The Democrats' convention was to open in Philadelphia on Monday 25 July 2016. On the Friday before, 22 July, WikiLeaks published 19,252 emails and 8,034 attachments taken from the accounts of seven staff at the Democratic National Committee, spanning January 2015 to May 2016. The intrusion was not news: the DNC had disclosed it on 14 June, when CrowdStrike named two Russian intelligence groups, and a persona calling itself Guccifer 2.0 had appeared a day later claiming to be a lone Romanian (June). What was new was the reading. The committee's chief financial officer had suggested raising Bernie Sanders's religious beliefs before the Kentucky and West Virginia primaries; the chair had called his campaign manager "a damn liar"; and the dump carried, unredacted, the Social Security and credit-card numbers of ordinary donors.
The consequences arrived in order. On Saturday 23 July party officials said Debbie Wasserman Schultz would neither gavel the convention open nor address it, and Marcia Fudge of Ohio was named to chair it in her place. On Sunday she announced she would resign when the convention closed. On Monday morning she was heckled at breakfast by her own Florida delegation, and the FBI confirmed it was investigating the intrusion. The Clinton campaign's manager, Robby Mook, had already said on television that experts believed Russian state actors had taken the emails and released them to help Donald Trump — a campaign's claim at that point, not a finding. The Kremlin called the suggestion absurd. Julian Assange declined to identify his source and said there was no proof of it. Each position held for the rest of the year.
On Wednesday 27 July, at his golf resort at Doral, Florida, Trump held a press conference and turned to Hillary Clinton's deleted private-server emails. "Russia, if you're listening, I hope you're able to find the 30,000 emails that are missing," he said. "I think you will probably be rewarded mightily by our press." His campaign said afterwards that he had meant anyone holding them should hand them to the FBI; he would later tell the special counsel, in writing, that he had been joking. On Friday 29 July the Democratic Congressional Campaign Committee confirmed that it, too, had been breached, and in August Guccifer 2.0 began posting its files. The month ended as it had begun: attribution rested on private researchers and a candidate's campaign, and no government had yet said the word Russia on the record.
Hindsight supplies the rest. On 7 October 2016 the Department of Homeland Security and the Director of National Intelligence said publicly that the Russian government had directed the thefts — the same afternoon the Podesta emails began to appear. On 13 July 2018 a federal grand jury indicted twelve named officers of the GRU's Units 26165 and 74455, and set out July's chronology: an encrypted file sent to WikiLeaks on 14 July; WikiLeaks confirming on 18 July that it had the archive and would publish that week; the release on the 22nd. Guccifer 2.0, the indictment said, had been those officers. None has faced trial. The DNC's own suit against Russia, WikiLeaks and the Trump campaign was dismissed with prejudice on 30 July 2019: Russia was immune as a sovereign, the judge found, and those who published what others had stolen were protected by the First Amendment.
The keys to the account
Pokémon Go went live in Australia, New Zealand and the United States on 6 July, and within a week tens of millions of people were walking into lamp-posts; India would wait until December for an official release. Two security stories followed at the speed of the downloads. On 7 July, at 09:19 UTC, someone uploaded a modified Android build to a file-sharing service; Proofpoint found it carrying DroidJack, a remote-access trojan, its opening screen identical to the real one and its command server registered under a Pokémon-themed dynamic-DNS name. Players in countries the game had not reached were being taught by websites how to side-load exactly such files. Then, on 8 July, a researcher named Adam Reeve noticed that signing in on an iPhone with a Google account had granted the app full account access — mail, files, photos — and by the 11th it was front-page news. Niantic said the request was erroneous, that only a user ID and email address were ever read, and shipped a fix; Google agreed; Reeve later softened his warning. The parable held anyway: a consent screen that a planet's worth of players tapped through without reading.
A ledger rewritten by vote
The DAO, the crowd-funded investment contract that had raised more than $150 million in ether by May, was drained of 3.6 million ETH on 17 June (June); the same code held the proceeds for twenty-eight days, and the community spent them arguing. On 20 July, at block 1,920,000, most of the Ethereum network ran new software that moved about twelve million ETH out of the attacker's and the rescuers' contracts into one from which token-holders could withdraw — a state change by decree, backed by a non-binding poll of ether holders in which only a small share of the supply was cast, and by roughly 85 per cent of mining power. Those who held that a blockchain must never be edited kept mining the old chain, and Ethereum Classic was born. Elsewhere in the month's ledger: on 7 July Wendy's raised its count of restaurants hit by till malware from fewer than 300 to 1,025, blaming a service provider's stolen remote-access credentials; on 26 July O2 customers' logins turned up for sale, reused from a 2013 breach of the gaming site XSplit — "We have not suffered a data breach," O2 said, accurately; and the same day President Obama signed PPD-41, which settled which American agency answers which phone when a serious intrusion is reported.
A reconciliation and a day
India's Bangladesh Bank moment came in July 2016, and the country heard of it in two sentences. An email styled as a Reserve Bank of India circular reached a handful of inboxes at Union Bank of India; some recipients flagged it as phishing, one opened the attachment, and the malware inside worked its way to the bank's SWIFT access. Instructions went out on 20 July through the bank's dollar nostro account at Citibank in New York, moving about $171 million — roughly ₹1,150 crore — towards banks in Cambodia, Thailand, Taiwan, Hong Kong and Australia. The transfers surfaced the next day, 21 July, when New York queried the instructions and the bank's own reconciliation would not tally. With the RBI and outside forensic help, the trail was traced and the money stopped and pulled back inside a week; on 22 July the bank told the stock exchanges only that there had been an attempted cyber attack on its dollar nostro account and that it had suffered no loss — no amount, no method. The money, it has maintained ever since, came back in full. The figure, the email and the chase came out only in April 2017, from the Wall Street Journal. Bangladesh Bank had lost $81 million the same way in February; Union Bank's difference was a reconciliation and a day.
