On 11 February 2019, every externally facing system belonging to VFEmail — an independent American mail provider that had run out of Milwaukee since 2001 — went dark at once: website, webmail and the mail hosts behind them. This was not an outage. An intruder had logged in and was erasing the company disk by disk, and by the time the day ended the firm's own account had posted the plainest damage report in this archive: "At this time, the attacker has formatted all the disks on every server. Every VM is lost. Every file server is lost, every backup server is lost." Eighteen years of customers' stored mail, and the backups that should have made the loss theoretical, were gone inside a day.

What set it apart from every other destructive intrusion of the era was what did not happen next. No note appeared, no payment portal, no countdown clock. "There was no ransom," the company wrote. "Just attack and destroy." VFEmail had caught its attacker at the console, midway through formatting a backup server, and published the very wipe command it found running — launched over SSH from an address at a Bulgarian hosting provider under the username aktv, most likely a rented or hijacked machine. The precautions that ordinarily limit such damage did not apply: the servers ran different operating systems, used separate credentials and sat in more than one data centre. All of them took the same command anyway.

Founder Rick Romero's own accounting was quiet and final. "Yes, @VFEmail is effectively gone," he wrote the next morning. "It will likely not return. I never thought anyone would care about my labor of love so much that they'd want to completely and thoroughly destroy it." Asked who might do such a thing, he could offer only two theories: "There definitely was something that somebody didn't want found. Or, I really pissed someone off." He told the journalist Brian Krebs he did not have "very high expectations of getting any U.S. data back", and he was right. A single backup drive hosted in the Netherlands was recovered; the American archive stayed erased, and no attacker was ever publicly identified or charged.

The industry drew two lessons, and this archive has spent the years since watching both play out. The first is architectural: a backup reachable from the network it protects is not a backup, only another disk awaiting the same command. The second is stranger. The economics of security assumed attackers were rational — data is stolen to be sold, encrypted to be ransomed. VFEmail's destroyer asked for nothing, took nothing and vanished. Destruction was the entire transaction. The wipers that crossed into Ukraine in this archive's early-2022 editions would make the same point at the scale of nations; a small independent mail provider made it first, and paid for the demonstration with everything it had.

Also that month · 617 million accounts

The breach supermarket opens

On 11 February, The Register reported that a seller calling themselves gnosticplayers had listed account records from sixteen breached websites on the Dream Market dark-web bazaar, asking a little under $20,000 in bitcoin for the lot — roughly 617 million accounts in all. The shelves held household names: 162 million from Dubsmash, 151 million from MyFitnessPal, 92 million from MyHeritage, with ShareThis, Whitepages, 500px and Coffee Meets Bagel further down the aisle. The tallies were the seller's own claims, but they held up uncomfortably well: 500px confirmed its months-old breach within days, DataCamp reset user passwords, and Coffee Meets Bagel — a dating app — notified its users on Valentine's Day. Some of the stock was old; MyFitnessPal's breach had been disclosed a year earlier. The seller kept restocking through spring: four further rounds by late April, more than 900 million records claimed across the five, and a stated ambition, given to reporters, of a round billion. The retail era of the mega-breach had arrived.

Also that month · A fraud wearing a tragedy

Quadriga: the vault was already empty

In a Halifax courtroom on 5 February, Canada's largest cryptocurrency exchange was granted protection from its creditors for the strangest reason in insolvency: the keys had died with the founder. Gerald Cotten, 30, had died suddenly on 9 December 2018 in Jaipur, India, while on his honeymoon — and, QuadrigaCX told the court, the keys to the cold wallets holding most of the roughly C$250 million owed to 115,000 customers lived on a single encrypted laptop only he could open. The month supplied its own grim comedy: days into the proceedings, Quadriga inadvertently sent a further 103 bitcoins into the very wallets it could not unlock. Then the story turned. Ernst & Young, the court-appointed monitor, reported on 1 March that five of the six cold wallets had been empty since April 2018 — eight months before Cotten died. In June 2020 the Ontario Securities Commission concluded Quadriga had been "an old-fashioned fraud wrapped in modern technology": Cotten had traded customers' real money against invented balances, and creditors eventually saw about thirteen cents on the dollar. The grief was real. The vault had been empty long before the funeral.

India desk · February 2019

Indane: millions of Aadhaar-linked records, one unlocked portal

On 18 February, TechCrunch reported that a portal Indane — the LPG brand of state-owned Indian Oil — runs for its dealers had been left partly open to the internet: a section that should have sat behind a login had been indexed by Google, and from it a simple script could pull customer records carrying names, addresses and Aadhaar numbers, the identity number that subsidised gas connections had made a routine field in a fuel company's files. The French security researcher Baptiste Robert — better known then by his Twitter handle Elliot Alderson, and already a recurring character in Aadhaar's public troubles — said his script had retrieved about 5.8 million records before his access was blocked, and estimated 6.7 million customers were exposed in all. The figures were his; Indane, which serves tens of millions of households, never published its own.

