The post went up on Pastebin on 18 September 2012, and it said in advance what it meant to do. A group calling itself the Izz ad-Din al-Qassam Cyber Fighters wrote that it would attack American banks in protest at a video circulating on YouTube that mocked the Prophet, and that it would go on until the film was gone. Bank of America's website began failing for customers that Tuesday; JPMorgan Chase's followed on the Wednesday. Neither bank would call it an attack. Chase said the slowness had been resolved by late afternoon, and a Bank of America spokesman said that customer and client information, the online banking platform and the related systems remained safe and secure. Nothing had been taken. Nothing could be reached either.
The second week kept to the schedule. The group posted again naming Wells Fargo, U.S. Bancorp and PNC, and said it would take down a different bank each day for eight hours. Wells Fargo's site began to fail at about two in the afternoon Eastern time on 25 September, U.S. Bank's at about half past eight the next morning, and PNC, publicly told it was next, said it had put additional security measures in place. What arrived was not the ordinary flood of hijacked home computers. Researchers who examined the traffic identified a PHP attack script known as itsoknoproblembro running on compromised web servers — machines in data centres, with far more bandwidth behind them than any domestic line. Peaks were reported at around a hundred gigabits a second.
Attribution came quickly and stayed unproven. On C-SPAN's Newsmakers, recorded on 21 September, Senator Joseph Lieberman said he did not believe these were just hackers and that the work had been done by Iran and the Quds Force; American officials said much the same to reporters without their names attached, and the Washington Post reported on 21 September that officials suspected the Iranian government of sponsoring the attacks. Iran denied it. So did the group, which said it depended on no government and had merely wanted to protest against the film. None of it was evidence, and none of it was tested that year. What the public had that month was a claim of responsibility, a row of denials, and a set of bank websites that would not load.
The campaign ran in phases: the first to late October, a second from 10 December to the end of January 2013, a third from March. Then, on 24 March 2016, a grand jury in Manhattan indicted seven Iranian men who prosecutors said had worked for two Iran-based companies, ITSecTeam and Mersad, for the Iranian government and the Revolutionary Guard. The charge sheet put it at 46 victims and more than 176 days of attacks from about December 2011 to May 2013 — sporadic at first, near-weekly from September 2012, Tuesdays to Thursdays in business hours — with peaks near 140 gigabits a second, hundreds of thousands of customers locked out and tens of millions in remediation. None of the seven has been arrested, and no court has weighed the allegations.
Twelve million, and a publisher in Florida
The claim arrived overnight on 3 and 4 September 2012: AntiSec published about a million Apple device identifiers and said they came from a file of more than twelve million taken in March from the laptop of an FBI supervisory special agent. The FBI said on 4 September there was no evidence a bureau laptop had been compromised, or that it had sought or obtained such data; Apple said the next day that the FBI had never asked and Apple had never supplied. Then David Schuetz, a consultant at the Intrepidus Group, worked through the file and found the same identifiers repeating under device names belonging to a single company. On 10 September BlueToad, a digital publishing firm in Florida, said the data was its own, at a correlation its chief executive, Paul DeHart, put at ninety-eight per cent. The same day GoDaddy went dark for about six hours and an account on Twitter claimed it; the company said afterwards that internal network events had corrupted router data tables. The month's one uncontested exposure had nobody claiming it: on 25 September a researcher, Radu Drăgușin, published what he had found a week earlier and had reported to IEEE before going public — web server logs left on a public FTP site, some 100,000 members' usernames and passwords in plain text among them.
Infected before the box was opened
Microsoft's Digital Crimes Unit bought twenty computers from PC malls in several Chinese cities. All twenty ran counterfeit Windows, and four came with malware already on them — three dormant, one running a family called Nitol that woke as soon as the machine reached the internet, able to join a denial-of-service flood, spread by USB drive and open the way for more. Microsoft placed the infection in the distribution chain rather than at any factory. On 10 September a federal court in Virginia granted an ex parte restraining order against Peng Yong, operator of the Chinese domain 3322.org, which carried nearly seventy thousand malicious subdomains and over five hundred strains of malware; Operation b70 was unsealed on 13 September and settled on 2 October, the bad subdomains routed to a sinkhole. In between, an Internet Explorer flaw already in use against real targets drew an advisory on 17 September, a stopgap fix on the 19th and an out-of-band patch on the 21st. On 27 September Adobe said a build server with access to its code-signing service had been compromised and two malicious utilities signed with a valid Adobe certificate; it said it would revoke, on 4 October, everything signed after 10 July. A signature meant less than it looked, as February 2013 would show again.
The drawings and the section
The first information report was eight months old: registered in January 2012 over cartoons displayed at an anti-corruption rally in Mumbai late in 2011 — the national emblem's lions drawn as wolves, Parliament as a lavatory — and it cited sedition under section 124A of the Indian Penal Code, section 2 of the Prevention of Insults to National Honour Act, 1971, and section 66A of the Information Technology Act. Aseem Trivedi, a cartoonist of twenty-five who had campaigned openly, presented himself at the Bandra-Kurla Complex police station on 8 September 2012, and a metropolitan magistrate sent him to judicial custody the next day. He said he would not ask for bail while the sedition charge stood. On 11 September the Bombay High Court ordered his release on a personal bond of five thousand rupees, and he left Arthur Road jail the following day. The state's home minister said the government would review the case and the charge.
