Research date: September 15, 2026. A reference timeline built from three dedicated historical research streams (~50,000 words of sourced material) covering incidents and threat evolution, policy and standards, and defensive technology and markets. Defensive and educational framing throughout; incidents are described by what happened and what changed, not by how they were carried out.
How to use this document
This is the historical spine for the site. Three things it is designed to do:
Give the present tense a past. Almost every current practice — phishing-resistant MFA, KEV-driven patching, SBOM, immutable backups, zero trust — has a specific origin in a specific failure. Readers retain the control when they know the incident that produced it.
Show direction, not just position. A single-year statistic tells you where things are. The seven-year series tells you where they are going, which is the more useful thing for anyone making a decision.
Demonstrate that things reverse. Six significant policy positions established in this window were reversed within it. Compliance guidance written in 2023 may describe obligations that no longer exist. That is a teaching point in itself, and it is why every page on the site carries a date.
Part 1 — The eight-year arc in one page
| Year | The defining shift |
|---|---|
| 2019 | Extortion learns to publish. Maze invents double extortion in November. Municipal ransomware (Baltimore, Atlanta) makes local government a target class. Capital One shows cloud misconfiguration at scale. |
| 2020 | The perimeter retires. COVID moves the workforce home in weeks. SolarWinds, disclosed in December, makes the build system an attack surface and resets the supply-chain threat model. |
| 2021 | Ransomware becomes national security. Colonial Pipeline causes fuel shortages; JBS hits the food supply; Kaseya cascades through MSPs. Executive Order 14028 follows Colonial by five days. Log4Shell closes the year. |
| 2022 | Identity becomes the battleground. Lapsus$ teenagers defeat mature enterprises with social engineering. Conti's internal leaks expose the criminal org chart. MFA fatigue and attacker-in-the-middle defeat push and OTP. |
| 2023 | Mass exploitation and the cloud's crown jewels. MOVEit hits 2,700+ organizations through one file-transfer flaw. Storm-0558 reaches US officials' email. MGM and Caesars fall to help-desk phone calls. LLMs arrive. |
| 2024 | Single points of failure. Change Healthcare halts US claims processing. CrowdStrike's own update crashes 8.5 million machines. XZ Utils is caught by luck. Snowflake tenants fall to credentials without MFA. |
| 2025 | Social engineering at industrial scale. UK retail, Salesloft Drift's 700-organization OAuth cascade, F5's source-code theft, Jaguar Land Rover's five-week shutdown. Regulation begins to reverse in the US. |
| 2026 | Identity, supply chain, and the deregulatory turn. Developer tooling compromised at the build layer. Destructive attacks return to European infrastructure. US federal mandates are rescinded while EU instruments come into force. |
Part 2 — Year by year
2019 — The year extortion learned to publish
The incidents that mattered. Norsk Hydro (March) refused to pay LockerGoga, ran aluminium plants on manual control, and published its recovery openly — the first major demonstration that transparency and refusal were survivable, and still the reference case for BC/DR communications. Capital One (disclosed July) exposed roughly 100 million records through a cloud misconfiguration, making "the customer's side of shared responsibility" concrete. Baltimore (May) and the municipal wave made local government a target class and exposed how little recovery capacity it had. Travelex (New Year's Eve) began a months-long outage that nearly sank the company.
The structural change. In November 2019, Maze published a victim's data for the first time. Double extortion — steal, then encrypt, then threaten to publish — changed the economics permanently. Backups stopped being a complete answer, because the leverage was no longer only availability. Every subsequent development in the ransomware economy descends from this.
Also in 2019: Gartner coined SASE in August, naming an architecture that would not be needed urgently for another seven months.
2020 — Remote work and the supply chain
COVID as an inflection. Within weeks, organizations that had planned multi-year remote-access programs executed them in days. Gartner's own segment data captures the shift: cloud security spending rose over 33% in a single year while network security hardware fell nearly 13%. The temporary became permanent — the perimeter model never came back.
Twitter (July) showed that a phone call to the right employee could reach the administrative tooling behind 330 million accounts, three years before Scattered Spider industrialized the same idea.
