The statement went out in the early evening of Thursday 7 September 2017, after the New York markets had closed. Equifax, one of the three bureaus that keep credit files on nearly every American adult — files assembled about people rather than from them, under no contract anyone signed — announced that intruders had been inside its systems from mid-May until late July, and that the records of approximately 143 million United States consumers were potentially affected: names, Social Security numbers, birth dates, addresses, some driver's licence numbers, and around 209,000 payment card numbers. The company's own security staff had found the intrusion on 29 July, on a portal where consumers dispute errors in their files. The public had then been told nothing for forty days.

The door had been open since spring. The way in was CVE-2017-5638, a command-injection flaw in the Apache Struts framework, fixed on 6 March 2017, publicly detailed the next day and exploited in the wild within about forty-eight hours — the same flaw this archive's March edition records as a warning while it was still fresh. Equifax circulated the patch notice internally on 9 March; on the dispute portal it was never applied, and a scan days later found nothing amiss. The intruders settled in on 13 May and worked until the end of July, running thousands of queries against dozens of databases and drawing the data out in small encrypted parcels — unseen, because the device meant to inspect that traffic had been left sitting behind an expired certificate.

What followed became a manual of what not to do. The help site went up not on equifax.com but on a fresh domain, equifaxsecurity2017.com, of exactly the shape phishing sites take; browsers flagged it, and its eligibility checker gave different answers to identical queries. The terms attached to the free credit monitoring contained an arbitration clause waiving the right to sue, withdrawn within days after New York's attorney-general and several senators objected. The PIN protecting a newly frozen credit file turned out to be nothing more than the date and minute the freeze was placed. And when a software engineer named Nick Sweeting spent ten dollars cloning the help site as securityequifax2017.com to prove the danger, Equifax's own Twitter account directed victims to his fake — repeatedly, beginning 9 September, before anyone at the company noticed.

Then there were the share sales. On 1 and 2 August, days after discovery, chief financial officer John Gamble and two division presidents sold stock worth about $1.8 million; the company said none of them had known of the intrusion, and a special committee of the board concluded that November that the trades were clean. Jun Ying — chief information officer of a business unit, next in line to be global CIO — was different: he deduced the breach from internal clues, exercised his options, sold for roughly $950,000, and in 2019 became the only person imprisoned over the affair, four months for insider trading. The chief security officer and the corporate CIO retired on 15 September; chief executive Richard Smith followed on the 26th, summoned to face Congress the following week.

Also that month · Supply chain

The update with a target list

On 18 September 2017, Piriform — maker of CCleaner, a disk clean-up tool its owners said had been downloaded two billion times, and freshly acquired by the anti-virus firm Avast — disclosed that version 5.33.6162, published on 15 August, had shipped with a backdoor compiled in before signing. The download was the genuine article from the genuine servers, carrying Piriform's valid digital signature, and about 2.27 million machines ran it. The security firm Morphisec had alerted Avast on 12 September; researchers at Cisco Talos found the same thing independently. The chilling part was the restraint. The first stage merely profiled each machine and phoned home; a second stage went only to computers inside a shortlist of technology companies. Talos's copy of the command server's database, covering barely three days, showed that stage delivered to about twenty machines at eight firms; Avast's fuller reconstruction later settled on roughly forty, while allowing the true figure could be higher. Talos noted overlaps with code used by a group researchers link to China. Two and a quarter million infected; forty intended. Supply chain as a precision instrument.

Also that month · The gatekeepers

The regulator and the auditor

The month's other confessions came from institutions meant to set the example. On 20 September, Jay Clayton, chairman of the US Securities and Exchange Commission, published a four-thousand-word statement with the news buried midway: EDGAR, the system through which listed companies file market-moving documents, had been penetrated in 2016 through a flaw in its test-filing component. The hole had been patched promptly, the statement said; only in August 2017 did the agency conclude the intrusion "may have provided the basis for illicit gain through trading". In 2019 prosecutors charged a Ukrainian hacker and a ring of traders they said turned stolen filings into $4.1 million. Five days later, The Guardian revealed that Deloitte, auditor to much of the corporate world, had had its email compromised through an administrator account with no two-factor authentication, possibly since late 2016; the firm said very few clients were affected, while reporting by Brian Krebs described something far wider, which Deloitte disputed. Washington had opened the month setting deadlines for others: on 13 September, Homeland Security's Binding Operational Directive 17-01 gave agencies ninety days to remove Kaspersky software, over the company's denials of improper ties.

