The operation was three days old before anyone was told about it. Investigators moved against the GameOver Zeus network on 30 May 2014 and had it in hand within hours; the announcement came on 2 June, at a press availability at the Department of Justice in Washington, where Robert Anderson, an executive assistant director of the FBI, described what had been done. Court orders had authorised the bureau to redirect the botnet's communications to a substitute server under its own control, and separately to block the traffic that reached the domains distributing CryptoLocker. No content and no personally identifying information were captured in the process, Anderson said. GameOver Zeus was, in his words, "the most sophisticated botnet the FBI and our allies have ever attempted to disrupt".

It had been assembled in September 2011 as an update to the Zeus banking trojan, whose source code had leaked earlier that year. Its distinguishing feature was that it had no fixed centre to seize. Each infected machine kept a list of other infected machines and relayed instructions onward, so the operators sat behind a proxy layer built out of their own victims — an arrangement Dell SecureWorks described as a proxy network made of the botnet itself. Estimates put the population between 500,000 and one million computers at its height across 2012 and 2013. Behind it was a closed group of perhaps fifty people, mostly Russian and Ukrainian speakers, who rented access and recruited money mules; by June 2014 more than $100 million had gone out of bank accounts.

CryptoLocker reached people with no corporate account to drain. It first appeared on 5 September 2013 on machines the botnet had already taken, encrypting documents and photographs and putting a countdown on screen — seventy-two hours, or a hundred — against a demand that began near $100 and reached $500 by the spring, payable in vouchers or bitcoin. Miss the deadline and the price rose to ten bitcoin, still payable through a service they ran for it. The FBI said more than $27 million in ransoms had been paid in the first two months. The figure did not survive: Fox-IT's accounting, published on 6 August 2014, counted 545,146 infections to May 2014, found about 1.3 per cent of victims paid, and put nine months of receipts at roughly $3 million.

The disruption came with a warning that the network would probably be rebuilt in two weeks. The estimate held. Infections were down about a third by 11 July; a successor without the peer-to-peer layer appeared five weeks later and had 8,494 machines by 25 July. The indictment unsealed on 2 June named Evgeniy Mikhailovich Bogachev, who worked as Slavik and lucky12345, and the FBI added him to Cyber's Most Wanted; on 24 February 2015 a $3 million reward was posted, then the largest for a cyber criminal. He has never been arrested. What reached victims came later: in August 2014 Fox-IT and FireEye used recovered key material to open a service returning a private key against one uploaded encrypted file, chosen because it held nothing the owner minded strangers seeing.

Also that month · 10–18 June

A company killed in a night

The denial-of-service attack on Code Spaces, a British host of code repositories, began on 17 June 2014. While it ran, the company found messages in its own Amazon EC2 control panel: somebody held the credentials, wanted a large payment, and left a Hotmail address. Code Spaces changed the passwords. The intruder had already made spare logins, and started deleting — snapshots, storage buckets, machine images, the instances themselves. Most of its data, backups, configurations and offsite backups had been partially or completely deleted, the company's notice said; it could not operate beyond that point. The offsite copies were reachable from the same console as production, and the account had no second factor. The week was not unusual. Evernote was knocked offline on 10 June and Feedly on 11 June, which said it had been told to pay and refused; on 13 June a group calling itself Rex Mundi claimed 592,000 Domino's Pizza records from France and 58,000 from Belgium — names, addresses, passwords, delivery notes, preferred toppings — and asked €30,000 by the evening of the 16th. Domino's refused; no card data was involved. On 26 June Brian Krebs called it the year extortion went mainstream.

Also that month · 5–25 June

A handshake, a wire and a warrant

On 5 June 2014 the OpenSSL project disclosed CVE-2014-0224, a flaw in how the library handled the ChangeCipherSpec message. An attacker between two machines could force a session key of zero length, then read or alter everything that followed. Both ends had to be running vulnerable code — every version on the client side, only 1.0.1 and later on the server — and the defect had been present since at least 1998, older than most of the software that depended on it. It arrived eight weeks after Heartbleed, into an industry that had just promised itself the library would be read properly. A day later Vodafone published a law-enforcement disclosure report, saying that in some of the countries it operated in the authorities maintained permanent direct links into its networks, requiring no request at all. And on 25 June the Supreme Court decided Riley v. California, Chief Justice John Roberts writing, Justice Samuel Alito concurring separately: the police generally need a warrant to search a mobile phone taken from a person under arrest. The contents of a phone, the court held, are not the contents of a pocket.

India desk · June 2014

Eight hundred and eighteen machines

One clause of the court order mattered more to India than anything said from the podium in Washington: it authorised the bureau to pass the addresses of infected machines to computer emergency response teams around the world, and to service providers, so people at those machines could be told. India's share had already been measured once. Between 22 October and 1 November 2013 Dell SecureWorks' Counter Threat Unit took control of CryptoLocker's fallback domains and counted what called home: 31,866 unique addresses in ten days, of which 22,360 were in the United States, 1,767 in the United Kingdom and 818 in India. Nothing in Indian law in 2014 obliged anyone to tell a person their machine was infected, or a customer that their records had gone somewhere.

