2022–2024: Lapsus$, Change Healthcare & the XZ Backdoor
← Back to the full list · Previous: Part 5 — 2020–2021
The World in 2022
The newest era of cybercrime runs on three engines. First, stolen credentials: infostealer malware has harvested billions of username-password pairs from infected browsers, and a password for sale for $10 opens a Fortune 500 tenant. Second, extortion without encryption: why lock the files when leaking them hurts more? The steal-and-dump model scales better and skips the operational risk of deploying ransomware. Third — the oldest engine of all — the human being: a phone call to a help desk, an MFA prompt spammed until someone accepts it, an insider paid in cryptocurrency.
The seven stories in this final part feature teenagers defeating giants, a regulator-vs-insurer fight over a nation’s medical secrets, a Vegas empire downed by one convincing call, the largest healthcare breach in history, a cloud credential heist touching a billion people — and the most sophisticated supply-chain attack ever discovered, caught three weeks before it could have owned the internet.
27. Lapsus$ (2022) — Teenagers Take Down Titans
| Attackers | A loose crew largely made up of UK-based teenagers (core suspects 16–17; two convicted in London in 2023) |
| Targets | Nvidia, Samsung, Ubisoft, Microsoft, Okta (via a vendor), T-Mobile, Uber, Rockstar Games, Brazil’s Health Ministry, Portugal’s media giant Impresa, and more |
| Method | Pure social engineering: SIM swaps, purchased stolen passwords, MFA-prompt fatigue, help-desk impersonation, bribing insiders via Telegram |
| Damage | Massive source-code and data leaks — including the biggest leak in gaming history (GTA VI) |
| Cost | Direct costs never totaled; forced industry-wide changes to MFA and help-desk verification |
How the attack unfolded
In early 2022 a group calling itself Lapsus$ appeared and broke the industry’s mental model of “advanced threats.” Their victims were among the hardest targets on Earth; their techniques were things a motivated 15-year-old could execute — because, in large part, that’s who several of them were.
Their method inventory read like a Mitnick revival with modern parts:
- Buy the password. Infostealer malware harvests credentials from millions of infected browsers; the crew simply bought logs containing corporate employee passwords from criminal marketplaces.
- Beat MFA with fatigue and the phone company. They spammed employees’ authentication apps with push notifications until someone tapped “Approve” to make it stop; and they SIM-swapped victims — convincing mobile carriers to transfer a target’s number to the attackers’ phone, hijacking SMS-based verification and password resets wholesale.
- Call the help desk. They impersonated employees (rich LinkedIn profiles made it easy) to reset credentials and enroll attacker-controlled devices in MFA.
- Recruit insiders. They openly solicited company employees on Telegram, offering thousands of dollars for credentials, VPN access, or a laptop handed over.
The trophy list accumulated absurdly fast. Nvidia (February 2022): a terabyte of data — credentials, schematics — with the hackers cheekily demanding Nvidia open-source its drivers and remove its Ethereum-mining limiter. Samsung: source code behind Galaxy device bootloaders and Knox security. Ubisoft: internal systems briefly accessed. Microsoft: partial source for Bing and Cortana, acknowledged by Microsoft (which found no customer data affected). Brazil’s Health Ministry: systems wiped/defaced during COVID-data chaos, data erased. Okta — the identity provider securing thousands of companies — was compromised through a third-party support engineer’s access (via contractor Sitel), exposing a superuser console; Okta’s initial “2.5% of customers potentially affected” framing drew fierce criticism when screenshots showed the scope. T-Mobile: a SIM-swap spree. Uber (September 2022): an attacker (linked to the same milieu) bought a contractor’s password, bombarded him with MFA prompts until approval, then wandered Uber’s internal network — Slack, AWS, vSphere hypervisor consoles — announcing themselves to the entire company by posting in Uber’s all-hands Slack channel (with an adult-video URL appended for infamy).
