The indictment was returned by a grand jury in the Southern District of New York on 17 December 2018 and unsealed three days later, on 20 December, at a press conference in Washington where the Deputy Attorney General, Rod Rosenstein, and the FBI Director, Christopher Wray, stood together to name two men neither expected to see in an American courtroom. Zhu Hua and Zhang Shilong were said to have worked for a private company — Huaying Haitai Science and Technology Development Company, in Tianjin — and to have acted in association with the Chinese Ministry of State Security's Tianjin State Security Bureau. Wray said the roll of victims read like a who's who of the global economy. The method already had a name: Cloud Hopper.

Cloud Hopper did not attack its targets. It attacked the firms those targets had hired to run their computers — managed service providers, the outsourced IT departments that hold administrative credentials for dozens or hundreds of client networks at once and are connected to all of them by design, in the ordinary course of doing the job they are paid for. Compromise one provider and the trusted connection carries the intruder wherever the provider is trusted to go, through no door that anybody thinks of as a door. Prosecutors said clients in at least a dozen countries were reached this way, among them Brazil, Canada, Finland, France, Germany, India, Japan, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.

The indictment charged a second and much older campaign alongside it, running from at least 2006 against more than forty-five companies and government agencies based in at least a dozen American states, across aviation, satellites, maritime technology, oil and gas, pharmaceuticals and advanced electronics, from which prosecutors said hundreds of gigabytes were taken. Two NASA centres were named — Goddard Space Flight Center and the Jet Propulsion Laboratory — along with the Department of Energy's Lawrence Berkeley National Laboratory. The detail that stayed with people was smaller and more personal. From more than forty Navy computers, prosecutors said, the conspirators had taken the personal information of over 100,000 Navy personnel: names, social security numbers, dates of birth, salary details, private phone numbers and email addresses.

What made 20 December unusual was the chorus. Five allied governments — the United Kingdom, Australia, Canada, New Zealand and Japan — issued statements the same day, and Britain's National Cyber Security Centre published an advisory naming both APT10 and the Ministry of State Security outright; the Foreign Secretary, Jeremy Hunt, called the campaign one of the most significant and widespread cyber intrusions against the UK and its allies yet uncovered. Two days earlier the New York Times had reported, on cables supplied by Area 1 Security, that thousands of European Union diplomatic messages had been drawn out of the COREU network — an intrusion Area 1 attributed to the People's Liberation Army, not the MSS. Beijing rejected the accusations. Neither Zhu nor Zhang has ever stood trial.

Also that month · Six days in November

Google+ brought forward its own funeral

Google disclosed on 10 December 2018 that a bug introduced in a software update in November had left profile information for roughly 52.5 million users reachable by applications those users had authorised — names, email addresses, occupation and age, including fields their owners had kept private. The fault was live for six days and was fixed within a week of its introduction. Google said it had found it during standard internal testing, and that it had no evidence any developer had realised the access existed or had misused it. It was the company's second Google+ API disclosure in three months, after the 8 October admission covering up to 500,000 accounts, and it cost the product what remained of its life: the consumer shutdown was pulled forward from August 2019 to April, with every Google+ API to be retired inside ninety days. Consumer Google+ closed on 2 April 2019, and a United States class action covering both bugs settled for $7.5 million. A week earlier, Quora had disclosed a breach of about 100 million accounts — the larger number, and the one nobody remembers.

Also that month · The wiper returns

Shamoon comes back for the oil business

The Italian oil services contractor Saipem said its servers were attacked on 10 December 2018, and identified the malware two days later, on 12 December: a variant of Shamoon, the disk wiper that had destroyed tens of thousands of machines at Saudi Aramco and RasGas in 2012. Its own statement placed the damage in the Middle East, India, Aberdeen and, in a limited way, Italy. Its head of digital and innovation, Mauro Piasere, told Reuters that between 300 and 400 servers and up to 100 personal computers had been crippled out of roughly 4,000 machines. Shamoon overwrites the master boot record, so an affected machine does not quietly leak anything — it simply refuses to start, and someone arriving for a shift finds a screen that never reaches a login prompt. Saipem said in a final update on 17 December that there had been no theft or loss of data and that restoration from backups was near completion. Researchers had long associated Shamoon with Iranian interests and Saudi targets; Saipem's largest client at the time was Saudi Aramco. No attribution was ever publicly confirmed.

India desk · December 2018

Ten agencies, one order

The Ministry of Home Affairs issued Statutory Order 6227(E) on 20 December 2018, signed by the Home Secretary, Rajiv Gauba. It named ten central agencies authorised to intercept, monitor and decrypt any information generated, transmitted, received or stored in any computer resource: the Intelligence Bureau, the Narcotics Control Bureau, the Enforcement Directorate, the Central Board of Direct Taxes, the Directorate of Revenue Intelligence, the Central Bureau of Investigation, the National Investigation Agency, the Cabinet Secretariat's Research and Analysis Wing, the Directorate of Signal Intelligence, restricted to Jammu and Kashmir, the North East and Assam, and the Commissioner of Police, Delhi. It was made under Section 69(1) of the Information Technology Act, 2000, read with Rule 4 of the interception rules of 2009, which require each case to be approved by the Union Home Secretary.

