In June 2012 someone posted 6.5 million password hashes from LinkedIn on a Russian forum. LinkedIn confirmed the theft, and the number entered the record as the size of the breach, where it stood for four years. In the third week of May 2016 the technology site Motherboard reported that a seller using the handle Peace had listed the same theft on The Real Deal, a darknet market, for five bitcoin — about $2,200 — and that the file held some 167 million accounts, 117 million of them with both an email address and a password hash. The hashes were unsalted SHA-1, a scheme already thought inadequate in 2012; LeakedSource, a search service that had obtained a copy, claimed to have cracked nine in ten of them within 72 hours.

LinkedIn's chief information security officer, Cory Scott, wrote on 18 May that the company "became aware of an additional set of data" claiming to be the credentials of more than 100 million members from the same 2012 theft, that nothing suggested a new breach, and that it was invalidating the password of every account not reset since then. The human detail of the month was that reset. Millions of people who had not opened LinkedIn in years received an email asking them to choose a new password for a site they barely remembered, protecting a credential a great many were still using somewhere else. That was the point. A password stolen in 2012 and never changed was not a LinkedIn problem in 2016; it was an everything problem.

LinkedIn was the middle of a parade. Around 9 May the same seller had offered 40 million accounts from the dating site Fling, taken in 2011, reportedly with plain-text passwords. On 12 May Tumblr told users a third party had obtained "a set" of email addresses and salted, hashed passwords from early 2013, before Yahoo bought it, and gave no figure; on 30 May Troy Hunt counted 65,469,298. On 27 May LeakedSource announced the largest of all — 360 million MySpace accounts with 427 million passwords, unsalted SHA-1 again, from before the site's June 2013 relaunch — and Time Inc., MySpace's new owner, confirmed on 31 May that the stolen data was on offer in a hacker forum. Four sites, more than 600 million accounts, and not one theft was new.

The ending belonged to a courtroom and took four years. On 5 October 2016 Czech police detained a Russian, Yevgeniy Nikulin, in Prague on an American warrant; after an extradition fight he reached San Francisco in March 2018, was convicted by a jury in July 2020 of the 2012 intrusions at LinkedIn, Dropbox and Formspring, and on 29 September 2020 was sentenced to 88 months. Peace, the seller, was never publicly identified, and nothing established that the two were the same person. What the month proved was simpler. A breach is not an event with a size. It is a stock of keys that keeps being tried in new doors, and its number only grows; the small figure of 2012 had been the very large one all along.

Also that month · After Bangladesh

The second bank, and the one before it

Three months after the Bangladesh Bank theft, SWIFT said on 12 May that a second bank had been hit by similar malware; the victim named itself three days later. Tien Phong Bank in Hanoi confirmed on 15 May that late in 2015 it had spotted fraudulent SWIFT messages seeking to move more than €1 million — about $1.1 million — and had stopped them before any money left, pointing to a third party's software it used to reach the network. On 20 May Reuters found an older case in a January lawsuit in New York: Ecuador's Banco del Austro said thieves holding the bank's own SWIFT credentials had moved about $12 million through Wells Fargo to accounts in Hong Kong, Dubai, New York and Los Angeles over ten days in January 2015. Wells Fargo denied fault, saying it had properly processed instructions that arrived as authenticated SWIFT messages and that its own systems were not compromised. SWIFT told Reuters it had only just learned of it. On 24 May in Brussels SWIFT's chief executive, Gottfried Leibbrandt, announced a Customer Security Programme; on 26 May Symantec said code in the Bangladesh malware matched tools of the Lazarus group blamed for the 2014 Sony attack. Wells Fargo settled the Ecuador suit in February 2018, a month before trial.

Also that month · Wichita and Dublin, Ohio

A ransom paid, then a second demand

Kansas Heart Hospital in Wichita was hit on Wednesday 18 May by ransomware that its president, Dr Greg Duick, said became widespread through the institution. The hospital paid what he called a small amount to recover its files. The attackers took the money, restored only part of the access and asked for more. The hospital refused — paying again, it said after consulting its advisers, was no longer a wise strategy — and rebuilt from backups; it said treatment continued throughout and that no patient information had been taken. In Dublin, Ohio, meanwhile, Wendy's put a number on a card breach first reported in January: malware installed with a third-party vendor's stolen credentials had run on the tills of fewer than 300 of its roughly 5,500 franchised North American restaurants since the autumn of 2015, the hamburger chain said on 11 May. By July the count was 1,025. The two stories taught the same lesson in different accents: the first number is rarely the last, and paying does not close a case.

India desk · May 2016

One crore, or none

The claim reached IRCTC from the police rather than the other way round. In the first days of May the Maharashtra police cyber cell told the railway ticketing corporation that the registration details of about one crore of its users — names, telephone numbers, email addresses and, in some records, PAN numbers — appeared to have leaked and were being sold, by one account on a compact disc priced at ₹15,000. The reports broke on 5 May. IRCTC's answer was flat: its technical teams had detected no intrusion into its systems, the website was running normally, and a joint committee with the Centre for Railway Information Systems would examine whatever data the police could produce. Its chairman, A.K. Manocha, said he was "99 percent certain" the data was not IRCTC's, while allowing that some of it might have come from partner sites for hotels, taxis and food.

