Honda's computer network began failing on Sunday 7 June 2020, and by Monday the failure had reached the physical world. Car production paused at plants in Ohio and Turkey; motorcycle lines stopped in India and Brazil; customer service and financial services operations went quiet alongside them. The company's first account was deliberately plain — a disruption in its network that had affected its ability to access servers, use email and run internal systems — and it noted that production had been suspended at some plants while it worked. What made assembly stop was not damaged machinery but blindness: a modern line cannot build vehicles when the systems that schedule, track and quality-check each one stop answering.
Honda itself never said the word ransomware. The identification came from outside: researchers examining a fresh sample of SNAKE — or EKANS, the name reversed, the marker it stamps on the files it encrypts — uploaded to VirusTotal that Monday. The sample tried to resolve mds.honda.com, a hostname that answers only inside Honda's private network, and if the name did not resolve, the program exited without encrypting a single file. Whoever built it knew the company's internal addressing and meant the code to run nowhere else. Honda confirmed only a cyberattack on its network and said there was "no current evidence of loss of personally identifiable information" — a position this archive records alongside the researchers' analysis, not in place of it.
EKANS had been on the industrial world's desk since February, when the security firm Dragos published its analysis of a ransomware family that arrived with a kill list: before encrypting, it works down a roster of named processes to terminate, and alongside the usual databases and backup agents the roster includes industrial software — processes belonging to GE's Proficy data historian, GE Fanuc licensing services and Honeywell's HMIWeb among them. It does not manipulate valves or robots; it stops the programs through which people see and steer them, which in practice can be enough to stop a plant. Weeks before Honda, reporters had linked the same family to an attack on Fresenius, Europe's largest private hospital operator. June made the pattern unmissable.
The ending, for Honda, was quick and quiet. Production resumed at most sites within days — the Ohio, Turkey, India and Brazil lines were the last reported still suspended — and the company repeated that it had found no evidence of data being taken; it never made public any ransom demand, payment or cost figure. The idea the attack demonstrated was not quiet at all. Code that stops the software watching physical processes had crossed from research papers into a global carmaker's Monday morning — and eleven months later, when a pipeline company shut its own pumps as a precaution, everyone reaching for a precedent reached for this one.
A prime minister announces an intrusion
On Friday 19 June, Scott Morrison opened an unscheduled press conference in Canberra with a sentence prime ministers do not usually say: Australian organisations were under attack from a "sophisticated state-based cyber actor", and had been for months, with rising frequency. The target list he read out was effectively the country — all levels of government, industry, political organisations, education, health, essential services, critical infrastructure. He declined to name the actor; asked directly about China, he said only that few states have such capabilities. Beijing rejected the inference, which reporting citing government sources had drawn within hours. The technical companion, published the same day, was almost deflating: the Australian Cyber Security Centre's Advisory 2020-008 dubbed the campaign "copy-paste compromises", because the actor had assembled it largely from public proof-of-concept exploits for known, patchable flaws in Telerik UI, Citrix and SharePoint products. Eleven days later Canberra announced A$1.35 billion for cyber defences over the following decade, billed as the nation's largest such investment. The campaign was never formally attributed in public.
UCSF pays $1.14m while a reporter watches
The NetWalker gang's ransomware was detected inside the University of California San Francisco on 1 June, encrypting servers in the School of Medicine — a campus then engaged in COVID-19 antibody testing and clinical trials. UCSF said patient care and its coronavirus work were not impeded, but the encrypted files, reports said, could not be restored from backups. What made the case singular was visibility: tipped off anonymously, the BBC watched the dark-web negotiation as it happened. NetWalker's operators demanded $3 million; the university's negotiator offered $780,000 and was mocked — in the exchange the BBC published, the gang suggested UCSF keep the sum and spend it on McDonald's for its employees. A day later the two sides settled at $1,140,895, paid in 116.4 bitcoin, for a decryption tool and the return of the data taken. UCSF confirmed the payment on 26 June, calling it a difficult decision, taken because the encrypted data served academic work pursued in the public good. In January 2021, US and Bulgarian authorities seized NetWalker's infrastructure; one of its most prolific affiliates, a former Canadian government IT worker, was later sentenced to twenty years in an American federal prison.
