On 14 June 2016, The Washington Post reported that hackers working for the Russian government had been inside the Democratic National Committee's network and had taken its opposition research on Donald Trump. CrowdStrike, called in by the committee at the end of April, published its account the same day and described two intruders. The group it called Cozy Bear, assessed to work for the FSB, had been reading email and chat since summer 2015; Fancy Bear, tied to military intelligence, had arrived in April and gone for the Trump file. Neither showed any sign of knowing the other was there. The Kremlin's spokesman, Dmitry Peskov, said the same day that he completely ruled out any government involvement. In June, that was one firm's finding against one state's denial.
The New York Times reconstructed the rest that December. In September 2015 an FBI special agent, Adrian Hawkins, telephoned the committee and was put through to its help desk, where Yared Tamene, a contractor from a Chicago firm, took the call. The agent said at least one DNC system had been compromised by hackers known as the Dukes. Tamene searched Google for the name, checked the logs, found nothing, and wrote a memo saying he had no way to tell the call from a prank. Hawkins rang back for weeks and left voicemails; nobody returned them, and nobody walked over from the FBI's Washington field office, about a mile away. The committee's leaders were never told. CrowdStrike was engaged at the end of April 2016, seven months on, and found the Dukes still inside.
A rival author appeared within a day. On 15 June a WordPress blog under the name Guccifer 2.0 claimed the whole intrusion for a lone hacker, Romanian like the original Guccifer, and posted the Trump dossier. Readers of the metadata soon noticed that the Word files had last been saved by a user named, in Cyrillic, Felix Edmundovich — Dzerzhinsky's name and patronymic, the founder of the Soviet secret police. When Motherboard interviewed the persona on 21 June and asked it to continue in Romanian, it produced a few sentences that native speakers found full of errors, then declined, saying it did not want to waste its time. It said it did not like Russians or their foreign policy and hated being attributed to Russia. CrowdStrike said the posting might itself be part of a Russian intelligence disinformation campaign.
On 22 July WikiLeaks published nearly twenty thousand DNC emails — the files the persona had said on 15 June it had already given them (July 2016). On 7 October the US intelligence community formally attributed the theft to Russia's senior leadership (October); December brought sanctions and expulsions (December). In March 2018 The Daily Beast reported that the persona had once posted without its VPN, from an address at GRU headquarters in Moscow. On 13 July 2018 a federal grand jury indicted twelve GRU officers of Units 26165 and 74455, naming Guccifer 2.0 as their persona (July 2018). Russia denied it then and denies it now, and none of the twelve has faced a court. The contractor who took the call was never accused of anything worse than doubt.
A third of the treasury
The DAO was a venture fund without managers: smart contracts on Ethereum that opened on 30 April and by late May had drawn more than $150 million in ether from more than eleven thousand contributors. On 12 June one of its creators, Stephan Tual, acknowledged a recursive-call bug and said no funds were at risk. On 17 June somebody used it. The split function paid out ether before updating the caller's balance, so a contract that called back in mid-payment was paid again and again: about 3.6 million ether, roughly a third of the fund, some $50 million at that day's falling price, went into a child DAO locked by its own rules for about four weeks. The pause made the argument possible. On 21 June a Robin Hood group said it had used the same flaw to move most of what remained beyond reach, while the community argued whether code was law or the chain should be rewound. The hard fork of 20 July returned the funds and left Ethereum Classic running the unforked chain. Poly Network, WazirX and Bybit descend from it.
The summer of old passwords
The LinkedIn cache that surfaced in May spent June paying out. On Sunday 5 June a group calling itself OurMine took over Mark Zuckerberg's Twitter and Pinterest accounts and said his password, dadada, had come straight from the LinkedIn dump. The same weekend a seller using the name Peace advertised some 100 million accounts from VK, the Russian social network, on a Tor market for one bitcoin; VK said the data was old logins from 2011 and 2012 and that it had not been hacked directly. On 8 June LeakedSource, a breach index, said it had received 32 million Twitter records with plain-text passwords from a source using the alias Tessa88, the same hand behind the VK cache. LeakedSource itself said Twitter had not been hacked; the passwords had most likely been harvested by malware from infected browsers. Twitter said its systems had not been breached and locked the accounts it judged exposed. Reuse was the whole story. The month closed with Google's Tavis Ormandy disclosing on 28 June that the engine inside Symantec and Norton products unpacked hostile files in the kernel — the Digital Guard desk's story.
A clock starts in Mumbai
On 2 June 2016 the Reserve Bank of India sent circular RBI/2015-16/418, Cyber Security Framework in Banks, to every scheduled commercial bank. Its preamble noted that the number, frequency and impact of cyber incidents had increased manifold, especially in finance; it arrived four months after the Bangladesh Bank heist, which it did not need to mention. The demands: a board-approved cyber security policy, distinct from the bank's IT policy, confirmed to the RBI's examination cell by 30 September; a gap assessment against the circular's baseline controls by 31 July; a security operations centre at the earliest; a cyber crisis management plan covering detection, response, recovery and containment; and reports of every unusual incident, including failed attempts. Annex 3 supplied the Security Incident Report form, due within two to six hours.
