British Airways disclosed the theft late on 6 September 2018, the day after a third party told the airline what had been happening on its own website. The company put the skimming window to the minute — 22:58 BST on 21 August to 21:45 BST on 5 September 2018 — and said the details entered in roughly 380,000 booking transactions had been taken: names, addresses, card numbers, expiry dates and security codes together. Customers who had booked or changed a flight in those fifteen days were emailed overnight and told to call their banks. On the morning of 7 September the chief executive, Álex Cruz, went on BBC Radio 4 and called it "a very sophisticated, malicious criminal attack" on the airline's website, promising to compensate anyone left out of pocket.

The mechanism became public five days later, and not from the airline. RiskIQ published its analysis on 11 September 2018: a single file served from British Airways' own domain — a modified copy of the Modernizr JavaScript library, version 2.6.2, loaded on the baggage-claim information page — carried twenty-two extra lines at the end. The lines waited for the customer to press the payment button, copied the form exactly as typed, and posted it to a server called baways.com, hosted on a Romanian address. The airline's mobile app loaded the same script and was skimmed the same way. Nothing was redirected; the attackers had bought a certificate for the domain — issued on 15 August 2018, six days before the window the airline gave, which suggested they had been inside for longer than the airline said — and the padlock was real. That account was the researchers'; the airline never confirmed it publicly.

On 25 October 2018 British Airways revised the arithmetic in both directions. Of the 380,000 transactions first announced it now believed 244,000 had actually been affected, while a further 185,000 customers who had made reward bookings between 21 April and 28 July 2018 had also been exposed — 77,000 of them including the card security code, 108,000 without. The regulator's eventual count was 429,612 customers and staff, and it established what the airline had not known in September: an intruder had held access since 22 June 2018 using a third-party supplier employee's credentials. Researchers placed the airline in a sequence, not an event: Ticketmaster's UK site in June, covered in its own edition, and the retailer Newegg from 14 August to 18 September, where no victim count was ever published.

The ending took two more years. The Information Commissioner's Office issued a notice of intent on 8 July 2019 for £183.39 million, about 1.5 per cent of the airline's 2017 worldwide turnover and by far the largest penalty it had ever proposed. Its announcement that day described user traffic being diverted to a fraudulent site — a description the technical accounts never supported and the eventual penalty notice did not repeat. The fine actually issued on 16 October 2020 was £20 million: a starting figure of £30 million, reduced by £6 million for the airline's prompt notification and remediation, and by a further £4 million for the pandemic's effect on aviation. In July 2021 the airline settled the resulting UK group claim out of court, on undisclosed terms.

Also that month · Fifty million, then thirty

Facebook loses its keys

Facebook's engineers noticed an unusual spike in traffic on 16 September 2018, traced the cause on 25 September, and disclosed it publicly on 28 September, notifying Ireland's Data Protection Commission inside the GDPR's 72-hour window. Three bugs interacting inside the "View As" feature — which lets people see how their own profile appears to someone else — made a video uploader appear where it should not have and issue an access token belonging to the person being viewed. Facebook reset tokens for the roughly 50 million accounts it first believed affected and for 40 million more as a precaution, logging 90 million people out overnight. On 12 October it revised the count downwards: about 30 million tokens were actually taken, 15 million losing name and contact details, 14 million losing those plus profile detail down to religion, relationship status and their fifteen most recent searches, and one million losing nothing at all. Ireland's regulator opened a statutory inquiry on 3 October 2018 and closed it on 17 December 2024, fining Meta €251 million — part of it because the original notification had not contained everything the regulation required.

Also that month · One name on the charge sheet

The programmer the Justice Department named

On 6 September 2018 the US Department of Justice unsealed a criminal complaint charging Park Jin Hyok, a North Korean computer programmer, with conspiracy to commit computer fraud and conspiracy to commit wire fraud — the first American criminal charges brought against a hacker working for the North Korean state. The complaint alleged that Park had worked from China and from North Korea for a government front company, Chosun Expo Joint Venture, and placed him inside the group responsible for three of the decade's defining intrusions: the destruction of Sony Pictures Entertainment's network in November 2014; the February 2016 theft from Bangladesh Bank's account at the Federal Reserve Bank of New York, where fraudulent payment instructions for roughly $951 million produced $81 million that actually moved; and the WannaCry outbreak of May 2017, which this archive covers in its own edition. The Treasury designated Park and Chosun Expo the same day. North Korea rejected the charge through state media and said the man named did not exist. He has never been arrested.

India desk · September 2018

The line the court drew

On 26 September 2018, after 38 days of hearings — the second longest argument in the court's history — a five-judge Constitution Bench of India's Supreme Court upheld the Aadhaar Act by four to one in Justice K.S. Puttaswamy (Retd.) v. Union of India. Justice A.K. Sikri wrote for himself, Chief Justice Dipak Misra and Justice A.M. Khanwilkar, with Justice Ashok Bhushan concurring separately: the scheme was proportionate where it delivered subsidies drawn from the Consolidated Fund of India under Section 7, and Aadhaar–PAN linking stood. What the court took away mattered more. It struck down the part of Section 57 that let private companies demand Aadhaar authentication under a contract, ending it as a condition of a bank account or a SIM card; struck down Section 33(2), which permitted disclosure on national-security grounds; and cut retention of authentication records from five years to six months. Schools, the CBSE and NEET could no longer require the number.

