The timer fired at eight minutes past eleven in the morning. On Wednesday 15 August 2012, in the last days of Ramadan and with much of the workforce away for the holiday, the workstations of Saudi Aramco — the Saudi state oil company, the largest oil company in the world — began overwriting their own disks. Files were replaced by a repeating fragment of a photograph, a thousand bytes of a burning American flag, and the record that starts a machine went last, so that a computer ordinary at eleven would not boot at noon. A post on Pastebin that day, signed Cutting Sword of Justice, said the group had sent a virus to destroy thirty thousand computers on the company's network.

Aramco said that day it had isolated all its electronic systems from outside access after a sudden disruption, and that production operations were not affected. What that looked like was described three years later by Chris Kubecka, a consultant brought in afterwards: technicians pulling cables out of the backs of servers at data centres around the world, offices unplugged by hand, reports typed on typewriters, tanker drivers turned away because nothing could take payment. Employees returned from the Eid holiday on 25 August. A statement reported on 27 August said the computers had been cleaned and restored to service, that the virus had come from external sources and had affected about thirty thousand workstations, and that exploration and production ran on isolated networks never reached.

Symantec, Kaspersky Lab and Seculert all published on 16 August. Symantec catalogued the malware as W32.Disttrack; the name that stuck came from a path left in the code, C:\Shamoon\ArabianGulf\wiper\release\wiper.pdb. Inside it sat a legitimate, signed disk driver from EldoS, a product sold for exactly the kind of raw disk access that turns an ordinary write into a destructive one. On 23 August Kaspersky's Dmitry Tarakanov reported a time compiled into the sample — 15 August 2012, 08:08 UTC, which is eight minutes past eleven in Dhahran, the minute the Pastebin post had claimed. Kaspersky stayed careful all the same: writing in September, it said that despite persistent media reports it still could not definitively confirm that Shamoon was the malware that hit Aramco.

On 27 August the office systems and website of RasGas, the Qatari gas producer, went down; a spokesman said extraction and processing were unaffected, and what struck it was never established publicly. Attribution went the way such things went then. Leon Panetta described the attack publicly on 11 October, calling it probably the most destructive the private sector had seen — October's edition has the speech — without naming Iran. Within days American intelligence officials were reported to suspect Iran; the evidence stayed unpublished, and Iran denied the 2012 attacks laid at its door. In December the Saudi interior ministry said an organised group had attacked from outside the kingdom and that no employee or contractor was involved.

Also that month · 3–21 August

The last four digits

On Friday 3 August 2012 Mat Honan, a Wired writer, lost his digital life in fifteen minutes. At 4.50 in the afternoon someone reset his iCloud password and deleted the confirmation; at 4.52 a Google recovery message arrived; at five his iPhone was wiped remotely, at 5.01 his iPad, at 5.05 his MacBook Air. His Google account was deleted; his Twitter account — the three-letter handle that was the point of it — and Gizmodo's carried racist and homophobic messages. Nothing had been broken into. As Honan set out on 6 August, a caller with his name, email address and billing address could reach the last four digits of a card through Amazon's telephone support; Apple's support took those digits and the address as proof of identity and issued a temporary password. Amazon said the gap was closed that Monday afternoon; Apple suspended Apple ID resets by telephone the next day, pending stronger verification. The photographs of his daughter's first year were not backed up; on 17 August Honan reported that DriveSavers had recovered the bulk of the drive, tens of thousands of photographs among them, because the wipe had stopped short.

Also that month · 9–14 August

The payload nobody could open

On 9 August 2012 Kaspersky Lab published Gauss, found in June while the firm was examining Flame for the International Telecommunication Union. Built on the Flame platform, it came, Kaspersky said plainly, from the same factory or factories that had produced Stuxnet, Duqu and Flame. Its interest in money made it unusual: alongside browser passwords, cookies and system data it carried instructions for the online banking of named Lebanese institutions — Bank of Beirut, Byblos Bank, Fransabank, BlomBank, Credit Libanais and EBLF — and for Citibank and PayPal. By the end of July the firm's cloud had counted about 2,500 infected machines, 1,660 of them in Lebanon, 483 in Israel and 261 in the Palestinian territories; the command servers had gone quiet in mid-July. One module, called Godel, carried a payload encrypted under a key derived from the target machine's own program paths — ten thousand rounds of MD5, then RC4 — so that it would open on one configuration and no other. On 14 August Kaspersky published the scheme and asked the world's cryptographers for help. So far as the public record shows, it has never been opened.

India desk · August 2012

The trains out of Bangalore

From about 15 August 2012, Independence Day, students and workers from India's northeast crowded Bangalore City station for Guwahati, the region's main railhead, after text messages and word of mouth warned of reprisals. The warnings followed violence a month earlier in Kokrajhar and neighbouring districts of Assam, in which more than eighty people were killed and hundreds of thousands driven into relief camps. Photographs of violence elsewhere circulated with captions placing them in Assam. Karnataka's deputy chief minister went to the station to persuade people to stay, with little success; by a count reported in The Hindu, as many as thirty thousand left Bangalore alone within four days, with smaller departures from Chennai, Hyderabad and Pune.

