Capital One announced its data security incident on the evening of 29 July 2019: personal information relating to roughly 106 million credit-card applicants and customers, about 100 million in the United States and six million in Canada. The haul was credit-card applications submitted between 2005 and early 2019 — names, addresses, phone numbers, dates of birth, self-reported income — plus around 140,000 Social Security numbers, 80,000 linked bank-account numbers and roughly a million Canadian Social Insurance numbers. The theft itself had happened in March. The bank learned of it on 17 July, when a stranger emailed its responsible-disclosure address to say the data appeared to be sitting in someone's GitHub account, and confirmed the breach on 19 July. Twelve days after that first email, the world knew.

The mechanism mattered as much as the numbers. Capital One was the most cloud-forward large bank in America, an institution that spoke openly about closing its own data centres in favour of Amazon Web Services. According to the FBI's complaint and subsequent analyses, a misconfigured web application firewall could be tricked, through server-side request forgery, into querying the cloud platform's internal metadata service — which obligingly handed back temporary credentials, and those credentials unlocked hundreds of storage buckets. Amazon's infrastructure had not been breached; it had worked exactly as designed. The gap sat in the customer's half of what the industry calls the shared-responsibility model, and July 2019 is the month that phrase stopped being a slide in a sales deck.

The person the FBI arrested that same Monday was Paige Thompson, a 33-year-old software engineer from Seattle, formerly of Amazon Web Services, who posted online as "erratic". By every public account she had not sold a single record. She had talked instead — in a Slack channel, in Twitter direct messages, in files left on a GitHub account that led back to her CV — about pulling data from Capital One and, prosecutors later said, from more than thirty other misconfigured cloud accounts. Agents searched her Seattle home on the morning of 29 July, and the Justice Department announced a single computer-fraud charge the same day as the bank's press release: the rare breach whose disclosure and arrest arrived together.

Everything about the ending is known now. The Office of the Comptroller of the Currency fined Capital One $80 million in August 2020 for the risk-management failures behind the misconfiguration, and a class action later settled for $190 million. Thompson was convicted in June 2022 of wire fraud and of unauthorised access to and damage of protected computers — acquitted of identity-theft charges — and sentenced that October to time served and five years of probation. The US Attorney called the sentence "not what justice looks like"; in March 2025 an appeals court agreed, vacating it as unreasonably light and ordering resentencing — whereupon the district judge reimposed time served all the same, adding three years of home confinement and 250 hours of community service to the supervised release. One week before the disclosure, Equifax had agreed to pay up to $700 million for 2017's breach. The old era's bill and the new era's breach arrived in the same July.

Also that month · The regulator's opening bid

£282 million in two days

On 8 July the Information Commissioner's Office announced its intention to fine British Airways £183.39 million under the GDPR, for the 2018 attack in which traffic to the airline's website was diverted to a fraudulent site and around 500,000 customers' details were skimmed — an operation researchers had attributed to the Magecart web-skimming crews. The figure was about 1.5 per cent of BA's worldwide turnover, and more than 350 times the £500,000 ceiling that had bound the regulator's Facebook fine only months earlier. Twenty-four hours later came a second notice: £99.2 million for Marriott International, whose acquired Starwood reservation system had been compromised since 2014, exposing some 339 million guest records worldwide. Nothing on this scale had been proposed under the GDPR before. Hindsight tempers the thunder: after a year of representations and a pandemic that gutted both industries, the final penalties landed in late 2020 at £20 million and £18.4 million — roughly a tenth and a fifth of the opening bids. The precedent, not the arithmetic, turned out to be the point.

Also that month · A nation's tax files

The download link in the newsroom inbox

On 15 July, journalists at Bulgaria's major news outlets received an email offering a download link: 11 gigabytes of files in 57 folders, lifted from the National Revenue Agency. The records covered roughly five million people — names, national identification numbers, incomes, tax and social-insurance payments, debts, even online gambling data. Bulgaria has seven million residents; this was, in effect, the financial file on nearly every adult in the country. The agency confirmed the data was genuine, dating the intrusion to late June and saying about three per cent of its databases were affected; the sender claimed the full haul was nearly twice what had been shared. Police arrested a 20-year-old cybersecurity worker within two days, then downgraded the charges and released him; he denied involvement. Finance minister Vladislav Goranov stood in parliament and apologised to every citizen the state had made vulnerable, and in August the data-protection commission fined the agency itself 5.1 million leva — about €2.6 million. The criminal case crawled on until 15 July 2025, six years to the day after the emails landed, when a Sofia court closed it with a plea agreement and a nine-month suspended sentence.

