patch&proof.
← Field manual

History / Field guide

Seven years that changed cybersecurity: 2019 to 2026

Every piece of current security advice came from a specific failure. Here are the incidents between 2019 and 2026 that produced the rules everyone now follows.

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Nearly every piece of security advice you'll encounter today was written in response to something that went wrong. Phishing-resistant authentication exists because teenagers social-engineered their way into Microsoft and Okta. Backup immutability exists because ransomware crews started deleting backups first. Software supply-chain security exists because one compromised update reached 18,000 organizations.

Knowing the failure makes the control make sense. Here's the seven-year arc.

2019: extortion learns to publish

Ransomware existed long before 2019, but in November of that year a group called Maze published a victim's stolen data for the first time. That single move changed the economics of the entire crime permanently.

Until then, the defence against ransomware was backups. If you could restore, you didn't need to pay. After Maze, attackers stole the data before encrypting it, so refusing to pay meant your data got published anyway. Backups stopped being a complete answer.

The same year, Norsk Hydro was hit and did something unusual: it refused to pay, ran its aluminium plants on manual control, and published its recovery in near real time. It remains the reference case for handling a crisis in public.

2020: the perimeter retires, and the supply chain opens

In March, COVID moved the workforce home in a matter of weeks. Organizations that had planned multi-year remote access programmes executed them in days. The corporate network — the thing security had been built around defending — stopped being where the work happened. It never came back.

Then in December, SolarWinds. A nation-state actor compromised the build system of a network monitoring product and shipped a backdoored update to around 18,000 customers. The specific victims mattered less than the idea: the software you buy, and the pipeline that builds it, is part of your attack surface.

Everything now sold as software supply chain security traces to that December.

2021: ransomware becomes a national security problem

Colonial Pipeline, in May, was the moment the general public noticed. A ransomware attack led to a precautionary shutdown that halted fuel distribution across the US East Coast, and produced panic-buying. The way in was a legacy VPN account without multi-factor authentication.

Five days later, the US president signed an executive order that reshaped federal security requirements for years. Then JBS hit meat processing, Kaseya cascaded through managed service providers into their customers over a holiday weekend, and Log4Shell closed the year with a trivially exploitable flaw in a logging component embedded almost everywhere.

Also in 2021, quietly: CISA created the Known Exploited Vulnerabilities catalog, which changed how the whole industry prioritizes patching. Instead of chasing severity scores — thousands of critical-rated flaws, most never actually used — the question became "is anyone actually exploiting this?" (That model was itself revised in June 2026; see the regulation tracker (planned reference; not yet available).)

2022: identity becomes the battleground

A group called Lapsus$, largely teenagers, worked their way into Nvidia, Samsung, Microsoft and Okta. They didn't use novel exploits. They used social engineering, SIM swapping, and sheer persistence with authentication prompts.

The official review that followed concluded that a loose group of teenagers had defeated mature enterprise defences, condemned text-message and voice-call MFA, and told the industry to move to hardware-backed authentication. That recommendation shaped the next four years.

The same year, an insider leaked the internal chats of the Conti ransomware group — salaries, management structure, HR complaints, negotiation playbooks. It was the clearest look anyone has had at a ransomware business from the inside.

And in May, Apple, Google and Microsoft jointly committed to passkeys, which is why you're now being offered them everywhere.

2023: mass exploitation, and the cloud's crown jewels

MOVEit was the year's defining event: one flaw in a file-transfer product used by thousands of organizations, exploited at scale, producing more than 2,700 victim organizations and roughly 95 million affected individuals (tallies compiled by Emsisoft and KonBriefing) — almost entirely through data theft, with no encryption at all.

It proved that extortion without ransomware works, and that a single vendor's flaw can produce a breach event for a meaningful slice of an economy.

Then in September, attackers phoned the IT help desks at MGM Resorts and Caesars. Caesars paid around $15M. MGM didn't, and absorbed roughly $100M in losses per its own regulatory filings and days of operational chaos. "Verify the identity of the person calling for a password reset" became a product category.

