On 31 August 2014 a set of photographs began appearing on the imageboard 4chan and on a smaller site devoted to the same trade, and moved within hours to Imgur, Reddit and Tumblr. Close to five hundred explicit images and videos were posted in all, taken from the private accounts of more than a hundred people, almost all of them women. A subreddit created to gather them took on over a hundred thousand subscribers in a single day; Reddit's administrators closed it on 7 September, citing copyright notices and the staff time the traffic consumed. The press reported the month as a leak and adopted a coinage built on a crude joke. One of the women whose photographs were taken said afterwards, publicly, that it had been a sex crime.
Two separate things were confused in that first week. On 30 August a proof-of-concept named iBrute had been posted to GitHub, showing that Apple's Find My iPhone endpoint accepted password attempts without limit, so a short list of common passwords could be run against an Apple ID until one fitted. Apple closed that hole on 1 September. On 2 September, after more than forty hours of investigation, the company said certain celebrity accounts had been compromised by "a very targeted attack on user names, passwords and security questions", and that none of the cases it had examined came from a breach of an Apple system. Both things can be true at once. The accounts were opened with their owners' own credentials, which is a different problem, and a worse one.
The prosecutions, when they came, described something duller and far more ordinary than a break-in. Ryan Collins, of Lancaster, Pennsylvania, ran a phishing scheme from November 2012 until the first days of September 2014: messages built to look as though Apple or Google had sent them, asking the recipient to confirm a username and password. He reached at least fifty iCloud accounts and seventy-two Gmail accounts, most belonging to women in the entertainment industry, and in some cases commercial forensic software — the kind sold to police for emptying a handset — was used to pull down a whole iPhone backup. Collins pleaded guilty in March 2016 and was sentenced that October to eighteen months. Investigators said they found no evidence tying him to the posting of any image.
Four more men were convicted over the following years, and none of them was shown to have posted anything either: Edward Majerczyk of Chicago, nine months in January 2017; Emilio Herrera, sixteen months in March 2018; George Garofano of Connecticut, eight months on 29 August 2018; and Christopher Brannan, a Virginia schoolteacher whose victims included minors, thirty-four months in March 2019 on charges including aggravated identity theft. Apple's answer was to make the account noisier — alerts when a device was restored from a backup or when an account was reached through the web, and a harder push towards two-step verification. What it did not touch in 2014 was the model underneath, in which a woman's mother's maiden name stood between a stranger and every photograph she had ever taken.
Heartbleed, four months late
Community Health Systems, a chain then running 206 hospitals across 29 states, filed an 8-K with the Securities and Exchange Commission on 18 August 2014 saying data on about 4.5 million patients had been taken: names, addresses, dates of birth, telephone numbers and social security numbers, but no card, clinical or medical records. Mandiant, brought in to investigate, assessed that an advanced persistent threat group originating from China was responsible; researchers later filed the activity under APT18. The Heartbleed connection came from outside the company. Dave Kennedy of TrustedSec said, citing three sources close to the investigation, that the entry point had been a Juniper appliance still vulnerable to the OpenSSL flaw, its memory giving up credentials that were then used over the corporate VPN. The company itself never confirmed that. The three dates are worth keeping apart: the intrusions were placed in April and June, the FBI had warned the chain's shared-services arm in April, and the disclosure came in August — four months after a patch existed.
A number and the firm selling it
On 5 August the New York Times reported that Hold Security, a small firm in Milwaukee, had found a Russian group holding 1.2 billion unique username-and-password pairs, gathered by botnet from more than 420,000 websites through SQL injection. No victim site was named, no sample was published, and nothing was checked by anyone else. Within a day the argument had shifted to the firm's business model, which offered organisations a paid service to learn whether they appeared in the data; the company answered that the first thirty days were free, and its founder, Alex Holden, told Forbes on 12 August that the coverage was damaging his business. The figure was never independently confirmed. Two smaller and entirely checkable things happened in the same fortnight. On 18 August Nextgov published an inspector-general file showing that about 215 employees of the US Nuclear Regulatory Commission had been sent a credential-harvesting email pointing at a Google spreadsheet, and a dozen had filled it in. On 20 August UPS said card-stealing malware had been running in 51 franchised stores across 24 states.
Two directions of traffic
On 5 August 2014 ThreatConnect published research carried out with FireEye on a campaign it called Operation Arachnophobia, running since early 2013 and aimed at Indian entities. The tool was a custom backdoor, BITTERBUG, delivered inside documents dressed as material on Indian affairs and built to collect Office files from a desktop. Early samples carried build paths containing the string Tranchulas, the name of an Islamabad security company. The researchers were careful about what that proved: a name in a debug path is an association, not authorship, and anyone can write a name into a path. The firm rejected the inference. The work was also read against Operation Hangover, disclosed in 2013 and attributed to Indian actors — which is the point: the subcontinent's traffic already ran both ways.
