WhatsApp's security team found the flaw in early May: a buffer overflow in the app's voice-calling stack, catalogued as CVE-2019-3568, which let an attacker run code on a phone simply by ringing it. The call never had to be picked up, and in some cases the missed-call entry was scrubbed from the log afterwards. What the exploit delivered was Pegasus, the surveillance product of Israel's NSO Group, sold to government clients. WhatsApp pushed a server-side block on Friday 10 May, shipped patched apps on Monday 13 May — the day the Financial Times broke the story — and urged all 1.5 billion users to update, saying the attack bore "all the hallmarks of a private company known to work with governments".
The first known target was a man who asked not to be named: a UK-based human rights lawyer who had been receiving WhatsApp video calls from unknown numbers at odd hours for months, and grew suspicious enough to approach Citizen Lab, the Toronto research group that had tracked Pegasus since 2016. He had helped Mexican journalists and a Saudi dissident bring lawsuits against NSO. On Sunday 12 May — the server-side fix already live, the public still unaware — one final attempt was made against his phone. It failed. Asked how many people had been attacked through the flaw, WhatsApp said in those first days only that the number was at least in the dozens; Citizen Lab said the pattern was consistent with the targeting of civil society.
NSO's response became the industry's standard text: its technology is licensed to vetted government agencies to fight crime and terrorism, the company does not operate it for its clients, and credible allegations of misuse are investigated. This archive records that as a claim, made while researchers were documenting targets who were neither criminals nor terrorists. What May 2019 changed was the mechanics. Since Citizen Lab's first Pegasus casework in 2016, infection had needed the target to tap a poisoned link, and years of security training had been spent teaching people not to. Now the delivery method asked nothing of the victim at all. The industry reached for a new term — zero-click — and the phones of careful people rang anyway.
The ending is known because WhatsApp went to court. Its October 2019 lawsuit — that month's story in this archive — told roughly 1,400 users their phones had been targeted between 29 April and 10 May 2019, journalists, diplomats and human-rights defenders among them, including more than a hundred in India whose notifications would set off a political storm of their own. Six years of litigation followed. In December 2024 a federal judge found NSO liable for hacking and breach of contract; in May 2025 a California jury ordered it to pay WhatsApp $444,719 in compensatory damages and just over $167 million in punitive damages — a punitive award the judge cut to $4 million that October, even as she permanently barred NSO from targeting WhatsApp again. The most consequential phone call of 2019 was one that nobody answered.
Thirteen bitcoin for Baltimore
Baltimore's network went down on the morning of 7 May. RobbinHood ransomware locked an estimated 10,000 city computers, and the note demanded 13 bitcoin — about $76,000 — with the price rising $10,000 a day after day four. The city refused, then learned what refusal costs: email dead for weeks, water billing suspended, hundreds of home sales stalled because staff could not check liens. The budget office put the bill near $18 million — roughly $10 million in recovery, $8 million in lost or deferred revenue. On 25 May The New York Times reported the attack had spread using EternalBlue, the stolen NSA exploit. The claim did not survive examination: analysts who obtained the binary found no EternalBlue code and no ability to spread on its own, and Senator Chris Van Hollen, briefed by the NSA, said the government saw no evidence of it either. It was never substantiated. The ending took six years: in May 2025, Iranian national Sina Gholinejad pleaded guilty in a US federal court for his role in the RobbinHood operation, prosecutors putting Baltimore's damage above $19 million.
One digit away
The month's largest exposure involved no malware and no intruder anyone could name. On 24 May, Krebs on Security reported that the website of First American Financial, one of America's biggest title insurers, would hand over the paperwork of sixteen years of property closings — bank statements, Social Security numbers, tax records, wire instructions — to anyone who changed one digit in a document link. The files were numbered sequentially; the earliest dated to 2003; the counter stood near 885 million. Ben Shoval, a Washington-state property developer, had found it, got nowhere with the company, and went to the press. First American called it "a design defect in an application" and cut external access that afternoon. Hindsight made it worse. New York's financial regulator, filing its first-ever cybersecurity enforcement action in July 2020, said the flaw had been introduced in a 2014 update — and that First American's own penetration testers had found it in December 2018, six months before Shoval did, without it being fixed. The company paid the SEC just under half a million dollars in 2021, and settled with New York for $1 million in November 2023.
