On 29 August 2019, Ian Beer of Google's Project Zero published what the security industry had long assumed it would never see: evidence of iPhone exploitation at scale. Google's Threat Analysis Group had found a small collection of hacked websites that attacked every iPhone that visited them — no targeting, no phishing lure, no click required; simply opening the page was enough. Behind the sites sat five complete exploit chains built from fourteen vulnerabilities, covering almost every release from iOS 10 through iOS 12, at least one chain still a working zero-day when Google found it at the start of the year. The operation had run, Google assessed, for at least two years, on sites receiving thousands of visitors a week.
The chains delivered a monitoring implant running with root privileges, checking in with its command server every sixty seconds. It could report the phone's live GPS position up to once a minute, copy the keychain with every stored password and token, and lift the message databases of WhatsApp, Telegram and iMessage in plaintext, along with photos, contacts and Gmail — end-to-end encryption means little on a device owned this deeply. Two details stood out: the implant did not survive a reboot, and with a victim's credentials taken it did not need to; and it uploaded everything unencrypted, over plain HTTP. Apple had patched the final chains in iOS 12.1.4 in February 2019, days after Google's private report. No update could recall two years of visits.
Google's post named neither victims nor attacker. Within days others filled the silence: reporting from 31 August, citing sources familiar with the matter, identified the hacked sites as ones serving the Uyghur community and said the same campaign had reached Android and Windows; researchers at Volexity separately documented related Uyghur-focused sites attacking Android devices. Then on 6 September Apple did something it almost never does — it published a rebuttal. The statement confirmed the campaign and its focus on content related to the Uyghur community, but disputed nearly everything else: fewer than a dozen websites, Apple said, operational for roughly two months, not the two years Google implied — and Google was "stoking fear among all iPhone users" with a false impression of mass exploitation. Google said it stood by its research. The two accounts were never reconciled.
No perpetrator was ever charged, and neither company named one; contemporaneous reporting described a state-backed surveillance operation aimed at a Muslim minority, which this archive carries as reporting rather than adjudicated fact. Ian Beer ended his post soberly: mass exploitation still existed, and to be targeted might mean simply "being born in a certain geographic region", or belonging to a particular ethnic group. In hindsight, this is where the mercenary-spyware era of these pages begins. The assumption that iPhones were in practice unhackable died in August 2019. The Pegasus Project of July 2021 and Apple's Lockdown Mode of 2022 descend directly from this month — and the dispute over scale between two of the world's largest companies was never settled.
Texas, all at once
Around dawn on Friday 16 August 2019, ransomware detonated across small-town Texas — city halls, police departments, utility offices — in what the state's Department of Information Resources first announced as twenty-three victims, later revised to twenty-two. Nobody had attacked the towns one by one. A single REvil affiliate had compromised a managed service provider whose remote-administration tool reached into every client's network at once. Borger lost the systems that issue birth and death certificates; Keene could not take utility payments, and its mayor told NPR the collective demand was $2.5 million — a figure this archive carries as his account. The state activated its emergency operations, and officials said no entity paid; within about a week, most towns were restored or rebuilding. The ending took two years: in November 2021 the US Justice Department indicted Yevgeniy Polyanin, a Russian national, for the attack and seized some $6.1 million in alleged ransom proceeds, though Polyanin himself remained at large. The model — one supplier, many governments — returns in this archive as Kaseya, July 2021.
One million fingerprints, in the clear
On 14 August, researchers Noam Rotem and Ran Locar of vpnMentor disclosed that BioStar 2 — a web-based biometric access-control platform built by the South Korean firm Suprema and used by thousands of organisations across dozens of countries, reportedly including police forces, banks and defence contractors — had left a database of about 27.8 million records, some 23 gigabytes, reachable on the open internet. It held over a million actual fingerprints and facial-recognition data, alongside unencrypted usernames and passwords, staff details and logs of who opened which door, and when. The researchers said they could not only read records but alter them — in principle, enrol their own fingerprints on someone else's account. The exposure was closed on 13 August, and no malicious access was ever publicly confirmed; Suprema said it was evaluating the findings, and a US senator wrote demanding answers within weeks. The uncomfortable part was permanent anyway. A leaked password is rotated in a minute; a fingerprint is attached to its owner for life.
Kashmir, disconnected
In the last hours of 4 August 2019, mobile networks, mobile data, broadband and eventually landlines fell silent across the Kashmir Valley; the next morning, 5 August, the Government of India revoked Jammu and Kashmir's special constitutional status under Article 370. This archive records what followed as a connectivity event, and it was an extraordinary one: roughly seven million people in the Valley began August unable to place a call, send a message or reach the internet. Commerce, banking and travel bookings fell back to paper; families outside the region went weeks without word. Journalists queued for shared terminals at a government-run media facilitation centre in Srinagar to file copy. Landlines returned in stages through September, postpaid mobiles on 14 October, SMS on 1 January 2020.