Then the crown jewel. In September 2022, 90 development videos of the then-unannounced Grand Theft Auto VI leaked from Rockstar Games — the biggest leak in gaming history, moving markets and memes alike. The culprit, London’s Old Bailey would hear, was Arion Kurtaj, an 18-year-old from Oxford — and the detail that made him a legend: he did it while on police bail in a Travelodge hotel, with his laptop confiscated. Unable to use normal computers, he connected an Amazon Fire TV Stick to the hotel television, used a hotel phone and the TV’s browser plus cloud services, contacted Rockstar’s IT help desk claiming to be an employee, and talked his way into the company’s Slack and Confluence. Kurtaj — autistic, assessed as highly skilled and highly motivated to reoffend — was deemed unfit to stand trial in the conventional sense; a jury found the facts proven, and in September 2023 he received an indefinite hospital order (a secure hospital, essentially, until doctors deem release safe). A 17-year-old co-defendant (also convicted for Nvidia and BT/EE intrusions) received a youth rehabilitation order — and, in a scene from a different century, was banned from using VPNs.
The damage
The direct financial damage was real but diffuse; the strategic damage was total. Lapsus$ proved that the barrier to breaching the world’s best-defended companies is no longer skill — it’s nerve and a phone. Every CSO had to answer the board’s obvious question: if teenagers can do this to Nvidia, Microsoft, and Uber in one year, what does our help desk verify before a reset?
Aftermath & lessons
- The industry’s MFA migration accelerated from “something you have” to phishing-resistant factors — FIDO2/WebAuthn passkeys, number matching, hardware keys — precisely because push-fatigue and SIM swaps defeated the older generation of two-factor.
- Help-desk identity verification became a formal control: video verification, manager callbacks, “known facts” policies, and geographic/device anomaly flags on privileged resets.
- The insider-recruitment-for-hire model (Telegram bounties for corporate access) moved from rumor to documented reality and now features in every serious insider-threat program.
The core lesson: Lapsus$ closed the loop this series opened — Mitnick proved in 1995 that a phone call beats technology; a century of security spending later, a phone call still beats technology. Defenses that don’t account for the human channel are defenses against the last war.
28. The Medibank Breach (2022) — A Nation’s Medical Secrets Put Up for Ransom
| Attacker | Russia-linked extortionists; Australia sanctioned hacker Alexander Ermakov (allegedly tied to REvil) |
| Target | Medibank — Australia’s largest health insurer |
| Method | Credentials stolen from a third-party IT contractor, lacking MFA |
| Damage | Health data of 9.7 million Australians — roughly a third of the country — dumped online in cruel, sorted leaks |
| Cost | AU$126M+ direct; Australia’s largest privacy class action; nationwide legal reform |
How the attack unfolded
On October 13, 2022, intruders entered the systems of Medibank, Australia’s largest health insurer, using credentials stolen from a third-party IT contractor — a privileged account, unprotected by multi-factor authentication, purchased from an initial-access broker. The intruders spent days escalating and exfiltrating before Medibank detected unusual activity; by then, they held one of the most intimate datasets imaginable: records concerning 9.7 million current and former customers — about 40% of Australia’s population — including hundreds of thousands of health claims for mental-health treatment, addiction care, HIV status, and abortion.
Then came the extortion: roughly $10 million in cryptocurrency. Medibank’s board, on advice, refused to pay — publicly reasoning that paying would fund further attacks on Australians everywhere and that criminals’ promises to delete data are worthless. It was a defensible, even principled, decision. What followed tested the principle’s limits: the attackers — linked to the REvil ecosystem — opened a slow-drip campaign of cruelty on their leak site. They released data in staged batches with names attached, deliberately sorted into lists like “naughty list,” “abortions,” “boozy,” and “addicts,” taunting journalists and victims directly. Australians opened news sites to find their neighbors’ — or their own — most private medical moments exposed. The government called it a weaponization of private health data; regulators called it the gravest privacy failure in Australian history.
