Skip to content
The Cyber Security Place

Chronology

A security timeline, 2014–2026: what was known, and when

An incident is not a day. It is a multi-year process of finding out, and the first number published is almost never the last one.

Last reviewed August 29, 2026

Understanding lags the event by years. Yahoo's 2013 breach went from 500 million accounts to one billion to all three billion over roughly 13 months; Marriott's fell from up to 500 million people to about 383 million records, a different unit reported in the same sentence; Equifax rose from 143 to some 147 million. Coverage lags too: in this archive the median piece on Equifax appeared 385 days after disclosure and on Mirai 651 days after the outage. And the single most covered development of the period was not an attack but a rule — GDPR appears in 203 entries against 61 for WannaCry, the most covered incident. Across 32 milestones from Heartbleed to the CrowdStrike outage, the recurring thread is trust granted to something nobody examined.

What was known, and when

Four incidents whose headline figure changed after publication. Each step below is dated to when that version was the current one. The longest to settle was Yahoo, at 13 months from first disclosure to final figure.

Yahoo

Public from September 2016 · settled 13 months later

  1. September 2016: About 500 million accounts, in a 2014 intrusion.
  2. December 2016: A separate 2013 intrusion is disclosed, put at about 1 billion accounts.
  3. October 2017: The 2013 figure is revised again: all 3 billion accounts that existed.

Three years and two upward revisions, ending at six times the first number. The final figure was not a bigger breach; it was the same breach, understood.

Equifax

Public from September 2017 · settled 6 months later

  1. September 2017: About 143 million people affected.
  2. March 2018: Revised upward to roughly 147 million, with more data types than first stated.

The headline number moved little. What moved was the list of what had been taken, which kept growing for months after the story stopped being news.

Marriott

Public from November 2018 · settled 2 months later

  1. November 2018: Up to 500 million guests affected.
  2. January 2019: Revised down to roughly 383 million records — records, not people, since one guest may hold several.

Revisions go down as well as up, and the unit changes quietly. A count of records and a count of people are different quantities reported in the same sentence.

Change Healthcare

Public from February 2024 · settled 11 months later

  1. February 2024: Scope unknown. The visible effect is that pharmacies cannot process prescriptions.
  2. January 2025: Reported as affecting around 190 million people, later put near 193 million.

Nearly a year between the outage everybody noticed and a number for who was in it. The operational story and the data story ran on completely different clocks.

None of these revisions indicates dishonesty. An organisation discovering an intrusion has a notification deadline measured in days and a forensic investigation measured in months, and it is obliged to say something before it knows. The predictable consequence is that the number entering public memory is the one produced under the least information, and that it is the number most often repeated afterwards.

How long does the truth take to arrive?

The archive underneath this site allows the question to be answered rather than asserted, at least for its own coverage. Taking the date each event became public and measuring when pieces about it were published gives a distribution rather than a moment.

Equifax
21 pieces. First after 1 day, median after 173 days.
NotPetya
13 pieces. First after 2 days, median after 244 days.
Mirai
12 pieces. First after 38 days, median after 762 days.
WannaCry
61 pieces. First after 3 days, median after 102 days.

Mirai is the extreme case at 762 days, which is not a criticism of anybody's reporting. It is what it looks like when the significance of an event is only legible in retrospect: the botnet that took down a DNS provider mattered most as the moment consumer hardware became an industrial weapon, and that reading took years to become the standard one.

One caution about these figures, since the page turns on them. They measure this collection's coverage, not the world's, and a collection assembled from one publication's output will reflect its editorial rhythm. What they support is a claim about how trade coverage of an incident behaves — a small burst, then a long tail that is bigger than the burst — rather than a precise measurement of when facts became available.

A decade that was not a smooth curve

32 milestones across 13 years, counted by year. The empty slots are drawn rather than skipped.