The month's other Indian story was the switch itself. Burhan Wani, a Hizbul Mujahideen commander with a large social-media following, was killed by security forces at Kokernag on 8 July, and protests spread across the Valley within hours. Mobile internet was cut overnight; a curfew imposed on 9 July was not withdrawn from the whole Valley until 31 August, fifty-three days later; on 16 July police raided Srinagar's printing presses and seized plates and copies, and no newspaper appeared for three days. Jammu's mobile internet returned on 26 July. The Valley's stayed dark for months, while more than ninety civilians died in the unrest that followed and thousands were injured, many by pellet guns. Shutdown as policy had arrived; India would go on to use it more often than any other country in the years this archive covers.
Forty Per Cent Off the Cooling Bill
On 20 July 2016 DeepMind said its machine learning had cut the energy Google spent cooling a data centre by 40 per cent. Richard Evans and Jim Gao had trained an ensemble of deep neural networks on historical readings from thousands of sensors — temperatures, power, pump speeds, setpoints — to forecast temperature and pressure an hour ahead. In 2016 it only advised operators; by August 2018 it was running the cooling itself, supervised, saving around 30 per cent. On 5 July DeepMind Health had announced its first medical research project with an NHS trust, after the Moorfields consultant Pearse Keane approached it: a million anonymised retinal scans to train a system on diabetic retinopathy and macular degeneration. The Nature Medicine paper of August 2018 reported referral decisions across more than fifty conditions matching expert clinicians. And Prisma, the Russian app that redrew photographs with the neural style-transfer method Leon Gatys's group published in 2015, reached Android on 24 July, the company claiming ten million iOS downloads; its later app Lensa would flood feeds with "magic avatars" in late 2022.
Avast Buys AVG for $1.3 Billion
On 7 July 2016 Avast agreed to buy AVG Technologies for $25 a share in cash — about $1.3 billion, a third above the previous close. The two had grown up three years apart, Avast in Prague in 1988 as ALWIL and AVG in Brno in 1991 as Grisoft, though AVG was by then domiciled in Amsterdam and listed in New York. Avast's own count put the combined network at more than 400 million endpoints, 160 million of them mobile. The tender closed on 30 September; this was the Avast that floated in London in May 2018 and was absorbed by NortonLifeLock in September 2022 to become Gen Digital. On 25 July Europol, the Dutch National Police, Kaspersky Lab and Intel Security opened nomoreransom.org with four decryptors, the Shade tool holding more than 160,000 keys from a seized server; by its first anniversary Europol counted more than 28,000 devices decrypted. On 19 July Carbon Black bought Confer, terms undisclosed, to sell what it called next-generation antivirus as Cb Defense — the firm VMware would pay $2.1 billion for in 2019.
⏳ Time capsule — July 2016
- NASA's Juno spacecraft entered orbit around Jupiter on 4 July after a five-year journey, its main engine firing for thirty-five minutes on its own timing, out of contact with Earth and within a second of the plan.
- Portugal beat host France 1–0 in the Euro 2016 final at the Stade de France on 10 July, Éder scoring in extra time after Cristiano Ronaldo had limped off injured in the first half — the country's first major football title.
- Theresa May became Prime Minister of the United Kingdom on 13 July, three weeks after the Brexit referendum ended David Cameron's premiership; she was the second woman to hold the office.
- Rajinikanth's Kabali opened worldwide on 22 July with the biggest opening day yet for a South Indian film; AirAsia India wrapped an Airbus A320 in the star's image for the occasion, a first for an Indian film.
The hack-and-leak
Ten years on, the July 2016 release is the founding case of a category. What mattered was not the theft — every intelligence service steals email — but the timing of publication to a party convention, and the placing of a persona between thief and publisher so that everyone downstream could plead ignorance of the source. The template was reused against France's election in May 2017, an operation that appeared on the charge sheet when six officers of the same Unit 74455 were indicted again in October 2020, that time for NotPetya. The 2018 indictment put names to the persona, and names are where it stopped: the twelve remain in Russia, Russia has never accepted any of it, WikiLeaks has never identified its source, and the DNC's own lawsuit ended in 2019 without a trial.
The smaller stories aged in different directions. Pokémon Go's consent screen reads now as a preview of the argument the General Data Protection Regulation wrote into law two years later: a permission nobody reads is not a permission. Ethereum's fork settled nothing philosophically and everything practically — Ethereum Classic still exists, and the SEC concluded in a July 2017 report that DAO tokens had been securities all along. Union Bank's near-miss was a two-sentence exchange filing for nine months; the debit-card breach of that October could not be kept quiet, and Cosmos Bank in Pune lost $13.5 million in August 2018 to a raid that combined SWIFT and cloned cards — the lesson learned, then relearned. Kashmir's switch was thrown again in August 2019, and high-speed mobile internet did not return for eighteen months, though the Supreme Court held in January 2020 that speech and trade conducted over the internet carry constitutional protection and that indefinite shutdowns do not. The switch is still there.