On 19 May 2014 the United States Department of Justice announced the indictment of five officers of Unit 61398 of the Third Department of the People's Liberation Army. A grand jury in the Western District of Pennsylvania had returned thirty-one counts against Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu and Gu Chunhui — named twice over, as officers and by the handles they signed their work with: UglyGorilla, Jack Sun, WinXYHappy, hzy_lhx, KandyGoo. The Attorney General, Eric Holder, said these were the first charges ever brought against known state actors for infiltrating American commercial targets by cyber means. John Carlin, his assistant attorney general for national security, put it plainly: the department was exposing "the faces and names behind the keyboards in Shanghai".
The indictment was unusually concrete about what those keyboards had done. In 2010, while United States Steel was pursuing trade cases against Chinese steel companies, Sun sent spearphishing messages to its employees, some of them in the division working on one such case; three days later, the government alleged, Wang took the hostnames and descriptions of more than 1,700 of the company's servers. In the same year, while Westinghouse was building four AP1000 plants in China and negotiating the terms with a Chinese state-owned enterprise, Sun reached its network and took design specifications for the pipes, pipe supports and pipe routing inside the reactor buildings. The oldest conduct charged was older still: Alcoa announced a partnership with a Chinese state enterprise in February 2008, and about three weeks after the announcement a spearphishing message arrived. In April 2012, with Allegheny Technologies in a joint venture and a trade dispute with a Chinese state firm at the same time, Wen took network credentials for very nearly every employee of the company.
The fifth victim supplies the month's human detail. SolarWorld's American arm was fighting a trade case against Chinese solar manufacturers and knew nothing until the telephone rang. Ben Santarris, the company's United States spokesman, said the FBI called to tell them their email had been read; there had been no inkling of it before the call. What had gone, by the company's account, was the trade-case strategy itself, together with financials, costs, profit-and-loss statements, technology road maps and research. The unit was no mystery by then: Mandiant had described it in February 2013, down to a twelve-storey building off Datong Road in Pudong. What was new in May 2014 was five wanted posters, on a wall at the FBI's field office in Pittsburgh.
Beijing answered at once. China's foreign ministry called the charges fabricated and a serious violation of the basic norms of international relations, and suspended the working group the two countries had set up to discuss precisely this. Nobody was arrested. There is no extradition treaty with China, and the five stayed where they were. What the indictment produced instead was a form: attribution written the way a court requires it, with named defendants, dated acts and specific files, so the document could carry the argument in place of an anonymous briefing. Sixteen months later, on 25 September 2015, Barack Obama and Xi Jinping announced that neither government would conduct or knowingly support cyber-enabled theft of intellectual property for commercial advantage (September 2015).
One database, every customer
On 21 May 2014 eBay asked its users to change their passwords. A database had been compromised, the company said, holding customers' names, encrypted passwords, email addresses, physical addresses, telephone numbers and dates of birth. Three separate dates mattered, and eBay gave all three: the database was reached between late February and early March; the compromised employee log-in credentials that let the intruders in were first detected about a fortnight before the announcement; the announcement itself came on the 21st. A small number of staff credentials had been taken, the company said, and it had no evidence of unauthorised access to financial or credit card information, which was held separately and encrypted, no evidence of increased fraudulent activity on the site, and no evidence of any compromise of PayPal. The reset reached roughly 145 million active accounts — the largest single consumer notification anyone had yet had to make. Within a day advertisements appeared offering the stolen eBay list for bitcoin; Brian Krebs reported on 22 May that they were bait, and no seller ever produced the data.
A trojan, a forum and a warning page
Three pieces of software ended the month differently. On 19 May the Justice Department announced action against more than a hundred people who had bought or used Blackshades, a remote-access trojan sold on a hacking forum for about $40, which on the government's account reached more than half a million computers; the operation took in more than $350,000 in sales between September 2010 and April 2014. Almost a hundred arrests followed, with 359 searches and more than 1,100 storage devices seized; its co-creator Michael Hogue had been picked up in an FBI sting in June 2012. On 26 May Avast's chief executive, Vince Steckler, wrote that the company's own support forum had been broken into over the weekend, and that nicknames, user names, email addresses and hashed passwords were gone — fewer than 0.2 per cent of its two hundred million users, and no payment, licence or financial systems. On 28 May truecrypt.org began redirecting to a page saying the software might contain unfixed security issues and that development had ended; version 7.2, uploaded the day before and signed with the project's usual key, could only decrypt.