The claims did not rest on the researcher alone: TechCrunch checked a sample of the exposed numbers against UIDAI's own online verification tool, and each came back a positive match. Neither Indane nor UIDAI answered the reporters' questions, and UIDAI had in the past dismissed such disclosures as "fake news" — insisting its central biometric database, which this exposure never touched, remained unbreached. That defence was accurate and beside the point, as it had been a year earlier, the last time Indane figured in an Aadhaar exposure. The number was never meant to be secret, its custodians kept repeating; meanwhile it kept spreading, copy by copy, through dealer portals and utility databases beyond anyone's recall. A general election was weeks from being called, and the law that would eventually govern such data was more than four years away.

AI Tech desk · February 2019

OpenAI shows GPT-2, then withholds it

On 14 February 2019, OpenAI announced GPT-2, a language model trained on eight million web pages that could continue any prompt in fluent, plausible prose — and then declined to release the full version, citing the potential for mass-produced disinformation and spam. The press shorthand, "too dangerous to release", followed the lab all year as it ran the experiment in stages: a small model at announcement, larger ones in May and August, the full version in November once no serious misuse had surfaced. The demonstration mattered more than the withholding — the samples, including an invented news report about unicorns in the Andes, were the first glimpse many people had of what scaled-up text prediction could do, and every frontier-model release debate since has been conducted in its shadow. Three days earlier, on 11 February, the White House had issued its American AI Initiative executive order, directing agencies to prioritise AI research while attaching no new money; the same day in San Francisco, IBM's Project Debater argued for subsidised preschools and lost to the human champion Harish Natarajan.

Digital Guard desk · February 2019

Backup meets anti-virus: Carbonite buys Webroot

The consolidation that would remake the anti-virus industry's mid-tier began on 7 February, when Carbonite, a Boston backup company, agreed to buy Webroot — the Colorado firm that had spent two decades selling lightweight, cloud-managed anti-virus, latterly through the managed-service providers who look after small businesses' machines — for roughly $618.5 million in cash. The logic was the pairing this archive's ransomware years would vindicate: protection and recovery under one roof, the endpoint defended and its data restorable when the defence failed. The deal closed in March; before 2019 was out, OpenText had bought Carbonite whole, and Webroot had changed hands twice inside a year. Five days later, on 12 February, Symantec bought Luminate Security, a young Israeli firm whose software-defined perimeter admitted users to individual applications rather than whole networks — the zero-trust idea the industry would spend the next five years repeating. Symantec's own turn came that August, when it agreed to sell its enterprise business to Broadcom; of that February's two buyers, neither ended the year as quite the company it had been.

⏳ Time capsule — February 2019

  • A suicide bombing at Pulwama in Kashmir killed 40 Indian paramilitary personnel on 14 February; twelve days later Indian jets struck Balakot, the first Indian air raid inside Pakistani territory since 1971.
  • NASA declared its Opportunity rover's mission complete on 13 February — fifteen years after the machine landed on Mars for what was planned as a 90-day assignment.
  • Airbus announced on 14 February that it would end production of the A380 after Emirates cut the order that had kept the double-decker alive.
  • Green Book won Best Picture at the 91st Academy Awards on 24 February — the first Oscars ceremony in three decades to go without a host.
Where it stands today — 2026

The month that asked for nothing

February 2019's threads run long through this archive. VFEmail's destroyer — motive unknown, never caught — prefigured the era in which deletion itself became the weapon, through to the wipers that crossed into Ukraine hours before the tanks in the early-2022 editions. Gnosticplayers' shelves fed years of credential-stuffing, the quiet compound interest of every mega-breach since. Quadriga's empty wallets found their rhyme in November 2022, when FTX collapsed and another exchange's ledger proved imaginary. And the month's quietest story — a "sophisticated state actor" inside Australia's Parliament House, disclosed on 8 February, and, as the prime minister told parliament ten days later, inside its three biggest parties; never officially attributed, though later reporting pointed at Beijing — became the template for a decade of pre-election intrusions.

India's thread is the steadiest of all. The Indane portal joined a lengthening ledger of Aadhaar-adjacent exposures, each met with the same dismissals and silences, while the country kept digitising faster than it legislated. The DPDP Act finally passed in August 2023 — this archive traces it through the editions of that month and after — and its rules were still being argued over as these pages were restored in 2026. The Vault continues backwards from here: January 2019 waits below, and with it Collection #1, the 773 million email addresses that taught the world how long a stolen password lives.