On 30 April 2015 several members of the German Bundestag opened an email that appeared to come from the United Nations. Its subject line said the conflict with Russia had left Ukraine's economy in ruins; the link inside led to what looked like a UN bulletin and quietly installed a trojan. Around 8 May staff in the parliament's administration reported that something was wrong, and on 12 May the domestic intelligence service, the BfV, warned the parliament's classified-information office that a foreign service had seen suspicious traffic leaving Bundestag computers. From 15 May the federal security office, the BSI, was working inside the building. The network was Parlakom: some 20,000 accounts for members, staff and constituency offices, among them the Bundestag office of the Chancellor, Angela Merkel.

About fifteen members' offices were touched, including that of a vice-president of the house, Johannes Singhammer, and two Social Democrats from the confidential panel that oversees the intelligence services' budget. Only a handful of machines were compromised at first; from those the attackers took administrative rights and spread. Attribution arrived in stages. In June Der Spiegel reported clues pointing at the SVR, Russia's foreign intelligence service. The Left Party meanwhile commissioned the researcher Claudio Guarnieri to examine its own servers; his report of 19 June described a remote-execution tool and a tunnelling backdoor compiled on 22 April 2015, calling home to an address rented through a reseller on French hosting. A neighbouring address carried a certificate for the Ukrainian foreign ministry's mail server. He named Sofacy — the group also called APT28.

The last outflow of data anyone could later date was 20 May, the last action attributed to the intruders 27 May; officials spoke of isolated outflows. On 11 June German reports said the BSI could no longer defend the network and that a new one would have to be built. Late that month more than a hundred thousand websites were put beyond reach of parliamentary machines as a quarantine. On 30 July the Bundestag's president, Norbert Lammert, wrote to members: the IT would be switched off on 13 August and back by the 17th, unless the Greek bailout talks got in the way. They did. The shutdown began on 20 August instead; on the 24th the rebuilt network returned, the internet back at half past eleven. At least sixteen gigabytes had gone — mailboxes, calendars, documents — and the rebuild was later put at €1.4 million.

The federal prosecutor opened an espionage investigation on 15 January 2016, and then four years passed. On 5 May 2020 the Süddeutsche Zeitung reported a warrant for Dmitry Badin, an officer of the GRU's Unit 26165 already wanted in the United States over the Democratic National Committee and the World Anti-Doping Agency (June 2016, July 2018). On 13 May Merkel told the Bundestag that Russian intelligence services were responsible and did not rule out consequences. On 22 October 2020 the European Union imposed travel bans and asset freezes on Badin, on the GRU's director Igor Kostyukov and on the unit itself; Britain announced matching sanctions the same day (October 2020). Russia denied all of it — Sergei Lavrov's answer to Merkel was that five years had passed and not one concrete fact had been produced — and Moscow barred German officials in December. Nobody has stood trial.

Also that month · 26 May

Questions already answered

On 26 May 2015 the Internal Revenue Service said criminals had used Get Transcript, its web feature for downloading past returns, to reach the records of about 100,000 taxpayers between February and mid-May, from some 200,000 attempts. The feature asked for a name, date of birth, Social Security number and filing status, then four multiple-choice questions drawn from credit files and supplied by Equifax. Brian Krebs observed that thieves cleared them more than half the times they tried; the answers were already circulating. The commissioner, John Koskinen, told the Senate Finance Committee in June that some 13,000 questionable returns for tax year 2014 had produced about $39 million in refunds. Then the count moved: on 17 August the IRS put the number reached at roughly 334,000, and on 26 February 2016 added 390,000 more, going back to January 2014, for a total past 724,000 (February 2016). The application stayed offline for thirteen months, returning in June 2016 behind a stiffer check. Elsewhere: CareFirst BlueCross BlueShield disclosed 1.1 million members on 20 May, from a June 2014 intrusion found that April; 3.9 million Adult FriendFinder profiles were circulating; and mSpy denied a breach its own customers confirmed.

Also that month · 13 and 20 May

The floppy drive and the export cipher

Two of the month's flaws sat beneath everything else. On 13 May Jason Geffner of CrowdStrike disclosed VENOM, CVE-2015-3456: an overflow in QEMU's virtual floppy-disk controller, code added in 2004 and inherited by Xen, KVM and VirtualBox, which let an attacker inside a guest reach the host underneath. It worked whether or not a virtual floppy drive had been attached, because the controller starts on every x86 guest and cannot be switched off: nobody had used a floppy in a decade, and nobody had read the code. Patches went out across the Linux virtualisation stack within days. On 20 May researchers from CNRS, Inria, Microsoft Research, Johns Hopkins, Michigan and Pennsylvania published Logjam, CVE-2015-4000: an attacker between browser and server could force a Diffie-Hellman exchange down to the 512-bit export grade that United States law had once mandated, and 8.4 per cent of the top million HTTPS domains still allowed it. Their larger warning was arithmetic: break one common 1024-bit prime, work they argued a state could afford, and passive eavesdropping opens on 18 per cent of those domains, 66 per cent of VPNs and a quarter of SSH servers.

