The tip came from a routine internet-mapping project. In early September 2019, researchers at vpnMentor found an Elasticsearch server on a Miami IP address with no password on it, and inside, roughly 18 gigabytes of structured data on Ecuadorians — some 20.8 million records by ZDNet's count, in a country of about 16.6 million people. The arithmetic was the story: the database outnumbered the population because it carried duplicates and the dead. The server appeared to belong to Novaestrat, a small Ecuadorian consultancy in data analytics and strategic marketing that almost nobody in Ecuador had heard of — and that held, in practice, a copy of the nation.

The records read like a state's filing cabinet. Names, dates of birth, addresses and phone numbers sat alongside cédula national identity numbers and taxpayer IDs. Entries mapped family relationships — parents, spouses, children — into ready-made family trees, and researchers counted almost seven million minors among them. Financial fields, apparently drawn from the state social-security bank Biess, listed account balances and credit types; other tables, seemingly from the automotive association Aeade, recorded car ownership. One entry concerned a naturalised citizen then sitting in a London prison: Julian Assange, granted Ecuadorian citizenship during his years in the country's London embassy, present in the database with a national ID number like everyone else.

vpnMentor reported the exposure through Ecuador's computer emergency response team, and the server went dark on 11 September — five days before the public learned of it on the 16th. What followed was unusually fast. Police raided the home of Novaestrat's general manager, William Roberto G., seizing computers and detaining him for questioning, and the government announced that a data-protection bill — drafted, ministers said, over the previous eight months — would go to the National Assembly within days. What nobody could say was who else had found the server first. This was an exposure, not a proven theft; evidence that criminals downloaded the data never surfaced, which is not the same as evidence that they did not.

In 2026 the ending is known. Ecuador's Organic Law on Personal Data Protection passed in May 2021 — the catastrophe-first route to privacy legislation this archive watches country after country take. Assange's Ecuadorian citizenship was revoked by a court that same year. Novaestrat's name survives mainly in conference slides, the type specimen of a pattern the following years made routine: state registry data, copied to a private analytics firm, parked on rented infrastructure abroad, guarded by nothing. A country's population can be leaked exactly once. There is no password reset for a family tree, and Ecuador spent the 2020s living with that.

Also that month · Silicon, not software

checkm8: the exploit Apple could never patch

On 27 September, a researcher known as axi0mX published checkm8, an exploit for the bootrom — the read-only first code an iPhone runs when it powers on. Because that code is burned into the silicon at manufacture, Apple could not fix it with any update, ever. Every device on the A5 through A11 chips was affected: iPhone 4S through iPhone X, plus generations of iPads and iPod touches — hundreds of millions of devices, permanently. It was the first public bootrom exploit since the iPhone 4 in 2010. The limits mattered: checkm8 needed a USB cable and physical possession, did not survive a reboot, and could not be fired remotely. Within weeks the checkra1n jailbreak was built on it, reviving a scene Apple had spent a decade suffocating — and the mobile-forensics industry quietly absorbed it too, because an unpatchable way into an iPhone is worth more to an evidence lab than to a hobbyist. Devices from the A12 onward were immune; everything older remains exploitable today.

Also that month · A hospital on paper

Gillette, Wyoming, 3:30 a.m.

Campbell County Health, which runs the 90-bed Campbell County Memorial Hospital in Gillette, Wyoming, discovered ransomware on its network at about 3:30 in the morning on Friday 20 September. All 1,500 of the organisation's computers were affected. What made the case notable was its candour: the hospital said publicly, that day, that it was cancelling services — surgeries, radiology exams, laboratory work, respiratory therapy — diverting emergency transports and transferring some patients to facilities elsewhere in Wyoming and in South Dakota. Staff fell back to paper charts. State agencies, the governor's office and the FBI were brought in; officials later said that, to their knowledge, no ransom was paid, and the organisation said it found no evidence that patient information had been compromised. Systems came back gradually over the following weeks. In 2019, a rural American hospital openly cancelling operations because of malware still read as extraordinary. The archive's later volumes — Düsseldorf in September 2020, the US healthcare payments system in February 2024 — would remove the novelty.

India desk · September 2019

Maya: a period diary that talked to Facebook

On 9 September 2019, the London-based charity Privacy International published an analysis of period-tracking apps and their advertising plumbing. Among the worst offenders was Maya, built by Bengaluru's Plackal Tech and installed more than five million times from Google Play, with much of its user base in India. The researchers found the app began sharing data with Facebook through the company's software development kit the moment it was opened — before the user had agreed to any privacy policy, and whether or not she had a Facebook account. What flowed out was the app's entire point: symptoms, moods, contraceptive use, notes on sexual activity, even personal diary entries, with some data also reaching the mobile-analytics firm CleverTap.