Counting day, and a database for sale
For India the month narrowed to a single Thursday: 23 May, when the votes of the seventeenth general election were counted. Polling had run in seven phases from 11 April to 19 May, with some 912 million people eligible and turnout above 67 per cent — the highest a general election had recorded. For the security community, the quiet story was procedure. This was the first general election in which every polling station's electronic voting machine — a standalone device, never networked — was paired with a paper-trail printer, and under the Supreme Court's April order the slips of five machines per assembly segment were matched against electronic tallies during the count. The results were accepted, and the machines survived another round of the argument about them.
The other Indian story of the month carried a price tag. On 22 May, reports surfaced of a dark-web listing offering what the seller described as Truecaller user data — the Indian records for about ₹1.5 lakh, a global set for 25,000 euros — with phone numbers, email addresses and home addresses among the fields. India was the caller-ID company's largest market, the bulk of a user base then counted at around 140 million. Truecaller denied any breach of its database, saying there was "no sensitive information being accessed or extracted", and attributed the listing to unauthorised copying of the kind its search limits were built to stop. This archive treats the listing as a seller's claim. A year on, researchers found what appeared to be the same trove — 47.5 million Indian records — relisted for a thousand dollars. The denial held; the price fell; and the law that would eventually govern such data was still four years away.
A ban, a model, a rulebook
On 14 May 2019, San Francisco's Board of Supervisors voted eight to one to bar city agencies, the police included, from using facial recognition — the first American city to refuse the technology, and the start of a municipal wave that reached Somerville and Oakland within months. OpenAI, meanwhile, loosened its grip on GPT-2: on 3 May it published the medium version of the text generator it had judged too risky to release in full — announced at 345 million parameters, a fraction of the withheld original — and the staged release ran to completion by November; from 2026 the model reads as a miniature, though the argument it opened about releasing model weights has never closed. And on 22 May in Paris, 42 countries adopted the OECD's AI Principles, the first intergovernmental standard for the field — non-binding, but the G20 borrowed the text within a month, and the frameworks that followed kept its vocabulary.
Symantec stumbles, CrowdStrike files to float
Symantec ended 9 May 2019 without a chief executive. Greg Clark, who had arrived with the 2016 Blue Coat deal, stepped down with immediate effect on the evening the company reported quarterly revenue short of expectations and guided lower; director Richard Hill took over on an interim basis, and the shares fell by more than a tenth in after-hours trading. The exit read as symptom rather than cause: within three months Broadcom had agreed to take the enterprise business for $10.7 billion, and by November the remainder had renamed itself NortonLifeLock — the break-up traced at this archive's August and November desks. Five days after Clark's departure, CrowdStrike filed the prospectus for its June flotation, the endpoint market's next generation going public as its old one came apart — a newcomer that would become one of the industry's most valuable names and, five years on, the author of its most visible outage. On 31 May GandCrab's operators announced their retirement, claiming — the figure was theirs alone — over two billion dollars in ransoms; researchers soon traced the same hands to REvil.
⏳ Time capsule — May 2019
- On 1 May, Emperor Naruhito acceded to Japan's Chrysanthemum Throne, opening the Reiwa era after his father's abdication.
- Game of Thrones ended on 19 May after eight seasons; HBO said 19.3 million people watched the finale that night.
- On 20 May, the redefinition of the SI units took effect: the kilogram is now fixed by the Planck constant, retiring the platinum-iridium cylinder kept outside Paris since 1889.
- Bong Joon-ho's Parasite won the Palme d'Or at Cannes on 25 May — the first South Korean film to take it; the following February it would win Best Picture.
The month nobody had to answer
The Pegasus thread runs the length of this archive. It resurfaces in October 2019, when WhatsApp files suit and India learns who was on the list; in July 2021, when the Pegasus Project prints the numbers a missed call made possible; in September 2021, when Forced Entry shows Apple's iMessage had its own zero-click door; and in May 2025, when a jury finally attaches a dollar figure to the business model. First American's open door begins a different lineage — the breach with no break-in — that reaches its fullest expression in January 2023, when an abused API hands over 37 million T-Mobile accounts without anything being hacked at all.
And some threads mattered because they frayed. BlueKeep, the wormable Windows flaw patched on 14 May with fixes Microsoft shipped even for Windows XP, was supposed to be the next WannaCry; the worm never came, and when exploitation finally arrived that November it installed cryptocurrency miners. Stack Overflow's intrusion, disclosed on 16 May, ended at 184 affected users; Canva's 139 million, claimed by a hacker on 24 May, joined the credential piles that power everything since. The lesson of May 2019 has kept its shape for seven years: the catastrophes announced loudest are rarely the ones that arrive. The Vault continues backwards from here.