On 2 June 2011 a group calling itself Lulz Security published a file it said came from SonyPictures.com, with a press release claiming "over 1,000,000 users' personal information" — passwords, email addresses, home addresses, dates of birth. The site, it wrote, had been taken by "a very simple SQL injection", and Sony had "stored over 1,000,000 passwords of its customers in plaintext". The Associated Press said it had verified part of the data by contacting people named in it. The million was never verified: the group posted a fraction of it, and on 8 June Sony Pictures Entertainment began notifying about 37,500 people that their details might have been taken. The same group said that month that it had been inside a Nintendo server and taken nothing, liking the N64 too much.
The method of the month was attention. On 13 June it posted directory listings and account data from a public Senate web server; Martina Bradford, the deputy Senate sergeant at arms, said the machine "is for public access and is in the public side" and that the main Senate network had not been reached. On 14 June, a day it called Titanic Takeover Tuesday, it knocked over the login servers of EVE Online, Minecraft and League of Legends and published a telephone number, 614-LULZSEC, answered by a recording in a French accent; it claimed that evening to have had 5,000 missed calls and 2,500 voicemails. On 15 June the Central Intelligence Agency's public website was unreachable from about 5.48 until 8 in the evening, Eastern time. "Tango down", the group wrote.
On 20 June the website of Britain's Serious Organised Crime Agency went off the air briefly; the agency said it had pulled the site down itself to spare others hosted by the same provider. Three days later came the release with a plausible human cost. Under the title Chinga La Migra the group published material it said had come from Arizona Department of Public Safety servers — email addresses and passwords, intelligence bulletins, training manuals, hundreds of documents marked sensitive or for official use only — and said it had chosen Arizona because of SB 1070, the state's alien registration law. Arizona's objection was to the officers' names and their families' details; it stood up its counter-terrorism information centre and cut off remote email access. A final dump on 25 June carried what the group's own inventory called half a gigabyte of AT&T internal files and more than 750,000 username and password pairs.
Just after midnight British time on 26 June the group posted "50 Days of Lulz". It said the fifty days had been the plan from the start, that it was not stopping because it feared law enforcement, and signed off as a "crew of six". Part of that was not true: its most visible member had been under arrest in New York since the evening of 7 June and had been posting for the Federal Bureau of Investigation ever since, which only became public in March 2012. The work outlived the name. The wider campaign it had announced that month carried on through July and into December, and most of what it took came out of the same kind of public-facing web form that had opened Sony Pictures.
The number in the address bar
Citigroup said on 9 June 2011 that its Citi Account Online service had been misused to reach the records of North American credit card customers. The bank had found the problem on 10 May, concluded about two weeks later that data had been taken, and posted notification letters on 3 June; its public statement put the loss at roughly one per cent of its card customers, reported at the time as about 200,000 accounts. On 15 June it revised the figure upward to 360,083. The flaw was not sophisticated. Someone who logged in with one valid account could edit the account number in the browser's address bar and be served another customer's page: names, account numbers and contact details including email addresses, but not card verification codes or expiry dates. Citigroup later attributed about $2.7 million in losses to the episode. On 28 June the Federal Financial Institutions Examination Council issued a supplement to its 2005 guidance on authentication in internet banking and told examiners to assess banks against it from January 2012.
Two ways to skip a password
Two unrelated failures fell on the same day. At 1.54 in the afternoon Pacific time on 19 June, Dropbox pushed a code change that broke its own password check; the company found the fault at 5.41 and fixed it at 5.46 — three hours and fifty-two minutes in which an account could be opened with the wrong password. Dropbox said much less than one per cent of users signed in during that window, and later put the accounts actually reached at fewer than a hundred — all of them by one person, who had looked at files that were not theirs. It became public because the person who found it sent the exchange to a security researcher, who published it. The same day, on the Tokyo exchange Mt. Gox, an account carrying administrative rights over the database was used to alter balances and drive the bitcoin price from about $17.50 to one cent within minutes; roughly 2,000 bitcoin were taken off the exchange before its daily withdrawal limit stopped any more, a loss the exchange itself had to absorb. The user database, passwords hashed, was published. Mt. Gox reversed the trades and halted trading; its end came in February 2014.
A message addressed to the prime minister
Some time on the night of 6 June 2011 a page on the National Informatics Centre's domain — informatics.nic.in/oldnewsonline/abc.html — stopped being a page about old news. In its place was a message addressed to the prime minister and signed in the manner of Anonymous: "We exist without nationality", "NIC took 3 ins", "Expect us." The NIC hosts the Union government's websites. The stated reason was the Delhi police action two nights earlier, when a fast by the yoga teacher Ramdev at the Ramlila Maidan was broken up and his supporters cleared from the ground. By the next afternoon the message was gone and the NIC's main site was showing a maintenance notice; no theft of data was reported. The same campaign, calling itself Operation India, knocked the Indian Army's website off the air for about an hour later that month, then dropped the target after its own Indian supporters objected.
