The takeover announced itself in a single voice. Through the afternoon of 15 July 2020, US Eastern time, the accounts of Elon Musk, Bill Gates, Jeff Bezos, Barack Obama, Joe Biden, Kanye West, Apple and Uber began promising, one after another, that any bitcoin sent to the address in the tweet would be returned doubled. Twitter could not immediately tell how the accounts were being taken, so it reached for the bluntest brake it had: for several hours, every verified account on the platform was blocked from tweeting. The blue ticks fell silent mid-sentence. In Illinois, National Weather Service offices found they could not tweet tornado warnings; the man who now owns the platform could not post either.
Twitter's own accounting, published on 30 July, remains the clearest description of what happened. Attackers ran a phone spear-phishing operation against employees — calling staff and talking them into surrendering credentials — and not everyone they fooled had access to account tools, so they used the first accounts to learn the company's processes and find colleagues who did. With access to an internal administrative console, they targeted 130 accounts, tweeted from 45, opened the direct-message inboxes of 36 and downloaded the full account data of up to 8. For all the reach involved, the scam collected just over $100,000 in bitcoin by the US Justice Department's accounting — the price of hijacking the communications channels of presidents, billionaires and two of the world's biggest companies.
The arrests took sixteen days. On 31 July, Florida police took Graham Ivan Clark, aged 17, from an apartment in Tampa; state prosecutors charged him with 30 felonies, taking the case because federal law treats juveniles differently. The same day, US federal prosecutors charged Mason Sheppard, 19, of Bognor Regis in England, and Nima Fazeli, 22, of Orlando, over their alleged brokering of account sales. The endings are known now. Clark pleaded guilty in March 2021 and, dealt with as a youthful offender, received three years in a juvenile facility plus three years' probation. A fourth participant, Joseph O'Connor, was arrested in Spain in 2021 and sentenced in New York in June 2023 to five years.
What made July 2020 a hinge was not sophistication but location. The attackers never touched Twitter's code; they telephoned its people, and the people opened the console that could speak as anyone on Earth. Within weeks the FBI and CISA were jointly warning that voice-phishing crews were working through the credentials of newly remote workforces, and a New York financial regulator's post-mortem that October argued that platforms this central to public life needed oversight of the kind reserved for banks. The month's real disclosure was that the world's town square had a master switch, that a phone call could reach it — and that the fastest way to stop the bleeding was silence.
Garmin goes dark
Garmin's services failed in the early hours of 23 July — Garmin Connect stopped syncing runs and rides, call centres went unreachable, and flyGarmin, which pilots use for flight plans and aviation database updates, went down with them. The company first called it an outage; on 27 July it confirmed a cyber attack had encrypted some systems. Employees told reporters the malware was WastedLocker, which researchers had linked to Evil Corp, a Russian group under US Treasury sanctions since December 2019, and that the demand was $10 million — figures Garmin has never confirmed. That sanction is what makes the ending instructive. Sky News later reported the company obtained its decryption key through an intermediary, after a first negotiation firm refused the job over sanctions risk; BleepingComputer confirmed a working decryptor existed inside Garmin. The company restored services within about a week and said there was no indication customer data had been taken. Whether a ransom was paid, and by whom, has never been officially acknowledged — which was rather the point of the arrangement.
Blackbaud pays for a deletion no one can see
Blackbaud is not a household name, which is precisely why its 16 July disclosure mattered: the South Carolina company runs fundraising and donor databases for tens of thousands of nonprofits, universities, schools and health systems. It revealed that ransomware operators had been inside its systems for months before being expelled in May 2020, and that although the encryption was stopped, the attackers had already copied a subset of customer data. Then the remarkable sentence: Blackbaud paid the ransom in exchange for confirmation that the copy had been destroyed. Hundreds of organisations on three continents spent the rest of 2020 writing to donors, alumni and patients about a breach they had not suffered themselves. Hindsight made it worse. US regulators later found that within days of saying bank details and Social Security numbers were untouched, Blackbaud's own staff learned they were not — and the public was told at the end of September. The company paid the SEC $3 million in 2023, and $49.5 million to settle with US state attorneys general, over how it described that July.
Clones banned, couriers breached
The app bans of June did not end in June. On 24 July the government signed an order blocking 47 more Chinese applications, and when the news broke on 27 July the list turned out to be largely déjà vu: TikTok Lite, Helo Lite, SHAREit Lite, Bigo Live Lite, CamScanner Advance — lighter clones and mirrors of the 59 apps banned on 29 June after the Galwan Valley clash, republished to slip past the first order. The total stood at 106, with reports of a further list of more than 250 apps under review for privacy and security concerns. The message of the second order was procedural rather than dramatic: the ban was not a gesture but a policy, and it would be maintained against workarounds.