Australia responded with unusual aggression. In January 2023, the government used its new cyber-sanctions framework for the first time, naming and sanctioning Alexander Ermakov, a 33-year-old Russian national it assessed as responsible for the intrusion — travel bans, asset freezes, and criminal penalties for anyone dealing with him — alongside a standing AU$10 million bounty for information leading to his identification or conviction (allies, including the US, echoed the attribution). Ermakov, reportedly linked to the REvil ransomware crew, remains in Russia.
The damage
Medibank’s direct costs exceeded AU$126 million (incident response, systems hardening, customer support), before the legal reckoning: Australia’s information commissioner launched what became the country’s landmark privacy case against Medibank (a civil penalty action still before the courts, with theoretical exposure in the hundreds of millions), while a monster class action on behalf of affected customers progressed through the Federal Court. The human damage — counseling demand, shame, fear of seeking care — was immeasurable and, victims’ advocates argued, was precisely the point of the sorted leaks.
Aftermath & lessons
- Australian law changed within weeks: Parliament surged maximum Privacy Act penalties from ~AU$2 million to the greatest of AU$50 million, 3× the benefit gained, or 30% of adjusted turnover. The 2023–2030 Cyber Security Strategy and the Cyber Security Act 2024 followed — including mandatory ransom-payment reporting for critical infrastructure and security standards for smart devices.
- The case became the global reference point in the pay-vs-don’t-pay debate: Medibank’s refusal was praised by governments and devastating for victims — and it proved that when the data is health data, “we won’t pay” has a human cost that no policy paper fully prices.
- Third-party contractor credential hygiene — the actual door — became regulated territory, not just a questionnaire item.
The core lesson: what criminals monetize is not data, it’s shame and fear — and the decision of whether to fund them is now a national-policy question, not just a corporate one.
29. The MOVEit / CL0P Campaign (2023) — Thousands of Organizations, One Zero-Day
| Attacker | CL0P (Clop) — a Russian-speaking extortion gang with suspected FIN11/TA505 roots |
| Targets | Users of Progress MOVEit file-transfer software: governments, banks, airlines, retailers, hospitals, universities |
| Method | Zero-day SQL injection in MOVEit, industrial-scale data theft, extortion without encryption |
| Damage | 2,000+ organizations and ~93–96 million individuals affected |
| Cost | Estimated up to ~$12 billion — the largest ransomware-linked campaign by victim count |
How the attack unfolded
In late May 2023, the extortion gang CL0P quietly weaponized a previously unknown SQL-injection vulnerability (CVE-2023-34362) in MOVEit Transfer — the managed file-transfer appliance enterprises deploy precisely because moving sensitive documents securely is hard. MOVEit installations held tax forms, claims data, payroll files, government records: a data-to-go counter for the confidential economy. CL0P’s exploit installed web shells that let the gang enumerate and bulk-download whatever each victim kept in the system, in a harvesting campaign that ran roughly May 27 into early June.
Then came the twist that defined the event: no encryption at all. CL0P simply mass-listed victims on its leak site and started naming non-payers. It was pure steal-and-extort — the model the gang had rehearsed in earlier campaigns against the Accellion file-transfer product (2021) and GoAnywhere (February 2023), now executed at their largest scale. By their own messaging, the gang had moved to “we only steal information” as a deliberate strategy: less operational risk, same leverage.
The blast radius, cascading through third parties, kept expanding for months as vendors discovered they’d been caught in customers’ and clients’ footprints. The eventual public tally (tracked by Emsisoft and others) surpassed 2,700 organizations directly and indirectly — with roughly 93–96 million individuals whose data was exposed. The marquee names included: Delta Air Lines (via a data-analytics vendor), British Airways and the BBC (via payroll provider Zellis, alongside Boots and Aer Lingus), the US Department of Energy and its contractor network (including national-lab support organizations), state agencies across the US (Oregon’s DMV alone reported ~3.5 million records), federal contractor Maximus (~11 million people’s health-program data), financial giants like Charles Schwab and Putnam Investments, dozens of universities, and government agencies across the US, UK, Canada, and Europe. Whole classes of victims — pension funds, school districts, utilities — discovered their MOVEit instance through their ransom note.
