The cascade began on 3 June 2019, when Quest Diagnostics told US regulators that a collections vendor — the American Medical Collection Agency, reached through Quest's own billing contractor — had been breached, and that roughly 11.9 million patients' names, Social Security numbers, financial details and medical information might be exposed. LabCorp followed on 4 June with up to 7.7 million patients; BioReference Laboratories added about 422,000 two days later. An intruder had been inside AMCA's web payment portal from 1 August 2018 to 30 March 2019, and the first warning had come from outside the company: analysts at Gemini Advisory found some 200,000 payment cards for sale on a dark-web market in late February and traced them back to the portal.

Almost none of the people affected had ever heard of the company that lost their data. AMCA — legally Retrieval-Masters Creditors Bureau, working out of Elmsford, New York — collected small overdue medical bills: the unpaid remainder of a blood test, passed from the laboratory that ran it to a billing contractor to a collections firm three links removed from the patient. Everything the portal touched flowed down that chain — names, dates of birth, card and banking details typed into a payment page, Social Security numbers for Quest's patients and, for some, test information and diagnostic codes. Nobody whose data was taken could have withheld consent from AMCA, because nobody had ever given it anything.

The commercial verdict arrived faster than any regulator's. By mid-June, all four of AMCA's largest clients — Quest, LabCorp, Conduent and CareCentrix — had stopped sending it work. Notifying victims cost about $3.8 million for seven million mailed letters, $2.5 million of it a personal loan from the company's own chief executive, Russell Fuchs. On 17 June, exactly two weeks after the first disclosure, Retrieval-Masters filed for Chapter 11 protection in the Southern District of New York, listing assets and liabilities of no more than $10 million each and describing breach expenses "beyond the ability of the debtor to bear". The breach had not merely embarrassed its custodian; it had ended it.

The tally kept climbing after the month closed: by August, more than twenty client companies had come forward and the affected count passed twenty million. The formal ending took two more years — in March 2021, forty-one state attorneys general settled with the company over a breach they put at about 21 million people, a $21 million penalty suspended almost entirely because there was nothing left to pay it with, while former clients went on settling class actions of their own. June 2019 is the cleanest early proof in this archive of a rule later editions keep restating: your data's weakest custodian is one you have never heard of, and a breach can be the last thing a company does.

Also that month · Two ransoms in eight days

The week Florida paid

Riviera Beach's trouble began on 29 May, when a city employee opened an infected email attachment; the infection took down email, some phones and systems supporting the water utility's pump stations, and left police and fire dispatchers writing 911 calls down on paper. On 17 June the city council voted unanimously to let its insurer pay the attackers 65 bitcoin — roughly $600,000 — on top of nearly $1 million already approved for replacement computers. A week later, on 24 June, the council of Lake City, in the state's rural north, met in emergency session and voted to pay 42 bitcoin, a little under half a million dollars at the time, after a 10 June infection its officials described as a triple threat: an emailed document carrying Emotet, which fetched TrickBot, which delivered Ryuk. Insurance covered all but a $10,000 deductible; the city then fired its IT director, who had not been the one to open the attachment. Baltimore had refused to pay the month before and was facing a recovery bill estimated at more than $18 million. In June 2019, American cities looked at both ledgers and started choosing the ransom.

Also that month · Retaliation by keyboard

The strike that wasn't an airstrike

On 20 June, Iran's Revolutionary Guard shot down an American surveillance drone over the Strait of Hormuz — inside Iranian airspace by Tehran's account, over international waters by Washington's. President Trump said he approved retaliatory airstrikes that evening and called them off with minutes to spare. What went ahead instead, according to reporting by Yahoo News and the Associated Press over the following two days, was a US Cyber Command operation against computer systems the Guard used to control rocket and missile launches, and against a group linked to attacks on tankers. The Pentagon declined to comment, and Iran's telecoms minister later insisted no attack had succeeded. On 22 June, CISA director Christopher Krebs issued a public warning about rising Iranian activity against US industries and government agencies, including destructive wiper malware that erases whole networks. A military confrontation had been conducted, publicly and deliberately, in code — and both governments allowed the world to understand it that way.

India desk · June 2019

Cloud Hopper names TCS

On 26 June, a Reuters investigation into the Chinese espionage campaign known as Cloud Hopper named eight technology service providers it said had been compromised — among them Tata Consultancy Services, the largest company in India's flagship industry. Cloud Hopper, attributed by the US government and researchers to the APT10 group working with China's Ministry of State Security, did not attack its ultimate targets directly: it burrowed into the managed service providers that run email, servers and networks for much of the world's business, then hopped from their systems into their clients'. Alongside TCS, Reuters named HPE, IBM, Fujitsu, NTT Data, Dimension Data, Computer Sciences Corporation and DXC Technology. TCS declined to comment.