No public finding settled where the file came from, and the story ended the way Indian breach claims ended in 2016: a denial, a committee, silence. IRCTC's defence — that the records had been stitched together from elsewhere — was plausible, and beside the point for the passenger whose name and phone number were now on a disc. The year's real Indian breach became public in October, when banks began recalling 3.2 million debit cards exposed by malware that had sat in a payment processor's network since the summer — a compromise the processor first said it had found no evidence of, and confirmed only in February 2017. In December 2022 a forum seller claimed the data of three crore railway users, and the ministry said once more that nothing had left its servers. The rules that would eventually require an answer within six hours, and place a duty on whoever holds personal data, took six and seven more years.

AI Tech desk · May 2016

An Assistant, a Speaker and a Chip

Google's developer conference ran from 18 to 20 May 2016 at the Shoreline Amphitheatre in Mountain View, and its opening keynote set the decade's agenda. Sundar Pichai introduced Google Assistant, a conversational successor to Google Now that could take a follow-up question; Google Home, a speaker for it; and Allo, a messaging app with the Assistant inside. He also disclosed that a custom chip, the Tensor Processing Unit, had been running in Google's data centres for more than a year, under RankBrain, Street View and the AlphaGo that beat Lee Sedol in March. Nine days earlier, at TechCrunch Disrupt in New York on 9 May, Siri's co-founder Dag Kittlaus had given the first public demonstration of Viv, which Samsung bought in October and folded into Bixby; on 12 May Google open-sourced its SyntaxNet parser, Parsey McParseface. In hindsight the chip mattered most. The Home shipped in November, Allo closed in March 2019, and in March 2025 Google said Gemini would replace the Assistant, while the TPU became the foundation of Google's AI hardware.

Digital Guard desk · May 2016

The Ransomware That Said Sorry

The month's strangest document was a ransom note in reverse. TeslaCrypt had been winding down through the spring, its distributors drifting to a rival, CryptXXX, and an ESET analyst who noticed the retreat asked the operators, through the support chat on their payment site, for the master key. On 18 May 2016 the answer went up: the key, a note that the project was closed, and an apology. The same day ESET published a free decryptor for the .xxx, .ttt, .micro and .mp3 variants, an approach that No More Ransom formalised that July and still runs a decade on. Two days earlier the guard itself had failed. On 16 May Symantec pushed a fix through LiveUpdate for a flaw Google's Tavis Ormandy had found in the engine beneath Norton and Symantec's enterprise products: a buffer overflow in parsing ASPack-packed executables, triggered by an emailed file the victim need not open, and running, on Windows, inside the kernel. Ormandy called it "about as bad as it can possibly get"; his fuller account on 28 June was worse.

⏳ Time capsule — May 2016

  • On 2 May Leicester City, 5,000-1 outsiders in August, became champions of England for the first time in their 132-year history when Tottenham drew 2-2 at Chelsea; the players watched it on television at Jamie Vardy's house.
  • ISRO flew its first winged Reusable Launch Vehicle Technology Demonstrator from Sriharikota on 23 May — a 6.5-metre, 1.75-tonne craft that rode a solid booster to about 65 kilometres and came down in the Bay of Bengal roughly thirteen minutes after lift-off.
  • On 27 May Barack Obama became the first sitting American president to visit Hiroshima, laying a wreath at the cenotaph after the G7 summit at Ise-Shima and speaking to an audience that included survivors of the bomb.
  • Sunrisers Hyderabad won their first IPL title on 29 May, beating Royal Challengers Bangalore by eight runs at the Chinnaswamy Stadium; Virat Kohli finished on the losing side with 973 runs, a record for a single season.
Where it stands today — 2026

The stock of keys

Ten years on, the spring of 2016 reads as the origin of the decade's default attack. The dumps did not stop in May: June brought 100 million accounts from Russia's VK, a claimed 32 million from Twitter, which said its own systems had not been breached, and the hijacking of Mark Zuckerberg's Twitter account by a group that said his password came out of the LinkedIn file. What followed was industrialisation. Credential stuffing — replaying old email-and-password pairs against every login page — became the ordinary way to take accounts, and the archive's later landmarks are this month's descendants: Collection #1 in January 2019, 773 million addresses from a decade of exactly these thefts; the Snowflake campaign of May 2024, opened with credentials stolen years earlier; the sixteen-billion compilation of June 2025.

The remedies took longer than the attacks. LinkedIn had salted its hashes within days of the 2012 theft; the industry needed most of a decade to make a second factor the default, and the passkey standard that offers a way past passwords arrived only in 2022. The SWIFT thread ran in parallel: the Customer Security Programme of 24 May became mandatory annual attestation for every member, Symantec's Lazarus finding became an American criminal complaint against a North Korean programmer, unsealed in September 2018 and followed by an indictment in 2021, and India's own two-day heist followed at Pune's Cosmos Bank that August. Kansas Heart Hospital's second demand became the standard argument against paying, and the one-crore claim, never proven or disproven, was the first of many India would meet with the same denial until the law required an answer.