India desk · May 2015

A searchable copy

On Thursday 28 May 2015 a hacker in Lahore who used the name Mak Man announced that he had been through Gaana.com, the music-streaming service owned by Times Internet, by way of a SQL injection flaw. He put up a searchable page: type in an email address and it returned the account holder's name, date of birth, MD5-hashed password and linked Facebook and Twitter profiles, alongside screenshots of the site's administration panel. His post said the database held more than ten million users; the counter on the page read 12.5 million. Both figures were his, and neither was ever confirmed. Gaana went offline behind a maintenance notice.

Satyan Gajwani, Times Internet's chief executive, answered in public the same day. He took the intention to be the demonstration of a vulnerability rather than the exposure of anyone, said the company was "100% on it", and asked for the page to come down; it came down. The hole, he said, was patched within an hour of its discovery, nothing beyond Gaana login credentials had been reached, and every password had been reset. He invited the hacker to help find other problems. The hacker said he had reported the flaw months earlier through the site's feedback form and been ignored, and that he had not stored a single row; Inc42 noted there was no evidence of that earlier report. Unsalted MD5 is not much of a defence against a rainbow table. No Indian law then required that users be told anything at all: CERT-In's six-hour rule was seven years away and a data-protection statute eight.

AI Tech desk · May 2015

Photographs nobody had to label

At Google I/O in San Francisco on 28 May 2015 the company launched Google Photos: storage offered without a stated limit for images resized to sixteen megapixels and video to 1080p, and, more to the point, a search box that answered questions about people, places and things in pictures nobody had tagged. The same keynote showed Now on Tap, a context reader built into the next version of Android that read whatever was on the screen and offered to look it up. Photos went on to become Google's default library, and the free tier closed on 1 June 2021; Now on Tap was folded into the Assistant within two years. Mid-May also brought a claim from Baidu that its Minwa system had cut ImageNet's classification error to 4.58 per cent, past the 4.82 Google had reported in March. On 1 June 2015 the paper was amended: too many submissions, from too many accounts. The organisers barred the team for a year. Ren Wu, who led it, denied wrongdoing.

Digital Guard desk · May 2015

The trap was not for researchers

On 4 May 2015 Cisco's Talos group described Rombertik, a credential stealer that hooked Internet Explorer, Firefox and Chrome to read what was typed before the browser encrypted it, arriving as a screensaver attached to spam. More than ninety-seven per cent of the packed file was junk, and it wrote a byte of random data to memory some 960 million times to outlast a sandbox. If a hash check on its embedded command address failed, it overwrote the master boot record, printed "Carbon crack attempt, failed" and looped; failing that, it encrypted the home folder with RC4. The press called it suicide malware. Graham Cluley answered on 6 May that the payload would almost never fire on an ordinary machine, and Symantec placed it differently again: Rombertik was a build of the Carbon Grabber kit, and the check punished criminals running cracked copies rather than researchers. On 29 May Raytheon closed its joint venture with Vista Equity Partners, paying $1.9 billion for Websense and taking 80.3 per cent of the result; it was renamed Forcepoint the following January.

⏳ Time capsule — May 2015

  • On 2 May Floyd Mayweather beat Manny Pacquiao on a unanimous decision at the MGM Grand Garden Arena in Las Vegas — about 4.6 million pay-per-view buys and a gross above $600 million, and, most who watched agreed, a dull fight.
  • India's heat wave had killed at least 2,500 people by early June, most of them in Andhra Pradesh and Telangana — the deadliest since 1979. Khammam reached 48 degrees on 24 May; three days earlier, road markings in Delhi were reported curling on softened asphalt.
  • On 22 May Ireland voted 62.07 per cent to 37.93 to allow same-sex marriage, on a turnout of 60.5 per cent; the result was declared the next day, the first time any state had legalised it by popular vote. The law took effect on 16 November.
  • On the morning of 27 May Swiss police arrested seven FIFA officials at the Hotel Baur au Lac in Zürich on a United States indictment naming fourteen. Sepp Blatter was re-elected president two days later and announced on 2 June that he would go.
Where it stands today — 2026

The long way to a name

A decade on, May 2015 reads as the month a legislature learned what it costs to be read, and how slowly the reading gets attributed. The Bundestag's answer travelled from a magazine's guess at the SVR, through a researcher's report on one party's servers, to a prosecutor's warrant in 2020 and a European sanctions list that October; the same unit had already been named in Washington over the Democratic National Committee (June 2016, July 2018), and Britain matched the European sanctions on the same day in October 2020. Moscow rejected the sanctions and barred German officials in return; nobody has stood trial. The remedy — switch everything off, rebuild, and let the federal security office inside a parliament's own network — was argued bitterly that summer, and has been the argument in other capitals since.

The rest ended in changed defaults. The IRS count that rose from 100,000 to 334,000 to 724,000 joins TalkTalk's four million, then fewer in the small literature of numbers that grow after the press conference; the knowledge-based questions it discredited depended on data that Equifax itself lost in 2017. Logjam finished export-grade cryptography in browsers and hurried short Diffie-Hellman groups into retirement. VENOM's warning, that a guest can reach its host through code nobody has read since 2004, returned at a deeper layer with Meltdown and Spectre. And the searchable page built out of Gaana's users was the shape of what Indian consumers would see again — through the card compromise of 2016 and after — until the DPDP Act of 2023 created a duty to tell them.