Estimated aggregate losses (response, notification, credit monitoring, downtime, settlements) ran toward $10–12 billion in industry analyses — for a campaign that never encrypted a single file.
The damage
MOVEit 2023 demonstrated the economics of modern extortion at scale: a single zero-day in a single niche product, monetized across thousands of victims simultaneously, with near-zero per-victim cost and no malware footprint to clean up. It also exposed a structural reality: the global economy runs through a long tail of “boring” enterprise appliances — file transfer, HR portals, print servers, ticketing systems — each a concentration point holding data for thousands of organizations.
Aftermath & lessons
- CISA issued an emergency directive for federal agencies and a stream of advisories; Progress patched repeatedly (further CVEs surfaced); breach notifications set records globally. CL0P itself faced no known arrests — the gang operates as one of the most durable franchises in the criminal ecosystem.
- The insurance and legal aftermath (class actions against MoveIT customers, vendors, and Progress itself) is still working through courts, testing liability when your vendor’s product leaks your customers’ data through no action of yours.
- Security teams relearned an inventory lesson with a twist: it’s not just knowing your servers — it’s knowing every third-party product that holds a copy of your data, a category nobody had fully enumerated.
The core lesson: in the steal-only era, the attack surface isn’t your network — it’s every place your data rests, including vendors you forgot you had. And “we only steal” turned out to be more scalable than ransomware ever was.
30. The MGM Resorts Hack (2023) — A $100 Million Casino Takedown by Phone Call
| Attackers | “Scattered Spider” (UNC3944) — a young, Western social-engineering crew — running ALPHV/BlackCat ransomware as an affiliate |
| Targets | MGM Resorts (Sept 10); Caesars Entertainment (late August/early September, disclosed days before) |
| Method | A ~10-minute vishing call to the IT help desk impersonating an employee |
| Damage | ~$100 million quarterly impact; slot machines dark; hotel keys dead; sportsbooks offline |
| Cost | MGM ~$100M + $10M one-time expenses; Caesars reportedly paid ~$15M ransom |
How the attack unfolded
On Sunday, September 10, 2023 — opening weekend of the NFL season, when sportsbooks are fullest — Las Vegas began to malfunction in ways visitors couldn’t believe. MGM Resorts, which operates a dozen of the most famous casino properties on the Strip (Bellagio, MGM Grand, Aria, Mandalay Bay and more), saw systems fail in cascade: slot machines displaying error screens, the MGM app and websites down, digital room keys dead with guests unable to enter rooms, hotel desks reduced to handwritten rate cards and paper folios, casino cages limiting transactions, and sports betting kiosks dark. The outage ground on for days, with full restoration taking nearly two weeks. MGM’s regulatory filings later quantified the blow: roughly $100 million of lost EBITDAR impact, plus about $10 million in one-time technology and legal expenses.
The intrusion vector, reconstructed from the attackers’ own bragging and subsequent reporting, was almost insulting: a phone call. A member of the crew known as Scattered Spider — a loose collective of young (many teenage) hackers from the US and UK, previously behind the 2022 wave of help-desk and MFA-fatigue attacks on Twilio, Cisco, Reddit, Riot Games, DoorDash, Mailchimp and others — looked up an MGM employee on LinkedIn, phoned the IT help desk, and, in roughly ten minutes of confident impersonation (researchers later reproduced the approach; samples of the attackers’ casual, convincing phrasing circulated widely), persuaded an agent to reset credentials and enroll a new device in MFA. The attacker walked out of that call holding the keys: identity-provider access, then privilege escalation through MGM’s identity stack and admin tooling, and finally ALPHV/BlackCat ransomware (run by the crew as affiliates of the Russia-based RaaS) encrypting VMware ESXi hypervisors and backend infrastructure. Caesars, hit a week or two earlier through a similar social-engineering path, had quietly paid — reportedly around $15 million of a $30 million demand — to avoid exactly the outage MGM then suffered.