SolarWinds / SUNBURST (disclosed December 13). A nation-state actor compromised the build system of a network monitoring product and distributed a backdoored update to roughly 18,000 organizations. The specific victims mattered less than the conceptual change: the software you buy, and the pipeline that builds it, is part of your attack surface. SBOM, SLSA, Sigstore, provenance attestation, build-runner isolation, and the entire supply-chain security industry trace to this event.
Also in 2020: NIST published SP 800-207 in August, arbitrating what "zero trust" meant after years of vendor definition-shopping.
2021 — Ransomware becomes a national security problem
Microsoft Exchange / ProxyLogon (March). Mass exploitation of on-premises Exchange, attributed to Hafnium, moved from targeted espionage to indiscriminate web-shell deployment in days once the flaws were public. It established the pattern — patch release as starting gun — that would define the edge-device era.
Colonial Pipeline (May 7). DarkSide ransomware caused a precautionary IT shutdown that halted fuel distribution across the US East Coast, producing panic-buying and shortages. The entry was a legacy VPN account without MFA. Five days later, President Biden signed Executive Order 14028 — the most consequential single cybersecurity document of the period.
JBS (May) hit meat processing. Kaseya VSA (July 2) cascaded through managed service providers into their customers over a US holiday weekend, demonstrating MSP concentration risk. Log4Shell (December 9) ended the year with a trivially exploitable flaw in a logging library embedded nearly everywhere, and the Cyber Safety Review Board would later call it an "endemic vulnerability" expected to persist for a decade.
The policy response. EO 14028 triggered SBOM minimum elements (July 2021), the federal zero-trust strategy, secure software attestation, and the CSRB. In November, BOD 22-01 created the KEV catalog — replacing "severity" with "evidence of exploitation" as the prioritization trigger, and arguably the most influential artifact CISA ever produced.
2022 — Teenagers, leaks, and the identity perimeter
Lapsus$ ran a spree against Nvidia, Samsung, Microsoft, Okta and others using social engineering, SIM swapping, and MFA fatigue rather than novel exploits. The CSRB's review concluded that a loosely organized group of mostly teenagers had defeated mature enterprise defenses, condemned SMS and voice MFA, and recommended the industry move to FIDO. That recommendation shaped the next four years of authentication guidance.
Conti's collapse (February–May). After the group declared support for Russia's invasion of Ukraine, an insider leaked its internal chats — exposing salaries, management structure, HR practices and negotiation playbooks. It was the clearest public view ever obtained of a ransomware business, and it fragmented the ecosystem.
Uber and Rockstar (September) fell to MFA-fatigue and social engineering by the same milieu. LastPass (August and December) demonstrated that encrypted vault theft is a slow-motion breach: vaults exfiltrated in 2022 were still being cracked years later, with consequences for anyone whose master password was weak.
The authentication turning point. On May 5, 2022, Apple, Google and Microsoft jointly committed to multi-device FIDO credentials — the announcement that made passkeys a platform feature rather than an enterprise project.
Also in 2022: the DOJ's good-faith security research charging policy (May 19) and Joe Sullivan's conviction (October 6) — the former protecting researchers, the latter establishing that a security executive can face personal criminal liability for concealing a breach.
2023 — Mass exploitation and the cloud's crown jewels
MOVEit (from May 27). Cl0p exploited a file-transfer product used by thousands of organizations and, over months, claimed more than 2,700 victim organizations and roughly 95 million individuals — almost all through pure data theft with no encryption. It was the template for exfiltration-only extortion at industrial scale, and it demonstrated that one vendor's flaw could produce a breach event for a substantial share of an economy.
Storm-0558 (disclosed July). A Chinese actor forged authentication tokens to reach the email of US officials. The CSRB's April 2024 report called the intrusion "preventable," the result of "a cascade of avoidable errors," and Microsoft's security culture "inadequate and requiring an overhaul" — an unprecedented finding that is widely credited with triggering Microsoft's Secure Future Initiative.
MGM and Caesars (September). Scattered Spider called IT help desks. Caesars paid roughly $15M; MGM did not and absorbed roughly $100M in losses plus days of operational chaos. Help-desk identity verification became a product category.