A new government, and no duty to tell
India spent the first half of May voting and the second half changing government. Polling ran in nine phases from 7 April to 12 May across an electorate of 834,082,814, of whom 66.44 per cent voted; counting on 16 May gave the Bharatiya Janata Party 282 seats and its alliance 336, and on 26 May Narendra Modi was sworn in as the country's fourteenth prime minister, with the SAARC heads of government watching. In the same fortnight eBay wrote to every account it held. Indian account holders learned of it the way everyone else did, from an American press release: nothing in Indian law then obliged a company to tell the people whose records had been taken. CERT-In had existed since 19 January 2004 under section 70B of the Information Technology Act; the direction that put a clock on reporting was still eight years away.
The new government's own machinery supplied the year's Indian security story six weeks later. On 2 July 2014 Google found unauthorised certificates for several of its domains, issued under the National Informatics Centre, whose intermediate certificates were trusted through India's Controller of Certifying Authorities. The CCA revoked them within a day; Google's Adam Langley noted that Chrome on Windows would have refused them anyway, because of public-key pinning, and Google said it saw no sign of widespread abuse. Digital India, which would put identity, payments and records online at national scale, launched on 1 July 2015. The duties May 2014 lacked arrived later: CERT-In's six-hour reporting direction in 2022, and the DPDP Act in 2023, which gave Indians a right to erasure of the kind the European court invented on 13 May that month.
A car with no steering wheel
On 27 May 2014 Chris Urmson, director of Google's self-driving car project, published photographs of a two-seat vehicle with no "steering wheel, accelerator pedal, or brake pedal", as he put it. Inside were seatbelts, a space for luggage, buttons to start and stop, and a screen showing the route; the speed was capped at 25 mph, and about a hundred were to be built. Sergey Brin showed the car the same day at the first Code Conference in Rancho Palos Verdes, where Gurdeep Pall, Microsoft's corporate vice president for Skype and Lync, put an English speaker and a German speaker on one call and let neural-network speech recognition translate between them, promising a Windows beta before the year was out. That beta arrived on 15 December 2014, in Spanish and English rather than German. The project became Waymo in December 2016; the pedal-less prototype, later known as Firefly, was retired in June 2017, capped at 25 mph to the last.
Symantec calls its own product dead
In an interview published in the first week of May 2014, Brian Dye, Symantec's senior vice president for information security, told the Wall Street Journal that antivirus "is dead" and that the company no longer regarded it as a moneymaker. He put the catch rate at about 45 per cent of attacks — his own estimate, and one rival vendors spent the following weeks disputing — and said growth had moved from prevention to detection and response. Endpoint products still supplied a large share of Symantec's revenue. Two events framed the claim. On 1 May, three weeks after support for Windows XP had formally ended, Microsoft issued an out-of-band fix for an Internet Explorer flaw already under attack and extended it to XP regardless, calling that an exception granted because the disclosure came so soon after the cut-off. On 9 May FireEye completed its purchase of nPulse Technologies, a network forensics firm: detection and response, bought rather than built. Symantec sold the enterprise half of itself to Broadcom in 2019.
⏳ Time capsule — May 2014
- On 10 May the Eurovision Song Contest, held in Copenhagen, was won by the Austrian entrant Conchita Wurst with "Rise Like a Phoenix".
- On 22 May the Royal Thai Army carried out a coup d'état, taking control of the country's government.
- On 24 May, at the Estádio da Luz in Lisbon, Real Madrid beat Atlético Madrid 4–1 after extra time for a record tenth European title, Sergio Ramos having headed an equaliser in the third minute of stoppage time to keep the match alive.
- On 28 May the writer Maya Angelou died at Winston-Salem, North Carolina, aged 86, forty-five years after I Know Why the Caged Bird Sings and twenty-one after she read at a presidential inauguration.
The indictment habit
Twelve years on, the posters are the point. None of the five has ever appeared in an American courtroom; the practical effect on their lives was to make travel awkward. The effect on everyone else was procedural. May 2014 established that a government could publish attribution in the form a court demands — named defendants, dated acts, specific files — and let it argue in place of an anonymous official. The habit held: three men from a Guangzhou firm charged in November 2017, two linked to the Tianjin State Security Bureau in December 2018, five more in September 2020, and the same instrument turned on the intrusion into an American political party of June 2016. Whether it deters is still argued. That it left a public record is not.
The month's other three aged plainly. eBay's loss — a handful of employee credentials, a move sideways, one database holding everything — is the shape of most breaches since, and 145 million was a record that did not last the decade. Blackshades showed what a forty-dollar program eventually cost its buyers: one creator had already been arrested in June 2012, and the doors came off across three continents nearly two years later. Buying malware leaves a customer list. TrueCrypt's silence was answered by work, not words: the audit its developers walked away from finished on 2 April 2015 and found no deliberate backdoors, and VeraCrypt carried the code forward, patching the Windows driver flaws disclosed in September 2015 that TrueCrypt never got. The warning page is still up. Nobody has ever said why.