2015 in the archive: the biggest year, and the one nothing is remembered from
More entries than any other year here, and almost no story that outlived it. Counting what was filed shows a field working hard and not yet agreed on what mattered.
Last reviewed September 3, 2026
- Volume and memory are different quantities. The largest year in this archive left the least behind it.
- The famous events are 1.7% of it. Five names, 52 entries, out of 2,997.
- The tallest month has no story in it. Apr holds 328 entries and not one named event.
- The future was already filed. Ransomware and connected devices were both here, in single digits, marked as nothing in particular.
The shape of the year, month by month
Each column is a month. The marked portion at the base is the share of that month concerning any of the five events from 2015 that are still named. In most years such a chart shows one or two columns pushed upward by something that happened. This one does not, and the marked sliver is the reason to look at it.
Dark: all entries for the month. Red: those concerning a named event. Peak Apr at 328; trough Oct at 197; monthly average about 250.
What did the year's biggest story actually get?
13 entries. That is the largest single subject in 2,997, and it is roughly one entry in every two hundred.
The full roll-call of the year's named events, counted across the whole of 2015:
- 13Hacking Team
- 12The personnel records breach
- 11Ashley Madison
- 10The health insurer breach
- 9TalkTalk
Together, allowing for the handful of entries that mention more than one, they come to 52 — about 1.7% of the year. For a sense of what that is not, a single attack two years later drew nearly three times the coverage of the largest subject here, and a regulation that had not yet come into force drew five times it.
A year can be described by its centre of gravity, and this one does not have one. The events happened, they were real, and several of them are still cited in arguments about what organisations owe the people whose records they hold. At the time they were filed and the week moved on.
Why is the tallest month the emptiest?
Apr holds 328 entries against a monthly average near 250, which makes it the busiest month of the busiest year in this collection. It contains no entry about any of the events listed above. Not a small number. None.
What it contains instead is the ordinary texture of the field: a large denial-of-service attack on a datacentre, advice for people working away from the office, a browser vendor shipping a security feature, an argument about how far employees are responsible for breaches, a defence against phishing, a flaw affecting tens of thousands of mobile applications at once.
Every one of those is a legitimate thing to publish and none of them is a story anybody will refer to again. That is not a criticism of the writing. It is what most weeks in this field actually consist of, and the reason it is worth pointing at here is that in 2015 there was nothing else layered on top of it.
A month like this one is the base rate. In a year with a defining event, the base rate is what the event rises above and nobody looks at it. Here it is the whole picture.
Where the volume actually went
Two subjects, and neither is an event. The cloud appears in 296 entries and mobile working — phones, tablets, bringing your own device — in 295. Between them that is around 20% of the year, and each individually is many times the coverage of anything that actually happened.
Both describe a migration rather than an incident. Work was moving off managed desktops onto personal handsets and out of owned datacentres into rented ones, and that produced a question every week for years: how do you secure something you do not own, cannot image, and did not choose. There is no date on which that was reported, because it was never finished.
The specific anxieties, in the vocabulary of the moment: shadow IT, bring-your-own-device, containerisation, jailbreak detection, remote wipe, device management agents, data residency, multi-tenancy, encryption at rest, key escrow, vendor lock-in, and the perennial question of who owned a handset an employee had bought themselves. Each carried a product category behind it, an analyst quadrant ranking the products, and a conference track disputing the ranking.
None of them resolved. That is exactly why they sustained several hundred entries apiece without ever yielding an incident anybody remembers by name: an unanswered question generates writing indefinitely, whereas a settled one stops.
Set against them, the subjects that dominate security conversation now are barely present. Insider risk appears 26 times across the whole year and state-sponsored activity 17. Those were not absent from the world; they were absent from what was being written for the audience this archive served.
The tags applied to the year point the same way:
- 171Software Security
- 81Identity Theft
- 80Cyber Attack
- 78Mobile Security
- 77Network Security
- 75Hardware Security
- 67Cyber Security Report
- 66Data Breach
Software, identity, mobile, network, hardware. These are the divisions of a product catalogue rather than of a threat landscape, which is a reasonable way to organise a field whose readers were mostly deciding what to buy.
The next five years were already here, in single digits
Ransomware appears in 55 entries from 2015 and connected devices in 53. Both were filed. Neither was marked as anything.