The policy peak. The National Cybersecurity Strategy (March 2) proposed shifting the security burden onto the organizations best placed to bear it, explicitly contemplating software liability. The SEC adopted cyber disclosure rules in July. This was the high-water mark of US regulatory ambition in the period.
Also in 2023: ChatGPT's late-2022 release began producing security consequences throughout 2023 — better phishing, new data-leakage paths, and the first serious work on securing LLM applications.
2024 — Edge devices, single points of failure, and a near-miss
Change Healthcare (February). ALPHV entered through a Citrix portal without MFA and halted claims and pharmacy processing across much of US healthcare for weeks. Roughly 193 million people affected — the largest US healthcare breach — with UnitedHealth costs near $2.9B and a $22M ransom paid, after which the group exit-scammed its own affiliate. It is the definitive case for two lessons: a single missing control at a single access point, and vendor concentration as systemic risk.
XZ Utils (March 29). A multi-year social-engineering campaign against an open-source maintainer nearly placed a backdoor into the SSH path of most Linux distributions. It was caught by one engineer investigating a performance anomaly. The vulnerability was the trust model, not the code, and it triggered a serious reckoning about open-source maintainer sustainability.
The Snowflake campaign (April–July). Infostealer credentials, some years old, unlocked roughly 165 customer tenants that lacked MFA. No platform breach — entirely the customer's side of shared responsibility.
CrowdStrike (July 19). A faulty content update crashed roughly 8.5 million Windows machines worldwide. Not an attack, but the event that turned the security agent itself into a governance problem: staged deployment, N-1 rings, and recovery runbooks became standard expectations, and it accelerated the move of security agents out of the Windows kernel.
Also in 2024: NIST CSF 2.0 (February 26) added the Govern function and broadened scope beyond critical infrastructure; FIPS 203/204/205 (August 13) made post-quantum cryptography an operational programme rather than a research topic; and Salt Typhoon surfaced in the autumn.
2025 — Social engineering at industrial scale, and the regulatory turn
The UK retail wave (April–May). Help-desk social engineering produced DragonForce ransomware at M&S, with a company-estimated £300M profit impact. Co-op pulled its own systems offline mid-intrusion — a containment decision worth teaching, because it worked. The Cyber Monitoring Centre put combined losses at £270–440M.
Salesloft Drift (August). Stolen OAuth tokens for a chatbot integration allowed bulk export of Salesforce data from more than 700 organizations, including Cloudflare, Zscaler and Palo Alto Networks. SaaS-to-SaaS integrations were revealed as an unmanaged supply chain.
F5 (disclosed October 15). A nation-state actor held long-term access to F5's product development environment and stole BIG-IP source code and undisclosed vulnerability details. CISA issued an emergency directive. The security vendor's own development environment is part of the customer's attack surface.
Jaguar Land Rover (from August 31). A five-plus-week production shutdown, a £196M direct charge, roughly £1.9B in estimated UK economic impact, and a £1.5B government loan guarantee to stabilize the supply chain — assessed as the UK's most economically damaging cyber event.
Shai-Hulud (September, again in November). A self-replicating worm compromised hundreds of npm packages, harvesting developer tokens and cloud keys and republishing itself. Registry hardening — trusted publishing, provenance, mandatory maintainer MFA, short-lived tokens — accelerated sharply.
The policy reversal begins. EO 14306 (June 6) rewrote the previous administration's second cyber executive order, striking software attestation and digital identity provisions while keeping post-quantum deadlines. The CSRB had been disbanded in January, terminating its in-progress Salt Typhoon review, which was never published. On September 30, the Cybersecurity Information Sharing Act of 2015 lapsed (later extended, most recently to 11 December 2026), removing the liability protections underpinning a decade of threat sharing. In November the SEC dismissed its SolarWinds case with prejudice.
2026 to date — Identity, supply chain, and two opposing regulatory clocks
The developer-tooling wave (March–April). Build-chain compromises at Trivy, Checkmarx and Bitwarden reached downstream users including major technology companies. The attack surface moved one layer further up: not the dependency, but the tool that scans the dependency.
