercial encryption, and within days a standards body withdraws its own random number generator.

August 2013

The Keys on Paper

An encrypted email service closes rather than surrender the keys to every account it holds β€” and hands them over once, in eleven pages of four-point type.

July 2013

An Arrest in Amsterdam

An indictment unsealed in Newark names five men over 160 million stolen card numbers; two of them have already sat in Dutch custody for thirteen months.

June 2013

The Ongoing Daily Basis

A secret court order for a telephone network's daily call records reaches print, and eighteen days later its source is in Moscow under Espionage Act charges.

May 2013

The Limits Came Off

Eight men are charged in Brooklyn after withdrawal ceilings lifted inside two card processors become $45 million in cash from machines in two dozen countries.

April 2013

The Machines Read It First

A hijacked wire-service account posts one false sentence, and trading algorithms take 143 points off the Dow before the newsroom finishes reading it.

March 2013

The Two O'Clock Bomb

A wiper timed for two in the afternoon takes tens of thousands of South Korean machines off their own disks, and Seoul misattributes it in public within a day.

February 2013

The Building on Datong Road

Mandiant names a PLA unit and prints its Shanghai street address, a whitelisting vendor's own certificate signs malware, and one forum infects four tech giants.

January 2013

The Advice That Stayed

A Java flaw is already in the exploit kits when homeland security tells the world to switch the plug-in off β€” and does not take the advice back after the patch.

2012

6 of 12 editions restored β€” July to December βœ“β–Ύ

The restoration schedule

The Vault grows backward in batches. The 2026 runway plus thirteen complete years β€” 2025 through 2013 β€” and the second half of 2012 are restored: 169 editions plus the WannaCry special β€” an unbroken monthly record from July 2012 to July 2026 β€” and from August 2026 the archive continues forward with the magazine's own back issues, beginning with the relaunch issue. Every one of them carries a monthly AI Tech desk and Digital Guard desk alongside the India desk and the time capsule. From here, history returns a year at a time until the archive spans twenty-one years of digital defense.

Back issues βœ“: Aug 2026 (1) Done βœ“: Jul 2026 β†’ Jan 2025 (19) Done βœ“: 2024 (12) Done βœ“: 2023 (12) Done βœ“: 2022 (12) Done βœ“: 2021 (12) Done βœ“: 2020 (12) Done βœ“: 2019 (12) Done βœ“: 2018 (12) Done βœ“: 2017 (12) Done βœ“: 2016 (12) Done βœ“: 2015 (12) Done βœ“: 2014 (12) Done βœ“: 2013 (12) In progress: 2012 Β· Jul β†’ Dec βœ“ (6 of 12) Next: 2012 Β· Jan β†’ Jun Then: 2011 β†’ 2005

The Sentry Briefing

New Vault editions and this week's news β€” once a week, in your inbox.

Free Β· unsubscribe anytime.