214215216317318119220421122223524325226

The shape argues against the story of a steadily worsening decade. It is lumpy —2024 carries 5 while 2 of the years hold one apiece — which describes a small number of episodes large enough to change practice, separated by longer stretches in which the same lessons were already available and were not taken. Heartbleed said something about unpaid maintainers in 2014 that the XZ backdoor said again in 2024, and the intervening ten years did not lack for opportunities to act on it.

Why was the most covered event a rule?

Counting mentions across the archive, GDPR appears in 203 entries. WannaCry, the most heavily covered incident of the period, appears in 61. The regulation outweighs the attack by a factor of about 3.3.

There are dull explanations for part of that. A regulation has a long runway — it is written, debated, dated and then applied — so it generates coverage for years before it does anything, while an attack generates coverage after. A compliance deadline also creates an audience that must read about it, which is a commercial fact about publishing as much as an editorial one.

The less comfortable explanation is that it reflects where attention actually went. Attacks were something that happened to other people; the deadline was going to happen to you. Security work that had been argued for on grounds of prudence for a decade became fundable in a year once failure carried a number attached to global turnover, and every practitioner who lived through that period can name the meeting where it changed.

That is worth holding onto when reading predictions about what will drive security spending next. The mechanism with the best track record in this period was not a demonstration of harm. It was a deadline.

What connects them?

Read in sequence, the milestones are not a catalogue of clever attacks. Most turn on something that had been granted trust without anybody examining it, usually because examining it was understood to be somebody else's job.

Heartbleed and the XZ backdoor are the same story a decade apart: critical code maintained by very few people, unpaid, with no mechanism by which the organisations depending on it would notice. NotPetya, SolarWinds, Kaseya and MOVEit are one story told four times: the update channel and the file transfer product are trusted paths into an organisation precisely because they are boring, and boring is what nobody inspects. Marriott is due diligence that examined the accounts and not the network. The CrowdStrike outage is what happens when the agent granted the deepest access on every machine has a bad day.

The practical form of that observation is a question rather than a control. What do we currently trust that nobody here has looked at, and who would notice if it changed? Answering it produces a shortlist that rarely includes the things a threat report would put first — it includes a build server, a monitoring agent, a certificate authority, a small supplier with wide access, and whatever piece of software everyone assumed the vendor was auditing.

The other durable pattern is that the victim and the owner of the weakness are frequently different parties. The owners of the cameras in the Mirai botnet lost nothing. Equifax's affected population were not its customers and had no relationship to end. Where the party who could fix a problem is not the party who suffers from it, the problem persists regardless of how well understood it is, which is an argument about incentives rather than about technology.

The chronology

32 milestones, 2014 to 2026, with what each one established.

2014

Flaw or failure

Heartbleed

A flaw in OpenSSL let anyone read the memory of servers using it, including keys and passwords.

The first time a bug in an unpaid library became everyone's emergency at once. The lesson about who maintains critical code was available a decade before it was learned.

Breach or intrusion

Sony Pictures

An intrusion destroyed systems and published internal email, contracts and unreleased films.

Established that the damage from a breach can be reputational and contractual rather than financial, and that publication is a weapon in itself.

2015

Breach or intrusion

The OPM breach

Background investigation records for about 21.5 million people, including fingerprints and the answers given during security clearance interviews, were taken from a United States government agency.

The data cannot be reissued. A credit card is replaceable and a completed clearance questionnaire about your relatives, debts and foreign contacts is not, which made it the clearest case of a breach with no remedy available to its victims.

Breach or intrusion

TalkTalk

A telecoms breach affecting hundreds of thousands of customers, followed by a record regulatory fine at the time.

One of the first cases where the regulator's response, rather than the intrusion, set the cost.

2016

Breach or intrusion

The Bangladesh Bank heist

Attackers used a central bank's access to the international payment messaging network to issue fraudulent transfer instructions, moving roughly 81 million dollars before a spelling mistake in one order raised suspicion.

The network itself was not broken. One participant's terminal was, which is all it takes when membership of a trusted system is the credential.

Breach or intrusion

Mirai and the Dyn outage

A botnet of home cameras and routers took down a major DNS provider, and with it a large part of the consumer web.

