What was the most significant cyber security event of the last decade?
Measured by how much was written about it in this archive, not an attack at all: GDPR appears in 203 entries against 61 for WannaCry, the most-covered incident. Measured by cost and disruption, NotPetya and the SolarWinds compromise changed practice most, the first by destroying data across companies that were not its target and the second by making supply chain compromise a matter of state policy.
Why do breach victim numbers keep changing?
Because the first figure is an early estimate made under time pressure, usually from incomplete forensics, and often to meet a notification deadline rather than because the investigation has finished. Yahoo's 2013 breach went from 500 million accounts to one billion to all three billion over about thirteen months. Marriott's went the other way, from up to 500 million people to roughly 383 million records.
How long does it take to find out what actually happened in a breach?
Longer than the news cycle by a wide margin. In this archive the median piece about Equifax appeared 385 days after disclosure and the median piece about Mirai 651 days after the Dyn outage. The reporting keeps developing for years after the initial story stops being news.
Was WannaCry preventable?
The patch had been available for about two months when it spread. That makes it preventable in the narrow sense and misleading as a lesson, because the organisations worst affected were running systems they could not patch without taking clinical or industrial equipment out of service.
What made NotPetya different from ransomware?
It asked for payment and had no working mechanism to recover the data, which makes it destruction wearing the costume of extortion. It also spread through an update to legitimate accounting software, reaching multinationals whose only connection to the target country was an office there.
What did SolarWinds change?
It moved supply chain compromise from a theoretical concern to a policy one. The response included executive orders, procurement requirements and the push for software bills of materials — the idea that a buyer should be able to enumerate what is inside the software they run.
Why is the XZ Utils backdoor considered a near miss?
It was inserted over roughly two years by a contributor who had built up trust in the project, and it was found days before reaching stable distribution releases — by an engineer investigating a delay of about half a second in a login. Nothing systematic caught it.
Was the 2024 CrowdStrike outage a cyber attack?
No. A faulty update to security software crashed around 8.5 million Windows machines. It belongs in any honest timeline because the effect was indistinguishable from a major attack and the cause was a product bought to prevent one.
Has the number of major incidents increased over time?
The milestones here are lumpy rather than steadily rising, with clusters in 2017 and 2024 and quieter years between. Counts of this kind measure notability rather than frequency, and notability depends partly on what else was happening that month.
What is the common thread across these events?
Trust in something that was not examined. An unpaid library, an update channel, an acquired company's network, a file transfer product sitting between organisations, a security agent with kernel access. In each case the compromised thing had been granted trust because examining it was somebody else's job.
Why does regulation appear in a security timeline?
Because it changed behaviour more reliably than the incidents did. Breach notification deadlines and turnover-linked fines made board attention a legal necessity rather than a matter of persuasion, which is why the coverage volume for GDPR exceeds that of any attack in this period.
How should a timeline like this be used?
As a source of comparable cases rather than as a chronology to memorise. When facing a decision about update channels, acquisition due diligence or concentration in one supplier, there is now a documented precedent for how it went wrong elsewhere, including how long the truth took to assemble.