The file appeared on 11 July 2012. A group calling itself D33Ds Company had run a union-based SQL injection against a Yahoo subdomain, dbb1.ac.bf1.yahoo.com, and come away with 453,492 email addresses and the passwords that went with them — not hashed, not salted, but in plain text, legible to anyone who opened the dump. The posting carried a note saying the group hoped that whoever managed the security of the subdomain would treat it as "a wake-up call, and not as a threat". Researchers going through the contents reported the five commonest passwords as 123456, password, welcome, ninja and abc123; ESET's Anders Nilsson put the commonest length at eight characters, a third of them using nothing but lower-case letters.
Yahoo answered the following day, in wording chosen with care. What had been taken, the company said, was "an older file" from its Contributor Network, "previously Associated Content", holding roughly 400,000 names and passwords and "stolen yesterday, July 11"; fewer than 5 per cent of the Yahoo accounts in it still had working passwords. Associated Content was a user-generated content business Yahoo had agreed to buy on 18 May 2010, for a sum it never disclosed and the press put at about $100 million. The addresses were not all Yahoo's to lose: the security firm Sucuri counted more than 100,000 Gmail addresses in the file, with Hotmail and AOL users among the rest. Marcus Carey of Rapid7 said the storage was "not even security 101".
The criticism that lasted was structural rather than technical. The researcher Joseph Bonneau faulted Yahoo for not having moved the Associated Content accounts into its own far stronger login system: a database inherited in an acquisition had gone on living by the standards of the company that built it. The month made the point twice more. On 10 July Formspring found 420,000 of its password hashes posted to a security forum — salted SHA-256, its founder Ade Olonoh said, taken after someone broke into a development server and used it to reach a production database — and disabled the passwords of all 28 million members. Nvidia closed its developer forums the same week and told users to change any password they had reused elsewhere.
Dropbox's turn began with spam. From about 17 July its support forums filled with users in Germany, Britain and the Netherlands receiving casino spam at addresses created for Dropbox and used nowhere else; the company brought in "an outside team of experts" on 18 July. The answer came on 31 July in a post by Aditya Agarwal: passwords stolen from other websites had been used to sign in to a small number of accounts, and one had opened an employee's own Dropbox account, which held a project document of user email addresses. Two-factor authentication was promised, and arrived on 27 August. What the company did not yet know was that the same intrusion had carried off user credentials too — 68,680,741 of them, as the world learned four years later.
Crude, and it worked
Seculert and Kaspersky Lab published on 17 July 2012 on an espionage campaign they had been tracking jointly, which Kaspersky called Madi and others rendered Mahdi after a file the malware left behind. About 800 victim systems were identified, most of them in Iran, with others in Israel, Afghanistan and scattered further afield: critical-infrastructure engineering firms, government agencies, financial houses and academics. Delivery was social engineering rather than exploitation — PowerPoint slide shows carrying embedded executables, one of them named Moses_pic1.pps and filled with serene wilderness and religious imagery, and a right-to-left override trick that made an .scr file look like a picture. The Delphi backdoor logged keystrokes, recorded audio and took screenshots when the victim opened webmail, instant messaging or a social network. Kaspersky's own framing was blunt: "No extended 0-day research efforts, no security researcher commitments or big salaries were required." Attribution went no further than the code; Seculert's Aviv Raff said only that whoever wrote it was fluent in Persian. Exposure changed little. By early September Seculert had counted roughly 150 fresh victims in the six weeks since publication, taking the running total to nearly a thousand, and Raff's summary was that "these guys continue to work".
What a takedown was worth
Two deadlines fell that month. On the morning of 9 July the temporary DNS servers, run under the court order the FBI obtained after the November 2011 Operation Ghost Click arrests, were switched off, and machines still carrying DNSChanger lost their route to the internet. Four million had been infected at the time of those arrests; the group formed to clean them up counted over 300,000 still infected weeks before the cut-off. Grum went next. FireEye's Atif Mushtaq published where the spam botnet's command servers sat; a Dutch provider pulled two, the Panamanian host of another gave way, the operators raised six in Ukraine, and researchers working with Spamhaus and Russia's CERT-GIB had those and the last Russian machine dead by 18 July. "There are no longer any safe havens," Mushtaq wrote. A month later Spamhaus agreed Grum was dead — and noted that a rival, Festi, had absorbed the missing spam. On 27 July the NSA's director, General Keith Alexander, told DEF CON in Las Vegas that "in this room is the talent our nation needs to secure cyberspace", a year before the conference asked federal employees to stay away.
The pen drive and the inbox
The month opened with a USB stick. On Sunday 1 July 2012 the Indian Express reported that computers in and around the headquarters of the Eastern Naval Command at Visakhapatnam — where INS Arihant, India's first nuclear-missile submarine, was undergoing trials — had been found infected by malware carried on pen drives. The code searched for documents matching set keywords, hid copies in a folder on the drive, and waited: when the stick went into a machine with an internet connection, the files left for IP addresses in China. The Navy said an inquiry had been convened and that findings were awaited, adding that there was "a constant threat in the cyber domain from inimical hackers worldwide"; a board of inquiry was reported to have indicted at least six officers for procedural lapses. Attribution stopped at the addresses, and Sophos's Graham Cluley noted that a Chinese IP address does not make a Chinese hacker.
