The account appeared on 1 June 2012, drawn from Confront and Conceal, a book by the New York Times correspondent David Sanger that was published four days later. Stuxnet, the worm researchers had been taking apart since the summer of 2010, was, he reported, an American and Israeli operation code-named Olympic Games. It dated from 2006, when President George W. Bush saw few good options on Iran, and it had been tried against replicas of Iran's P-1 centrifuges, the tests spread across several of the Energy Department's national laboratories so that even trusted staff could not tell what they were for. Near the end of Bush's term the wreckage of a centrifuge was laid out on the conference table in the Situation Room, as proof of what code could do.
In the summer of 2010 an error in the code let the worm onto an engineer's computer connected to the centrifuges; when the engineer left Natanz and went online, it failed to notice its surroundings had changed and began copying itself around the world. Within days Barack Obama, who had ordered the attacks stepped up from his first months in office, met Vice President Joe Biden and the CIA director, Leon Panetta, in the Situation Room. "Should we shut this thing down?" he asked, according to people in the room. Biden, by the same account, blamed the Israelis. Told it was unclear how much Iran understood, Obama let it run; within a week another version took nearly a thousand of Iran's five thousand centrifuges out of service for a time.
No official would be named. The account rested on eighteen months of interviews with current and former American, European and Israeli officials, none of whom would be identified because the effort remained classified and parts of it were still running. The White House would not discuss the substance. Senator John McCain accused the administration of leaking to serve the President's political ambitions; on 8 June Obama told reporters that the notion his White House would deliberately release classified national security information was offensive. The same day the Attorney General, Eric Holder, put two United States attorneys, Ronald Machen in Washington and Rod Rosenstein in Maryland, in charge of criminal investigations into this leak and another, about a disrupted bomb plot by al-Qaeda in the Arabian Peninsula.
The inquiry reached a man Sanger's account had placed near the beginning. General James Cartwright, who had set up a small cyber unit inside Strategic Command and helped put the idea to Bush, had retired in 2011 as vice chairman of the Joint Chiefs of Staff. He was never charged with leaking. On 17 October 2016, before Judge Richard Leon in Washington, he pleaded guilty to making false statements: interviewed by the FBI on 2 November 2012, he had denied providing or confirming classified information to Sanger, or to Daniel Klaidman of Newsweek. He said he had not been the source of the story and had wanted only to protect American interests and lives. On 17 January 2017, three days before leaving office, Obama pardoned him.
Signed in Microsoft's name
On Sunday 3 June 2012 Microsoft said components of Flame, the espionage toolkit made public on 28 May, had been signed with certificates that passed as Microsoft's own. They came from its Terminal Server Licensing Service, whose certificates for customers' licence servers used an older algorithm and could sign code; three intermediate certificates went into Windows' untrusted store. On 4 June Kaspersky's Alexander Gostev showed what that bought: an infected machine told its neighbours it was their web proxy and handed them a fake Windows Update. On Vista and later the forgery needed an MD5 collision, and on 7 June the cryptanalyst Marc Stevens of CWI called it a completely new variant of the chosen-prefix attack. On 11 June Kaspersky reported an early Flame module inside a 2009 build of Stuxnet: two teams, it said, had cooperated at least once. On 19 June the Washington Post, citing Western officials with knowledge of the effort, reported that the NSA, the CIA and Israel's military had built Flame to map Iran's networks under Olympic Games, the programme American officials had told the Times it was no part of. No government confirmed it.
The second lock
On 6 June 2012, 6,458,020 unsalted SHA-1 password hashes, without usernames, turned up on a Russian forum, apparently for help cracking them. Researchers found the hashes of their own LinkedIn-only passwords, and LinkedIn's Vicente Silveira confirmed that day that some matched members' accounts, whose passwords were invalidated. eHarmony, reportedly the source of a second list of about 1.5 million, said a small fraction of its users were affected; Last.fm asked every user to change password on 7 June. The LinkedIn figure was the least of it, as May 2016 would show. On 1 June a caller had talked AT&T into redirecting the voicemail of CloudFlare's chief executive, Matthew Prince, which opened his Gmail; a flaw in Google's account recovery got past the two-factor login on his company address, the pattern August would make notorious. On 26 June McAfee and Guardian Analytics described bank fraud automated from servers, which in Europe got round chip-and-PIN by asking customers to produce the code: at least €60 million attempted from accounts at 60 or more institutions, by their estimate, and up to €2 billion if every campaign matched the Dutch one. Attempts, not losses.
