The password was "Reeeeeeeeeeeeeee". On Good Friday, 14 April 2017, the group calling itself the Shadow Brokers posted "Lost in Translation", the latest act in a performance that had run since August 2016, when they first offered stolen NSA tooling at auction and found almost no buyers. A retirement notice had followed in January; then, on 8 April, an aggrieved open letter to President Trump about the Syria strike, with the password to an older archive of Unix exploits attached at the bottom. The new release asked for nothing at all. Inside were three folders — windows, swift and oddjob — and the first of them held what Matthew Hickey of Hacker House judged the most powerful cache of exploits ever made public: a point-and-click attack framework called FuzzBunch, and the weapons it fired.

The names inside sounded like a catalogue of secret weapons, which is what they were: EternalBlue, EternalRomance, EternalChampion and EternalSynergy, all attacking Windows file-sharing over SMB; EsteemAudit, which walked through Remote Desktop on Windows XP and Server 2003; and utilities for lingering afterwards, chief among them DoublePulsar, a stealthy kernel implant that most of the exploits planted. The swift folder was stranger: presentations and spreadsheets suggesting the NSA had penetrated EastNets, a SWIFT service bureau in Dubai, to monitor the transactions of client banks across the Middle East. EastNets said reports of a compromise of its network were "totally false and unfounded"; SWIFT said there was no evidence its own network had been accessed without authorisation. The documents said what they said, and nobody was made to reconcile the two.

Microsoft's answer appeared late the same evening, an unusual hour for corporate blogging. In a post titled "Protecting customers and evaluating risk", Phillip Misner of the Microsoft Security Response Center wrote that most of the exploits were already patched. The four Eternals had been closed a month earlier, on 14 March, by security update MS17-010; three others did not work on any supported product, which was another way of saying they still worked on Windows XP and Server 2003; the rest had been fixed years before. What the post did not say was who had reported the flaws. Microsoft had cancelled February's Patch Tuesday outright, had credited no researcher on MS17-010 where credit is customary, and told The Intercept that no individual or organisation had contacted it about the tools. The month ended with that question still open.

What remained was arithmetic. MS17-010 was a month old, and the world's record on installing patches was well known. Within days researchers were scanning port 445 for DoublePulsar's telltale handshake, and the counts climbed while the methods argued: Below0Day found 30,626 implanted machines on 18 April and 56,586 three days later; BinaryEdge's daily scans ran from 106,410 on 21 April to 183,107 by the 24th; other scans found half that, and sceptics noted the check could in principle be fooled. The direction was not in dispute — and the machines running XP had no patch to install at all. From the Friday of the leak to the second Friday of May was exactly four weeks. The clock, though nobody could hear it, was already running.

Also that month · A clear night in Texas

Ninety minutes of sirens

Dallas keeps 156 outdoor sirens to warn 1.3 million people about tornadoes. Shortly before midnight on Friday 7 April 2017, under a clear sky, every one of them went off — wails of about ninety seconds, over and over, until engineers shut the whole system down in the small hours of Saturday morning, roughly an hour and a half later. More than 4,400 calls reached 911 in that window, and waits stretched to six minutes, which on a different night could have mattered a great deal. The city called it a malfunction in the first confused hours and a hack later that Saturday; by Monday officials had explained the detail that made it a parable: nobody had breached a computer network, because the sirens were commanded by radio tones, and someone — the city believed someone local — had learned and replayed the right tones. Dallas added encryption before switching the sirens back on. The Federal Communications Commission was consulted, and no arrest was ever announced.

Also that month · The front desk

Twelve hotels become 1,200

In February 2017 InterContinental Hotels Group had disclosed card-stealing malware at the restaurants and bars of twelve managed hotels. On 19 April, when the examination of its franchised estate finished, the count became about 1,200 hotels across the United States and one in Puerto Rico — Holiday Inns and Crowne Plazas among them, roughly one American franchise in three. The malware had sat on front-desk payment systems from 29 September to 29 December 2016, reading track data from the magnetic stripes of cards as transactions passed through hotel servers. IHG said the malware had been erased during the investigation, published a state-by-state lookup tool rather than a list of names, and noted that franchises which had adopted its point-to-point encryption before late September were untouched. The same week supplied the sequel's opening scene: on 25 April Chipotle told investors it had detected unauthorised activity on its payment network. The details — malware at most of its roughly 2,250 restaurants between 24 March and 18 April — were only confirmed on 26 May.

India desk · April 2017

The pension list anyone could read

The website of Jharkhand's Directorate of Social Security existed so that officials could administer old-age pensions. Until the night of Saturday 22 April 2017 it was also, for anyone who typed the address, a directory of the pensioners themselves: names, addresses, Aadhaar numbers and bank account details, with transaction-level records of pension payments beneath them. Hindustan Times, which reported the exposure that weekend, noted that the state had more than 1.6 million pensioners, about 1.4 million of whom had seeded their bank accounts with Aadhaar. Officials in Ranchi described a programming error and took the site down that Saturday night; publishing an Aadhaar number is itself an offence under Section 29(4) of the Aadhaar Act, though no prosecution followed. UIDAI's standing position held throughout: the central biometric database was untouched — a state department had simply displayed what it held.

