On 13 August 2016 a Twitter account with no history pointed at a Pastebin page and a GitHub repository, written in a broken English that read like a costume. The sellers called themselves the Shadow Brokers and said they had hacked the Equation Group — the name Kaspersky Lab had given, in February 2015, to the most capable espionage operation it had ever studied, and understood across the industry to mean the NSA. As proof they gave away roughly 300 megabytes of exploits and implants for the firewalls guarding corporate and government networks, filed under vendor names — Cisco, Fortinet, Juniper, the Chinese firm TOPSEC — and cryptonyms that read like a canteen menu: EXTRABACON, EGREGIOUSBLUNDER, JETPLOW. The rest, they wrote, would go to the highest bidder in bitcoin.

Verification took days. On 16 August Kaspersky's researchers reported that the archive used a peculiar implementation of the RC5 and RC6 ciphers, turning on the constant 0x61C88647 where public code uses its positive twin — a quirk seen only in Equation Group malware, and now in more than three hundred of the leaked files, too many to forge. On 17 August Cisco confirmed that EXTRABACON exploited a flaw in the SNMP code of its ASA firewalls that the company had not known existed, CVE-2016-6366, issuing advisories the same day. Fortinet's EGREGIOUSBLUNDER hit a FortiOS cookie parser fixed back in 2012. On 19 August The Intercept matched a sixteen-character tracking string from a classified NSA operator's manual in the Snowden archive to fourteen files in the dump.

The auction was the part nobody believed. A million bitcoin — about $568 million that week — for the encrypted second archive, bids non-refundable, losers to receive nothing. The money arrived in fractions of a coin. Days in, the address held roughly 1.6 bitcoin against an ask of half a billion dollars, and the sale was later abandoned for a crowdfunding appeal that also failed. Edward Snowden, tweeting on 16 August, offered a reading rather than a finding: circumstantial evidence, he judged, indicated Russian responsibility, and the release looked like a message that escalation in the attribution game could turn messy fast. Reuters reported the following month, citing unnamed officials, that investigators were examining whether an operator had left the toolkit on a remote staging server and failed to wipe it.

The month's one arrest was in Maryland, and was never connected to the group. On 27 August FBI agents searched a house in Glen Burnie, its garden shed and the car outside, took away Harold T. Martin III, a fifty-one-year-old Booz Allen Hamilton contractor who had worked in the NSA's hacking unit; prosecutors later described fifty terabytes carried home across two decades. The public heard nothing until 5 October, and the arrest belongs to that edition. Martin pleaded guilty and was sentenced to nine years in 2019, never charged in connection with the Shadow Brokers — and nobody else has been either. What August settled was narrower and worse than the mystery: the arsenal was genuine, one exploit in it still worked, and it was now a file anyone could download.

Also that month · Published 24 August

Three zero-days and one dissident

On 10 and 11 August, Ahmed Mansoor's iPhone received two text messages promising new secrets about detainees tortured in Emirati jails, each carrying a link. Mansoor — an Emirati human-rights defender and the 2015 Martin Ennals laureate, whom Citizen Lab had already found targeted with FinFisher's spyware in 2011 and Hacking Team's in 2012 — did not tap. He forwarded the messages instead. Working with the mobile security firm Lookout, Citizen Lab's Bill Marczak opened the link on a test handset and watched it jailbreak the phone through three previously unknown iOS flaws, one in the browser engine and two in the kernel, which the researchers named Trident; the payload identified itself internally as Pegasus, the product of the Israeli firm NSO Group. Apple was notified on 15 August and shipped iOS 9.3.5 on the 25th, the day after the report appeared. NSO said it sold only to authorised governments and did not operate the systems itself. It was the first Pegasus attempt documented against a named target.

Also that month · 119,756 bitcoin

The exchange that made everyone pay

On 2 August the Hong Kong exchange Bitfinex halted trading and said 119,756 bitcoin — about $72 million at that morning's price — had left customer accounts in roughly two thousand approved withdrawals. The wallets were meant to be the careful kind: two-of-three multisignature accounts co-signed by the custody firm BitGo, so that a stolen exchange key alone should not have moved anything. BitGo said its own servers had not been breached. Bitcoin fell about a fifth within hours. Bitfinex's remedy was to socialise the loss — every customer balance, touched or not, cut by a little over 36 per cent and replaced with BFX tokens, IOUs redeemable at a dollar, all of them honoured by April 2017. The thieves stayed unknown for five and a half years. In February 2022 US agents arrested a New York couple, Ilya Lichtenstein and Heather Morgan, and seized bitcoin then worth $3.6 billion — the largest financial seizure the Justice Department had ever made. Lichtenstein admitted the hacking; in November 2024 he was sentenced to five years and Morgan to eighteen months.

India desk · August 2016

Twenty-two thousand pages

On 24 August The Australian published extracts from what it said were 22,400 pages of DCNS documents on the Scorpène submarines being built for the Indian Navy at Mazagon Dock in Mumbai — six boats ordered in 2005 for about €2.4 billion, already years behind schedule. The pages, stamped Restricted Scorpene India, described what a submarine exists to conceal: the frequencies it radiates and the noise it makes at each speed, its diving depth, its magnetic and infrared signatures, its sensors and communications, with several hundred pages on the torpedo tubes alone. The newspaper said it had redacted the most sensitive figures before publishing. DCNS said French national security agencies would open an in-depth inquiry into the documents and those responsible, and pointed away from itself — towards a leak begun elsewhere, and towards commercial rivalry.