India desk · July 2019

Aadhaar, amended: voluntary by law

India's security month was legislative. The Lok Sabha passed the Aadhaar and Other Laws (Amendment) Bill on 4 July, the Rajya Sabha followed on 8 July, and presidential assent on 23 July converted a March ordinance into permanent law. The Act amends the Aadhaar Act, the Telegraph Act and the anti-money-laundering law so that banks and telecom companies may accept Aadhaar authentication for customer verification — voluntarily, the statute insists, with no service denied to anyone who declines. It adds offline verification that avoids touching the central biometric database, lets a person enrolled as a child cancel the number at eighteen, and creates civil penalties of up to one crore rupees for entities that misuse the system. The redrafting was forced: in September 2018 the Supreme Court had struck down Section 57 of the original Act, ending private companies' power to demand the number as a condition of service.

The stakes were structural then and remain so. Aadhaar was already the largest biometric identity system on earth, with more than 1.2 billion people enrolled, and the amendment restored the commercial plumbing of instant electronic KYC for bank accounts and SIM cards that the court had shut off. Supporters called it convenience with consent written into the text. Critics answered that consent requested across a shop counter is rarely experienced as a choice, and that the deeper gap was untouched: in July 2019 India had no general data-protection law at all. The bill meant to supply one was still a draft, and a national law would not arrive until the DPDP Act of 2023. For the entire span this archive covers, the biometric spine of Indian daily life ran ahead of the statute meant to guard it.

AI Tech desk · July 2019

A billion dollars for general intelligence

Microsoft announced on 22 July that it would invest $1 billion in OpenAI, a four-year-old San Francisco laboratory then better known for research papers than products. The terms mattered more than the sum: Azure became OpenAI's exclusive cloud provider, Microsoft its preferred partner for commercialising whatever emerged, and the stated goal — artificial general intelligence — was widely filed under eccentric ambition. Read from 2026, it is the founding document of the partnership this archive's later AI desks track through GPT-3, ChatGPT and the Copilot era. The month's louder story was FaceApp, the Russian-developed app whose neural network aged users' selfies. It went viral again in mid-July; Senator Chuck Schumer asked the FBI and the FTC on 17 July to investigate its data handling, and the developer answered that most photos were deleted within 48 hours and that user data was not transferred to Russia. On 16 July Elon Musk unveiled Neuralink's flexible electrode threads and sewing-machine-like implant robot, demonstrated on a rat, hoping for a human patient by the end of 2020; the first implant waited until January 2024.

Digital Guard desk · July 2019

The fortnight Symantec was for sale

Bloomberg reported late on 2 July that Broadcom, the chipmaker that had developed an appetite for infrastructure software, was in advanced talks to buy Symantec — keeper of the Norton yellow that had defined consumer anti-virus for nearly three decades. Neither company would comment, but the market did: Symantec shares rose as much as 16 per cent the next day, their biggest intraday gain in months. By 15 July the talks had stalled, reportedly after due diligence prompted Broadcom to trim its offer and Symantec declined to take less; the shares surrendered the whole gain. Written from 2026, the ending is on file: Broadcom returned within weeks for the enterprise business alone, a $10.7 billion purchase the next edition records, and the consumer arm carried on as NortonLifeLock. The month's other endpoint story was Check Point's disclosure, on 10 July, of "Agent Smith": Android malware that had silently replaced legitimate apps, WhatsApp among them, with advertising-stuffed clones on roughly 25 million devices, about 15 million of them in India, spread through a popular third-party app store rather than Google Play.

⏳ Time capsule — July 2019

  • England won the Cricket World Cup at Lord's on 14 July, beating New Zealand on boundary count after both the final and its Super Over finished tied.
  • On 20 July the world marked fifty years since Apollo 11 put the first people on the Moon.
  • ISRO launched Chandrayaan-2, India's second Moon mission, from Sriharikota on 22 July — a week after a technical snag halted the first countdown 56 minutes before lift-off.
  • Boris Johnson became Prime Minister of the United Kingdom on 24 July, the day after winning the Conservative leadership contest.
Where it stands today — 2026

The month the cloud grew up

July 2019 is the month cloud security stopped being an abstraction. Capital One's misconfigured firewall opened a decade in which the defining breaches involved no malware and often no intrusion in the old sense — only credentials that worked and interfaces that answered — a pattern this archive meets again and again, most nakedly in the Snowflake campaign of May 2024, when the passwords were already gone. Amazon hardened its metadata service within months, though switching the protection on remained the customer's job: shared responsibility, again. The ICO's £282 million of opening bids shrank to £38.4 million by late 2020, yet the direction held — the privacy fines that followed grew larger, arrived faster, and increasingly stuck.

The other threads run just as far. Bulgaria's emptied tax agency posed the question later editions keep meeting — what a state owes the citizens whose data it compels — and India's Aadhaar amendment deferred its own version of that question until the DPDP Act of 2023, which this archive's India desk still tracks. Louisiana closed the month under a statewide cyber emergency after malware crippled school districts, an early tremor of the municipal ransomware wave that shapes the editions around this one. The Vault continues backwards from here; July 2019 is where the modern era's ledger opens.