It was not one website. Within days journalists found similar displays on other official portals, Chandigarh's among them, and on 1 May the Centre for Internet and Society in Bengaluru published a study of just four scheme portals — the National Social Assistance Programme, NREGA and two Andhra Pradesh sites — estimating that around 130 to 135 million Aadhaar numbers and some 100 million bank account numbers had been made public. UIDAI objected, and CIS later clarified it was describing disclosure by government bodies, not a breach of UIDAI's systems. The estimates were disputed; the screenshots were not. The argument they started — whether a number designed to be everywhere could also be secret — runs through the rest of this archive.

AI Tech desk · April 2017

Giving the machinery away

The month the NSA's tools were given away against its will, the AI industry gave its own away deliberately. On 18 April 2017, the first day of the F8 conference in San Jose, Facebook open-sourced Caffe2, a lightweight deep-learning framework built to run neural networks on phones as readily as in data centres, with Nvidia, Intel, Qualcomm, Amazon and Microsoft already optimising for it — the production partner to PyTorch, the research framework Facebook had released that January. Eleven days earlier DeepMind had open-sourced Sonnet, a TensorFlow library carrying its internal habits for building networks; and on 6 April Google described federated learning, by which Gboard on Android improved its suggestion model on the handset itself, sending model updates to the cloud rather than keystrokes. The hindsight is tidy: Caffe2 was folded into PyTorch the following year, and the merged framework became the bench on which most of the coming decade's machine learning — the systems this archive's later pages reckon with — was built.

Digital Guard desk · April 2017

Thirteen minutes at Webroot

While the rest of the endpoint industry spent the month writing detections for the leaked Eternal exploits and hunting DoublePulsar implants, the sharpest lesson in the trade came from an update rather than an attack. On Monday 24 April 2017 a Webroot rule change began classifying legitimate Windows system files — some signed by Microsoft — as W32.Trojan.Gen and quarantining them, while also flagging Facebook as a phishing site. The rule was live for about thirteen minutes before internal safeguards caught it: long enough to reach machines worldwide, and to fall hardest on the managed service providers who ran Webroot across whole client fleets and watched Windows stagger without files it needed. A manual fix came the same day; a repair utility for business customers, tested with a group of MSPs, followed on 26 April; support threads were still walking administrators through recovery on the 28th. No breach, no attacker — one bad rule, in a shape the trade knew from McAfee in 2010 and would meet again, far more expensively, when a defective CrowdStrike update felled Windows machines worldwide in July 2024.

⏳ Time capsule — April 2017

  • Security officers dragged Dr David Dao, a 69-year-old physician, off United Express Flight 3411 at Chicago O'Hare on 9 April to free his seat for airline staff; passengers' phone videos circled the world overnight, and United settled with him, confidentially, before the month was out.
  • Sergio García won the Masters on 9 April — his first major title after nearly two decades of trying — beating Justin Rose with a birdie on the first playoff hole, on what would have been Seve Ballesteros's 60th birthday.
  • France voted on 23 April, and for the first time in the Fifth Republic neither of the two parties that had traded power for decades reached the presidential runoff: Emmanuel Macron and Marine Le Pen went through.
  • On 26 April the Cassini spacecraft threaded the roughly 2,400-kilometre gap between Saturn and its rings for the first time — the opening dive of the Grand Finale that would end its twenty-year mission that September.
Where it stands today — 2026

The four-week fuse

Nine years on, Lost in Translation reads as the hinge of this archive's first decade. Four weeks after the leak, EternalBlue carried a worm around the world in an afternoon — the story of the special restoration Three Days in May — and six and a half weeks after that, with EternalRomance beside it, it helped NotPetya wreck its victims from Kyiv outward. Then the long afterlife: cryptominers, botnets, and the disputed forensics of Baltimore's ransomware, argued over in the May 2019 edition. Reporting after WannaCry attributed Microsoft's quiet March patch to a warning from the NSA itself; neither the agency nor the company ever confirmed it on the record. The Shadow Brokers advertised a monthly exploit subscription, posted on into 2017, and went silent — never publicly identified, never charged.

The smaller stories aged in character. Dallas encrypted its siren radios, and the quiet held until 2019, when two of its suburbs woke to the same trick performed on their own sirens. Front-desk malware of the IHG kind was the late style of magnetic-stripe crime; chip cards and encrypted terminals pushed the trade toward the web, where later editions of this archive keep finding it. Jharkhand's pension list proved to be a genre rather than an accident: official portals publishing Aadhaar data became a running pattern that fed India's right-to-privacy judgment that August, years of argument after it, and eventually the DPDP Act of 2023. And the gap between a patch and its installation became the industry's standard cautionary tale — four weeks long, and taught ever since.