Monzo's fraud team found the pattern on 6 April 2018. Around fifty of the bank's customers had reported card transactions they did not recognise, and when analysts looked for something the victims had in common, roughly seven in ten of them turned out to have bought tickets through Ticketmaster. On 12 April Monzo staff took the evidence to Ticketmaster in person, at its offices. On 19 April Ticketmaster wrote back to say that an internal investigation had found no evidence of a breach of its systems. Monzo replaced about six thousand cards anyway. The Information Commissioner's Office later recorded that nine weeks passed between Ticketmaster being alerted to possible fraud and Ticketmaster beginning to monitor the network traffic leaving its own payment page.
What sat on that page was a chatbot. Ticketmaster had taken a piece of JavaScript written for it by Inbenta Technologies, a supplier of customer-support software, and placed it on the page where customers typed their card numbers. Someone found the script, added to it, and turned it into a skimmer that copied each payment form as it was filled in and posted the contents elsewhere. The regulator later established that the malicious code had been in place on the British payment page since 10 February 2018; on the international sites Ticketmaster itself told customers the exposure reached back to September 2017. Ticketmaster removed the chatbot from most of its sites on 23 June and from the French sites and GETMEIN! the following day, notified the ICO on 23 June, published a statement on 27 June, and began writing to affected customers on 28 June.
The blame never settled. Inbenta's chief executive, Jordi Torras, said publicly that the code at the centre of the incident was a single piece of JavaScript his company had customised to Ticketmaster's requirements for a support function, that Ticketmaster had applied it to its payments page without telling Inbenta, and that Inbenta "would have advised against" that use of it had it known. Ticketmaster's position was the mirror image: the malicious code had sat inside third-party software, and its own systems had not been breached — a line the company was still holding publicly in December 2018. Its first estimate was fewer than five per cent of its global customer base, reported at the time as about 40,000 people in Britain who had bought tickets between February and 23 June.
The real figure arrived two and a half years later. On 13 November 2020 the ICO fined Ticketmaster UK £1.25 million and found that up to 9.4 million customers across the European Economic Area had potentially been affected, some 1.5 million of them in the United Kingdom, with around 60,000 Barclays cards known to have been used fraudulently; Ticketmaster said it would appeal. Nothing had visibly broken at any point. When WannaCry ran through NHS trusts in May 2017, screens changed colour and clinics stopped within a morning; here the checkout worked perfectly for four and a half months while it was being read. On 22 June 2018, the day before Ticketmaster pulled its chatbot, an intruder first entered British Airways' network — September's edition.
The database nobody signed up for
On 27 June, WIRED reported that Exactis, a Florida marketing data broker, had left roughly 340 million records — about 230 million on consumers and 110 million on business contacts — on a server reachable from the open internet. Vinny Troia of Night Lion Security found it among the thousands of ElasticSearch instances that answer a Shodan query; he reported it to Exactis and the FBI, and the server went quiet. Each record ran to more than 400 variables: not card numbers or Social Security numbers, but religion, whether the person smoked, whether they kept pets, their interests, the ages and genders of their children. Troia told WIRED that not all of it was current or verifiable. Nobody in the file had filled in a form to be there. Exactis said almost nothing in public and stopped trading; the class action stalled against a defendant with no money. Three weeks earlier, on 4 June, MyHeritage had disclosed a file found on an outside server with the email addresses and hashed passwords of 92,283,889 users — everyone signed up to the genealogy service by 26 October 2017, the date of the theft.
Dixons Carphone starts counting
On 13 June, Dixons Carphone told the market that a review of its systems had found unauthorised access to 1.2 million records of non-financial personal data, and an attempt to compromise 5.9 million payment cards in one processing system serving Currys PC World and Dixons Travel stores. Almost all of those cards carried chip-and-PIN protection, and the company said no PINs, card verification values or authentication data had been taken; about 105,000 non-EU cards without chip-and-PIN had been compromised. Both halves of the announcement were provisional. On 31 July the company revised the personal-data figure to approximately 10 million records — more than eight times its first estimate — while maintaining that those records held no payment or bank details and that it had seen no evidence of resulting fraud. The intrusion ran from July 2017 to April 2018; only the disclosure belonged to the new regime, and the gap decided the penalty. When the ICO closed its investigation in January 2020 it fined DSG Retail Limited £500,000, the maximum available under the Data Protection Act 1998, because the conduct predated the regulation that had taken effect less than three weeks before the announcement — and it put the number of people whose personal data had been compromised at approximately 14 million, higher again than the company's own revision.
The month the Aadhaar number became optional at the counter
From 1 June 2018, under a circular the UIDAI had issued on 10 January, every agency licensed to perform Aadhaar authentication was supposed to accept a Virtual ID in place of the number itself. A Virtual ID is a temporary sixteen-digit number mapped to an Aadhaar number, which only the holder can generate, replace or revoke, and from which the UIDAI said the underlying number cannot be derived. Two quieter measures travelled with it: limited KYC, under which most agencies would receive only need-based details — name, address, photograph — rather than a full record, and the UID Token, an agency-specific identifier that lets a company recognise a returning customer without ever storing the Aadhaar number. Agencies that failed to migrate were to lose their authentication services.
