A look at the worst hacks of 2020: SolarWinds, Twitter, Blueleaks, University Hospital Düsseldorf, Vastaamo, and Garmin
From ransomware schemes to supply chain attacks, this year melded classic hacks with extraordinary circumstances. — WHAT A WAY to kick off a new decade.
Context & Ripple Effects
Wired's year-end inventory closes an arc that began with ZDNet's ten-year cybersecurity retrospective a year earlier — and it deliberately spans every threat category rather than picking one theme: a confirmed Orion supply-chain compromise at SolarWinds, a mass account-takeover at Twitter, the BlueLeaks law-enforcement data dump, ransomware that took Garmin's services offline and disrupted University Hospital Düsseldorf, and the leak of Vastaamo patients' therapy records.
Days after publication, the same outlet reported that ransomware had already shifted from many small extortion payments to a few massive ones — the economic logic behind why a consumer-device maker and a hospital anchor this list alongside an espionage-grade intrusion.
First-order effects
- Ransomware now stops revenue-generating consumer services and clinical systems outright, as Garmin's service outage and University Hospital Düsseldorf's disruption show, while Vastaamo's patients faced direct exposure of their therapy records.
- SolarWinds' customers absorbed compromises delivered through a trusted vendor product, and Twitter's hijacked high-profile accounts demonstrated how one platform breach converts into public reach instantly.
Second-order effects
- The ransomware economics shift explains the target selection on this list: attackers chasing few, large victims whose downtime forces payment pulled hospitals and device makers into the blast radius previously reserved for individual users.
- A vendor whose distribution channel carried the compromise — SolarWinds foremost — faces buyers scrutinizing the software pipeline itself rather than only their own perimeters.
Third-order effects
- Orion's supply-chain compromise prefigures exploitation of shared software infrastructure at scale — the pattern Check Point measured a year later when Log4j attacks hit over 40% of corporate networks globally within 72 hours.
- The retrospective format itself is hardening into industry canon — decade review in 2019, this 2020 edition, then Wired's 2022 installment — concentrating which incidents get remembered and which drive policy attention.
The trend: Attacks are converging on shared chokepoints — vendor update channels, big-target ransomware, central platforms — so a single compromise scales far beyond any one victim.