In October the state's advocate general filed an affidavit dropping the sedition charge; the other two continued, and the High Court later held they reached only some of the cartoons. That court used the case on 17 March 2015 to set conditions on invoking sedition at all, and a week afterwards the Supreme Court struck section 66A down entirely (March 2015). The month's quieter half sat elsewhere: the group of experts on privacy chaired by Justice A.P. Shah was finishing its work that September, and on 16 October gave the Planning Commission a report proposing nine privacy principles, a general law and privacy commissioners. India then had neither a data protection statute nor a duty to disclose a breach; the duty came by direction in 2022, the statute in 2023, and the constitutional question beneath them waited until August 2017.
California's driverless-car law, signed at Google
On 25 September 2012 Governor Jerry Brown signed SB 1298 at Google's headquarters in Mountain View. Senator Alex Padilla's bill let driverless cars be tested on California's public roads with a licensed, bonded operator in the driver's seat, and gave the Department of Motor Vehicles until 1 January 2015 to write the rules; Nevada had legislated first. Sergey Brin, wearing Google Glass, said the years before ordinary people would experience such cars could be counted "on one hand". On 10 August 2023 the state let Waymo and Cruise charge for driverless rides at any hour across San Francisco, and in October suspended Cruise's permits after one of its cars dragged a pedestrian. A week before the signing, on 18 September, Rodney Brooks's Rethink Robotics unveiled Baxter: a two-armed factory robot with a screen for a face, built to work beside people without a safety cage, taught by a worker guiding its arms rather than by programming, and priced at $22,000. Sales fell short, and Rethink closed in October 2018 after a buyer backed out.
Sophos flags its own updater as malware
Kris Hagerman had been Sophos's chief executive for a fortnight, named on 4 September 2012 in succession to Steve Munford, when the company's software turned on its own updater. On 19 September a detection identity SophosLabs had released for its Live Protection system began reporting updater programs as malware under the name Shh/Updater-B, the updaters for Java and Flash among them, and Sophos's own. Only Windows was affected; a correction went out that evening but could not reach computers set to quarantine or delete what they found, because the component that fetched fixes was the one removed. Many administrators repaired machines one by one, and some customers found other software disabled too. Sophos called the issue very serious and promised a full investigation; Hagerman apologised, saying that in twenty-five years the company had "never experienced an incident quite like this". The hazard, a routine update reaching every customer at once and breaking what it was meant to protect, returned at far greater scale in July 2024, when a CrowdStrike content update crashed millions of Windows computers.
⏳ Time capsule — September 2012
- On 9 September the twenty-second flight of India's Polar Satellite Launch Vehicle left the first launch pad at Sriharikota — counted as the space agency's hundredth mission — carrying France's SPOT 6 and a fifteen-kilogram Japanese micro-satellite, PROITERES, to a 655-kilometre polar orbit.
- On 10 September, in a final pushed to the Monday by weather, Andy Murray beat Novak Djokovic at the US Open in four hours and fifty-four minutes: the first British man to take a Grand Slam singles title since Fred Perry in 1936.
- On 25 September China commissioned its first aircraft carrier, the Liaoning — a hull laid down in Soviet Ukraine in 1985, bought unfinished in 1998 and rebuilt at Dalian.
- On 28 September Apple's chief executive, Tim Cook, apologised for the Maps application that had shipped with iOS 6 nine days earlier, and suggested customers use rivals' maps until it improved.
The cost of being reachable
A hundred and forty gigabits a second was extraordinary in 2012 and is unremarkable in 2026. What September began was the industry's move from treating a flood as an outage to treating it as weather: banks bought scrubbing capacity they had never budgeted for, shared indicators through their sector's exchange, and stopped assuming a public website could be defended by the people who built it. The records kept falling — browsers made into a flood against a code repository in March 2015, home cameras in September 2016 — and the 2016 indictment charged one of the seven with something else entirely: obtaining access in 2013 to the control system of a small flood-control dam at Rye Brook, New York, whose sluice gate happened to be disconnected for maintenance.
The rest of the month resolved more neatly. Apple announced in March 2013 that from 1 May the App Store would refuse any app reaching for a device's permanent identifier; the claim about an FBI laptop was never substantiated, and the data had come from a publisher of digital magazines. The utilities signed on 27 September were early proof that a certificate attests only that someone reached a build server, a problem running through February 2013 and still opening doors in April 2023. What Microsoft found on twenty new computers in Chinese shops was an insecure supply chain, four years before the phrase became ordinary. In India, section 66A was struck down in 2015 and went on being used, and the privacy principles of that October waited eleven years for a statute.