MGM declined to pay the ransom, restored from backups and rebuilds (with help from Mandiant and others), and filed its SEC 8-K disclosures — this being the first mega-incident after the SEC’s new four-business-day material-incident disclosure rule took effect in December 2023 (MGM’s initial filings and timing drew their own scrutiny). Then a darkly comic coda: ALPHV, after taking MGM’s non-payment, allegedly exit-scammed its own affiliate — keeping ransom proceeds and stiffing Scattered Spider — prompting the crew to resell MGM’s stolen data on RansomHub’s forum out of spite. Crime, it turns out, has payroll disputes too.
The damage
Beyond the nine-figure financial hit and the surreal scenes of manual Vegas, the attack moved markets in security spending: the help desk — the humblest team in IT — was revealed as a privileged-access gateway to a $20 billion enterprise. Scattered Spider’s later campaigns (they resurfaced against retailers and insurers in 2024–2025, and US arrests finally began, including of a 17-year-old in the UK and several US-based members) kept the lesson current.
Aftermath & lessons
- CISA and the FBI issued joint advisories on help-desk social engineering, recommending identity-proofing for resets, manager callbacks, device/geolocation anomaly detection, and phishing-resistant MFA for privileged accounts — controls that became insurance requirements overnight.
- The case joined Colonial, Change Healthcare, and Snowflake (this part) as the definitive argument for FIDO2/passkeys and hardware keys everywhere — push approvals and SMS are the defeated generation.
- It also stress-tested the SEC disclosure era: investors and regulators now watch the 8-K as closely as the outage.
The core lesson: your identity infrastructure is your castle, and your help desk is its front gate. Every authentication flow — including human-to-human ones — must assume the caller is the adversary.
31. The Change Healthcare Ransomware Attack (2024) — America’s Pharmacy System Frozen
| Attacker | ALPHV/BlackCat ransomware operation (affiliate), then re-extortion by RansomHub |
| Target | Change Healthcare, a UnitedHealth Group unit processing ~half of all US medical claims |
| Method | Stolen credentials on a Citrix remote-access portal that lacked MFA |
| Damage | Weeks of nationwide claims paralysis; ~$3B+ in costs; a $22M ransom; data of ~190 million people |
| Cost | Largest healthcare data breach in US history; existential strain on independent pharmacies |
How the attack unfolded
On February 21, 2024, ransomware detonated inside Change Healthcare — a company most Americans had never heard of, and which the American healthcare system cannot function without. A subsidiary of UnitedHealth Group, Change operates the clearinghouse through which roughly half of all US medical claims flow, connecting pharmacies, insurers, hospitals, and doctors for prescriptions, eligibility checks, prior authorizations, and payments. When its systems went down, the entire payment nervous system of American healthcare went dark with them.
The entry, per UnitedHealth CEO Andrew Witty’s sworn Senate testimony (May 1, 2024), was an unpatched tragedy in two parts: attackers logged into a Citrix remote-access portal that did not have multi-factor authentication enabled, using credentials that had been compromised and offered for sale by an initial-access broker. Nine days after entry, the affiliate deployed ALPHV/BlackCat ransomware across Change’s estate. UnitedHealth isolated the environment — disconnecting Change from its parent and customers — and America’s pharmacies began the strangest weeks in their history: prescriptions could be filled, but claims couldn’t be adjudicated. Pharmacies handed out medications on trust, floating costs on credit; cash-flow dried up for providers nationwide; emergency instructions flew from insurers (paper claims, waived prior auths); UnitedHealth ultimately advanced billions of dollars in interest-free loans to keep providers solvent. Independent pharmacies, living on 2–3% margins, described the event as an extinction-level threat; surveys found many considering closure. Restoration of core services took weeks, with full recovery stretching into months.