Defacement itself was not rare. CERT-In's monthly counts put about 1,190 Indian websites defaced in June 2011, after 1,848 in May. What made the timing awkward was the policy running alongside. The Information Technology (Intermediaries Guidelines) Rules had been notified that April, obliging an intermediary to act within thirty-six hours on a complaint that material was, among other things, disparaging or blasphemous, with no judge involved. Sunil Abraham of the Centre for Internet and Society said that set beside other democracies in North America and Europe the Indian rules looked to be "on the China end of the spectrum". Officials said they were still willing to hear dissenting views and might consider changes; the conversations with the platforms themselves ran on into September. A defacement now has to be reported within six hours.
Nevada writes the first driverless-car law
Nevada's governor, Brian Sandoval, approved Assembly Bill 511 in mid-June 2011, the first law in America directing a state to write rules for autonomous vehicles on public roads; Google had lobbied for it. The bill defined an autonomous vehicle as one using "artificial intelligence, sensors and global positioning system coordinates" to drive itself, and told the Department of Motor Vehicles to set insurance, safety and testing requirements, test areas and a licence endorsement from 1 March 2012. The first licence followed that May. On 16 June Microsoft Research released the Kinect for Windows SDK beta, free for non-commercial use: raw depth, colour and microphone-array streams, skeletal tracking of two people, speech through the Windows recognition API. Days later its tracking method — every pixel of a depth image labelled as a body part by decision forests — took the best-paper award at CVPR; the sensor line ended with Azure Kinect in 2023. Facebook admitted on 7 June it had switched on face-recognition tag suggestions in most countries by default; European regulators opened an inquiry, and the system was shut in 2021.
A raid on the fake-antivirus trade
On 22 June 2011 the US Department of Justice announced Operation Trident Tribunal: 22 computers and servers seized in America and 25 in seven other countries, against two rings selling scareware — software that invents infections, then demands up to $129 to remove them. One ring had sold more than $72 million of it to an estimated 960,000 people; the FBI said a Conficker variant was among its delivery routes. The other, charged in Minneapolis, had bought advertising on the Star Tribune's website posing as an agency for a hotel chain, then rewritten it to infect readers; Peteris Sahurovs and Marina Maslobojeva were arrested in Rēzekne, Latvia, the day before. Five days later Kaspersky Lab's analysts described TDL-4, a bootkit that hid in the master boot record, ran on 64-bit Windows, took orders over the Kad peer-to-peer network and deleted rival malware, with more than 4.5 million infections logged in the year's first three months; its owners, they wrote, were trying to build an "indestructible" botnet. Sahurovs was found in Poland in 2016 and sentenced in 2018 to 33 months.
⏳ Time capsule — June 2011
- On 4 June Li Na beat Francesca Schiavone at Roland Garros to become the first player from Asia to win a Grand Slam singles title; the next day Rafael Nadal beat Roger Federer 7–5, 7–6, 5–7, 6–1 for a sixth French Open, equalling Björn Borg's Open-era record.
- On 8 June, for twenty-four hours from midnight UTC, more than 400 organisations published AAAA records for World IPv6 Day, an Internet Society test of what would break, anchored by Google, Facebook, Yahoo, Akamai and Limelight; IPv6's share of traffic, on the big carriers' measurements, rose from about 0.024 to 0.041 per cent and the anchors reported no significant trouble.
- On 24 June the New York State Senate passed the Marriage Equality Act by 33 votes to 29; the governor signed it at 11.55 that night and it took effect on 24 July.
- On 28 June Google launched Google+, built under Vic Gundotra and Bradley Horowitz; it had ten million users within a fortnight, and Google closed the consumer service on 2 April 2019.
What the fifty days proved
Nothing in the spree was technically new. SonyPictures.com fell to what its takers called one of the most primitive and common vulnerabilities; the Senate and Arizona material sat on public-facing servers. What was new was the pacing — a running commentary, a countdown, a request line — which set the agenda of a month on almost no technique. The courts arrived slowly and separately. Cody Kretsinger, who admitted using a proxy service to cover the Sony Pictures injection, was sentenced in April 2013 to a year in federal prison and $605,000 in restitution. In London on 16 May 2013 Ryan Cleary received 32 months, Ryan Ackroyd 30 and Jake Davis 24 in a young offenders' institution; a fourth, sixteen when the offences were committed, got a suspended sentence and community service.
The month's quietest story has aged the best. On 1 June 2011 Google said it had disrupted a campaign that phished the personal Gmail accounts of senior American officials, Chinese political activists and journalists, and that it appeared to originate in Jinan; at a briefing in Beijing on 2 June the Chinese foreign ministry spokesman Hong Lei called the allegation completely fabricated, with ulterior motives, and said China was a victim of hacking too. Credential theft aimed at named individuals rather than networks is now the ordinary shape of state-linked intrusion; the public naming of a city was the unusual part. Citigroup's flaw kept its name — an object reference the server never checked against the session — and the FFIEC supplement of 28 June 2011 became the baseline American banks are examined against. India's own reporting clock arrived in 2022, and its privacy statute in 2023.