On 22 September 2016, Yahoo's chief information security officer, Bob Lord, posted a notice on the company's own Tumblr and filed the substance of it with the Securities and Exchange Commission. Account information belonging to at least 500 million users had been stolen from Yahoo's network in late 2014, he wrote, by what the company believed to be a state-sponsored actor. The stolen fields were the ordinary furniture of an email account: names, email addresses, telephone numbers, dates of birth, hashed passwords — the vast majority protected with bcrypt — and, in some cases, security questions and their answers, encrypted or not. Yahoo said payment-card numbers and bank details were not stored in the affected system. It was, at that moment, the largest breach ever made public.
Three separate dates sat inside that announcement, and the announcement blurred two of them. The theft had happened in late 2014. Confirmation came in the summer of 2016, after a seller calling himself Peace — already associated with dumps from LinkedIn, MySpace and Tumblr — advertised 200 million Yahoo credentials on the dark-web market TheRealDeal in early August for roughly three bitcoin. Yahoo said it was aware of the listing and began investigating; what the investigation turned up was not that trove but an older and far larger one. Disclosure came on 22 September, eight weeks after Verizon had agreed, on 25 July, to buy Yahoo's operating business for about $4.83 billion. Verizon said it had been told two days before everyone else was.
The gap between theft and disclosure was the real story. In its April 2018 settlement order the SEC found that within days of the December 2014 intrusion Yahoo's security team had learned that Russian hackers had taken account data for hundreds of millions of users, and had said so internally — while the company's filings for the next two years described data breaches only as a risk that might one day occur. Six days after the disclosure, on 28 September 2016, the New York Times published what insiders said about the culture behind that silence: the security team, who called themselves the Paranoids, had run red-team break-ins against their own employer under Alex Stamos, the security chief until he left for Facebook in 2015, and had lost repeated arguments over budget and over a forced password reset.
The bill arrived in instalments. That December Yahoo disclosed a second, older theft — August 2013, one billion accounts — and in October 2017 raised that figure to every Yahoo account then in existence, three billion. Verizon cut $350 million from the price on 21 February 2017 and closed at $4.48 billion in June; the remainder, holding the Alibaba stake, was renamed Altaba, and it was Altaba that paid the SEC's $35 million penalty — the regulator's first for a breach kept quiet. On 15 March 2017 the Justice Department indicted four men, two of them serving FSB officers. Nor was Yahoo the month's only excavation: in the first week of September, credentials for 98.1 million Rambler.ru accounts, stored in clear text and dating to 2012, surfaced.
A botnet made of cameras
On 20 September the website of the security journalist Brian Krebs was buried under 620 Gbps of junk traffic — by Akamai's account nearly twice the largest it had ever absorbed. Krebs had been a pro-bono customer for four years. When the flood began to threaten paying customers, Akamai gave him two hours' notice and let him go; he asked for his traffic to be routed into a black hole so his hosting provider would not wear it, and the site went dark on 22 September, returning days later under Project Shield, Google's free protection for journalists. The same week the French host OVH said it had absorbed two simultaneous attacks peaking together near 990 Gbps; its founder, Octave Klaba, put the source at 145,607 cameras and other connected devices, and the botnet's ceiling at 1.5 Tbps. Those machines had not been broken into so much as logged into, with factory passwords never changed. On 30 September a user calling himself Anna-senpai published the source code on Hackforums. Three young Americans — Paras Jha, Josiah White and Dalton Norman — pleaded guilty in December 2017; none went to prison.
Medical files as ammunition
On 13 September a website calling itself Fancy Bears' Hack Team began publishing the confidential medical records of Olympic athletes — specifically their therapeutic use exemptions, the permissions that allow a competitor to take an otherwise-banned drug for a diagnosed condition. The first batch named the gymnast Simone Biles, the tennis players Venus and Serena Williams and the basketball player Elena Delle Donne; further batches followed over the days and weeks after. The documents recorded lawful exemptions; the site presented them as evidence of doping. Biles answered publicly that she has attention deficit hyperactivity disorder, has taken medication for it since childhood, and had declared it. The World Anti-Doping Agency confirmed the intrusion on 13 September, the day the leaks began, and later said the files had been reached through an account the International Olympic Committee had created for the Rio Games, with credentials obtained by spear-phishing, and that the account was entered repeatedly between 25 August and 12 September. Russia denied any involvement. In October 2018 the United States indicted seven officers of the GRU over the campaign against anti-doping bodies.
The month data went free
India's most consequential event that month was commercial. On 5 September, four days after announcing it at Reliance Industries' annual meeting, Reliance Jio began selling 4G service under a Welcome Offer that gave every new subscriber unlimited data and free domestic calls until 31 December. The company said it signed 16 million customers in 26 days. The price war it started did not stop there, and within a few years India had the cheapest and heaviest mobile data in the world. The security consequence was invisible on the day and unmistakable in hindsight: several hundred million people reached the internet for the first time, on a phone, with no prior habits to protect them — the population on which the next decade of payment fraud, forwarded rumour and impersonation scams would be run.