Then the sordid economics: UnitedHealth paid the affiliate’s operator a $22 million bitcoin ransom (the payment leaked via the gang’s own infrastructure screenshots, and Witty confirmed paying under oath — while declining to fully detail it). In a twist of criminal treachery worthy of a sequel, ALPHV then exit-scammed its own affiliate — taking the $22 million, staging a shutdown, and stiffing the affiliate who did the work. The affiliate, holding the stolen data, re-approached UnitedHealth under the RansomHub brand for a second extortion; reporting indicates a second payment was made, unconfirmed in amount. The data itself was the final horror: personal and health information of approximately 190 million people — nearly two-thirds of American adults — ultimately disclosed in the breach notification process, the largest healthcare data breach in US history and among the largest of any kind ever.
The damage
UnitedHealth’s 2024 cyber-related costs exceeded $3 billion (business disruption, response, advances — before legal exposure, which includes a sprawling class-action consolidated in Minnesota and state AG actions). The Senate Finance Committee’s staff report was unsparing: the breach was “preventable,” resting on absent MFA, unsegmented architecture, and a single point of failure the whole system had accepted without noticing. The hearing itself became a referendum on vertical integration: how did one company come to sit in the payment path of half of American healthcare — and what does it mean that one password froze it?
Aftermath & lessons
- The healthcare sector’s regulators (HHS/OCR) opened investigations and pushed new resilience expectations; hospital systems and pharmacy chains launched redundancy programs; “concentration risk” entered the regulatory vocabulary of American healthcare.
- The MFA mandate — again, the same missing control as Colonial Pipeline — completed its journey from “best practice” to “moral obligation” in the industry’s mind; CISA and HHS published joint alarms on initial-access brokers and remote-access portals.
- The ALPHV→RansomHub saga also clarified the criminal supply chain: initial-access broker → affiliate → RaaS operator → exit scam → successor brand. Disrupting “the gang” means disrupting a market.
The core lesson: the biggest breach in healthcare history didn’t need a zero-day — it needed one unauthenticated portal — and it proved that in a system optimized for efficiency, resilience is the security control nobody priced. When everything routes through one node, protecting that node is national security.
32. The Snowflake Customer Breaches (2024) — 560M Ticketmaster Records, 109M AT&T Call Logs
| Attackers | UNC5537 — a financially motivated crew (arrests in Canada and Turkey; US charges pending/ongoing) |
| Targets | Corporate customers of the Snowflake cloud data-warehouse who hadn’t enabled MFA |
| Method | Infostealer-harvested passwords replayed against cloud accounts lacking MFA |
| Damage | Ticketmaster (~560M records), AT&T (~109M customers’ call metadata), Santander, Neiman Marcus, Advance Auto Parts, LendingTree and more |
| Cost | AT&T reportedly paid ~$370K to delete its data; ~165 organizations potentially exposed |
How the attack unfolded
In the spring of 2024, a new attack pattern crystallised — and it contained no exploit at all. Attackers tracked as UNC5537 (Mandiant’s designation) — a crew including young hackers in North America and Turkey — simply assembled credentials stolen by infostealer malware: the ubiquitous trojans that silently scrape saved passwords from victims’ browsers. Corporate employees’ Snowflake console credentials were sitting in criminal logs, sometimes years old but never rotated. Where those Snowflake tenants hadn’t enforced multi-factor authentication, the attackers logged straight into some of the world’s best-known companies’ cloud data warehouses — and copied everything.