The month's Indian argument was about being watched rather than robbed. The Central Monitoring System, which the government had begun rolling out in April 2013, was meant to let the state intercept telephone and internet traffic without going through the operators at all; nine central agencies were empowered to intercept, carriers had been told to keep call records for at least a year, and India had no privacy law to set against any of it — as Human Rights Watch had warned when the system appeared, in a statement of 7 June 2013. The government that inherited it had been sworn in on 26 May, elected on minimum government and maximum governance. On 9 June the President's address to the new Parliament set out that government's programme, including expanding the National e-Governance Plan to reach government offices at every level. More was going online; still nothing required anyone to say when it failed. That came by direction in 2022, in CERT-In's six-hour rule, and by statute in 2023, in the DPDP Act.

AI Tech desk · June 2014

A Turing Test, Loudly Misread

On 7 June 2014 the University of Reading announced that a chatbot presented as a thirteen-year-old Ukrainian boy had convinced 33 per cent of thirty judges at a Royal Society event, and Kevin Warwick, who ran it, called Eugene Goostman "the first machine to pass a Turing test". The objections arrived within days. Turing's 1950 paper had spoken of an interrogator with no better than a seventy per cent chance of correct identification after five minutes — a different claim, differently measured — and critics including Gary Marcus noted that the persona did the work, a child writing in a second language being free to deflect whatever it did not understand. Murray Shanahan of Imperial College London thought the framing damaging to the field. Two arXiv postings that month passed without notice, both carrying Yoshua Bengio's name: the recurrent encoder-decoder on 3 June, and Ian Goodfellow's generative adversarial networks on 10 June. The theatre is forgotten; the papers became machine translation and the synthetic face.

Digital Guard desk · June 2014

Poisoned Updates and an Android First

The industry's research desks spent the month away from the Windows desktop. On 25 June 2014 ICS-CERT issued an alert, drawn from work by Symantec and F-Secure, on a remote access trojan called Havex: at least three industrial control system vendors, unnamed in the public alert, had had their own download pages turned into a delivery route, so an update fetched from a trusted supplier carried the malware with it. One payload enumerated OPC servers and catalogued vendor, version and running state — reconnaissance of a plant rather than of a computer. Symantec, publishing at the end of the month, gave the group espionage and persistent access as its objective, "with sabotage as an optional capability if required". Earlier, on 4 June, ESET had described Android/Simplocker, the first Android ransomware to encrypt files rather than merely lock the screen: photographs and documents on the memory card, AES, 260 hryvnia demanded in Russian. ESET called it a proof of concept, and it was — the key sat in the code. Both are ordinary in 2026, the poisoned update most of all.

⏳ Time capsule — June 2014

  • On 6 June the seventieth anniversary of the Normandy landings was marked at Ouistreham, on the stretch of coast codenamed Sword Beach, with nineteen heads of state and some eighteen hundred surviving veterans seated in stands built on the sand.
  • On 12 June the World Cup opened in São Paulo, Brazil beating Croatia 3–1 in the first match of the tournament.
  • On 19 June Felipe VI became King of Spain, following the abdication of his father, Juan Carlos I.
  • On 22 June Rani-ki-Vav, the stepwell at Patan in Gujarat, was inscribed on the UNESCO World Heritage List at the thirty-eighth session of the World Heritage Committee in Doha; the Great Himalayan National Park Conservation Area followed on 23 June.
Where it stands today — 2026

The keys that came back

June 2014 is where this archive's ransomware line begins, and the shape of the response has barely changed since. A court order, traffic redirected to a substitute server, victim addresses handed to national response teams, private companies doing the cleaning: the same template was used against Emotet, against Hive, against LockBit. So were its limits. The code was back inside five weeks in a reduced form, and Evgeniy Bogachev has not been arrested in the twelve years since; the reward posted in February 2015 is still unclaimed in 2026. Researchers who worked the case argued afterwards that the botnet's sideline in searching infected machines for government documents had bought its operator a degree of protection — an assessment, never a finding, and never confirmed by any government.

What actually returned people's files was not the takedown but the key material recovered alongside it, opened to the public in August 2014 at no charge. Almost nothing since has ended that way; the outbreak of May 2017 was halted by a sinkhole, not by decryption. The rest of the month hardened into rules. Code Spaces is still the case taught about cloud backups — a copy the credential reaching production can also delete is not a copy — and immutable, separately-held backups became the ordinary answer rather than the cautious one. Riley has held: in 2026 a phone taken at an arrest still needs a warrant. And in India the distance between fixing a hole and telling anyone closed by direction in 2022 and by statute in 2023.