The reaction split along a line that has not moved since: opposition members raised it in the Rajya Sabha and called it a surveillance state in the making, while the government said the order created nothing. There was, the ministry said, no new law, no new rule, no new procedure, no new agency and no blanket authorisation — only a notification of which bodies could use powers framed in the rules of 2009, under the previous government. Arun Jaitley told the upper house the opposition was making a mountain where not even a molehill existed. Both readings hold: the order conferred no fresh authority, and it also set out in one list how much already existed. The advocate Manohar Lal Sharma petitioned the Supreme Court, calling the notification illegal and unconstitutional; the court issued notice to the Centre on 14 January 2019, giving it six weeks to reply.

AI Tech desk · December 2018

AlphaFold takes first place in Mexico

The thirteenth Critical Assessment of Structure Prediction met from 1 to 4 December 2018 on Mexico's Riviera Maya, and the entrant that finished first had never competed before. DeepMind's AlphaFold came top of the field and top of free modelling — the category for proteins with no close relative already on record — returning the best predictions for 25 of 43 targets, where the runner-up managed three. Nobody called the problem solved that December; that came with a second version at CASP14 in 2020 and the open structure database this archive reaches in 2021. Two more announcements crowded the same fortnight. Waymo opened Waymo One around Phoenix on 5 December, billed as the first commercial self-driving service, though a trained employee sat behind every wheel and only the few hundred riders already in its trial could book; the public there rode without a driver only from October 2020. On 7 December, Science carried the AlphaZero paper a year after its preprint: nine hours of self-play from the bare rules of chess, and no human games.

Digital Guard desk · December 2018

Ryuk stops the Saturday presses

Tribune Publishing's production systems were encrypted over the last weekend of December 2018, and Saturday editions of the Los Angeles Times, the Chicago Tribune, the San Diego Union-Tribune and the Baltimore Sun went out late, along with the West Coast runs of the Wall Street Journal and the New York Times, printed at the Los Angeles Times plant. Encrypted files carried the extension .ryk; Tribune said subscriber and advertiser data was untouched, and the Los Angeles Times said the attack appeared to have come from outside the United States. Five days earlier, on Christmas Eve, the same family had entered the cloud host Data Resolution through a single compromised login. Ryuk was widely tied to North Korea that month, on code shared with Hermes; by January 2019 CrowdStrike had reassigned it to a Russian-speaking criminal group, Hermes having been sold openly as a kit. The lineage was real and the authorship was not; Ryuk went on from the presses to American hospitals and county governments.

⏳ Time capsule — December 2018

  • NASA's OSIRIS-REx spacecraft arrived at the asteroid Bennu on 3 December, after a journey of more than two years.
  • George H. W. Bush's state funeral was held at Washington National Cathedral on 5 December; he was buried in Texas the following day.
  • Theresa May survived a Conservative Party confidence vote on 12 December by 200 votes to 117, days after postponing the Commons vote on her Brexit deal.
  • Gatwick Airport's runway was shut for about 33 hours from the evening of 19 December after repeated drone sightings, disrupting around 1,000 flights and some 140,000 passengers. No one was ever charged.
Where it stands today — 2026

What December set running

The indictment named not one service provider. Reuters filled that silence in June 2019, reporting that the campaign had reached Hewlett Packard Enterprise, IBM, Fujitsu, Tata Consultancy Services, NTT Data, Dimension Data, Computer Sciences Corporation and DXC Technology; several declined to comment, and DXC said neither it nor its clients had suffered material impact. By then the shape was set. This archive's December 2020 edition follows a poisoned SolarWinds update into US federal networks, and its July 2021 edition follows another through Kaseya into as many as 1,500 businesses — the same idea, executed better each time: do not attack the target, attack what it installs or whom it trusts. Zhu Hua and Zhang Shilong were never arrested, and both remain on the FBI's list of wanted cyber suspects.

India's December order was never struck down. The Supreme Court's notice of January 2019 produced no judgment constraining the power, and the Home Ministry has since refused right-to-information requests asking how many interception approvals it has granted, so the number stays unpublished. Much of what follows in these pages rests on that unanswered question: the Pegasus disclosures that reach this archive's July 2021 edition, the CERT-In directions of 2022 that placed reporting duties and log retention on private networks under a different section of the same Act, and the Digital Personal Data Protection Act of 2023, which governs closely what companies may do with personal data while leaving the state's own agencies broadly exempt. The Vault keeps working backwards, and the further back it goes the fewer surprises it finds.