Stryker (March 11). An Iran-linked group abused the medical-device manufacturer's Intune device-management environment to wipe thousands of endpoints. Two lessons: destructive wiper attacks returned to Western commercial targets, and device management is the ultimate lateral-movement tool — it exists to push software everywhere at once, which makes it a Tier 0 asset.
Klue (June 12). A legacy API credential created in 2022 for a prototype that never launched, still valid four years later, exposed data from roughly 200 downstream companies including a dozen mature security vendors. The cleanest illustration of credential-lifecycle failure in the entire record.
European infrastructure. Destructive attacks against Polish energy and water facilities, a Swedish thermal plant, and a Norwegian dam whose controls were manipulated — attributed in reporting to Russian and pro-Russian actors with moderate confidence. This is the period's clearest evidence of OT targeting moving from pre-positioning to actual effect.
The two clocks. In the US: OMB M-26-05 (January 23) rescinded the software attestation mandate; a new three-page National Cyber Strategy (March 13) replaced the 34-page 2023 document and omitted software liability entirely; BOD 26-04 (June 10) revoked and replaced BOD 22-01. In the EU: NIS2 enforcement escalated to CJEU referrals for four member states (July 8), and the Cyber Resilience Act's vulnerability-reporting obligations took effect September 11, 2026 — four days before this document's research date.
Part 3 — Four threads traced across the period
Thread 1: The ransomware economy
| Year | Payments (Chainalysis, revised) | What changed |
|---|---|---|
| 2019 | ~$174M | Double extortion invented (Maze, November) |
| 2020 | ~$765M | Big-game hunting matures; payment rate ~70% |
| 2021 | ~$766M | Colonial and Kaseya; policy attention arrives; payment rate ~50% |
| 2022 | ~$567M | Ukraine invasion fractures Russian-speaking crews; sanctions risk; payment rate ~41% |
| 2023 | ~$1.25B | Record year, driven by Cl0p's MOVEit campaign and big-game activity |
| 2024 | ~$892M | Roughly 35% collapse, concentrated in H2 after the LockBit and ALPHV disruptions |
| 2025 | ~$820M | Down a further 8% while claimed attacks rose ~50% — activity and revenue decouple |
The single most important trend in the whole record: the payment rate fell from roughly 70% in 2020 to under 28% in 2025, and 15% for exfiltration-only cases by Q2 2026. The causes, roughly in order: better backups and tested recovery; accumulated public evidence that paying often fails (Change Healthcare being definitive); sanctions and legal exposure; insurer pressure; and six years of precedent for victims to reason from.
The group lifecycle across the period — GandCrab, Maze, REvil, DarkSide, Conti, Hive, LockBit, ALPHV, RansomHub, Qilin, Akira — shows the same pattern repeatedly: a brand rises, attracts law-enforcement attention, is disrupted or self-destructs, and its affiliates disperse into successor operations. Takedowns fragment; they rarely eliminate.
Thread 2: Authentication
Password rotation was deprecated by NIST guidance and then took years to die in practice. MFA adoption climbed on the strength of telemetry showing it blocked the overwhelming majority of account-compromise attacks. Then, from 2022, MFA fatigue and attacker-in-the-middle proxy kits defeated push and one-time codes at scale — which is why the recommendation shifted from "use MFA" to "use phishing-resistant MFA." The May 2022 Apple/Google/Microsoft commitment made passkeys viable for consumers; by May 2026 the FIDO Alliance reported roughly 5 billion passkey-enabled accounts, though only about 28% of organizations describe themselves as genuinely passwordless. The current frontier is non-human identity — service accounts, API keys, workload identities, and now AI agent credentials — which the Klue breach illustrated better than any advisory could.
Thread 3: The supply chain
SolarWinds (2020) made the build pipeline a target. SBOM minimum elements (2021) gave the artifact a definition. SLSA and Sigstore (2021–23) gave provenance a mechanism. XZ Utils (2024) revealed that the trust model itself — a burned-out volunteer maintainer accepting help from a patient stranger — was the vulnerability. The npm worms (2025) and the developer-tooling compromises (2026) pushed registry hardening: trusted publishing, provenance by default, mandatory maintainer MFA, and the end of long-lived tokens. SBOM as a practice survived the rescission of SBOM mandates, because by 2026 it had independent drivers in EU law, customer contracts, and tooling that assumed it.