Proved that insecure consumer devices are everyone's problem, because the victim of the attack is not the owner of the devices.

2017

Breach or intrusion

WannaCry

Ransomware spread by a leaked exploit reached hospitals, factories and rail operators within hours.

The patch had existed for two months. It remains the clearest demonstration that the gap between a fix existing and being applied is where the damage lives.

Supply chain

NotPetya

Malware delivered through an update to Ukrainian accounting software destroyed data across multinationals that merely had an office there.

The most expensive cyber incident on record for years, and the first mass demonstration that a trusted update channel is an attack path.

Breach or intrusion

Equifax

An unpatched web framework exposed the credit files of about 147 million people who were never its customers.

Detached breach victims from customer relationships. The people affected had no account to close and no supplier to leave.

2018

Flaw or failure

Meltdown and Spectre

Flaws in the way processors speculatively execute instructions allowed one program to read memory belonging to another, across almost every chip in service.

Not a bug in software but a consequence of a performance technique used for twenty years. The mitigations cost measurable performance, which made it the first widely felt case of security being paid for in speed.

Rule

GDPR takes effect

European data protection rules began to apply, with notification deadlines and fines tied to global turnover.

By a wide margin the most written-about development of the period. It made security a board matter by attaching a number to failure.

Breach or intrusion

Marriott

An intrusion inherited through an acquisition had been running in the acquired company's systems for four years.

The clearest case of a breach arriving inside a purchase, and of due diligence that examined the accounts and not the network.

2019

Breach or intrusion

Capital One

A misconfigured cloud component let an outsider read over a hundred million credit applications.

Moved the conversation from whether the cloud is secure to who is responsible for configuring it, which is where it has stayed.

2020

Breach or intrusion

The Twitter account takeover

Attackers persuaded staff to give them access to internal administrative tooling and used it to post from some of the most followed accounts in the world.

No software was exploited. An internal tool with broad powers and a persuasive phone call were enough, which is the whole argument for limiting what administrative interfaces can do.

Supply chain

SolarWinds

A state-aligned actor inserted a backdoor into a network management product used by thousands of organisations and governments.

Made supply chain compromise a matter of national policy rather than a technical curiosity, and started the software bill of materials effort.

2021

Breach or intrusion

Exchange Server mass exploitation

Flaws in on-premises mail servers were exploited at scale, first by one state-aligned group and then by everyone else once the details were public.

Established the pattern that now follows every serious edge vulnerability: a quiet targeted phase, then an indiscriminate scramble the moment a patch reveals what to look for.

Breach or intrusion

Colonial Pipeline

A ransomware incident at a fuel pipeline operator led the company to halt distribution across the eastern United States.

The operational systems were not encrypted; the billing systems were. It showed how far the consequences of an IT incident reach into physical supply.

Supply chain

Kaseya

Attackers compromised a tool used by managed service providers and reached their customers through it.

Demonstrated the multiplier in outsourced administration: one compromise, hundreds of downstream victims.

Flaw or failure

Log4Shell

A trivially exploitable flaw in a ubiquitous Java logging library sent every organisation searching for where it was running.

Most could not answer that question quickly, which turned a patching problem into an inventory problem and made software bills of materials a mainstream demand.

2022

Breach or intrusion

Uber and the Lapsus$ pattern

An attacker with stolen credentials sent repeated multi-factor prompts until an employee approved one, then reached internal systems through credentials found in a script.

Showed that a second factor a person can approve by accident is a second factor an attacker can request until they do, and moved the argument toward factors that cannot be handed over.

2023

Market shift

Lloyd's requires a cyber war exclusion

The London insurance market instructed its syndicates that standalone cyber policies must exclude losses from state-backed attacks, with wordings turning on whether an attack had a major detrimental impact on a state rather than on who carried it out.

It put attribution inside the contract. For an ordinary victim, naming a government changes almost nothing about the week's work and everything about whether a covered loss becomes an argument, decided on evidence the victim will never see.