Manohar Parrikar, the defence minister, called it a case of hacking and asked the navy chief for a report. Days later, briefed by the navy, he said the leak was not a big worry — while adding that the ministry was assuming the worst case, and that pockets of concern remained. The navy's argument was that the boats had not yet run sea trials, so the signature that matters most could not be in papers drafted years earlier, and that what had appeared was redacted anyway; India asked Paris for the full picture. No Indian official has ever set out in public which of the 22,400 pages were authentic, or what they would be worth to a navy that might one day hunt those submarines. The programme continued: INS Kalvari was commissioned on 14 December 2017, and the sixth, INS Vagsheer, on 15 January 2025.

AI Tech desk · August 2016

Mayhem wins the all-machine hacking contest

On 4 August, alongside DEF CON in Las Vegas, DARPA staged the Cyber Grand Challenge: seven computers played capture the flag against one another, finding and patching flaws in unseen software, no human permitted to intervene. Mayhem, from the Carnegie Mellon spin-off ForAllSecure, crashed partway through and took the $2 million prize on its early lead; against DEF CON's human teams that weekend it finished last. Within a year the Pentagon had Mayhem under contract; DARPA re-ran the contest with large language models as the AI Cyber Challenge, decided at DEF CON in August 2025 for $4 million, by which time machines reading code for flaws was ordinary work. The rest was acquisition. Apple's purchase of Turi emerged on 5 August and Intel agreed on 9 August to buy Nervana Systems, neither naming a price (GeekWire put the first near $200 million, Recode the second above $400 million); Intel shut Nervana's chip line in 2020. On 18 August Uber bought the self-driving lorry start-up Otto for a reported $680 million, later cut by court filings to roughly a third.

Digital Guard desk · August 2016

A new Symantec, a smaller FireEye

On 1 August Symantec completed its $4.65 billion purchase of Blue Coat, made Blue Coat's Greg Clark chief executive and called the result the industry's largest pure-play cyber security company. A day later Microsoft's Windows 10 Anniversary Update made two changes: Limited Periodic Scanning, an opt-in letting Defender's engine run occasional scans behind a rival's antivirus on consumer machines, and Windows Defender Advanced Threat Protection for enterprises — the service that became Microsoft Defender for Endpoint and, within a decade, the rival every vendor priced against. Kaspersky Lab opened its first bug bounty the same day: $50,000 over six months for flaws in its consumer and endpoint suites. On 4 August FireEye reported quarterly revenue of $175 million, short of its own forecast, cut its full-year outlook and said 300 to 400 of its 3,400 staff would go; the shares fell about a sixth next day, two months into Kevin Mandia's tenure, and Mandiant's name would outlast FireEye's. Cisco, Fortinet and Juniper spent the rest of the month working through the Shadow Brokers' exploits and implants against their firewalls.

⏳ Time capsule — August 2016

  • The Rio Olympics ran from 5 to 21 August, and both of India's medals were won by women — Sakshi Malik's freestyle wrestling bronze on 17 August, the first by an Indian woman wrestler, and P.V. Sindhu's badminton silver two days later, after three games against Carolina Marín. At the closing ceremony, Japan's prime minister Shinzo Abe rose out of a green pipe dressed as Mario.
  • On 24 August the European Southern Observatory announced Proxima b, a planet of at least 1.3 Earth masses circling Proxima Centauri every 11.2 days — the nearest star to the Sun, 4.2 light-years away, and therefore the closest exoplanet that can exist.
  • On 30 August the European Commission ruled that Ireland's tax arrangements with Apple amounted to illegal state aid and ordered Dublin to recover up to €13 billion; the Irish government announced within days that it would appeal against being paid.
  • On 31 August Brazil's Senate voted 61 to 20 to remove President Dilma Rousseff from office over budget manoeuvres, ending thirteen years of Workers' Party government; Michel Temer, acting president since May, was sworn in the same day.
Where it stands today — 2026

The file that got out

Ten years on, nobody has been publicly identified as the Shadow Brokers, and the agency has never acknowledged the loss. The rest of the archive came out regardless. In April 2017 the group gave its Windows exploits away for nothing, and within weeks EternalBlue was carrying WannaCry through hospital networks and, that June, NotPetya through the world's shipping — which is why a failed auction on a text-sharing site now reads as the origin story of everything after it. Harold Martin served his sentence without the government ever tying him to the group. The argument this month started, over whether a state should keep flaws in the products everyone else depends on, produced a written American disclosure policy in November 2017 and is reopened after every leak since.

The Pegasus thread begins here and has never closed: the silent calls of May 2019, the leaked list behind the Pegasus Project, the zero-click FORCEDENTRY of September 2021, NSO's blacklisting by the United States that November, and a California court's finding in December 2024 that the company had broken American computer-crime law, with damages set by a jury the year after. Ahmed Mansoor, whose refusal to tap a link put the name in the public record, was arrested in 2017 and remains in an Emirati prison; his sentence was raised to fifteen years in July 2024. Bitfinex's coins came back worth many times what they were taken for. India's six Scorpènes are all at sea. The edge firewalls the Shadow Brokers exposed remain, in 2026, among the most attacked machines on any network.