/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A look at the worst hacks of 2020: SolarWinds, Twitter, Blueleaks, University Hospital Düsseldorf, Vastaamo, and Garmin

From ransomware schemes to supply chain attacks, this year melded classic hacks with extraordinary circumstances.  —  WHAT A WAY to kick off a new decade.

Wired Lily Hay Newman

Context & Ripple Effects

Wired's year-end inventory closes an arc that began with ZDNet's ten-year cybersecurity retrospective a year earlier — and it deliberately spans every threat category rather than picking one theme: a confirmed Orion supply-chain compromise at SolarWinds, a mass account-takeover at Twitter, the BlueLeaks law-enforcement data dump, ransomware that took Garmin's services offline and disrupted University Hospital Düsseldorf, and the leak of Vastaamo patients' therapy records.

Days after publication, the same outlet reported that ransomware had already shifted from many small extortion payments to a few massive ones — the economic logic behind why a consumer-device maker and a hospital anchor this list alongside an espionage-grade intrusion.

First-order effects

  • Ransomware now stops revenue-generating consumer services and clinical systems outright, as Garmin's service outage and University Hospital Düsseldorf's disruption show, while Vastaamo's patients faced direct exposure of their therapy records.
  • SolarWinds' customers absorbed compromises delivered through a trusted vendor product, and Twitter's hijacked high-profile accounts demonstrated how one platform breach converts into public reach instantly.

Second-order effects

  • The ransomware economics shift explains the target selection on this list: attackers chasing few, large victims whose downtime forces payment pulled hospitals and device makers into the blast radius previously reserved for individual users.
  • A vendor whose distribution channel carried the compromise — SolarWinds foremost — faces buyers scrutinizing the software pipeline itself rather than only their own perimeters.

Third-order effects

  • Orion's supply-chain compromise prefigures exploitation of shared software infrastructure at scale — the pattern Check Point measured a year later when Log4j attacks hit over 40% of corporate networks globally within 72 hours.
  • The retrospective format itself is hardening into industry canon — decade review in 2019, this 2020 edition, then Wired's 2022 installment — concentrating which incidents get remembered and which drive policy attention.

The trend: Attacks are converging on shared chokepoints — vendor update channels, big-target ransomware, central platforms — so a single compromise scales far beyond any one victim.