2024: single points of failure

Change Healthcare in February is the most consequential breach in this entire list. Attackers entered through a remote access portal that lacked multi-factor authentication and halted medical claims and pharmacy processing across much of US healthcare for weeks. Around 193 million people were affected, per the breach total filed with US health regulators. UnitedHealth reported costs near $2.9 billion. A $22 million ransom was paid, after which the criminal group defrauded its own affiliate and vanished.

One missing control, at one access point, in one company that much of an industry depended on.

In March, the XZ Utils near-miss: a patient multi-year social-engineering campaign against an exhausted volunteer maintainer nearly placed a backdoor into the remote-access path of most Linux systems worldwide. It was caught by one engineer who noticed something was running slightly slowly. The vulnerability wasn't in the code — it was in the trust model.

And in July, CrowdStrike's own update crashed roughly 8.5 million Windows machines — Microsoft's own estimate. Not an attack. But it established that the security software itself is an operational risk that needs staged rollouts and recovery plans.

2025: social engineering at industrial scale

Help-desk manipulation came to UK retail, taking M&S offline at a company-estimated £300 million cost to profit. Co-op, hit by the same crew, pulled its own systems offline mid-intrusion — a decision that worked, and one worth studying.

Salesloft Drift showed the next frontier: attackers stole authentication tokens from a chatbot integration and used them to export data from more than 700 organizations' customer databases, including several major security vendors. The apps you connect to your systems are a supply chain you probably haven't inventoried — see the 2026 threat landscape for how far that has shifted.

And Jaguar Land Rover lost five weeks of global production, booked a £196 million charge, and prompted a £1.5 billion government loan guarantee to keep its suppliers solvent. The UK's Cyber Monitoring Centre estimated the wider economic impact at around £1.9 billion — the most damaging cyber event in UK history.

2026 so far: the tooling itself, and two opposing rulebooks

The attack surface moved another layer up. Compromises at Trivy, Checkmarx and Bitwarden reached users through the developer tools themselves — including, in several cases, the tools whose job is scanning for vulnerabilities.

At Stryker, an attacker abused the company's device-management platform to wipe thousands of endpoints. That platform exists to push software to every machine at once, which is exactly what makes it the highest-value target in a modern company.

And at Klue, a single API credential created in 2022 for a prototype that never launched — still valid four years later — exposed data belonging to roughly 200 downstream companies, including a dozen mature security firms. Credentials outlive the projects that create them.

Meanwhile regulation moved in two directions at once: the US rescinded several federal security mandates while the EU's Cyber Resilience Act came into force. Multinationals are now on two clocks.

What the seven years actually taught

The attacks that work are rarely sophisticated. A phone call, a missing MFA exception, a credential nobody revoked.

Your suppliers are your attack surface. Third parties were involved in roughly half of breaches in Verizon's 2026 report — 48%, up 60% year on year.

Backups need to be immutable and tested, because attackers go after recovery capability first.

Paying is losing its appeal. The share of ransomware victims who pay has fallen from roughly 70% in 2020 to under 28% in 2025, according to Chainalysis and Coveware data — better backups, harder legal exposure, and six years of evidence that paying often doesn't work.

And rules reverse. Six significant policy positions established between 2021 and 2024 were undone between 2025 and 2026. Anything you read about compliance needs a date on it.


What to do next: Pick the one control from this history that your organization is missing, and fix that. For most readers it's phishing-resistant MFA or a tested restore. Minimum viable security will tell you which.

Related: The 2026 threat landscape · Minimum viable security · Ransomware: attacks up, payments down · Which framework do you need?

Sources: Chainalysis Crypto Crime Report 2026 (Feb 2026) — ransom payment totals and payment rates. Verizon 2026 DBIR — third-party breach involvement. Mandiant M-Trends 2026 (Mar 2026) — dwell time and intrusion vectors. CISA advisories and the KEV catalog. Cyber Safety Review Board reports on Log4j (Jul 2022), Lapsus$ (Aug 2023) and Storm-0558 (Apr 2024). UK Cyber Monitoring Centre — M&S, Co-op and Jaguar Land Rover impact estimates. Emsisoft and KonBriefing — MOVEit victim tallies. Company disclosures for Change Healthcare, MGM Resorts, Caesars and Jaguar Land Rover.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval