The bucket was called verizon-sftp, and it opened for anyone who typed the address. On 8 June 2017 Chris Vickery, a researcher at the California firm UpGuard who hunted exposed data for a living, found inside it six months of Verizon call-centre records — folders named for each month from January to June, daily subfolders, zipped text files running to 23 gigabytes once opened — holding customer names, addresses, phone numbers and, in one file alone, about six thousand account PINs in plain text: the codes a caller reads out to prove who they are. One logged field graded each customer's FrustrationLevel. The server belonged not to Verizon but to NICE Systems, a contractor in Ra'anana, Israel. Vickery notified Verizon on 13 June; the bucket stayed open nine more days.

UpGuard published its account on 12 July and put the exposure at as many as 14 million customer accounts. Verizon confirmed the lapse but counted six million unique customers, and said no data had been lost or stolen. Five days later came the second name: a Dow Jones bucket called dj-skynet, found on 30 May and secured on 6 June, held subscriber records for the Wall Street Journal and Barron's — names, addresses, email addresses, the last four digits of payment cards. Dow Jones acknowledged about 2.2 million customers; UpGuard's conservative estimate ran nearer four million. In the first week of July, researchers at Kromtech had already surfaced a third: 3,065,805 WWE fan records, in plain text, no password asked — birthdates, home addresses, children's age ranges, even ethnicity.

None of this was hacking. Amazon ships its Simple Storage Service buckets closed; every one of these had been opened by hand. The Dow Jones repository was set to admit any authenticated user — a phrase that sounds like a safeguard and meant anyone holding a free Amazon Web Services account, more than a million of them. The pattern had a prologue: in June, Vickery had found 198 million American voter profiles left open by Deep Root Analytics, a contractor to the Republican National Committee. There was no vulnerability to patch and no attacker to indict, and the companies leaned on that distinction. Exposure was not breach, and breach-notification law turned on evidence of acquisition — which an open bucket, its access logging off by default, rarely keeps.

Vickery's method was disarmingly plain: guess likely bucket names, type them in, see what answers. That it kept working was the story of the summer, and the fixes arrived at the speed of product management rather than incident response. In November 2017, after Accenture's buckets and the Pentagon's had joined the list, Amazon added a bright orange Public badge beside every open bucket in its console. In November 2018 it shipped a master switch called Block Public Access. Not until April 2023 would newly created buckets refuse public readers by default. July 2017 was the month the excuse expired — after Verizon, Dow Jones and the WWE inside six weeks, no single instance could plausibly be called an accident again.

Also that month · Disclosed 31 July

1.5 terabytes, the attackers said

On the night of Sunday 30 July, reporters at entertainment outlets received a message from an address styling itself little.finger66. "The greatest leak of cyber space era is happening," it read, linking to a script for the Game of Thrones episode due to air the following Sunday. HBO confirmed the intrusion on Monday 31 July, and its chief executive, Richard Plepler, told staff a cyber incident had compromised proprietary information, including programming. The attackers put their haul at 1.5 terabytes — their figure, never HBO's. Unaired episodes of Ballers and Room 104 surfaced with that first message; through August came internal documents, one executive's email cache and a demand for roughly $6 million in bitcoin from a correspondent signing himself Mr. Smith. In November, federal prosecutors in Manhattan unsealed an indictment naming Behzad Mesri, an Iranian national they said had spent months on reconnaissance of HBO employees before working through their accounts. He was never arrested; a second American indictment named him again in 2019, and the charges have simply waited ever since.

Also that month · Twenty-seven days

The car crash at the gate

AlphaBay went offline on 5 July, and its customers assumed the oldest story on the dark web: the administrators had taken the money and run. The truth was in Bangkok, where Thai police had staged a minor car crash into the front gate of a house; when Alexandre Cazes — the 25-year-old Canadian who ran the world's largest dark-web market under the name Alpha02 — came out to investigate, officers walked in behind him and found his laptop open and logged in with administrator access. His undoing was old: the market's earliest welcome emails had gone out from pimp_alex_91@hotmail.com, his personal address, and investigators had pulled the thread. Cazes was found dead in Thai custody on 12 July, an apparent suicide. On 20 July the American attorney general and Europol announced the seizure, calling AlphaBay some ten times the size of Silk Road — and disclosed the harder twist. Dutch police had controlled Hansa, the market the refugees fled to, since 20 June, and spent twenty-seven days logging orders and addresses as registrations rose eight-fold.