It was aimed at the right target. Almost none of the Aadhaar exposures reported that year involved breaking into the UIDAI; they involved the number sitting somewhere else. The one January report that appeared to — The Tribune's account of paying ₹500 for portal access that returned the details behind any Aadhaar number — the UIDAI denied outright, calling it misuse of a grievance-redressal search facility rather than a breach of the database, and answering it with a police complaint that named the reporter. In an April 2018 case documented by the researcher Srinivas Kodali, an Andhra Pradesh government website published the Aadhaar numbers of about 134,000 people alongside their caste, religion, bank details and father's name. If the number never leaves the resident, it cannot leak from the thousandth database it was copied into. What June could not do was make anyone ready. The deadline moved to 1 July, then to the end of August, then to 31 October 2018, then to the end of January 2019, agencies still asking for time. The Supreme Court upheld the Aadhaar Act on 26 September 2018 but struck down Section 57, ending the legal footing on which private companies had demanded it; a data protection statute waited until the DPDP Act of 2023.
The four things Google would not build
Google Cloud's chief executive, Diane Greene, told staff on 1 June 2018 that the company would not renew Project Maven, its contract to apply image recognition to Pentagon drone footage, when it expired in March 2019; more than four thousand employees had signed an open letter arguing that Google should not be in the business of war, and about a dozen engineers resigned. Six days later Sundar Pichai published a set of AI principles naming four applications the company would not pursue — weapons, surveillance breaching internationally accepted norms, technologies likely to cause overall harm, and anything contravening international law and human rights — while saying other work with governments and the military would continue. Microsoft agreed to buy GitHub for $7.5 billion in stock on 4 June, closing in October; the public code it hosted would later help train Copilot, the assistant GitHub sold back to the developers who wrote it. On 11 June OpenAI released a 117-million-parameter language model almost nobody outside the field noticed. Google deleted the list of applications it would not pursue in February 2025.
Paragraph 76 names a single company
On 13 June 2018 the European Parliament adopted a report on cyber defence by 476 votes to 151, with 36 abstentions. Paragraph 76 called on the EU to review the software and equipment used in its institutions, exclude potentially dangerous programmes and devices, and ban those "confirmed as malicious, such as Kaspersky Lab". The report carried no legislative force and set out no evidence; the European Commission had said in April that it had no indication of any danger associated with the anti-virus engine in question. Kaspersky Lab answered the same day, rejecting the finding as untrue and temporarily halting its European cybercrime work — its cooperation with Europol, and its part in the No More Ransom project — pending clarification, while pointing to the transparency centre it was opening in Switzerland. No EU-wide ban followed. The prohibition that eventually closed a Western market came from Washington: a US Commerce Department determination announced on 20 June 2024 barred new sales from 20 July and updates from 29 September, and Kaspersky left the United States.
⏳ Time capsule — June 2018
- Donald Trump and Kim Jong-un met at the Capella hotel on Sentosa Island, Singapore, on 12 June — the first meeting between a sitting US president and a North Korean leader.
- The FIFA World Cup opened in Russia on 14 June; France won the final in Moscow on 15 July.
- Twelve boys aged 11 to 16 and their 25-year-old assistant football coach entered the Tham Luang cave in northern Thailand on 23 June and were cut off by rising water. British divers John Volanthen and Rick Stanton found them alive on 2 July, and all thirteen were brought out by 10 July; a former Thai Navy SEAL, Saman Kunan, died during the operation.
- Saudi Arabia's ban on women driving ended on 24 June, nine months after King Salman's decree announcing it.
The month the page still worked
Ticketmaster's chatbot is where web skimming stopped being an oddity and became an industry. RiskIQ published its analysis on 10 July 2018, placing the incident inside a campaign researchers had tracked as Magecart since 2015 and showing it reached past Inbenta — SociaPlus, PushAssist, Clarity Connect and Annex Cloud were compromised too. British Airways followed in September; the two British penalties landed a month apart in autumn 2020, £20 million for the airline on 16 October and £1.25 million for the ticket seller on 13 November. The lesson — that a payment page is only as trustworthy as every script loaded into it — took the card industry until 31 March 2025 to make compulsory, when the PCI DSS rules on inventorying and monitoring payment-page scripts came into force.
Exactis left a different residue. The month its database was found was also the month California passed the Consumer Privacy Act, signed on 28 June 2018 and in force from 1 January 2020 — the first American law to give people any purchase on companies they had never heard of, and the template a long line of states copied. India reached the same destination from the opposite direction, building the technical evasion in June 2018 and the statute five years later. Facebook's June was minor by comparison: a bug disclosed on 7 June had quietly set roughly 14 million users' new posts to public for about ten days in May, which reads now as a rehearsal for the access-token breach the company disclosed that September. The Vault continues backwards.