Snowflake itself was never “breached” — no flaw in its platform, no compromise of its systems. Its customers’ identities were the vulnerability. Mandiant assessed around 165 customer organizations were potentially exposed; the crew and associated data brokers (aliases like “Sp1d3r” and “Judische” became infamous) monetized via sale listings and extortion on criminal forums.
The roll call was staggering. Ticketmaster/Live Nation (confirmed May 31, 2024 in an SEC filing): data on 560 million customers — names, addresses, phone numbers, emails, partial payment-card details, and ticket-order histories (including Taylor Swift Eras Tour transactions, which turned the story into a pop-culture event) — listed for $500,000. AT&T (confirmed July 12, 2024): call and text detail records — metadata of who contacted whom, when, for how long, but not contents — for nearly all of its ~109 million mobile customers across May–October 2022 and January 2023, plus some landline interactions. The disclosure itself required Department of Justice review, because call metadata at that scale is a national-security matter: Washington Post reporting indicated the stolen set included numbers associated with prominent political figures, including then-candidate Donald Trump and JD Vance, their families, and government officials — a theft with obvious intelligence value. AT&T, notably, reportedly paid about $370,000 to the crew to delete the data — a payment never confirmed by the company, but reported in detail by Wired from sources including the hackers themselves.
Further victims streamed in through the summer: Santander (employees and some customers in Chile, Uruguay, and Spain), Neiman Marcus and Bergdorf Goodman (~31 million customer records), Advance Auto Parts (~79 million rows exposed in a leak forum posting), LendingTree’s QuoteWizard, Pure Storage, and others. In October–November 2024, arrests followed: Canadian police arrested Alexander Moucka in Kitchener, Ontario (awaiting extradition to the US on related charges), and Turkish authorities detained two suspects in Istanbul.
The damage
By raw records, the Snowflake campaign was among the largest data exposures in history — hundreds of millions of individuals across a handful of famous brands, plus a national-security scare over telecom metadata. For the industry, it also forced an awkward conversation: every victim was a sophisticated enterprise with a security budget; every breach traced to one employee’s infected browser plus no MFA. The “perimeter,” it turned out, had quietly moved to each user’s laptop — and to criminal marketplaces where its contents were already for sale.
Aftermath & lessons
- Snowflake responded by pushing (and later mandating) MFA across its customer base and releasing hardened-security guidance; the episode became the definitive case for enforcing phishing-resistant MFA on every cloud tenant, no exceptions, including service and admin accounts.
- The campaign mainstreamed infostealer-log monitoring: enterprises now treat “are our credentials in criminal datasets?” as a first-class detection problem — buying stolen-credential intelligence the way they once bought antivirus signatures.
- The AT&T episode re-ignited the debate over metadata retention: information companies keep “just in case” (who called whom, years back) became a strategic liability and a target.
The core lesson: the cloud didn’t move the goalposts — it highlighted them. Your tenant is only as safe as the weakest identity that can reach it, and the password for that identity may already be for sale. MFA isn’t a feature; it’s the floor.
33. The XZ Utils Backdoor (2024) — The Near-Miss That Terrified the Internet
| Attacker | Unknown — a patient, state-grade actor operating the alias “Jia Tan” (never identified) |
| Target | XZ Utils — a tiny open-source compression library embedded in nearly every Linux system |
| Method | A multi-year trust-building campaign to become a project maintainer, then a nearly invisible backdoor in the build process |
| Damage | None — caught weeks before it could have compromised SSH on millions of servers worldwide |
| Cost | A global emergency audit and a permanent reckoning for open-source sustainability |
How the attack unfolded
The most chilling attack of the modern era is the one that failed — by a margin of weeks and one engineer’s curiosity.
XZ Utils is a free, open-source compression library maintained for years largely by one volunteer, Lasse Collin, doing unpaid work that the entire digital world depends on: xz compresses data inside countless Linux distributions, and via its linkage to systemd on major distros, it sits adjacent to OpenSSH — the secure-login server running on effectively every Linux machine on Earth.
