The torrent went up on 11 July 2011, listed on the tracker at about 130 megabytes, under the heading Military Meltdown Monday: Mangling Booz Allen Hamilton. The people posting it, working under the banner of Operation AntiSec — an alliance of Anonymous and the remnants of LulzSec — said they had taken roughly 90,000 military email addresses with unsalted MD5 password hashes, a dump of the database that held them, and four gigabytes of source code from a version-control repository. "We infiltrated a server on their network that basically had no security measures in place," the statement read, describing how they had then run a program of their own there, which "turned out to be a shell." The Associated Press counted the addresses and found 67,000 unique ones, about 53,000 of them military.

Booz Allen Hamilton said nothing useful for two days. Its first answer, posted to Twitter, was that as a matter of security policy it generally did not comment on specific threats or actions taken against its systems. On 13 July it confirmed the intrusion, said it was conducting a full review of the nature and extent of the attack, and added that at that time it did not believe the attack had extended beyond data pertaining to a learning management system for a government agency. Three days after the torrent appeared, on 14 July, the deputy secretary of defense, William J. Lynn III, stood at the National Defense University and presented the Department of Defense Strategy for Operating in Cyberspace, the department's first. In March, he said, a foreign intelligence service had taken 24,000 files from a defence contractor's network in a single intrusion.

He would not name the contractor, and he would not name the service. The files were "related to systems being developed for the Department of Defense," Lynn said, and on who had taken them he went no further than "We think it was a foreign intelligence service." The strategy set out five initiatives. The first treated cyberspace as an operational domain alongside land, sea, air and space; the second introduced what it called active cyber defences, using "sensors, software, and signatures to detect and stop malicious code before it affects our operations" — machinery that works inside the network rather than only at its edge. The overriding emphasis, Lynn said, was on denying an attacker the benefit of an attack rather than on threatening retaliation. The contractor networks holding the designs were to be addressed through the Defense Industrial Base Cyber Pilot, which the department stressed was voluntary for every participant.

AntiSec spent the rest of the month on the same targets. On 8 July it published documents from IRC Federal, a small government contractor, taken, it said, by simple SQL injection; on 21 July it claimed about a gigabyte from a NATO server, releasing two procurement documents on services in Kosovo and withholding the rest as too sensitive; on 29 July it claimed ManTech International, an FBI contractor, using a cleared employee's credentials. These were claims; most of the organisations named declined to confirm them. The arrests came from another direction. On 19 July the Department of Justice announced sixteen, fourteen over a December 2010 denial-of-service attack on PayPal that the indictment said Anonymous had called Operation Avenge Assange. Charges against AntiSec's own organisers followed in March 2012.

Also that month · 4–18 July

The default PIN

The method was a four-digit number. Reporters working for the News of the World rang a target's mobile, waited for the voicemail to answer and entered the PIN, which was often a default such as 0000 or 1234; where that failed, a call could be made to appear to come from the handset itself, which the networks let through without a PIN, or a call centre talked into a reset. The papers seized from the private investigator who did much of it held, as Scotland Yard conceded to a Guardian freedom-of-information request, close to three thousand mobile numbers and the PINs of 91 different people. On 4 July 2011 the Guardian reported that the paper had intercepted the voicemail of a schoolgirl murdered in 2002, while she was still missing. James Murdoch announced the closure on 7 July; the last issue appeared on 10 July, after 168 years. On 13 July David Cameron confirmed an inquiry under Lord Justice Leveson. Rebekah Brooks resigned as chief executive of News International on 15 July and was arrested on 17 July. On 18 July LulzSec placed a false report of Rupert Murdoch's death on a News International address and pointed the Sun's homepage at it.

Also that month · 26–28 July

Thirty-five million in Seoul

On 28 July 2011 SK Communications, which ran the Nate portal and the Cyworld social network, said that user data had been taken two days earlier. About 35 million accounts were involved: names, user IDs, email addresses, telephone numbers, passwords and resident registration numbers, the identifier South Koreans used to open almost anything online. It was reported at the time as the country's largest breach; the Korea Communications Commission and the National Police Agency began investigating, the chief executive, Joo Hyung-chul, apologised to customers, and the police said the traffic had come from Chinese IP addresses. The route in was the more instructive detail. The company's machines had asked an update server for the file-compression program ALZip, made by ESTsoft, for a routine update and had been served malware instead — the maintenance habit turned into the way in. A Seoul court in February 2013 ordered SK Communications to pay 200,000 won each to 2,737 claimants, finding it had failed to notice a theft that proceeded in stages; ESTsoft and Symantec were named as defendants and found not liable.

India desk · July 2011

The screenshots nobody could check

The claim arrived by email, and nobody could check it. On 26 July 2011 a group calling itself the Pakistan Cyber Army said it had been inside BSNL, the state-owned telecom operator, and emailed images to The Hacker News: defaced administrative pages showing the names, email addresses, telephone numbers and locations of about ten thousand users, and internal pages listing virtual private network and circuit details. MediaNama, reporting it on 28 July, said it could not verify the screenshots. The group gave no motive and left no website, forum or address. No response from BSNL or from the government was recorded. The month in India was not being read for defacements: on 13 July three bombs in Mumbai killed 26 people and injured about 130.