Two films and the whole of Vimeo
The orders were about films. On 29 March 2012, the day before the Tamil film 3 opened — its song Why This Kolaveri Di had spread across YouTube from November — the Madras High Court granted a John Doe injunction, sought through the anti-piracy firm Copyright Labs for the producers, R.K. Productions, against unnamed infringers; a second followed on 25 April for the Telugu film Dammu. Neither named a website. From about mid-May subscribers of Reliance Communications and Airtel found Vimeo, Dailymotion, the Pirate Bay, Pastebin and torrent sites blocked whole, behind a page citing court orders. On 17 May attacks claimed by Anonymous took down the websites of the Supreme Court, the telecoms department, the Congress and the BJP; on 26 May it claimed to be inside Reliance's servers.
On 9 June it called protests in some sixteen cities. Digit counted about seventy-five at Azad Maidan in Mumbai, many in plastic Guy Fawkes masks Crawford Market sold for 180 rupees; MediaNama's tally for Nagpur was two, and in Hyderabad police told protesters to take off their masks and leave. The anti-piracy firm said infringing sites ignored takedown notices, the providers that they were obeying a court, the protesters that it was censorship. On 15 June, on the providers' application, the Madras court clarified that its April injunction covered only the particular URL where a film was kept, not the entire website, giving the applicant forty-eight hours to list them. That month, as reported at the time, the Bombay High Court granted Viacom18 a John Doe order for Gangs of Wasseypur. It stayed unsettled: in July 2016 Justice Gautam Patel of that court refused a sweeping order for the film Dishoom, then days later allowed one confined to links the applicant had checked one by one.
Ten million frames and a cat
On 26 June 2012 Jeff Dean and Stanford's Andrew Ng described on Google's blog a network, built in its X laboratory, that had learned to recognise faces and cats without being told what either was. Shown ten million unlabelled frames, one from each of as many YouTube videos, for three days on 16,000 processor cores, it ended with a unit that picked out human faces with 81.7 per cent accuracy and others that answered to cats' faces and human bodies. Given labelled images, it scored 15.8 per cent across some 22,000 ImageNet categories, against a previous best of 9.3. "It basically invented the concept of a cat," Dean told the New York Times, which ran the story on 25 June; the paper was presented at ICML in Edinburgh on 28 June. Faces were already a business: on 18 June Facebook bought Face.com, the Israeli firm whose software it had long used to suggest photo tags, price undisclosed. Out of X by then, the project went on as Google Brain until its merger into Google DeepMind in April 2023.
The samples already in the archive
On 1 June 2012 Wired published an essay by F-Secure's chief research officer, Mikko Hypponen, on why companies like his had missed Flame and Stuxnet. His company had since found Flame samples from 2010 and 2011 in its own archive, delivered by automated reporting and never flagged for a closer look. He called that a failure for F-Secure and the industry, and argued that consumer products could not stop well-funded states that tested against them first: "We were out of our league, in our own game." On 19 June Bruce Schneier disputed the explanation: criminals tested their malware too, and the difference lay in how slowly and quietly the state-built code had spread. Hypponen left the anti-malware business in 2025, after thirty-four years, for a Finnish maker of anti-drone systems.
⏳ Time capsule — June 2012
- On 3 June some 670 boats sailed seven and a half miles down the Thames, from Wandsworth to Tower Bridge, for the Queen's Diamond Jubilee — the largest parade of boats on record — and the Queen, at eighty-six, stayed on deck through about four hours of cold rain.
- Venus crossed the face of the Sun from 22.09 UTC on 5 June to 04.49 UTC on 6 June; in India the end of the transit was visible at sunrise, and the next will not come until December 2117.
- On 7 June, his thirty-eighth birthday, Mahesh Bhupathi won the French Open mixed doubles in Paris with Sania Mirza, beating Klaudia Jans-Ignacik and Santiago González 7–6, 6–1.
- On 23 June, the centenary of Alan Turing's birth, Google marked the day with a doodle that was a working Turing machine, set with twelve programming puzzles.
Neither confirmed nor denied
Fourteen years on, neither the United States nor Israel has openly acknowledged Stuxnet; the record rests on unnamed officials and on code that kept adding years. Symantec's account of an earlier build, in February 2013, had the operation at work by 2007; Kaspersky's Equation Group research in February 2015 found an older operation using two of Stuxnet's exploits before Stuxnet did. The leak inquiry of 8 June ended, on the public record, in one guilty plea to a false statement and one pardon. What lasted was the example: code had broken machinery in a sealed plant, and tools built for one target did not stay there — exploits said to be the Equation Group's were put up for sale in August 2016, one of them carrying WannaCry the next May.
Flame's forgery changed the plumbing. Microsoft gave the Windows Update client a certificate trusted for nothing else, and MD5's published weakness turned out to have been developed further, and separately, by whoever built Flame. The idea it proved — that the update channel is the most trusted door on a network — came back through a Ukrainian accounting package's updates in June 2017 and SolarWinds' in December 2020. In India the clarification of 15 June settled little: courts went on granting orders against unnamed defendants, the government's own blocking power under section 69A was upheld in March 2015, and whether an order should name a page or a whole site went on being argued film by film.