Thread 4: Regulation, and its reversal
The arc runs: expansion (2021–2024), then divergence (2025–2026). The US built EO 14028, the zero-trust mandate, KEV, attestation, the CSRB, SEC disclosure, and an ambitious national strategy — then rescinded attestation, disbanded the CSRB, let information-sharing protections lapse, dismissed the SolarWinds case, replaced the strategy with a three-page document omitting software liability, and revised KEV's flat clock into a risk model. Meanwhile the EU's instruments moved into force on the opposite schedule: NIS2 into enforcement, DORA into application, the CRA into reporting obligations.
CIRCIA is the case study in the gap between a statute and an obligation. Enacted March 2022, proposed rule April 2024, statutory deadline missed October 2025, target slipped to September 2026. Four and a half years after enactment, its reporting requirements are still not in force. The lesson to teach: ask of any statute whether the implementing rule has been finalized, and what its effective date is.
Part 4 — The ten inflection points
- Maze publishes a victim's data (November 2019). Backups alone stop being a complete ransomware answer.
- COVID forces remote work (March 2020). The perimeter model ends; identity becomes the control plane.
- SolarWinds disclosed (December 2020). The build system becomes an attack surface; supply-chain security becomes a discipline.
- Colonial Pipeline and EO 14028 (May 2021). Ransomware becomes national security policy; the federal standards cascade begins.
- BOD 22-01 and the KEV catalog (November 2021). Prioritization shifts from severity to evidence of exploitation.
- Apple, Google and Microsoft commit to FIDO (May 2022). Passwordless becomes a platform capability.
- The LLM moment (late 2022 into 2023). Attack quality rises, a new defensive tooling category appears, and a new class of vulnerability — prompt injection — arrives unsolved.
- MOVEit (2023). One vendor flaw produces an economy-scale breach event; exfiltration-only extortion industrializes.
- XZ Utils and the CrowdStrike outage (2024). The trust model and the security agent each become recognized risk surfaces.
- The regulatory divergence (2025–2026). US mandates contract while EU instruments come into force, leaving multinationals on two clocks.
Part 5 — What changed in practice, stated plainly
For readers who want the seven years compressed into what they should actually do differently:
MFA is no longer sufficient as a word. The question is whether it is phishing-resistant. Push and SMS are defeated routinely.
Patch by evidence of exploitation, with exposure as context. KEV was the first correction to CVSS-chasing; BOD 26-04's risk tiers are the second.
Backups must be immutable and restore-tested, and the identity and hypervisor planes must be protected as Tier 0 — because modern ransomware attacks recovery capability first.
Your vendors' failures are your incidents. Third-party involvement climbed from a minority factor to roughly half of breaches. Inventory vendor access and OAuth integrations before you need to.
The help desk is an attack surface. Identity verification for password and MFA resets is a control, not a courtesy.
Credentials outlive the projects that created them. Klue's four-year-old prototype token is the canonical case for dormant-credential auditing.
Compliance dates move, and mandates reverse. Check the effective date of the rule, not the date of the statute — and check whether the rule still exists.
Part 6 — Standing cautions for anyone using this record
Six positions established in this window were reversed within it. Pre-2025 US compliance guidance may describe obligations that no longer exist. Always check current status.
Chainalysis figures are revised upward over time as attribution improves. The same year will be reported differently across editions — cite the edition.
Attribution confidence varies enormously. Government advisories, vendor assessments, and group self-claims are three different evidentiary standards. The Jaguar Land Rover vector is disputed; the FBI DCSNet timeline is inconsistent across sources; the Baltimore "EternalBlue" claim was publicly retracted after wide repetition.
Some widely repeated claims are overstated. The Synnovis patient-death finding is more qualified in the original than in most coverage. The GTG-1002 autonomy percentage rests on a single vendor source and drew researcher skepticism.
Two items need checking before publication as of this writing: the Cybersecurity Information Sharing Act, having lapsed in September 2025 and been extended twice, now expires 11 December 2026 with long-term reauthorization unresolved, and the EU AI Act deferrals agreed in the May 2026 Digital Omnibus required formal adoption and Official Journal publication to become binding.