On 16 January 2019, the Australian security researcher Troy Hunt published his analysis of a folder that had been sitting on the MEGA file-sharing service and circulating on a popular hacking forum. It was called Collection #1: 87 gigabytes across more than 12,000 files, holding 2,692,818,238 rows of email addresses and passwords. Cleaned and de-duplicated, the counts settled at 772,904,991 unique email addresses and 21,222,975 unique passwords — the largest single dataset ever loaded into Hunt's breach-notification service, Have I Been Pwned. The name came from the root folder; the numbering implied a series, and the implication proved exactly right.
What Collection #1 was not, Hunt was careful to say, was a new breach. The forum listing advertised a collection of more than 2,000 dehashed databases — old thefts whose scrambled passwords had already been cracked back to plain text — with material dating mainly from 2008 to 2015. Some source sites were recognisable; many could never be verified at all. Brian Krebs traced the seller behind the packages, who used the handle Sanixer and priced Collection #1 at 45 dollars — the stalest, cheapest item on the shelf, with newer and larger stock behind it — and by the time Hunt saw the folder it had escaped even that price, posted for anyone to take. The alarming thing was not theft. It was distribution.
Hunt's most persuasive exhibit was himself: his own email address appeared in the dump, paired with a password he had genuinely used many years earlier, and both were accurate. That is the whole mechanism of credential stuffing, the attack this material existed to feed — replay hundreds of millions of old email-and-password pairs against login pages everywhere, automatically, and rely on the one habit the decade never broke: the same password, chosen once and never retired, still guarding an account years later. The list held 1,160,253,228 unique combinations. Each was a key that had already turned once, now carried from door to door to find where else it fit.
The sequels arrived within a fortnight. Researchers at Germany's Hasso Plattner Institute worked through the follow-on packages, Collections #2 to #5 — roughly 845 gigabytes and 25 billion rows in all — and distilled them to about 2.2 billion unique address-and-password pairs. The seller's own ending took longer: in May 2020, Ukraine's security service raided a home in the Ivano-Frankivsk region and detained a man it identified as Sanix, seizing computers that held some two terabytes of stolen credentials. Collection #1 was never a breach of anything. It was a monument to a decade of breaches — and the month the industry stopped treating an old password as an expired one.
The advent calendar
Germany began the year discovering that someone had spent December publishing its political class. Since the first of that month, a Twitter account called @_0rbit had posted daily instalments of private material — mobile numbers, home addresses, chat logs, credit-card details, copies of identity documents, family photographs — in the manner of an advent calendar. Almost nobody noticed until the story broke nationally on 3 and 4 January: nearly 1,000 public figures were affected, among them Chancellor Angela Merkel, politicians from every party in the Bundestag except the far-right AfD, and a supporting cast of journalists, comedians and YouTubers. On 6 January police searched a house in the state of Hesse; on 8 January federal investigators announced that a 20-year-old student who lived with his parents had confessed. He had destroyed a computer shortly before the search, said he had acted alone, and gave as his motive annoyance at his targets' public statements. Prosecutors charged him in May 2020 with offences spanning 73 victims; because of his age, the case was handled under juvenile law.
Heard before the answer
On 19 January, Grant Thompson, a 14-year-old in Tucson, Arizona, set up a Group FaceTime call with friends ahead of a round of Fortnite and noticed something no security lab had: by adding his own number to an outgoing call, he could hear a friend's microphone before the friend had answered. If the person being called pressed the power button from the lock screen, their video went out too. His mother, a lawyer, spent the following week emailing, tweeting and even faxing Apple, and got nowhere against a reporting process built for registered developers. The bug went public on 28 January, nine days after the family first tried to raise the alarm; it spread across the internet within hours, and Apple disabled Group FaceTime on its servers the same evening. A software fix followed on 7 February, crediting the teenager by name; Apple compensated the family and added a gift towards Grant's education, with the sums undisclosed. The month's most intimate vulnerability required no attacker at all — only a phone that answered before its owner did.
SBI Quick: the bank that texted its secrets
On 30 January, TechCrunch reported that State Bank of India — the country's largest bank, government-owned, with hundreds of millions of customers — had left a database server in a regional Mumbai data centre protected by no password at all. The machine ran the back end of SBI Quick, the enquiry service that lets customers send a text message or place a missed call and receive their balance or recent transactions by SMS. Anyone who found the server could watch the bank's outbound messages in real time — phone numbers, account balances, recent transactions, partial account numbers — and read back through archives holding roughly two months of daily traffic, millions of messages a day. No intrusion was required, because there was nothing to intrude past.
