Bloomberg Businessweek published "The Big Hack" on 4 October 2018. Chinese intelligence, the magazine reported, had caused a malicious component no bigger than a grain of rice to be added to server motherboards built for Supermicro, and those boards had reached almost thirty American companies, among them Apple and Amazon. The physical detail was the story's engine: in the late spring of 2015, Elemental Technologies — a video firm Amazon was then evaluating for acquisition — sent servers to Ontario for third-party security testing, and the testers, Bloomberg wrote, found a chip that had not been in the boards' original design. Seventeen people, all unnamed, were said to have confirmed the manipulation, and Supermicro's shares had the worst day in the company's history as a listed stock.

The denials arrived with the story and never softened. Bloomberg published statements from Amazon, Apple, Supermicro and the Chinese foreign ministry alongside the piece; Amazon said that at no time, past or present, had it found any issue relating to modified hardware or malicious chips in Supermicro motherboards in any Elemental or Amazon system. On 6 October the United States Department of Homeland Security said it had no reason to doubt the companies, echoing Britain's National Cyber Security Centre, which had said the same of the statements from Apple and Amazon the day before. On 8 October, Apple's vice-president of information security, George Stathakopoulos, wrote to Congress that Apple had never found malicious chips, hardware manipulations or vulnerabilities purposely planted in any server.

On 19 October Apple's chief executive, Tim Cook, told BuzzFeed News there was no truth in the story and that it should be retracted, a step the outlet described as unprecedented for the company. Andy Jassy, then running Amazon Web Services, and Supermicro's chief executive, Charles Liang, followed within days. Joe FitzPatrick, the hardware security researcher named in the piece, told the Risky Business podcast that he saw "a lot of details that I gave out of context" and had his doubts about it. On 11 December Supermicro told customers that Nardello & Co, an outside investigations firm it had engaged, had examined a representative sample of boards — including the type depicted in the article — and found no evidence of malicious hardware.

Nothing since has resolved it. Bloomberg did not retract, and in February 2021 published a follow-up, "The Long Hack", which widened the allegations and drew the same categorical denials from Supermicro and from the companies named in it. No implant has ever been produced in public, no tampered motherboard has been shown to anyone outside the reporting, and no independent corroboration has appeared in the eight years since. This archive therefore records the largest story of October 2018 as what it verifiably is: a serious allegation published by a major news organisation, disputed in unusual detail by every named party and by two governments' security agencies, tested by a commissioned audit that found nothing, and never withdrawn.

Also that month · The number, recounted

Facebook does the arithmetic again

On 12 October 2018 Facebook revised the breach it had announced a fortnight earlier. Of the fifty million accounts whose access tokens it had reset as a precaution, about thirty million had in fact had tokens stolen. The route was ordinary: attackers held a set of accounts connected to friends, moved automatically from account to account to take tokens for roughly 400,000 people, then used those people's friends lists to reach the rest. For fifteen million, the attackers accessed name and contact details. For fourteen million, they also took username, gender, relationship status, religion, hometown, birthdate, education, work, device types, the last ten places checked into or tagged in, and the fifteen most recent searches. For one million, tokens were stolen but nothing was read. Facebook said Messenger, Instagram, WhatsApp, Oculus, payments and third-party apps were untouched, and that it was cooperating with an FBI investigation. Thirteen days later the Information Commissioner's Office announced a separate £500,000 penalty over Cambridge Analytica — the maximum available under the Data Protection Act 1998, and unrelated to the tokens.

Also that month · Seven months of silence

Cathay Pacific tells 9.4 million people

Cathay Pacific announced late on 24 October 2018 that data on up to 9.4 million passengers had been accessed: names, nationalities, dates of birth, phone numbers, email and postal addresses, passport details, frequent-flyer numbers and historical travel information. The airline later put the exposure at about 860,000 passport numbers and roughly 245,000 Hong Kong identity card numbers, alongside 403 expired credit card numbers and 27 live ones without security codes. Three dates need keeping apart. Suspicious activity — a brute-force attack against one of its databases — was detected on 13 March 2018; unauthorised access was confirmed in May; the public was told in late October. Rupert Hogg, then chief executive, said there was no evidence any personal data had been misused. Hong Kong's Privacy Commissioner for Personal Data, Stephen Kai-yi Wong, reported on 6 June 2019 that the airline had shown a lax attitude to data governance and had kept identity card numbers longer than it needed to. Britain's ICO, notified on 25 October 2018, fined the airline £500,000 in March 2020 and found the intruders had held access from at least 15 October 2014 until 11 May 2018.