Around 2021-2022, a new contributor appeared: helpful, competent, friendly, going by “Jia Tan.” Over two-plus years, the persona (almost certainly one actor or a small team) submitted good patches, earned gratitude, and — assisted by a chorus of sockpuppet accounts that appeared, notably, to pressure and guilt the exhausted maintainer about slow releases and ask whether more help was needed — gradually assumed co-maintainer, then release-manager control of the project. It was social engineering at institutional scale: not a phone call to a help desk, but a years-long campaign to become the trusted colleague of a man doing the internet’s unpaid maintenance work.
Then, in early 2024, came the strike. Releases 5.6.0 and 5.6.1 (February–March 2024) shipped with innocent-looking additions: new test files with quirky names. Those files, however, contained deliberately corrupted data that the build process — under very specific conditions used by major Linux distributions (x86-64 Linux, gnu toolchain, integration with systemd’s sshd linking) — silently used to inject a backdoor into the compiled liblzma library. The backdoor hooked into SSH server authentication, such that an attacker holding a specific cryptographic key could send crafted certificates and achieve remote code execution as root — before authentication — on any affected server. No exploit traffic, no malware signature, no anomalous logs: just mathematically crafted input, recognized by the backdoored library, opening the door. It was, in the words of many researchers, the most sophisticated supply-chain attack ever discovered in the wild.
The margin of failure was almost providential. On March 29, 2024 — a Good Friday — Microsoft engineer Andres Freund, investigating performance anomalies, noticed that SSH logins on a Debian testing system were consuming about half a second more CPU than they should, and that valgrind diagnostics flagged errors in liblzma. Pulling the thread over a weekend, he traced the latency to a hidden obfuscated stage in xz’s build, documented the backdoor, and raised the alarm. Distros rolled back within hours. The internet had, by days or weeks, avoided shipping the backdoor into Ubuntu 24.04 LTS, Debian stable, and Fedora releases that would have propagated it onto millions of servers, workstations, and containers — from which it could never have been fully recalled.
The aftermath was a fever of forensics. GitHub (which suspended the xz repository to preserve evidence) and researchers reconstructed “Jia Tan’s” years: the sockpuppets, the pressure campaign, the meticulously clean commit history, the insertion of test infrastructure months earlier to make the malicious files look routine. No government formally attributed the operation; informed observers broadly assume a state intelligence service with rare patience and discipline. “Jia Tan” — whoever or whatever it was — vanished.
The damage (averted)
Had it landed, the plausible scenario was breathtaking: pre-auth root access to a substantial fraction of the world’s Linux servers — cloud infrastructure, banks, governments — with near-zero detection probability. As it stands, the “damage” is the mirror it held up: the global economy’s foundations include critical software maintained by one tired person, for free — and patient adversaries have noticed.
Aftermath & lessons
- A wave of investment followed in open-source sustainability and supply-chain security: maintainer funding (Sovereign Tech Fund-style investments exploded), identity verification for critical projects, build provenance and reproducible builds, and commit-level audit tooling. The OpenSSF and governments (including a US-commissioned open-source security roadmap) accelerated programs directly motivated by xz.
- Distributions re-examined trust models for upstream projects: more eyes on critical-path dependencies, reducing maintainer single points of failure, and treating “who can commit?” as a top-secret-grade question.
- The detection story became legend — not a mega-vendor, but one engineer’s noticing of 500 milliseconds — and entered security culture as the ultimate argument for curiosity, telemetry, and the irreducible value of humans in the loop.
The core lesson — and the series’ last: the next great attack isn’t necessarily against technology; it’s against trust — the maintainer’s, the help desk’s, the vendor’s, the certificate authority’s. Every era in this series ended with the same discovery in a new costume: systems fail at their human trust points. Defending those points — with verification, transparency, redundancy, and funded humans — is what the next thirty-five years of security must get right.
← Back to the full list: The 33 Biggest Cyberattacks in History
