SVB’s Collapse: When Banking Becomes a Security Problem
SVB’s March 2023 run froze payroll for half of venture-backed tech and minted a fraud wave targeting displaced customers. Treasury continuity lessons.
SVB’s March 2023 run froze payroll for half of venture-backed tech and minted a fraud wave targeting displaced customers. Treasury continuity lessons.
LockBit encrypted Royal Mail’s international sorting operations in January 2023 and demanded $80M. Royal Mail paid nothing and kept the letters moving.
The SEC’s June 2023 suits against Binance and Coinbase charged unregistered securities operations at crypto’s two biggest exchanges — a custody and platform-risk story wearing legal clothing.
Operation Cookie Monster seized the market selling browser sessions, cookies, and saved credentials for ~2M identities, with 119 arrests across 17+ countries. Session-security lessons.
Reused passwords took over 14,000 23andMe accounts, then the DNA Relatives feature amplified the access into profile data for 6.9 million genetically-linked users. The October 2023 breach rewrote breach math: your exposure now includes every relative’s password hygiene.
ChatGPT landed November 30, 2022 and hit 100M users in two months — and immediately made prompt injection a practical attack class. Still unsolved in 2026.
On June 19, 2024, ransomware hit CDK Global’s dealer management platform — the operational nervous system of ~15,000 North American dealerships — and a second strike during recovery extended the outage for weeks while finance desks, service bays and OEM ordering reverted to paper and fax. This account covers the June 19/22 double-hit timeline, the billion-dollar industry loss estimates, why DMS lock-in made fallback manual rather than competitive, and the concentration-risk docket the incident left for every regulator to cite.
Criminals entered Medibank via a contractor’s VPN credentials on a gateway without MFA, then dumped 9.7M customers’ health data after the ransom refusal.
On August 24, 2024, French authorities arrested Telegram founder Pavel Durov at Le Bourget airport, and two days later charged him with complicity in organized-crime offenses enabled by his platform’s refusal to cooperate with legal process — the first time a major encrypted-service executive faced criminal liability for governance choices. Released under judicial supervision within days, Durov’s case forced every platform lawyer to reprice jurisdictional arbitrage, moderation staffing, and the meaning of cooperation. This account lays out the charges, the encryption-policy fault lines, and the compliance playbook that followed.
On July 19, 2024, a routine sensor configuration update from CrowdStrike passed staged testing and rolled through the Falcon channel to roughly 8.5 million Windows hosts — and crashed them into Blue Screens of Death, grounding flights, halting broadcasters and hospitals in the largest IT outage in history. This account reconstructs the flawed content-deployment pipeline, the Channel File 291 logic that sent the kernel into chaos, the 78-minute Remediation and guidance HHCfollows, the blame theater that followed, and why the incident rewrote every argument about single-vendor concentration risk.
February 2024’s Operation Cronos seized LockBit’s infrastructure across a dozen countries — and then the leaks showed how long the FBI had been inside. This account covers the covert access, the sting timing driven by UK hospital targeting, the servers and affiliate accounts taken down, the hurried rebrand to LockBit 4.1, the affiliate diaspora to RansomHub and Akira, and the awkward questions the takedown’s trolling raised about reading crime statistics.
On 13 November 2023, DP World Australia disconnected its port systems from the internet to contain an intrusion — and container operations at Sydney, Melbourne, Brisbane and Fremantle stopped cold, stranding roughly 30,000 containers for three days. Operations resumed by 16 November, personnel data exposure was later confirmed, and no ransom payment was disclosed. The episode became Australia’s reference case for cyber-driven supply-chain disruption and a model of disciplined containment, rapid restoration and honest capacity communication under SOI-Act scrutiny.