India desk · October 2018

The deadline that did not move

The Reserve Bank of India's circular of 6 April 2018 on the storage of payment system data gave payment system operators six months to hold data relating to Indian payments only on servers inside India, and to report compliance by 15 October 2018. The deadline arrived and it held. More than sixty firms had complied, among them PhonePe and the Indian payment arms of Google and WhatsApp; Visa, Mastercard and American Express had not. The central bank declined to shift the date, rejected the industry's preferred compromise of mirroring — a copy held in India while processing continued abroad — and imposed no immediate penalty, requiring instead time-bound compliance schedules from the laggards. It was not an incident. It is the month India began treating payment data as infrastructure rather than a commercial asset.

The month's other Indian story was a reporting failure, not a breach. Gemalto's Breach Level Index for the first half of 2018 was reported as attributing more than a billion compromised records to Aadhaar, which would have made it the index's largest entry. Within days the company withdrew the figure, saying it had relied on an unverified news article and could not track any substantiated breach of the UIDAI database. The Unique Identification Authority of India issued a circular suspending procurement of the firm's products, and on 27 October Gemalto's chief executive, Philippe Vallée, published an apology as a newspaper advertisement. The withdrawal was correct; the pressure that produced it is worth noting. Both October stories turn on the same question — who may say what has happened to Indian data — which the Digital Personal Data Protection Act would not begin to answer for five years.

AI Tech desk · October 2018

BERT reads the sentence both ways

On 11 October 2018 four researchers at Google AI Language — Jacob Devlin, Ming-Wei Chang, Kenton Lee and Kristina Toutanova — posted "BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding" to arXiv. Its method was to mask words and make the model read context on both sides at once, and it advanced eleven natural language tasks, lifting the GLUE benchmark to 80.5 per cent and SQuAD v1.1 test F1 to 93.2. A year later Google said it was using BERT in Search, on about one English query in ten in the United States. The month's other AI news was more equivocal. Reuters reported on 10 October that Amazon had scrapped an experimental recruiting tool after it learned to mark down résumés containing the word "women's"; MIT announced a $1 billion college of computing on 15 October, anchored by a $350 million gift from Stephen Schwarzman; and on 25 October Christie's sold Portrait of Edmond de Belamy, made by the Paris collective Obvious with a generative adversarial network, for $432,500 against a high estimate of $10,000.

Digital Guard desk · October 2018

Windows Defender moves into a sandbox

On 26 October 2018 Microsoft announced that Windows Defender Antivirus could run inside a sandbox, which it said made it the first complete antivirus product to do so. The reasoning was stated openly: researchers had shown that flaws in the scanner's content parsers could be turned into code execution, and a process running at the highest privilege is a prize. It shipped to Windows Insiders as an opt-in setting. Nine days earlier ESET had published its GreyEnergy white paper, documenting a successor to the BlackEnergy group that had worked against energy companies in Ukraine and Poland since late 2015, used Mimikatz, PsExec and Nmap, and had stayed deliberately non-destructive. On 10 October Symantec described Gallmaker, a group that used no custom malware at all, only Office DDE, PowerShell and a Metasploit reverse shell; on 11 October the Five Eyes agencies named five publicly available tools in a joint alert, among them Mimikatz and PowerShell Empire. Signatures had less and less to match, which is the pressure that turned endpoint detection and response into the industry's next decade.

⏳ Time capsule — October 2018

  • Banksy's Girl with Balloon partly shredded itself at Sotheby's in London on 5 October, moments after selling for £1,042,000.
  • The IPCC's special report on global warming of 1.5°C was approved in Incheon and published on 8 October.
  • Paul Allen, who co-founded Microsoft with Bill Gates in 1975, died on 15 October at 65, of complications from non-Hodgkin lymphoma.
  • Canada legalised recreational cannabis on 17 October, the first major economy to do so nationwide.
Where it stands today — 2026

The month that never closed

Eight years on, The Big Hack occupies an awkward position: too serious to wave away, too unsupported to cite. No physical evidence has surfaced, no named party has moved an inch, and Bloomberg has withdrawn nothing. What the story did change was procurement. Hardware provenance, component-level attestation and firmware integrity moved out of research papers and into contract schedules, at a moment when the industry had already watched a single leaked exploit tear through unpatched machines worldwide in three days in May 2017. The compromises that actually arrived in the years afterwards were made of software rather than silicon, which is the quiet irony of the whole episode.

The regulatory thread runs longer than the technical one. Both British penalties here were capped at £500,000, not out of leniency but because the conduct predated the General Data Protection Regulation taking effect on 25 May 2018; Facebook settled and paid in 2019 without admitting liability; Cathay Pacific was fined in March 2020. The stolen tokens came due much later, when Ireland's Data Protection Commission closed its inquiries with €251 million in fines in December 2024, counting about 29 million accounts globally. India's answer took a different shape: the 15 October deadline hardened into enforcement, with American Express and Diners Club barred from adding new domestic customers from May 2021 and Mastercard from July 2021, the Diners Club curb lifted later that year and the Mastercard and American Express curbs only in 2022 — and the principle beneath it survives in the DPDP Act.