Measured as a share of the entries that carry a written summary, so that the two years are compared on the same footing:
- 2.5%→9.4%ransomware
- 0.8%→5.8%the internet of things
- 2.6%→3.3%phishing
- 11.8%→14.6%the cloud
Ransomware moves from 2.5% to 9.4% and connected devices from 0.8% to 5.8%, while the cloud — already enormous — grows barely at all. The subjects that would define the following years were not new arrivals. They were present here, at the bottom of the distribution, indistinguishable from a browser update or a survey about password habits.
There is a comfortable version of this observation in which the warning signs were there and somebody should have read them. The archive does not support it. A signal is only a signal against a background, and in 2015 these subjects were the background — a few dozen entries among three thousand, with nothing to distinguish them from the several hundred other things that were also going to matter and mostly did not.
Recognising which of the small things is the important one is not a skill anybody reliably has. What this page can show is that the raw material for the recognition was sitting in plain view.
Does that comparison survive checking?
It needs to, because comparing two years by counting words is the easiest way in this field to produce a rise that is not there.
The specific hazard is straightforward. These counts come from matching text in titles and summaries, and the two years do not carry the same amount of text: 643 entries from 2015 have a written summary. If a later year has proportionally more text to match against, every subject will appear to have grown, and the growth will be an artefact of the record rather than a fact about the field.
So the figures in the previous section are calculated only among entries that carry a summary, in both years. That removes the hazard, and the movement holds: ransomware and connected devices rise several times over while the cloud stays roughly flat. A uniform artefact would have lifted all four together, and it did not.
One weakness remains and is not fixable by arithmetic. A text match is generous — an entry that mentions ransomware once in passing counts the same as one about nothing else. Every subject figure on this page is therefore a ceiling on relevance and a floor on presence, and the useful information is in the ratio between years rather than in any single number.
Setting this out matters more than it might appear. Unchecked year-on-year comparison is the commonest way security statistics mislead, and a page that counted carelessly while arguing about how others count would not be worth reading.
Two hundred and forty-five publications
627 entries from 2015 name the publication they came from, and they name 245 different ones. The six most frequent supply about 25% of that total.
- 45net-security.org
- 30itsecurityguru.org
- 25theregister.co.uk
- 23informationsecuritybuzz.com
- 19securityaffairs.co
- 16finance.yahoo.com
The list itself records a moment in publishing. Independent blogs that had grown into staffed operations sit beside trade weeklies with print ancestry, aggregators, syndication wires, a financial portal, and occasionally a national title picking up a story that had escaped the sector. Nothing enforced a shared standard of what counted as news, which is both why the year is so dispersed and why it reads as unedited.
Two years later the same measurement reads 211 publications with the top six supplying 44%. Fewer outlets, and a much larger share of the material coming from a handful of them. Between 2015 and then, security writing consolidated.
That has a bearing on the rest of this page. A year assembled from 245 sources, none of them supplying more than a small fraction, has no editorial centre. Nobody was in a position to decide that a particular story was the story, because no publication was read by enough of the audience to make that stick.
Consolidation is usually discussed as a loss, and in most respects it is. It also supplies something a dispersed field cannot: an agreed list of what happened. Part of the reason 2015 left no canon is that there was nobody with the standing to write one.
The breaches that should have been bigger
Two of the year's events involved losses of personal records on a scale that would dominate a news cycle today. A government lost the personnel files of its own workforce, including the background-investigation material gathered on people applying for clearance — which by its nature also describes their relatives, their finances and their histories. A health insurer lost the records of its members.
They drew 12 and 10 entries respectively.
The scale of those losses is not in dispute and this page does not need to quantify them to make the point, because the point is the gap between what happened and what was written. Both are among the largest disclosures of personal information in the period this archive covers, and each occupies about a third of one percent of the year that contains it.
Part of the explanation is repetition. A breach story has a short productive life: something was taken, here is roughly how, here is who should have stopped it. Once those are written there is nowhere for a second article to go, unless litigation, testimony or a regulator supplies a new fact — and in 2015 those processes were slower and less covered than they later became.
The rest of the explanation is that nobody yet had a frame for it. The argument that people are exposed by organisations they never chose to deal with is now standard, and this site has made it repeatedly about breaches and the time they take to establish. In 2015 that argument had not been assembled, so a breach of this kind read as a very large version of an ordinary incident rather than as a different category of thing.