Supply chain

MOVEit

A flaw in a managed file transfer product was exploited at scale, reaching more than 2,700 organisations and the data of some 93 million people.

Showed that a single niche product sitting between organisations can expose an entire economy's worth of records.

2024

Rule

The national catalogue stops keeping up

The United States vulnerability database announced it could no longer analyse incoming reports at the rate they arrived, leaving thousands of entries published without the severity data that downstream tooling assumes is there.

Every patching queue, scanner and compliance rule in the industry treats that catalogue as a fixed point. When the fixed point admitted it was behind, the arithmetic underneath a decade of prioritisation stopped working, and almost nothing changed in response.

Rule

The first post-quantum standards

After eight years of public competition, the first cryptographic standards designed to resist a quantum computer were finalised and published.

It converted an argument about physics into a migration schedule. The deadline is not when such a machine arrives but how long today's traffic must stay confidential, which means anything intercepted now with a twenty-year sensitivity is already spent.

Breach or intrusion

Change Healthcare

Ransomware at a payments clearing house disrupted prescriptions and provider payments across the United States, eventually reported as affecting around 193 million people.

Concentration risk made concrete: a company most patients had never heard of sat between them and their medicine.

Supply chain

The XZ Utils backdoor

A backdoor planted over years in a compression library used by major Linux distributions was found days before it reached stable releases.

It was caught because one engineer investigated a half-second delay. The nearest of near misses, and an uncomfortable answer to how such things get found.

Flaw or failure

The CrowdStrike update

A faulty update to security software crashed some 8.5 million Windows machines, grounding flights and stopping hospitals.

The largest IT outage of its kind was caused by a security product, not an attacker. Agents with kernel access are themselves a concentration of risk.

2025

Market shift

The shortage loses its number

The annual workforce study was published without an estimate of unfilled cybersecurity jobs for the first time in a decade, its authors reporting that respondents consistently described missing skills rather than missing people.

A figure quoted in ministerial speeches, funding bids and university prospectuses simply stopped being issued. It is the second institution in two years to withdraw a number it could no longer defend, and both withdrawals were quieter than any revision would have been.

Rule

The FTC's GoDaddy order

A settlement finalised with the United States consumer protection regulator barred a hosting company from misrepresenting its security measures, after failures tied to breaches between 2019 and 2022.

Moved the marketing claim from a commercial matter to an enforceable one. A datasheet sentence and a contract sentence now sit closer together than they did.

Market shift

Paying becomes the minority position

The share of ransomware victims paying fell to a record low near a third, from roughly half a year earlier, with about two thirds of organisations declining outright.

Refusal works because restoring works. Once that became common the encryption half of the business lost its leverage, and extortion shifted toward publishing stolen files — which good backups do nothing about.

2026

Breach or intrusion

Commercial models used as the intrusion tool

One operator ran an intrusion campaign against nine government bodies in Mexico using two commercial coding assistants, which produced thousands of executed commands across roughly a thousand prompts and carried out most of the remote operations.

The operator claimed to be doing authorised work and nothing in the session could test the claim. It moved the assistant from a thing attackers might misuse in theory to a component of the operation, and it did so without any flaw in the assistant being exploited.

Market shift

Exploitation overtakes stolen credentials

The annual breach study recorded vulnerability exploitation as the leading route into an organisation for the first time, at roughly a third of initial access, while third-party involvement reached close to half of all breaches.

Two decades of security awareness spending were premised on the person being the way in. That premise stopped describing the data in the same year the industry admitted only about a quarter of known-exploited flaws get fully remediated.

Where the next one comes from

A pattern is only worth having if it points forward. If the recurring shape is trust extended to something nobody examined, then the useful exercise is to ask what currently occupies that position — not the threats a report would rank first, but the boring, deeply trusted components that nobody has been asked to look at.

Build and deployment systems are the clearest candidate. They hold credentials for everything they deploy to, they run code from repositories, and they are administered by whoever set them up. A compromise there is indistinguishable from a legitimate release, which is precisely the property that made update channels effective in NotPetya and SolarWinds. Very few organisations can say when their build system was last reviewed by somebody who did not build it.