The answer was a communications curfew. On 17 August the government capped SMS and MMS at five for fifteen days (at a time or a day, by different readings); the telecoms department raised it to twenty a day per SIM on 23 August, and the home ministry withdrew the cap on the 30th. Between 18 and 21 August providers were ordered to block 309 items — 85 on YouTube, more than a hundred on Facebook, twelve on Twitter — including, by the Centre for Internet and Society's reading, posts debunking the rumours. Among the accounts providers were told to block were a journalist's and a television anchor's; Twitter separately removed six impersonating the Prime Minister's Office. The home ministry said the pages threatened national security and that much of the material had been uploaded from Pakistan; Pakistan rejected the charge as baseless and asked India to share the evidence, which was not made public. Section 69A, the blocking power, was upheld by the Supreme Court in March 2015 on the day it struck down section 66A; the machinery has run on since.

AI Tech desk · August 2012

A dozen cars and 300,000 miles

On 7 August 2012 Chris Urmson, engineering lead of Google's self-driving project, wrote that its cars, about a dozen of them on the road at any given time, had completed more than 300,000 miles of testing without a single accident under computer control, and that team members would soon use them solo, not in pairs, for the commute. He listed what they had still to master: snow-covered roads and temporary construction signals. The next day Google extended the Knowledge Graph, its database of more than 500 million people, places and things, to every English-speaking country. On 21 August Vicarious, building visual-perception software on what it called a recursive cortical network, raised $15 million in a round led by Dustin Moskovitz's Good Ventures; its co-founder Dileep George said products were several years off. The field still leaned largely on hand-designed features and curated knowledge, weeks before an autumn result in image recognition turned it towards deep neural networks. The car project became Waymo in December 2016, and first offered the public rides with no safety driver in October 2020.

Digital Guard desk · August 2012

An antivirus maker goes into search

On 16 August 2012 Qihoo 360, the Beijing company that gave its security software away and counted 425 million monthly users on the PC, opened a search engine of its own, and within days made it the default on its hao.360.cn start page and its browsers in place of Google. Its results on 21 August showed revenue more than doubled year on year, most of it from advertising. Claims of a tenth of Chinese search within a week were disputed. Late on 28 August Baidu began sending visitors who reached its encyclopedia and question-and-answer pages through Qihoo to its home page, and said it welcomed competition but opposed acts that infringed its services; Qihoo served cached copies and denied taking rivals' results. Two older engines changed hands: on 1 August Commtouch agreed to buy the antivirus arm of Iceland's FRISK Software, whose F-PROT dated from 1989, and Russia's Agnitum bought the engine of VirusBuster, its Hungarian supplier since 2006, which left the market on 1 October. Cyren, as Commtouch became, retired F-PROT's endpoint products on 31 July 2021.

⏳ Time capsule — August 2012

  • On 6 August at 05.17 UTC NASA's Curiosity rover landed in Gale Crater on Mars, lowered the last 7.6 metres on a tether from a rocket-powered descent stage that then cut it loose and flew away.
  • On 12 August, the closing day of the London Olympics, Sushil Kumar took silver in freestyle wrestling; India finished the Games with six medals, two silver and four bronze, twice the three it had won at Beijing in 2008.
  • On 15 August Ek Tha Tiger opened in Indian cinemas, taking ₹33.5 crore on its first day — the largest opening Hindi cinema had seen — and ending the year as its highest-grossing film.
  • On 25 August Neil Armstrong, the first person to walk on the Moon, died in Ohio at the age of 82, of complications following coronary bypass surgery.
Where it stands today — 2026

The option that stayed open

Shamoon outlived whoever wrote it. Seven months later a wiper timed for two in the afternoon took tens of thousands of South Korean machines off their disks (March 2013); in November 2014 the same shape arrived at Sony Pictures. Wiping the backups before demanding money is now ordinary. It returned on 17 November 2016 against Saudi targets, the burning flag replaced by a photograph of a drowned Syrian child, again in January 2017, and in December 2018 at Saipem, a contractor working for Aramco; nobody has been charged. What Aramco got right became doctrine: the networks that move oil sat apart from those that move email. The bill was five months of restoration and seventeen days of fuel given away inside the kingdom because nothing could take payment.

The month's other lesson took longer. Honan's accounts were not broken; a support desk was persuaded, and the answer was a second factor — Apple's two-step verification arrived in March 2013, in five countries — until that became the thing to talk a stranger past. The route was still open in September 2023, when calls to outsourced help desks put two casino companies onto handwritten receipts. Gauss's encrypted module has still not been read, fourteen years on: it was built to arm itself on one machine only, and that machine was never identified. In India the emergency of August 2012 set the pattern for the blocking orders of the decade that followed, while a duty to report a breach waited for CERT-In's six-hour direction in 2022.