The month's Indian breach was homegrown. On 11 July, Dunzo — the Google-backed delivery startup that Bengaluru leaned on through lockdown — disclosed that a server belonging to a third party it worked with had been compromised, exposing its user database. The tally, when the data later surfaced, was about 3.46 million accounts: names, email addresses, phone numbers, IP addresses, device details and last-known locations, though the company said payment information and home addresses were not stored in the affected database. No regulator fined anyone, because there was nothing to fine them under: India's Personal Data Protection Bill was still in committee, would later be withdrawn entirely, and the law that finally arrived — the DPDP Act — was three years and one rewrite away.
English in, working code out
The technology story of the season was a demonstration reel. OpenAI had begun admitting testers to its GPT-3 API in June, and through July their screen recordings carried a research preview into general conversation. On 13 July the developer Sharif Shameem posted a layout generator that turned plain-English descriptions into working React code, followed days later by debuild, a fuller demonstration that assembled small applications the same way. The week around it produced Figma mock-ups, SQL queries and regular expressions conjured from sentences, while the text adventure AI Dungeon shipped Dragon, a paid tier running on GPT-3 and among the first consumer products built on the model. MIT Technology Review's 20 July verdict — fluent, comprehending nothing — slowed nobody, and Sam Altman himself called the hype “way too much”. By late July a Berkeley student's GPT-3-written blog had reached the top of Hacker News, barely edited and barely detected. From 2026 the shape is familiar: a raw model, a waitlist, demos doing the work of a launch — the ChatGPT pattern, two years early.
Seventeen years inside Windows DNS
The month's defining security bulletin was seventeen years old. Microsoft's 14 July Patch Tuesday fixed CVE-2020-1350, a flaw in Windows DNS Server that Check Point's researchers named SIGRed: present in the code since 2003, rated a maximum 10.0 for severity, and wormable — a malicious DNS response could seize a server and spread onward with nobody clicking anything. Two days later CISA gave US federal civilian agencies twenty-four hours to patch or apply the registry workaround, an unusually short fuse that measured how bad the alternative looked. The industry's quieter movement ran the other way. Microsoft Defender ATP for Android, announced as a public preview on 23 June, spent July rolling out to enterprises — scanning for malicious apps, checking links for phishing, and reporting phones into the same console as the desktop fleet. Renamed Defender for Endpoint that autumn, it kept absorbing platforms; with hindsight, this was the operating system's maker settling in as the endpoint industry's largest vendor, a position the standalone antivirus firms have contested ever since.
⏳ Time capsule — July 2020
- Three missions left Earth for Mars in eleven days: the UAE's Hope probe on 19 July (UTC), China's Tianwen-1 on 23 July and NASA's Perseverance rover on 30 July — all racing the same launch window.
- EU leaders agreed the €750 billion pandemic recovery fund on 21 July, after a summit that ran more than four days — among the longest in the bloc's history.
- Hagia Sophia in Istanbul held its first Friday prayers as a mosque in 86 years on 24 July, following a court ruling earlier in the month.
- Comet NEOWISE made its closest approach to Earth on 23 July — the brightest comet seen from the Northern Hemisphere since Hale-Bopp in 1997.
The decade answers the phone
July 2020's cover story looks, from 2026, like a proof of concept. The phone call that opened Twitter's console became the signature intrusion of the following five years: a contractor talked past his MFA prompts at Uber in September 2022, a help desk talked into a password reset at MGM in September 2023 — both months in this archive — and, throughout, teenagers doing the talking, from Tampa to Lapsus$. The quieter July items travelled too. APT29, named on 16 July by three governments over COVID-19 vaccine espionage, was five months from being found inside SolarWinds, where December 2020's edition picks it up. And the EU's first-ever cyber sanctions, imposed on 30 July over WannaCry, NotPetya and Cloud Hopper, turned a diplomatic toolbox into a working instrument.
The money threads run just as far. Garmin's unconfirmed payment, squeezed through an intermediary because the counterparty was sanctioned, prefigured the US Treasury advisory that October warning that paying sanctioned ransomware actors could fall foul of sanctions law — the start of an argument that runs through this archive to Britain's 2025 proposal to ban public-sector payments outright. Blackbaud's purchased confirmation of deletion became the standing example of a promise no victim can audit. And India's July — a ban list lengthening faster than its data-protection bill could move — set the shape of the years ahead: enforcement first, legislation eventually, the DPDP Act finally passing in August 2023. The Vault continues backwards from here.