In the same month India was laying down the surface it would have to defend. The Digital India programme was presented to the Union Cabinet on 20 August 2014, to be launched on 1 July 2015 (see June 2015). On 28 August, announced a fortnight earlier from the Red Fort, the Pradhan Mantri Jan Dhan Yojana opened: roughly fifteen million accounts on the first day, and 18,096,130 in the week from 23 to 29 August, a Guinness record for the most bank accounts opened in a week. Each carried a RuPay debit card with one lakh of accident cover. It was financial inclusion at a scale nothing had attempted, producing millions of first-time cardholders with no experience of a PIN or a fraud line. What that surface came to carry is the subject of the India desk's work on digital arrest scams, and of the deadline CERT-In imposed in 2022.
A Million Neurons, Seventy Milliwatts
On 8 August 2014 Science carried a paper from IBM and Cornell describing TrueNorth, a processor holding 4,096 cores, a million programmable neurons and 256 million configurable synapses across 5.4 billion transistors, fabricated on Samsung's 28-nanometre process and drawing about seventy milliwatts in operation — a power density IBM put at a ten-thousandth of a conventional microprocessor's, after some six years of work under DARPA's SyNAPSE programme. Three weeks later IBM announced Watson Discovery Advisor, its first Watson cloud service, pitched at research teams on the argument that a scientific paper now appeared every thirty seconds; Baylor College of Medicine, Johnson & Johnson and the New York Genome Center were named as early users. Earlier, on 3 August, Elon Musk had recommended Nick Bostrom's Superintelligence and called artificial intelligence "potentially more dangerous than nukes". Of the three, only the last compounded. The decade's compute went to graphics processors, neuromorphic silicon stayed a research line, and IBM sold the Watson health business in 2022.
Two Names Off Beijing's List
On 3 August 2014 the People's Daily reported that China's central procurement agency had struck Symantec and Kaspersky Lab from its approved list of security software, leaving five domestic suppliers. Both firms disputed the scope rather than the fact: Symantec said the list covered only certain types of procurement and that it still won Chinese government work; Kaspersky said the restriction reached only institutions funded from the central budget. The products themselves fared no better that week. On 4 August US-CERT warned that every version of Symantec Endpoint Protection Client 11.x and 12.x running Application and Device Control carried a privilege-escalation flaw in its sysplant driver, found by Offensive Security during a client engagement; a working exploit followed the next day. And the Backoff advisory, issued on 31 July and updated on 22 August, when the Secret Service put the number of affected American businesses above a thousand, recorded that the malware family was "largely undetected by anti-virus (AV) vendors". Three years later Washington would order Kaspersky off its own federal networks, the same argument in other hands.
⏳ Time capsule — August 2014
- On 6 August the European Space Agency's Rosetta probe reached comet 67P/Churyumov–Gerasimenko after more than ten years in flight, the first spacecraft to orbit a comet.
- On 8 August the World Health Organization declared the Ebola outbreak in West Africa a public health emergency of international concern; the recorded death toll passed a thousand on 12 August.
- On 13 August, at the opening of the International Congress of Mathematicians in Seoul, Maryam Mirzakhani was awarded the Fields Medal, the first woman and the first Iranian to receive it.
- The ice bucket challenge ran through the month: the ALS Association reported $41.8 million from more than 739,000 new donors between 29 July and 21 August, against $19.4 million across its whole financial year to January 2013, and passed $100 million by 29 August.
The word that did the damage
A decade on, the technical half of August 2014 has largely been closed. The security question has gone as a primary control at every large provider, replaced first by two-factor prompts and then by passkeys. Apple went further than it promised at the time: Advanced Data Protection, announced on 7 December 2022 and available worldwide from 23 January 2023, applies end-to-end encryption to iCloud Backup and Photos — the exact store that was emptied. The legal half took much longer. It was 19 May 2025 before the United States enacted the Take It Down Act, obliging covered platforms to remove non-consensual intimate images within forty-eight hours of a valid request; enforcement against services began on 19 May 2026. Eleven years, to make removal a duty rather than a favour.
The other August stories aged into shapes the archive now recognises. Community Health Systems' loss kept growing after the month closed: the count stood at 6,121,158 people across 237 entities when the chain's shared-services arm settled with the Department of Health and Human Services' Office for Civil Rights in September 2020 for $2.3 million, and with a class settlement of $3.1 million in 2019 and a multi-state agreement of $5 million the bill reached roughly $10.4 million — all of it downstream of a patch available since April. Hold Security's 1.2 billion was the first of a genre these pages keep meeting, the enormous unverifiable figure released beside a subscription. And the ledger India opened that month is the one the DPDP Act of 2023 was written to balance.