The second is the growing population of automated agents holding standing credentials — service accounts, integration tokens, and now software acting on behalf of people with the permissions of the person it acts for. They do not get offboarded, they rarely expire, and nobody notices when one starts doing something unusual because nobody knows what usual looked like. Every property that made the Twitter administrative tooling dangerous applies, with the additional difficulty that there is no human to phone and ask.

The third is the small supplier with wide access. Not the platform everyone worries about, whose security is examined by thousands of customers, but the specialist tool integrated years ago that quietly reads production data on a schedule. MOVEit was exactly that, and the reason it reached 2,700 organisations was not sophistication. It was that a boring product sat between them all.

None of this is a forecast, and a forecast is not what the record supports. What it supports is a question that can be asked this week and answered with names.

Common questions

What was the most significant cyber security event of the last decade?

Measured by how much was written about it in this archive, not an attack at all: GDPR appears in 203 entries against 61 for WannaCry, the most-covered incident. Measured by cost and disruption, NotPetya and the SolarWinds compromise changed practice most, the first by destroying data across companies that were not its target and the second by making supply chain compromise a matter of state policy.

Why do breach victim numbers keep changing?

Because the first figure is an early estimate made under time pressure, usually from incomplete forensics, and often to meet a notification deadline rather than because the investigation has finished. Yahoo's 2013 breach went from 500 million accounts to one billion to all three billion over about thirteen months. Marriott's went the other way, from up to 500 million people to roughly 383 million records.

How long does it take to find out what actually happened in a breach?

Longer than the news cycle by a wide margin. In this archive the median piece about Equifax appeared 385 days after disclosure and the median piece about Mirai 651 days after the Dyn outage. The reporting keeps developing for years after the initial story stops being news.

Was WannaCry preventable?

The patch had been available for about two months when it spread. That makes it preventable in the narrow sense and misleading as a lesson, because the organisations worst affected were running systems they could not patch without taking clinical or industrial equipment out of service.

What made NotPetya different from ransomware?

It asked for payment and had no working mechanism to recover the data, which makes it destruction wearing the costume of extortion. It also spread through an update to legitimate accounting software, reaching multinationals whose only connection to the target country was an office there.

What did SolarWinds change?

It moved supply chain compromise from a theoretical concern to a policy one. The response included executive orders, procurement requirements and the push for software bills of materials — the idea that a buyer should be able to enumerate what is inside the software they run.

Why is the XZ Utils backdoor considered a near miss?

It was inserted over roughly two years by a contributor who had built up trust in the project, and it was found days before reaching stable distribution releases — by an engineer investigating a delay of about half a second in a login. Nothing systematic caught it.

Was the 2024 CrowdStrike outage a cyber attack?

No. A faulty update to security software crashed around 8.5 million Windows machines. It belongs in any honest timeline because the effect was indistinguishable from a major attack and the cause was a product bought to prevent one.

Has the number of major incidents increased over time?

The milestones here are lumpy rather than steadily rising, with clusters in 2017 and 2024 and quieter years between. Counts of this kind measure notability rather than frequency, and notability depends partly on what else was happening that month.

What is the common thread across these events?

Trust in something that was not examined. An unpaid library, an update channel, an acquired company's network, a file transfer product sitting between organisations, a security agent with kernel access. In each case the compromised thing had been granted trust because examining it was somebody else's job.

Why does regulation appear in a security timeline?

Because it changed behaviour more reliably than the incidents did. Breach notification deadlines and turnover-linked fines made board attention a legal necessity rather than a matter of persuasion, which is why the coverage volume for GDPR exceeds that of any attack in this period.

How should a timeline like this be used?

As a source of comparable cases rather than as a chronology to memorise. When facing a decision about update channels, acquisition due diligence or concentration in one supplier, there is now a documented precedent for how it went wrong elsewhere, including how long the truth took to assemble.