The official accounting came the following week. On 4 August 2011 the minister of state for communications and information technology, Sachin Pilot, told the Lok Sabha in writing that 117 government websites had been hacked between January and June 2011, and set out what would follow: security audits before and after a site went live, a bar on the National Informatics Centre hosting anything un-audited, advisories from CERT-In, crisis management plans for ministries. None of it carried a deadline for telling anyone. The Information Technology (Intermediaries Guidelines) Rules, gazetted on 13 April 2011 and laid before Parliament that August, drew the opposite complaint — that they turned private companies into censors — and survived the statutory motion to annul them that a Kerala member moved in the Rajya Sabha on 23 March 2012, three months after a Delhi court summoned the platforms themselves (January 2012), and that the House defeated by voice vote on 17 May. Since CERT-In's direction of April 2022, a defacement must be reported within six hours.

AI Tech desk · July 2011

The face recogniser Google bought anyway

On 22 July 2011 Pittsburgh Pattern Recognition, the Carnegie Mellon spin-out that traded as PittPatt, announced on its own site that it was joining Google; no terms were disclosed then or since. Founded in 2004 on a decade of object-recognition work at the Robotics Institute, its software detected, tracked and matched faces in still photographs and in video. The timing was awkward. Seven weeks earlier, at the D9 conference on 1 June, Eric Schmidt had described face recognition as the one technology Google had built and then withheld — it had, he said, "decided to stop". Google now said only that it would not add face recognition to its products without strong privacy protections in place. Find My Face, opt-in, reached Google+ that December, and grouping photographs by face is unremarkable today. Two days before the deal surfaced Google had announced it was closing Google Labs, the public shelf for its own experiments. The field's own honours went elsewhere: IJCAI, meeting in Barcelona from 16 to 22 July, gave its research excellence award to Robert Kowalski, for logic programming.

Digital Guard desk · July 2011

Microsoft puts a price on Rustock

On 18 July 2011 Richard Boscovich, a senior attorney in Microsoft's Digital Crimes Unit, offered $250,000 for new information leading to the identification, arrest and criminal conviction of whoever had run the Rustock botnet. Microsoft and its partners had taken Rustock offline on 16 March, seizing command servers at five hosting providers; the company put its capacity at 30 billion spam messages a day, much of it advertising counterfeit pharmaceuticals. Notices published the previous month in two Russian newspapers, summoning defendants Microsoft could not name, had produced nobody. The reward drew tips but no conviction, and by September the company had handed its findings to the FBI; no one has been publicly charged with operating Rustock since. The month's other figures were commercial. On 27 July Symantec reported a record fiscal first quarter, revenue of $1.653 billion, up 15 per cent on the year. And on 19 July Google began showing infected users a yellow banner above their search results telling them to update their antivirus software — the warning arriving from the search box rather than the scanner.

⏳ Time capsule — July 2011

  • On 8 July Atlantis lifted off on STS-135, the 135th and final flight of the Space Shuttle programme, carrying four astronauts — the smallest crew since 1983, because no rescue shuttle remained — and landed in Florida on 21 July.
  • On 9 July South Sudan became independent, the fifty-fourth country in Africa; on 14 July it was admitted to the United Nations as its 193rd member.
  • On 15 July Harry Potter and the Deathly Hallows – Part 2, the eighth and last film of the series, opened in Britain and the United States after a premiere in Trafalgar Square on 7 July, and took $483.2 million worldwide over its first weekend.
  • On 17 July Japan beat the United States on penalties in Frankfurt to win the Women's World Cup, Saki Kumagai scoring the last kick — the first Asian side to win a FIFA World Cup, four months after the earthquake and tsunami at home.
Where it stands today — 2026

The contractor in the middle

Lynn's 24,000 files were never publicly attributed and the contractor was never named, which left the 14 July disclosure describing the shape of the problem rather than its author: the designs sat on networks the department did not run and could advise but not command. The rest of that July made the same point loudly and with far less verification, in claims the named organisations mostly declined to confirm. Booz Allen's own sequel needed neither an intruder nor a claim. In June 2013 a contractor the firm had placed at the National Security Agency in Hawaii walked out with the agency's documents, and Booz Allen dismissed him on 10 June, the day after he went public. By December 2020 the route ran through a software vendor's own build system.

The newspaper did not come back. Leveson reported on 29 November 2012 (November 2012), Rebekah Brooks was acquitted on all charges in June 2014 and was running the company again by 2015, and the default voicemail PIN quietly went away — from August 2011 one large American carrier required new subscribers to enter one even when calling from their own handset. South Korea drew the harder conclusion from its 35 million accounts, pushing the resident registration number off the commercial internet: restricted from 2012, and barred outright from 7 August 2014 except for government, banks and telecoms. India waited until 2023 for a privacy statute. The archive runs on behind this edition, back through June to January 2011.