On the night of Sunday 5 July 2015 the Twitter account of Hacking Team, a Milan company that sold governments a spyware suite called Remote Control System, began announcing its owner's undoing. "Since we have nothing to hide, we're publishing all our e-mails, files, and source code," the first message read, and links followed to more than 400 gigabytes of the company's own archive: invoices, contracts, years of internal mail, the source of the product sold as Galileo and Da Vinci, and the exploits that made it work. An engineer, Christian Pozzi, insisted on his own account that the torrent contained a virus and that what it showed was false; his account was taken shortly afterwards. On 8 July WikiLeaks put more than a million of the emails into a searchable index.
The files answered a question the company had deflected for a year. A United Nations panel monitoring the Sudan arms embargo had asked in 2014 whether Hacking Team sold to Khartoum; in January 2015 the company replied that it was not currently selling there, and that its product was not a controlled weapon. The archive held €960,000 paid in 2012 by Sudan's National Intelligence and Security Service. Reading the same files on 7 July, The Intercept counted Ethiopia, Bahrain, Egypt, Kazakhstan, Morocco, Russia, Saudi Arabia, Azerbaijan and Turkey among the customers, and found an internal argument over Ethiopia's €700,000 contract — suspended after a journalist was targeted, then reinstated on richer terms. Four months earlier Citizen Lab had reported that staff of the exiled broadcaster ESAT, working in the United States, were sent the suite three times, and that the same operator was still being supplied with updated builds in November 2014.
The criminal economy read the archive faster than the reporters did. On 6 July a researcher posted a working Flash Player exploit found in the files, together with the company's own instructions for using it. Malwarebytes' researcher Jerome Segura found it folded into the Angler and Neutrino kits the next day; by 8 July, when Adobe patched the flaw as CVE-2015-5119, three kits were serving it to ordinary web users, and the number had doubled by 10 July. A third Flash zero-day from the same archive was reported on 13 July and closed alongside the second the next day. On 20 July Microsoft shipped an out-of-band fix, MS15-078, for a Windows font-handling flaw that researchers at FireEye and Google's Project Zero had also found in the leak.
The intrusion was claimed by a persona calling itself Phineas Fisher, which had taken about 40 gigabytes from FinFisher's maker, Gamma, the year before and would publish a how-to in 2016 describing entry through a zero-day in a network appliance. It has never been identified, and the claim has never been tested in court. The leak landed inside a live argument about the trade: Google and much of the security industry objected, in a comment period that closed on 20 July 2015, that Washington's proposed implementation of the Wassenaar Arrangement's December 2013 controls on intrusion software was drawn so broadly it would leave billions of users, in Google's phrase, persistently less secure; Commerce agreed within the fortnight to withdraw the rule and write it again. Italy revoked Hacking Team's licence to sell outside Europe in 2016; InTheCyber bought what remained in April 2019 and renamed it Memento Labs. The thread runs on to Pegasus (August 2016) and the Pegasus Project (July 2021).
A Jeep on the highway
On Tuesday 21 July Wired published Andy Greenberg's account, under the headline "Hackers Remotely Kill a Jeep on the Highway—With Me in It", of driving a 2014 Jeep Cherokee while Charlie Miller and Chris Valasek worked it remotely through the cellular connection of its Uconnect head unit, carried on Sprint's network. The demonstration ran from the ventilation and the radio to the transmission, which they cut while he was on the highway; at lower speeds, Wired reported, they could reach the braking and the steering. Miller said afterwards that they could as easily have done the same to one of the hundreds of thousands of vulnerable vehicles on the road. Chrysler had shipped a patch on 16 July, installable by USB stick or at a dealership. On Friday 24 July Fiat Chrysler recalled about 1.4 million vehicles — Rams and Vipers, Grand Cherokees and Cherokees, Durangos, the Chrysler 200 and 300, the Charger and the Challenger — said network-level blocking had been tested and implemented on 23 July, and added that it was unaware of any real-world incident. The regulator said it would look into the matter. Senators Markey and Blumenthal introduced the SPY Car Act the day the story ran; it never became law.
Nine hundred and fifty million phones
On 27 July Joshua Drake of Zimperium disclosed flaws in libstagefright, the media library Android used to parse video and audio, reachable by a multimedia message the phone processed before anyone opened it. Zimperium put the exposure at some 950 million devices, about 95 per cent of Android, from version 2.2 to 5.1.1 — an estimate rather than a count, and the figure that travelled. Drake had told Google in April; Google applied fixes to its source repositories soon after, which is not the same thing as reaching a phone, and the full detail waited for Black Hat on 5 August. The lasting consequence was a calendar: the Nexus bulletin of 13 August 2015 opened the monthly Android security release that still arrives in 2026. Around it, a crowded month. On 9 July the Office of Personnel Management raised its count of stolen background records to 21.5 million people (June's edition) and its director, Katherine Archuleta, resigned the next day. Windows Server 2003 left support on 14 July. On 15 July the FBI and Europol announced the seizure of the Darkode forum, with 28 people arrested across twenty countries; it was back inside a fortnight. On 19 July Brian Krebs reported that a group calling itself the Impact Team had taken Ashley Madison's databases and demanded the site's closure — the dump came in August.
Digital India, and the shopping list
On 1 July 2015 Narendra Modi launched Digital India, a programme resting on three promises: digital infrastructure as a utility available to every citizen, governance and services on demand, and digital empowerment. Industry priced it on the spot, with pledges reported at ₹4.5 lakh crore and eighteen lakh jobs, led by ₹2.5 lakh crore from Mukesh Ambani's Reliance. The security question was raised at once, and by Indians: digital-rights lawyers asked why Aadhaar-based authentication was being extended to service after service while the gaps in the country's data-protection framework went unaddressed — a question already before the Supreme Court, which the following month restricted Aadhaar to a short list of voluntary uses. It was a fair question in 2015, and it stayed open for another eight years.