Justice D.Y. Chandrachud dissented alone and entirely, holding that the programme suffered constitutional infirmities from enactment, that meaningful consent had never been obtained, and that passing the Bill as a money bill — bypassing the Rajya Sabha — was "a fraud on the Constitution"; the majority upheld that route. The boundary held ten months. Parliament restored the commercial plumbing by consent in the Aadhaar and Other Laws (Amendment) Act of July 2019, letting banks and telecom companies accept Aadhaar voluntarily. In January 2021 the court dismissed review petitions, again four to one over his dissent; he became Chief Justice of India in November 2022. India still had no general data protection law, and would not until the DPDP Act of 2023.

AI Tech desk · September 2018

Two billion dollars and nine algorithms

DARPA made the month's largest commitment on 7 September 2018, when its director, Steven Walker, used the agency's sixtieth-anniversary symposium at National Harbor in Maryland to announce AI Next: more than $2 billion across a portfolio of new and existing work, with more than twenty programmes aimed at what the agency called the third wave of artificial intelligence — contextual adaptation, common-sense reasoning, and systems that could explain the reasoning behind a result. The rest of the month approached the same problem from the other end. On 11 September 2018 Google's People + AI Research team released the What-If Tool, a TensorBoard feature for probing a trained model's behaviour across subgroups without writing code. On 19 September 2018 IBM opened its AI Fairness 360 toolkit — nine bias-mitigation algorithms from research teams in India and at T.J. Watson — beside a cloud service that checked models for bias while they ran. IBM handed the toolkit to the Linux Foundation in 2020, by which point measuring bias had begun to look less like a courtesy and more like something regulators would ask to see.

Digital Guard desk · September 2018

Twenty-four hours of browser history

The month's first removal was not Trend Micro's: on 7 September 2018 Apple pulled Adware Doctor, the Mac App Store's top-selling paid utility, after Patrick Wardle and the researcher Privacy 1st showed it copying Safari, Chrome and Firefox history to a server in China. Six Trend Micro utilities followed by 10 September 2018 — Dr. Cleaner, Dr. Cleaner Pro, Dr. Antivirus, Dr. Unarchiver, Dr. Battery and Duplicate Finder. Trend Micro confirmed the collection that day: a one-time snapshot of the twenty-four hours of browsing before installation, taken to establish whether a machine had met adware and uploaded to a US server it controlled. It apologised, removed the feature and deleted the logs, while rejecting as false any report that the data had gone to an unidentified server in China. On 27 September 2018 ESET published LoJax, the first UEFI rootkit found in the wild: Absolute Software's LoJack anti-theft agent, trojanised by the Sednit group and written into SPI flash, where it outlived operating-system reinstallation and disk replacement. Firmware implants have recurred ever since, up to bootkits that defeat Secure Boot itself.

⏳ Time capsule — September 2018

  • Amazon briefly became the second American company, after Apple, to reach a trillion-dollar market value, on 4 September.
  • A five-judge bench of India's Supreme Court unanimously struck down the part of Section 377 that criminalised consensual same-sex relations between adults, on 6 September.
  • Naomi Osaka beat Serena Williams 6–2, 6–4 in the US Open final on 8 September, becoming the first Japanese player to win a Grand Slam singles title.
  • The SEC sued Elon Musk for securities fraud on 27 September over his "funding secured" tweet; the settlement announced two days later cost Musk and Tesla $20 million each and Musk the chairmanship for three years.
Where it stands today — 2026

What the padlock was worth

September 2018 is where the padlock stopped being an answer. Twenty-two lines running inside a trusted page, under a certificate that validated correctly, defeated everything the address bar could tell a customer, and the third-party script became the supply-chain problem the rest of this archive keeps returning to. Content security policy and subresource integrity — both available in 2018, neither widely deployed — became standard advice largely because of this month. The regulatory arc bent the other way: the sum the ICO proposed in July 2019 had shrunk to a ninth by the time the penalty issued in October 2020, and the deterrent everyone expected from the GDPR's first great test proved smaller and slower than the headline had promised.

The month's other endings took years. Uber's $148 million settlement with the attorneys general of all fifty states and the District of Columbia, announced on 26 September 2018 over its concealment of the 2016 breach, was only the civil half; the criminal half reaches this archive in August 2020. Facebook's stolen tokens became €251 million from the Irish regulator six years later. India's thread runs furthest: the court drew a line through Section 57 and Parliament redrew it by consent within a year, leaving the harder question — who may hold the data, on what basis, for how long — unanswered until 2023, and the duty to report a loss at all to arrive separately through CERT-In's directions. The Vault continues backwards from here.