December belonged to children
Two of the year's late breaches took data belonging to people too young to have agreed to anything. An entry dated the last day of November describes a toy manufacturer whose security practices had exposed a database of families; a follow-up three days later puts the figure at 6.4 million children and records that two jurisdictions had opened investigations. Three weeks after that, an entry notes a separate breach of a children's entertainment brand affecting 3.3 million accounts.
Subjects touching children, toys or minors appear 5 times across 2015, which is small in absolute terms and concentrated almost entirely in those weeks.
The reason to separate them from the rest is that the arithmetic of harm works differently. An adult whose details are exposed can watch their accounts, freeze their credit, and reasonably expect the exposure to age into irrelevance. A seven-year-old has none of those options and no reason to use them. Their name, date of birth and home address do not become less accurate with time; they become more useful, and the moment they are worth exploiting is a decade after nobody is still watching.
One entry from the middle of November puts it in a phrase the field has not improved on — that the invisible victims of identity theft are the children — and it was published a fortnight before the toy manufacturer supplied the demonstration.
There is no action here for a parent that resembles the advice given to adults, which is probably why the subject produced a few dozen entries and then stopped. A category of harm with no available remedy generates very little writing, regardless of how serious it is, because there is nothing to tell the reader to do.
What makes a year memorable?
Three properties, on the evidence of the years around this one. A canonical event needs a name people can use, a mechanism that can be explained in a sentence, and a lesson somebody can act on. Miss any of the three and the event is reported accurately and then forgotten.
2015 supplied names. What it did not supply were mechanisms with any novelty. Records were taken through credentials that should not have worked, applications that should have been patched, and access that should have been narrower — the same three sentences the field had already been writing for a decade, which is precisely why they generated so little.
The mechanisms behind this year's losses were, in every case, familiar. Credentials reused from a site that had already leaked them. A public-facing application trusting whatever a visitor typed into it. A machine two revisions behind a patch issued months earlier. A contractor's login that outlived the contract. An administrative console reachable from the open internet because a factory default had never been altered.
Any competent practitioner could have recited those five without being told which loss belonged to which, and had been reciting them for years. A mechanism that surprises nobody yields a single article, that article writes itself, and the subject is then finished.
Compare the attack that dominates 2017: it spread by itself, it used a stolen government exploit, and it stopped hospital admissions. The mechanism was new, the origin was extraordinary, and the consequence was visible to people with no interest in computers. It is remembered because all three held at once.
None of that makes the events of 2015 less serious for the people in those files. It explains why a year can contain a great deal of real harm and leave almost no mark on how the field talks about itself afterwards — and why the volume of writing about something is a poor proxy for how much it mattered.
Does any of this measure the world?
It measures one thing precisely and several things not at all, and the difference is worth being exact about.
What is precise: these are counts of what this archive filed during 2015. Nothing is estimated and nothing is typed in by hand.
What follows from that, and does not extend past it: the selection was made by whoever was choosing week by week, and their interests were not neutral. The sources are trade publications, so a subject those titles found unrewarding is smaller here than it was anywhere else. And 643 of 2,997 entries carry a written summary, which is a smaller proportion than the years after it — the reason the cross-year work above was restricted to the summarised subset rather than run across everything.
What survives all of that is the internal comparison, because every distortion applies equally to both sides of it. The same people, choosing the same way from the same kinds of publication, filed 296 entries about the cloud and 52 about every named event of the year combined. No selection bias produces a ratio of that size by accident.
Described honestly, this is a record of contemporaneous attention: what looked worth keeping at the time, before anybody knew which of it would matter. Hindsight is the one thing it does not contain, which is exactly what makes it worth counting.
The year ended before it knew how it ended
The final week of 2015 reads like any other. An acquisition in endpoint protection. A software vendor settling with a regulator over update practices. A new status code for pages blocked by censors. Warnings about fake parcel confirmations, which is the seasonal variety of an old trick. The ordinary business of a field going quiet for the holidays.
Threaded through the same days are two entries about electricity. One, on 21 December, asks whether a national power grid is vulnerable to foreign attack — the kind of speculative piece that had been written every year for a decade. The other is dated 30 December and asks whether attackers are infecting critical infrastructure in Ukraine.