The other half of the picture arrived within the week. Among the Hacking Team emails WikiLeaks indexed on 8 July, The Citizen counted about three thousand touching India from August 2011 onwards: the Israeli firm NICE Systems and the Indian house SEMCO acting as resellers; the Cabinet Secretariat, the Research and Analysis Wing and the Intelligence Bureau in the correspondence; state intelligence units in Delhi, Mumbai, Andhra Pradesh and Gujarat, and police in Chennai, Hyderabad and Kolkata; West Bengal's police seeking Galileo after the Bardhaman blast. Dawn's reading of the same archive added a February 2014 webinar for RAW, the NIA, the IB and the NTRO, a request on 12 June 2015 through a consultancy for the price of mobile interception licences — put at about a million dollars — and a demonstration pencilled in for Hyderabad in early July, the week of the launch. No completed sale to an Indian agency was established in the files — no signed contract, invoice or licence for an Indian buyer appears among them — and no Indian agency has ever acknowledged buying the suite. Six years later a different vendor's list reached Parliament (July 2021).
Meaningful human control, in Buenos Aires
On 28 July 2015, at the opening of the twenty-fourth International Joint Conference on Artificial Intelligence in Buenos Aires, the Future of Life Institute published an open letter seeking a ban on offensive autonomous weapons beyond meaningful human control, and calling them the third revolution in warfare, after gunpowder and nuclear arms. More than a thousand AI and robotics researchers had signed by then, among them Stephen Hawking, Elon Musk, Steve Wozniak, Noam Chomsky and DeepMind's Demis Hassabis; the institute's total has since passed thirty thousand. It joined an argument rather than starting one: the Campaign to Stop Killer Robots dated from 2013 and states had been debating the matter at the Convention on Certain Conventional Weapons since 2014; the General Assembly did not vote until 2023. On 1 July the institute had named 37 teams to share about seven million dollars of Musk's money, one of them on meaningful human control; the same day Google published the DeepDream code, and the hallucinated dogs and eyes of an image classifier became the first machine-made pictures to circulate well beyond the field.
The scanner that came with Windows
Windows 10 arrived on 29 July 2015, free for a year to Windows 7 and 8.1, and every copy shipped with a scanner. Windows Defender ran by default, stepping aside for a third-party product and returning when it was removed; Enterprise editions added Device Guard and Credential Guard. More consequential was the Antimalware Scan Interface, which let PowerShell and the Windows Script Host pass content to whichever engine was installed, Microsoft's or a rival's, before it ran. Defender was among the weaker products of the day, and the objections came later, Kaspersky's complaints to Russian, German and European regulators arriving in 2016 and 2017 and withdrawn once Microsoft agreed to give vendors more warning. On 13 July CrowdStrike closed a $100 million round led by Google Capital, its announcement arguing that traditional antivirus was rapidly losing effect. Bitdefender ended the month explaining its own breach: an extortionist demanded $15,000 and published business credentials held in plain text, which the company said touched under one per cent of its business customers. All of them spent it patching the Milan archive's Flash zero-days.
⏳ Time capsule — July 2015
- On 11 July, in a Wimbledon women's doubles final halted at five-all in the third set because the light had gone and finished under the closed Centre Court roof, Martina Hingis and Sania Mirza beat Ekaterina Makarova and Elena Vesnina 5–7, 7–6, 7–5; Mirza became the first Indian to win a women's doubles major.
- On 14 July at 11:49 UTC, nine and a half years after launch, NASA's New Horizons passed about 12,500 kilometres above Pluto — the first spacecraft to reach the dwarf planet.
- The same day, in Vienna, Iran and the P5+1 reached the Joint Comprehensive Plan of Action: limits and inspections on Iran's nuclear programme in exchange for relief from sanctions. The United States withdrew from it in 2018.
- On 27 July A. P. J. Abdul Kalam, India's former president, collapsed a few minutes into a lecture at IIM Shillong and died of a cardiac arrest, aged 83; he was buried at Rameswaram on 30 July.
The archive that never closed
A decade on, the Hacking Team files remain the surveillance trade's one complete primary source: a vendor's client list, its invoices and its excuses, readable by anyone with a torrent client. The company did not survive as itself — Italy took away its licence to sell outside Europe in 2016, and InTheCyber bought the remains in April 2019 and renamed them Memento Labs — but the trade did. The following August an unanswered text message on a dissident's iPhone exposed NSO Group's Pegasus (August 2016); in July 2021 the Pegasus Project published a leaked list of some fifty thousand numbers, Indian journalists, ministers and opposition politicians among them. Phineas Fisher was never identified. Flash Player, whose zero-days the archive scattered into criminal kits within a day, was switched off for good on 31 December 2020.
The month's other stories ended in habits rather than verdicts. The SPY Car Act never became law, but the recall of 24 July 2015 established that a software flaw could pull 1.4 million cars back to the dealership, and updating a vehicle over the air stopped being exotic. Stagefright left a calendar that outlived the bug: the monthly Android bulletin, still arriving eleven years on. And the promise made from a Delhi stage on 1 July is the one this desk keeps auditing. Digital India built the rails — Aadhaar-linked services, UPI, cheap data — while the data-protection law those rails implied waited for the DPDP Act of 2023, and the fraud economy that grew on them became a beat of its own (Fraud Watch).