India desk · July 2017

Type a number, read a name

On the evening of Sunday 9 July a website called magicapk.com began doing something no telecom database should permit: enter any Reliance Jio mobile number and it returned the subscriber's name, email address, SIM activation date and telecom circle, alongside an Aadhaar column that, for most queries, sat blank. The technology site FactorDaily reported it the same night; by around 11 pm the domain was suspended. Scale made it the story: Jio had signed up a hundred million subscribers within months of launching, and if the data was genuine, no Indian telecom had ever leaked more. Jio's position held two things at once — publicly it called the claims unverified and unsubstantiated, said the data appeared prima facie unauthentic and assured subscribers their information was safe behind the highest security; in its complaint to the police it alleged unlawful access to its systems.

The first information report went to Navi Mumbai's cyber police, and within days officers had detained a young computer-application graduate from Churu district in Rajasthan, named in reports as Imran Chhimpa, though the papers disagreed over the spelling and even his age. The motive wobbled too: free recharges by one police account, a search engine by another. What the case never produced was an authoritative account of what, if anything, had left Jio's systems — and in July 2017 nothing required one, because India had no data-protection statute and no duty on any company to notify anyone of a breach. The Aadhaar column lingered longest. Mostly empty, it implied a join between a private operator's rolls and the national identity number, and for a subscriber base that size, the possibility was the story.

AI Tech desk · July 2017

The plan that named 2030

On 20 July 2017 China's State Council published its Next Generation Artificial Intelligence Development Plan, and its defining line was a deadline: the world's primary centre of AI innovation by 2030. The plan staged its objectives — parity with the field's leaders by 2020, world-leading results in places by 2025, primacy by 2030 — and set industry targets and ministries behind them, making leadership in AI explicit national policy. The month had opened in the same key: at Baidu's developer conference on 5 July, Robin Li launched Apollo, an open-source autonomous-driving platform the company billed as the Android of the car industry, appearing by video link from a self-driving car on Beijing's Fifth Ring Road. The louder argument was American: Mark Zuckerberg, live-streaming on 23 July, called doomsday talk about AI "pretty irresponsible"; Elon Musk replied on 25 July that Zuckerberg's grasp of the subject was limited. Nine years on the quarrel is a footnote and the date is not — the 2030 plan now reads as the founding document of the decade's defining technology rivalry.

Digital Guard desk · July 2017

The vendor becomes the vector

On 11 July 2017 the US General Services Administration removed Kaspersky Lab from its schedules of pre-approved contractors, the lists federal agencies buy through. Nothing was banned yet — the directive ordering the software out of civilian agencies came in September, the statute in December, and later desks carry both — but the delisting was the saga's first concrete act, and the reasoning was the story: officials feared that anti-virus software, holding the deepest privileges a machine grants, could serve a foreign government as a way in. Kaspersky denied inappropriate ties to any government, said it had been caught in a geopolitical fight, and its founder offered his source code for American review and himself for testimony. Eight days later the Czech firm Avast announced its purchase of Piriform, the British maker of CCleaner, a clean-up utility counting, by Avast's reckoning, more than 130 million users; terms were not disclosed. Two months on, CCleaner's own update channel would be found delivering a backdoor — September's story — and July's two items would read, in retrospect, as one lesson about trust.

⏳ Time capsule — July 2017

  • Roger Federer won Wimbledon for a record eighth time on 16 July, at 35 the oldest men's singles champion of the professional era, without dropping a set in the tournament.
  • Christopher Nolan's Dunkirk, shot largely on 65mm IMAX film, premiered in London's Leicester Square on 13 July and opened in cinemas on 21 July.
  • Tesla handed the first thirty Model 3 cars — most of them to employees — to their owners at a factory event in Fremont, California on the evening of 28 July.
  • Ram Nath Kovind was declared winner of India's presidential election on 20 July and sworn in as the country's fourteenth president five days later.
Where it stands today — 2026

The checkbox and the certificate

The buckets kept opening for years — Accenture's in October 2017, Pentagon contractors' archives in November — and when S3 itself was finally fenced the failure migrated to unsecured Elasticsearch clusters and exposed APIs, where it lives still. Amazon's remedies came in deliberate steps: the orange badge in 2017, the Block Public Access switch in 2018, locked-by-default buckets from April 2023 — nearly six years after Vickery's summer. The fullest expression of the failure mode arrived exactly two years after this cover story, when one misconfigured firewall gave up 106 million credit applications; that month is the July 2019 edition, and its title — Shared Responsibility — is the doctrine this July made unavoidable.

Hindsight adds the story nobody printed that month. On 29 July 2017 an Equifax technician renewed a security certificate that had sat expired for some ten months; the traffic-inspection device behind it came back to life and began flagging suspicious activity at once. The intrusion it revealed had been running since mid-May, the public would hear nothing until 7 September, and the final count — 147.9 million people — would make every number in this edition look small. That reckoning belongs to the September edition. The quieter July verdict aged differently: exposure and breach stayed legally distinct for years, and the companies of that summer were right that the difference mattered — just wrong about which way history would rule.