The month's larger Indian compromise was not publicly known to be one until December. An official of the National Technical Research Organisation told the Indian Express then that on 12 July more than 10,000 email accounts had been taken across the Prime Minister's Office, the defence, home, finance and external affairs ministries, the intelligence agencies and the Indo-Tibetan Border Police, carrying away deployment details among much else — four days after the organisation's critical-infrastructure centre had circulated an advisory about malware aimed at named individuals. The official declined to name the state actors blamed. Nothing then obliged anyone to say: the duty to report arrived by direction in 2022, the statute in 2023.
Half the network, switched off at random
On 3 July 2012 Geoffrey Hinton and four Toronto colleagues — Nitish Srivastava, Alex Krizhevsky, Ilya Sutskever and Ruslan Salakhutdinov — set out on arXiv a technique they called dropout, a remedy for neural networks that fit their training data too closely. In training, every hidden unit had an even chance of being switched off on each example, so none could rely on particular others; the finished network ran whole with its outgoing weights halved, in effect averaging vast numbers of thinner networks. On the MNIST handwritten digits the best published result for a plain network, 160 errors in 10,000, fell to about 110; on the TIMIT speech benchmark errors went from 22.7 to 19.7 per cent. The authors reported "new records for speech and object recognition". The newspapers had spent late June on Google's network that taught itself to recognise cats in YouTube stills, presented at ICML in Edinburgh on 28 June; on 13 July Google began shipping the Nexus 7 with Google Now, its predictive assistant. Written up in full in 2014, dropout became standard equipment in deep learning.
Symantec changes its chief on results day
Symantec, then the largest security software company, replaced its chief executive on 25 July 2012, the day it reported quarterly results. Enrique Salem, chief since April 2009, left the job and the board; the company's filing recorded a resignation the day before, with severance due as for dismissal without cause. The chairman, Steve Bennett, formerly Intuit's chief executive, took the post and kept the chair; Daniel Schulman, the new lead director, said no particular event or impropriety lay behind the change. The results release, in Bennett's name, called the quarter solid — revenue of $1.668 billion, up 1 per cent — while his statement on taking over found the company "underperforming against the opportunity". The shares jumped. The same day Eugene Kaspersky answered a Wired profile, published on 23 July, describing his company's closeness to Russia's security services, rejecting it as misquoted and coloured by Cold War suspicion. Bennett was dismissed in March 2014 with the same assurance about impropriety; Washington ordered Kaspersky's software off federal networks in September 2017; Broadcom agreed to buy Symantec's enterprise half in August 2019.
⏳ Time capsule — July 2012
- On 4 July, at a seminar in Geneva relayed to a physics conference in Melbourne, the ATLAS and CMS teams at CERN reported a new particle near 125–126 GeV — ATLAS at five sigma, CMS at 4.9 — consistent with the long-sought Higgs boson; some 200 people watched the announcement at Fermilab at two in the morning.
- Pranab Mukherjee was sworn in as President of India on 25 July in the Central Hall of Parliament, six days after an election he won with 713,763 electoral-college votes to P.A. Sangma's 315,987.
- The London Olympics opened on 27 July at the Olympic Stadium with Danny Boyle's "Isles of Wonder", which included a filmed sequence of the Queen and James Bond apparently arriving by helicopter.
- India's northern grid failed at 2.35 in the morning on 30 July and the northern, eastern and north-eastern grids went together the next afternoon, leaving close to 620 million people without power across 22 states; about 200 miners were brought up from below, and the enquiry that reported on 16 August found overloaded transmission and a load-shedding scheme that did not act — no attacker.
What an older file was worth
Yahoo Voices was shut on 31 July 2014, two years and three weeks after the dump, and the Contributor Network behind it a month after that. The company's real reckoning came later and far larger: a theft from late 2014 disclosed in September 2016 at 500 million accounts, an older one from August 2013 disclosed that December at a billion and revised in October 2017 to all three billion. Storing passwords in plain text, the specific failure of July 2012, is indefensible everywhere now. The more useful lesson was the quieter one: a database that arrives with an acquisition keeps the habits of the company that built it until somebody does the work of moving it, and in 2026 that work has a name and a line in the due-diligence checklist.
The passwords outlived the companies. Dropbox's 2012 intrusion was worth 68 million credentials, which surfaced in the trade in old dumps in August 2016, when the company confirmed the file and reset every password older than mid-2012; LinkedIn's 6.5 million from that June proved to be 117 million, in the May 2016 edition that also carries the conviction of the man a San Francisco jury held responsible for all three 2012 intrusions — LinkedIn, Dropbox and Formspring — and his 88-month sentence in September 2020. Reuse became an industry: Collection #1, the Snowflake accounts, the sixteen-billion compilation. And for now this is where the archive begins; January to June 2012 are still to be restored.