The report carried the disputes this archive treats as essential. Shipbuilder Huntington Ingalls said it was confident no company data had been breached; the travel-reservation firm Sabre said an investigation of its earlier incident found no traveller data accessed; Beijing denied it all. The United States had indicted two alleged APT10 operators in December 2018, and the indictment was as far as it ever went. For India, the naming stung somewhere specific: the IT-services industry was built on a promise of custodianship — hand us your infrastructure and it will be safer with us than with you. June 2019 put the industry's biggest name on a list of espionage conduits. The supply-chain compromises that dominate this archive's later years run on the logic Cloud Hopper proved: why breach one company when you can breach the company that runs a thousand?

AI Tech desk · June 2019

The world was not yet ready

The reckoning that fills this archive's later years arrived early, in miniature. On 26 June 2019, Motherboard exposed DeepNude, a downloadable app that used a generative network to fabricate nude images from photographs of clothed women — and only women. Its anonymous creator withdrew it the next day, tweeting that the world was not yet ready; copies circulated anyway, and the "nudify" services descended from it reached into schools and, by mid-decade, had forced new criminal law in Britain and America. The month's research was steadier. On 19 June, researchers at Carnegie Mellon and Google released XLNet, a pretraining method that overtook BERT — then the benchmark to beat — on twenty language-understanding tasks, one more exchange in the escalation that produced this decade's large models. And on 27 June, Somerville, Massachusetts voted to become the second US city to ban government use of facial recognition, the same day Axon, the largest maker of police body cameras, accepted its ethics board's advice to keep the technology off them entirely.

Digital Guard desk · June 2019

Patch now, says the NSA

On 4 June 2019, the National Security Agency took the unusual step of publicly urging administrators to patch BlueKeep, the wormable Remote Desktop flaw Microsoft had fixed and twice warned about the month before. CISA followed on 17 June, disclosing it had achieved remote code execution against a vulnerable Windows 2000 machine while scans found exposed systems in the hundreds of thousands. The feared second WannaCry never came; exploitation, when it arrived that November, delivered a cryptocurrency miner that crashed nearly as often as it worked. The industry's month was louder: the cloud-endpoint firm CrowdStrike listed on Nasdaq on 12 June, priced at $34 and closing at $58, worth more than $11 billion — the sector's bellwether thereafter, though the name now also recalls the faulty update that grounded airlines and hospitals in July 2024. Consolidation continued: on 5 June Elastic agreed to pay $234 million for the endpoint firm Endgame, an early step towards what vendors later sold as XDR, and Sophos bought Rook Security for its managed-detection service — the model that became the industry's default.

⏳ Time capsule — June 2019

  • Commemorations in Portsmouth and Normandy marked the 75th anniversary of D-Day on 6 June, with surviving veterans in attendance.
  • The Toronto Raptors beat the Golden State Warriors on 13 June to win their first NBA championship — the first for a team based outside the United States.
  • Organisers said nearly two million people marched in Hong Kong against a proposed extradition bill on 16 June, a day after the government suspended it.
  • Donald Trump became the first sitting US president to set foot in North Korea on 30 June, stepping over the demarcation line at Panmunjom to meet Kim Jong-un.
Where it stands today — 2026

Three rehearsals

June 2019 rehearsed three futures at once. AMCA's collapse wrote the template this archive keeps reopening — the third party nobody chose, destroyed by data nobody knew it held — through the vendor cascades of 2020's Blackbaud and 2023's MOVEit to the data broker of our August 2024 edition, bankrupted the same way with far more to lose. And the Florida votes ended nothing: they demonstrated, in public session and on insurance money, that extortion against local government cleared payment. The wave of municipal and school-district attacks that fills the next two years of this archive treated those two council chambers as proof of market — and the ransom-payment debate that runs to our 2025 editions begins in them.

The quieter entries travelled just as far. GandCrab's operators had signed off on 31 May boasting of two billion dollars earned — their claim, never anyone's audit — and a Europol-backed decryptor for its final versions landed on 17 June; but the successor was already working. This archive meets Sodinokibi again at Travelex in January 2020 and at Kaseya in July 2021, under its better-known name, REvil. Cyber Command's answer to a downed drone made retaliation by keyboard an acknowledged instrument of statecraft, and Cloud Hopper taught a decade of attackers to aim at whoever runs the systems rather than whoever owns them. The Vault continues backwards from here, finding the same lessons already waiting.