Plackal responded by stripping Facebook's core and analytics kits from the app, retaining only an advertising component it said would run after consent. The episode measured precisely where Indian data protection stood: the most intimate health information millions of women recorded anywhere sat outside any statute, because there was none — the Personal Data Protection Bill would not reach the Lok Sabha until December 2019, and the DPDP Act that now governs such data was four years away. It was an exposure by design, not by breach, and it was perfectly legal — while September's most consequential Indian security event, a malware infection found in the Kudankulam nuclear plant's administrative network and flagged to CERT-In on 4 September, stayed invisible to the public until the end of October.

AI Tech desk · September 2019

Zao and the deepfake arms race

Zao, a face-swap app from the Chinese social firm Momo, appeared on 30 August 2019 and within days sat atop China's iOS App Store free chart, grafting users' selfies into Leonardo DiCaprio films in seconds. The backlash was nearly as quick: a user agreement granting Zao free, irrevocable, perpetual and re-licensable rights to uploaded faces was withdrawn by 1 September after an outcry, and WeChat blocked the app's links a day later, citing security risks. Deepfakes had gone consumer, and the defence hurried after them — on 5 September, Facebook, Microsoft and a consortium of universities announced the Deepfake Detection Challenge, putting more than $10 million behind detectors whose winning model, the following summer, still caught barely two-thirds of unseen fakes. OpenAI, meanwhile, published on 17 September what nearly 500 million games of hide-and-seek had taught its simulated agents — tool use, barricades and physics exploits nobody programmed — emergent behaviour from brute scale, and a quiet preview of the agentic decade that followed.

Digital Guard desk · September 2019

Carving up Symantec

The company that defined consumer antivirus spent the month being taken apart. A month after agreeing to sell its enterprise security business to Broadcom for $10.7 billion, Symantec drew reported interest from the private-equity firms Permira and Advent International at $26 to $27 a share — a valuation of about $16 billion, built around keeping the Norton and LifeLock consumer unit. The talks came to nothing; the Broadcom sale closed that November, the remainder renamed itself NortonLifeLock and, after absorbing Avast, now trades as Gen Digital — while Permira and Advent eventually led the group that bought McAfee instead. The month's sharpest vendor research came from Kaspersky, which on 23 September described Dtrack, a Lazarus Group espionage tool found inside Indian banks and research centres, alongside a sibling, ATMDtrack, built to skim card data from Indian cash machines. Within weeks the same family would surface somewhere more sensitive still — the administrative network of the Kudankulam nuclear plant, the story this edition's India desk records.

⏳ Time capsule — September 2019

  • India's Chandrayaan-2 mission lost contact with its Vikram lander on 7 September, moments before a planned touchdown near the lunar south pole.
  • Drone and missile strikes hit Saudi Arabia's Abqaiq and Khurais oil facilities on 14 September, briefly cutting the kingdom's output by roughly half.
  • About 150 people actually turned up on 20 September to "storm" Area 51 after more than two million joined the joke online; nobody stormed anything.
  • Thomas Cook, the world's oldest travel firm at 178 years, collapsed on 23 September, leaving some 150,000 British holidaymakers to be flown home in the UK's largest peacetime repatriation.
Where it stands today — 2026

The unpatchable month

September 2019's two defining stories shared a property the industry prefers not to discuss: permanence. Ecuador could detain a consultant and pass a law — it finally did, in May 2021 — but it could not recall twenty million records; a leaked cédula number and family tree stay leaked for a lifetime. checkm8 taught the same lesson in silicon: the checkra1n jailbreak arrived that November, forensic extraction tools followed, and every A5-to-A11 iPhone on earth remains exploitable in 2026, because no update reaches a bootrom. The misconfigured-server genre runs forward from Novaestrat through this whole archive, to India's DIKSHA exposure in January 2023 — different country, same open door, children's data again.

The rest of the month grew into genres too. Emotet restarted its spam machinery on 16 September after a silent summer, hauled ransomware into networks for sixteen more months, and fell to a coordinated police seizure in January 2021 — this archive's The State as Antivirus. DoorDash's 26 September disclosure of a 4 May intrusion, and the 218 million Words With Friends accounts an attacker claimed while Zynga confirmed only an incident, made the disclosure gap a genre of its own. Simjacker showed SIM cards could be turned into trackers by a single crafted SMS — on the word of the vendor that found it. And Campbell County's cancelled surgeries were the overture to ransomware's healthcare decade. The Vault continues backwards from here; the consequences run the other way.