The legal ending came in the Supreme Court. Anuradha Bhasin, executive editor of the Kashmir Times, had petitioned within days; on 10 January 2020, in Anuradha Bhasin v Union of India, the Court held that the freedom of expression and the freedom to carry on trade or business through the internet are protected under Article 19 of the Constitution, that indefinite suspension of internet services is impermissible, and that suspension orders must be published and periodically reviewed. The judgment ordered review, not restoration: 2G data returned for whitelisted sites on 25 January 2020, and full 4G service only on 5 February 2021 — eighteen months on, documented by digital-rights groups as the longest internet shutdown ever imposed in a democracy.
The Largest Chip Ever Built
The most arresting object of the month was unveiled at the Hot Chips conference at Stanford on 19 August 2019: the Cerebras Wafer-Scale Engine, a processor cut from an entire silicon wafer rather than diced into hundreds of chips. It carried 1.2 trillion transistors and 400,000 cores across 46,225 square millimetres — roughly fifty-six times the area of the largest GPU of the day — with 18 gigabytes of memory held on the silicon itself, all of it built for training neural networks. Many treated it as a stunt; three generations on, wafer-scale silicon runs some of the fastest commercial AI inference. The next day, 20 August, OpenAI released the 774-million-parameter GPT-2, the third instalment of a staged rollout of a text generator it had in February judged too risky to publish whole — caution that reads almost quaint from 2026. And on 23 August Huawei, three months onto the US entity list, launched the Ascend 910 — in its words the world's most powerful AI processor — with the MindSpore framework, opening the domestic-silicon effort China would lean on for years.
Symantec Sells Its Own Name
On 8 August 2019 Broadcom agreed to buy Symantec's enterprise security business for $10.7 billion in cash — and with it the Symantec name itself. The most famous brand in antivirus was splitting in two: the enterprise products, roughly half the company's revenue, went to a chipmaker turned software consolidator, while the consumer side — Norton and LifeLock — stayed behind to become NortonLifeLock, a renaming this desk reaches in November 2019. Two weeks later, on 22 August, VMware agreed to acquire the endpoint-detection firm Carbon Black at an enterprise value of about $2.1 billion, betting that endpoint security belonged inside the infrastructure layer. From 2026 the two deals share an ending: Broadcom bought VMware too, and by 2024 Carbon Black and Symantec sat in the same Broadcom security division. The month's happier story was defensive: Avast and the French Gendarmerie's cybercrime unit, having quietly seized the command server of the Retadup cryptomining worm, used it to instruct the malware to delete itself, disinfecting about 850,000 machines — Avast itself would fold into Norton's successor within three years.
⏳ Time capsule — August 2019
- India's Chandrayaan-2 spacecraft entered lunar orbit on 20 August, setting up a landing attempt the following month.
- Ben Stokes' unbeaten 135 at Headingley on 25 August won England the third Ashes Test by one wicket.
- Record fires in the Brazilian Amazon led the G7 summit at Biarritz to pledge $20 million in aid — which Brazil initially refused.
- Greta Thunberg arrived in New York on 28 August after a two-week, zero-carbon Atlantic crossing aboard the yacht Malizia II.
Three myths, one month
August 2019 retired three comfortable assumptions in thirty-one days. The first was that iPhones were, for practical purposes, unhackable: after Project Zero, exploitation of the world's most defended consumer device was a documented industrial process, and the argument that remained was only about volume. The road from those hacked websites runs straight through this archive — to the Pegasus Project in July 2021, to Apple suing NSO Group that November, to Lockdown Mode in 2022. The second was that small governments were too small to be worth attacking. One compromised supplier felled twenty-two Texas towns in a morning; almost two years later the same architecture, scaled through Kaseya, reached roughly 1,500 organisations over a single July weekend.
The third was that biometrics were an upgrade on passwords. BioStar 2's million exposed fingerprints established the plainer truth this archive returns to for years: credentials that cannot be changed demand protections that cannot be skipped. The month's smaller entries seeded futures of their own — Jack Dorsey's SIM-swapped Twitter account previewed July 2020, when the platform's admin tools were turned against it from inside; Imperva's stolen cloud key previewed the supply-chain reckonings of 2020; Hostinger reset fourteen million passwords; Mastercard's German loyalty leak handed GDPR an early cross-border test. And Kashmir's blackout, with the Article 19 ruling that followed, opens the connectivity thread that runs through this archive's India coverage into the DPDP era. The Vault continues backwards from here.