A security researcher had found the server and tipped off TechCrunch, which contacted the bank; the database was secured overnight. How long it had stood open was never established, and customers were not individually notified — in January 2019, no Indian law required it. That is what places the story in this archive: a hardened core-banking system undone by its friendliest feature, and an era in which disclosure depended entirely on who happened to find the door. India's six-hour incident-reporting mandate from CERT-In arrived in 2022, and the DPDP Act followed in 2023 — both traced in this archive's India desk — but the SBI Quick server belonged to the years when a leak's whole lifecycle could run: found by a stranger, reported by a journalist, closed by morning, never spoken of again.
AlphaStar wins ten, loses the eleventh
On 24 January 2019, DeepMind livestreamed the unveiling of AlphaStar, an agent for the real-time strategy game StarCraft II — the milestone the field had circled since Go fell: hidden information and real-time control rather than turns on an open board. In two five-game series recorded in December 2018, it had beaten the Team Liquid professionals Dario Wünsch and Grzegorz Komincz five games to nil apiece, trained on human replays and then in a league of versions playing one another. The evening's one live match went the other way: Komincz beat a newer agent restricted, as humans are, to a moving camera view. By October 2019 a constrained AlphaStar had reached Grandmaster on the public European ladder, above 99.8 per cent of ranked players — among the last of the grand game milestones before the field's attention turned to language. The month's other marker came from CES, where Google said its Assistant would pass one billion devices by the end of January: consumer AI counted in installations, research AI still in games.
The tip-off came from Kaspersky
On 9 January 2019, Politico reported that the tip which unmasked Harold Martin — the National Security Agency contractor found hoarding roughly 50 terabytes of classified material at home — had come from Kaspersky Lab. In August 2016, half an hour before the Shadow Brokers began publishing stolen NSA tooling, a Twitter account later linked to Martin sent cryptic messages to two Kaspersky researchers; the firm alerted the agency, and Martin was arrested within weeks. The irony was complete: the Russian vendor ordered off US government networks in 2017, then arguing its good faith through a Zurich transparency centre opened in November 2018, had helped catch one of the worst insider breaches in NSA history. Martin pleaded guilty that March and drew nine years. The same week, CrowdStrike and FireEye published analyses of Ryuk, the ransomware that had halted major American newspapers' printing at the turn of the year, attributing it not to North Korea but to a Russian-speaking criminal crew hunting large organisations for large ransoms — big game hunting, CrowdStrike called it, a model ransomware spent the following half-decade perfecting.
⏳ Time capsule — January 2019
- NASA's New Horizons probe flew past Ultima Thule on 1 January — at some 6.4 billion kilometres, the most distant object ever visited by a spacecraft, later renamed Arrokoth.
- China's Chang'e 4 made the first-ever soft landing on the far side of the Moon on 3 January.
- A stock photograph of an egg overtook Kylie Jenner on 13 January to become the most-liked Instagram post in history.
- Naomi Osaka won the Australian Open on 26 January and became the first Asian player to hold the world No. 1 singles ranking.
Where the archive begins
January 2019's inheritance runs the full length of this archive. Collection #1's warehouse logic — old credentials, endlessly replayed — feeds February's breach supermarket, then the infostealer economy, and arrives at the May 2024 edition, where the Snowflake campaign emptied corporate data warehouses using passwords stolen years earlier; that edition is titled The Passwords Were Already Gone, a sentence January 2019 had already proved. The student in Hesse was charged in May 2020 and convicted that September, under juvenile law — nine months' youth detention, suspended on probation. Apple opened its bug bounty to all researchers before 2019 ended — the nine days a teenager spent being ignored had made the case better than any conference talk. And Have I Been Pwned still runs in 2026, consulted by password managers and governments alike.
The month's quietest story proved the most institutional. On 22 January, CISA — barely two months old, in the closing days of what was then the longest government shutdown in American history — issued Emergency Directive 19-01, the first of its kind, giving short-staffed agencies ten business days to audit their DNS records and lock down registrar accounts against a hijacking campaign FireEye had linked, with moderate confidence, to Iran. The emergency directive became the following decade's reflex; by the January 2024 edition, the same instrument was ordering agencies to disconnect their Ivanti gateways by name. The Vault currently begins with this edition: December 2018 and everything before it are future restorations. For now the chain starts here — and February 2019 waits above.