The louder story was the Uri attack of 18 September, in which four militants killed nineteen Indian soldiers at a brigade headquarters in Jammu and Kashmir, and the cross-Line-of-Control strikes India announced on 29 September. Defacement crews on both sides escalated alongside the politics — though the large numbers usually attached to that September, including a Pakistani group's list of some seven thousand Indian sites, belong to the first days of October, and were claims the crews published about themselves, never independently audited. Defacement is noise. The serious Indian compromise of 2016 was by then already finished and still secret: between 21 May and 11 July malware had been injected into the network of a payment-services provider, exposing data from about 3.2 million debit cards. The country would find out in October.
Google's translator learns whole sentences
On 27 September 2016 Google switched Translate's Chinese-to-English service to a neural network, GNMT, that handled whole sentences rather than stitching phrases together. By Google's account, judged by bilingual raters, it cut translation errors by 55 to 85 per cent on several major language pairs, on a route Google said carried some 18 million requests a day. On 8 September DeepMind published WaveNet, which generated raw audio one sample at a time and, in its listening tests, closed more than half the gap between synthetic and human speech — too slow for any product until a far faster version began voicing the Google Assistant in October 2017. On 14 September Uber began carrying passengers in self-driving Ford Fusions in Pittsburgh, two employees aboard each; it agreed in December 2020 to sell the programme to Aurora, after one of its cars killed a pedestrian in Tempe, Arizona, in March 2018. Hindsight favours the translator: within nine months Google's own researchers had published the Transformer, the architecture that replaced GNMT's recurrent design and underlies every large language model since.
McAfee gets its name back
On 7 September 2016 Intel said it would spin off Intel Security — the McAfee business it had bought for about $7.7 billion and renamed in 2014 — into an independent company under the old name. TPG would put in $1.1 billion of equity for 51 per cent; Intel would keep 49 per cent and take $3.1 billion in cash, on a valuation of $4.2 billion, about half what it had paid. The deal closed the following April. On 15 September Sophos launched Intercept X, a layer that ran beside any vendor's antivirus, blocked exploit techniques without signatures and, through a component called CryptoGuard, stopped processes caught encrypting documents maliciously and rolled the files back. On 30 September Avast said its tender offer for AVG, worth about $1.3 billion, had brought in roughly 87 per cent of the stock; the two companies began operating as one on 3 October. The consolidation continued: McAfee was sold to private equity for $14 billion in 2022, and Avast merged with NortonLifeLock the same year to become part of Gen Digital.
⏳ Time capsule — September 2016
- A SpaceX Falcon 9 exploded on the pad at Cape Canaveral on 1 September during a routine pre-launch fuelling test, destroying the Amos-6 satellite whose capacity Facebook had leased to carry internet access to sub-Saharan Africa; the pad was clear and nobody was hurt.
- Samsung suspended sales of the Galaxy Note 7 on 2 September and offered to replace the roughly 2.5 million handsets already sold, two weeks after the phone reached shops; the United States Consumer Product Safety Commission issued a formal recall on 15 September.
- At the Rio Paralympics, held from 7 to 18 September, India won four medals — its best Games to that point — including high-jump gold for Mariyappan Thangavelu and a world-record javelin throw of 63.97 metres by Devendra Jhajharia, while Deepa Malik's shot-put silver made her the first Indian woman to win a Paralympic medal.
- The European Space Agency ended the Rosetta mission on 30 September by steering the spacecraft down onto Comet 67P/Churyumov–Gerasimenko; the signal died at the controllers' consoles in Darmstadt at 11:19 UTC, exactly as planned.
What the silence cost
Ten years on, September 2016 reads as the month two permanent problems introduced themselves in the same week. Yahoo's is the disclosure problem. The 500 million became three billion; the sale price fell by $350 million; the SEC's $35 million penalty in April 2018 was the first of its kind and the ancestor of the rule, in force since December 2023, requiring American public companies to report material cyber incidents within four business days. Of the four men indicted in March 2017, only Karim Baratov, arrested in Canada, ever stood before a court; he was sentenced to five years in 2018. The others were never produced. Security questions — a mother's maiden name, a first school — quietly stopped counting as proof of identity.
Mirai's is the device problem, and it was legislated at rather than solved. The code released on 30 September made the botnet common property; three weeks later a variant took down the DNS provider Dyn and much of the American web with it, which is October's story, and its authors pleaded guilty the following December. Governments answered slowly: California barred default passwords on connected devices from 2020, Britain's product security regime from April 2024. The attack figures in this archive kept climbing, from 620 Gbps to numbers measured in terabits, because the supply of cheap cameras with a factory login never ran out. And the hack-and-leak Fancy Bear tried on athletes' medical files — true documents arranged into a false argument — stopped being novel almost at once.