In hindsight the circular went out into a system already breached. Between 21 May and 11 July 2016, a forensic audit later found, malware inside Hitachi Payment Services, which ran ATMs and payment switches for Indian banks, was capturing card data; it surfaced in October as the compromise of some 3.2 million debit cards (October 2016), the largest in Indian banking to that point — a breach Hitachi at first said it had found no evidence of, and confirmed only in February 2017. In July a phishing email at Union Bank of India set a $171 million transfer moving through the bank's overseas accounts; the bank noticed the next morning and recovered the money within about a week (July 2016), though the public learned the details only in 2017. The clock the RBI started that June, two to six hours, is the direct ancestor of the six-hour rule CERT-In imposed on the whole economy in 2022.
A white trailer against a bright sky
On 30 June 2016 Tesla published a post headed A Tragic Loss. On 7 May a Model S under Autopilot had driven beneath a tractor-trailer crossing a Florida highway, killing its driver, Joshua Brown. Neither car nor driver had noticed the white side of the trailer against a brightly lit sky, Tesla wrote, so the brake was never applied — the first known fatality in over 130 million miles of a feature still in beta. The road-safety regulator, the NHTSA, had opened a preliminary evaluation two days earlier and closed it on 19 January 2017 without finding a defect. The NTSB, the accident investigator, found in September 2017 that the system's design had permitted the driver's prolonged disengagement; and a January crash in Hebei, reported only that September, would contest the word first. On 13 June Apple opened Siri to developers and adopted differential privacy for usage data; on 21 June six researchers at Google Brain, OpenAI, Stanford and Berkeley posted Concrete Problems in AI Safety, whose first two authors, Dario Amodei and Chris Olah, would found Anthropic in 2021.
Symantec buys Blue Coat, then patches itself
On 12 June 2016 Symantec agreed to buy Blue Coat for $4.65 billion from Bain Capital, which had paid $2.4 billion for it in 2015; Blue Coat's chief executive, Greg Clark, would run the combined company from 1 August. The deal defined Symantec until Clark left in May 2019; that November Broadcom bought the enterprise business for $10.7 billion and the consumer half became NortonLifeLock. On 8 June Cylance, the machine-learning challenger, had raised $100 million at a reported $1 billion valuation; BlackBerry would agree to pay $1.4 billion for it in 2018 and sell it to Arctic Wolf in 2025 for a headline $160 million plus shares. On 28 June Google's Tavis Ormandy disclosed flaws in the decomposer engine inside every Symantec and Norton product: unpackers running in the Windows kernel, triggered by an emailed file nobody need open, using open-source libraries unpatched for at least seven years — wormable, he wrote, and as bad as it gets. Symantec's advisory SYM16-010 went out the same day, with fixes by LiveUpdate where possible and by hand elsewhere.
⏳ Time capsule — June 2016
- Muhammad Ali died on 3 June in Scottsdale, Arizona, aged 74, after a decades-long fight with Parkinson's disease; Louisville, his home city, buried him a week later.
- On 19 June the Cleveland Cavaliers beat the Golden State Warriors 93–89 in Game 7 of the NBA Finals — the first team to come back from 3–1 down in a Finals, and Cleveland's first major title since 1964.
- On 22 June ISRO's PSLV-C34 carried twenty satellites into orbit from Sriharikota in a single flight, led by a Cartosat-2 series imaging satellite — a record for an Indian mission, and a rehearsal for the 104 of February 2017.
- On 23 June the United Kingdom voted to leave the European Union, 51.9 per cent to 48.1; David Cameron announced his resignation outside Downing Street the next morning.
Claims, and what became of them
A decade on, June 2016 reads as the month the modern hack-and-leak was assembled in public: a private attribution, a persona built to muddy it, a state denial, and the stolen files themselves used as the weapon. Each of the claims has since been tested. The attribution was adopted by the US intelligence community that October and by a grand jury in July 2018; the same military unit, 74455, was indicted again in October 2020 for NotPetya. None of the officers has faced a court, Russia's denial has never changed, and the playbook has been copied more than once since. The unreturned calls became the industry's standard parable: a warning is only as good as the door it arrives through.
The other two stories ended in code and in rules. The DAO's fork settled the money and unsettled the principle: code-is-law lost the argument in 2016 and has been re-argued at every large theft since, from Poly Network to WazirX to Bybit, while the re-entrancy pattern that emptied it is now the first thing an auditor checks. The password summer taught, expensively, what two-factor logins and breach-checking services later made routine; dadada remains the industry's shorthand for reuse. And the two-to-six-hour clock that a circular from Mumbai started that June became a national habit: when CERT-In gave the whole economy six hours in 2022, India's banks had been living to a tighter one for six years.