India desk · September 2017

Twenty-three million emails and a battery app

India spent September watching its inboxes. On 2 September the Indian Computer Emergency Response Team issued an alert on Locky, ransomware riding a spam wave that the security firm AppRiver had measured at more than 23 million messages inside twenty-four hours — emails with subject lines as plain as 'documents', 'photo' and 'please print', a zipped script attached, and a demand of half a bitcoin, reported at the time as about ₹1.5 lakh, to undo the encryption. The memory of May was doing the work: WannaCry had touched state police computers and a power utility here, and this time the machinery moved early. The Bombay Stock Exchange passed the warning to its brokers on 4 September, and corporate IT departments spent the week rehearsing backups. The wave broke without a marquee Indian victim, which in 2017 counted as a small victory.

The other warning was about the handset. Kaspersky Lab reported in the first week of September that a trojan it called Xafecopy, dressed up as battery-optimiser apps with names like BatteryMaster, had hit more than 4,800 users across 47 countries in a month — and that 37.5 per cent of the attacks it detected were aimed at India, the largest share of any country. The scheme needed no card number and no password: on networks that still supported WAP billing, the malware silently clicked subscription pages and let the charges land on the victim's mobile bill. In hindsight it reads like a first sketch of the decade India's fraud desks now live in — money moved by the phone itself, one small unauthorised consent at a time.

AI Tech desk · September 2017

The chip that learned its owner's face

The telephone the world met on 12 September 2017 mattered less for its screen than for its silicon. Inside sat Apple's A11 chip and its 'neural engine' — hardware reserved for machine learning, rated at six hundred billion operations a second — whose first job, Face ID, matched a depth map of the owner's face on the device itself, nothing sent to a server. The first handset on stage refused to unlock and asked for a passcode; Apple said staff handling it beforehand had tripped the lockout, so it had behaved as designed. Senator Al Franken wrote to Tim Cook the next day asking where the face data went. The wider argument had opened the month: Vladimir Putin told Russian schoolchildren on 1 September that the leader in artificial intelligence would become 'the ruler of the world', and on 7 September IBM and MIT announced a ten-year, $240 million joint AI laboratory. The neural engine, easy to read as marketing then, set the pattern — a decade on, hardly a phone ships without one.

Digital Guard desk · September 2017

Washington orders Kaspersky off its networks

On 13 September 2017 the Department of Homeland Security issued Binding Operational Directive 17-01, ordering every federal civilian agency to find Kaspersky Lab products on its systems within thirty days, plan their removal within sixty, and begin taking the software out at ninety — the stated worry being that Russian law could compel a company with deep access to the machines it protects to assist Russian intelligence. Kaspersky called the decision disappointing, said no credible evidence had been presented, denied inappropriate ties with any government and described itself as caught in the middle of a geopolitical fight; that December it sued, arguing it had been condemned without a hearing, and lost. The market had moved first — Best Buy cleared the company's boxes from its shelves the week before the directive — and on 18 September the Senate voted to write a government-wide ban into the annual defence bill, while CCleaner's poisoned update, covered above, showed trust broken by compromise rather than decree. The precedent — treating a vendor's home jurisdiction as the threat — has been reused ever since.

⏳ Time capsule — September 2017

  • NASA's Cassini spacecraft, nearly twenty years from launch and thirteen in orbit of Saturn, was deliberately flown into the planet's atmosphere on 15 September, transmitting until it broke apart.
  • Apple unveiled the iPhone X at the new Steve Jobs Theater on 12 September — a $999 telephone with no home button that unlocked by scanning its owner's face.
  • Hurricane Maria made landfall in Puerto Rico on 20 September and destroyed the island's power grid; the blackout became the longest in United States history, and a later study attributed nearly 3,000 deaths to the storm.
  • A royal decree issued on 26 September announced that women in Saudi Arabia would be licensed to drive from June 2018 — the last country in the world to permit it.
Where it stands today — 2026

The file that never surfaced

The count settled at 147.9 million in March 2018, after two further reviews added their findings. Nobody has ever been charged with using the data — in nine years it has not surfaced for sale — and the indictment of February 2020, charging four officers of the People's Liberation Army's 54th Research Institute, covered in that month's edition, stands as the accepted explanation: espionage, not fraud. The four remain in China. Equifax settled with the FTC, the CFPB and fifty US states and territories in July 2019 for at least $575 million, rising as high as $700 million; the advertised $125 cash payments dissolved into a few dollars each once claims flooded in. The durable fix was quieter — from 21 September 2018, federal law made freezing one's credit free.

The rest of the month kept its shape. CCleaner's forty chosen machines became the working drawing for a decade of supply-chain compromise, refined against ASUS in 2019 and carried into government through SolarWinds in December 2020 — an attack that entered its victims the way September 2017's attackers entered Piriform, through the update channel everyone is told to trust. The EDGAR intrusion ended in the 2019 charges; Deloitte never gave a fuller public accounting. The Kaspersky directive's ninety days grew, by mid-2024, into a ban on selling the software in the United States at all. And The Vault's restoration of 2017 now runs on either side of this edition — August behind it; ahead, October, with Congress waiting and three billion Yahoo accounts about to be recounted.