It is phrased as a question. Grid and electricity subjects account for 9 entries across the whole of 2015, and this is where they end: not with a finding, but with an uncertainty filed on the second-to-last day of the year.
What was happening is now well established, and it is the reference point for everything since about attacks with physical consequences. At the time it was a report from a distant country during the deadest week in the calendar, unconfirmed, competing for attention with a toy-brand breach and an acquisition announcement.
That is not a failure of anybody's judgement. Confirmation genuinely took weeks, and a responsible entry in the last days of December could not have said more than this one does. The observation is about the shape of a year rather than the quality of the reporting: the boundary between one year and the next is an administrative line, and events do not respect it.
They also cluster against it. An attack timed for the week when operations run on skeleton staffing and nobody is reading the news is not making a scheduling error, and the pattern has repeated in every December since.
What 2015 settled
Three things, none of them recognised as settled at the time. The first is that a government's own personnel records are reachable, and that the consequences fall on people who never chose to be in the file — the relatives, referees and former colleagues named in somebody else's background investigation.
The second is that personal data can be a weapon rather than an asset. A dating site's records were released not to be sold but to be read, and the harm was social rather than financial. Every subsequent argument about extortion built on exposure rather than encryption descends from that.
The third is that a company selling intrusion capability can itself be intruded upon, and that when it is, its tools become everybody's. That is the largest single subject of 2015 by coverage, at 13 entries, and it is the earliest clear instance of the argument this site now makes constantly about suppliers and concentrated failure.
What 2015 did not settle is what mattered. That question stayed open, and the archive shows the field answering it the way fields do: by writing about the migration in front of it, at length, while the things that would define the next five years sat in the same weekly list at one and two percent.
Common questions
How many entries does this archive hold for 2015?
2,997 — more than any other year here. 643 of them carry a written summary and 627 name the publication they came from.
Which was the biggest story of 2015?
By coverage in this archive, Hacking Team, at 13 entries out of 2,997. That is the largest single subject of the year and it is roughly one entry in every two hundred, which is the finding rather than an accident of counting.
How much of the year do its famous events account for?
52 entries, or about 1.7% of the year. The five events from 2015 that are still named — a surveillance vendor breached, a government personnel file taken, a dating site exposed, a health insurer emptied and a telecoms company attacked — together occupy under one fiftieth of what was filed.
Which month was busiest?
Apr, with 328 entries against a monthly average of about 250. It contains no entry about any of the year's named events. The tallest month of the largest year is made entirely of ordinary weeks.
So what filled the year instead?
Two long-running subjects. The cloud appears in 296 entries and mobile working in 295 — each one many times the coverage of any actual event. Neither is a story with a date; both are conditions that generated writing continuously.
Was ransomware already present in 2015?
Yes, and in small numbers: 2.5% of the entries with a written summary, against 9.4% two years later. It was in the archive, filed alongside everything else, with nothing to mark it as the thing that would close hospitals.
Is that rise real or an artefact of the data?
Real, as far as this archive can show. The comparison is made only among entries that carry a written summary in both years, so it is not distorted by one year having more text to match against. The internet of things moves the same way, from 0.8% to 5.8%.
How many publications are represented?
245 distinct titles, with the six most frequent supplying about 25% of everything that names a source. Two years later the same measure reads 211 titles and 44%, so the field was considerably more dispersed in 2015 than it became.
Does a big breach always produce a lot of coverage?
No, and this year is the clearest demonstration of it. Two of the largest losses of personal records in the period drew around a dozen entries each. Volume of writing tracks how much there is to say and how many people have a reason to say it, which is a different quantity from harm.
Was 2015 an unusually quiet year for security?
The opposite. It holds more entries than any other year in this archive. What it lacks is concentration: a great deal happened, and almost none of it became the kind of story that gets referred back to.
What does entry count actually measure?
Attention, and only attention. It measures what somebody thought worth filing that week. Attention responds to novelty, to how much can be written, and to who benefits from the subject staying in view — none of which is the same as consequence.
Can these figures be checked?
Yes. Every number is computed from the archive when the page is built rather than typed in, so it moves if the archive moves. The entries are reachable individually and each names the publication it came from.
2015 in the archive
The 2,997 entries behind this page run from January 1, 2015 to December 31, 2015. They are browsable by month, and each one names the publication it came from.
Browse the archive by month, read the same treatment of 2017, or search across every year.