Fifty-nine apps and a border
On 29 June 2020, India's Ministry of Electronics and IT banned 59 apps of Chinese origin — TikTok, UC Browser, WeChat and Shein among them — invoking Section 69A of the Information Technology Act and calling them "prejudicial to sovereignty and integrity of India, defence of India, security of state and public order". Two weeks earlier, on 15 June, twenty Indian soldiers had been killed in a border clash with Chinese troops in the Galwan Valley, and nobody missed the connection. TikTok — with an estimated 200 million users in India, its largest market outside China — disappeared from Indian app stores within days. The order was framed as data security and read as retaliation, at a scale no government had attempted before; further rounds followed that year, and in January 2021 the ban was made permanent.
The month had opened with a quieter Indian story that belongs beside the loud one. In the first days of June, researchers at vpnMentor disclosed a misconfigured Amazon S3 bucket tied to a website promoting the BHIM payments app — a sign-up campaign site run by CSC e-Governance Services — left publicly readable with about 409 gigabytes of data, which the researchers put at records on roughly seven million people: Aadhaar and PAN card scans, caste certificates, photographs. The exposure had been found on 23 April, reported to CERT-In on 28 April and closed on 22 May. NPCI, which operates BHIM, said there had been no data compromise at the BHIM app itself — a denial this archive carries, and a distinction (the app was not breached; a partner's website store was exposed) that mattered less to the people in the bucket.
The model becomes a product
OpenAI shipped its first commercial product on 11 June 2020: an API offering GPT-3, the 175-billion-parameter language model its researchers had described a fortnight earlier, as a paid service — text in, text out, access granted by invitation from a waitlist. The significance was less the model than the business around it: OpenAI would sell metered access to software it declined to release, and that arrangement became the template for the industry this magazine's AI desk now covers — ChatGPT, still two years away, arrived through the same door. The same week, facial recognition went into retreat. On 8 June IBM told the US Congress it was leaving the general-purpose business; on 10 June Amazon announced a one-year moratorium on police use of Rekognition; on 11 June Microsoft said it would not sell the technology to American police departments until a federal law existed. Announced amid the protests that followed George Floyd's killing, the pauses outlasted their moment: Amazon later extended the moratorium indefinitely, and the federal law the companies invited has still not arrived.
Defender leaves Windows
Microsoft Defender ATP stepped off Windows on 23 June 2020: the Linux version reached general availability, covering six major server distributions, and a preview for Android arrived the same day, screening apps and phishing links on a platform the antivirus industry had long treated as an afterthought. Renamed Microsoft Defender for Endpoint that autumn, it grew into one of the sector's dominant platforms, and the question a capable bundled agent poses — what, exactly, is the third-party licence buying? — has pressed on every vendor since. The same day, NCC Group published its analysis of WastedLocker, new ransomware from Evil Corp, the US-sanctioned Russian group behind the Dridex banking trojan; within days Symantec reported finding its operators at work inside at least thirty-one American organisations, eight of them Fortune 500 companies, and said the intrusions had been caught before encryption began. In a month when ransomware had already idled a carmaker's plants, the warning read as a forecast: a month later WastedLocker took Garmin's fitness cloud and aviation services offline for days.
⏳ Time capsule — June 2020
- New Zealand announced zero active COVID-19 cases on 8 June and moved to its lowest alert level, lifting nearly all domestic restrictions.
- Oxford's RECOVERY trial reported on 16 June that dexamethasone, a cheap and decades-old steroid, cut deaths among ventilated COVID-19 patients by about a third — the pandemic's first life-saving drug result.
- The English Premier League resumed on 17 June, 100 days after its last match, in empty stadiums.
- China's top legislature passed the Hong Kong national security law on 30 June; it came into force the same night.
Everything here happened again
June 2020 reads, from 2026, like a table of contents. Ransomware that stops physical operations runs from Honda's silent lines to the fuel queues outside American petrol stations in May 2021, when Colonial Pipeline shut its pumps — that edition sits in this archive too. And on 16 June, researchers at the Israeli firm JSOF disclosed Ripple20: nineteen flaws in a tiny TCP/IP library from Treck, built over two decades into medical, industrial and home devices — hundreds of millions of them, by the researchers' estimate. It was the everything-library problem, rehearsed eighteen months before Log4Shell, the fire that December 2021's edition records. The ancestor was documented; the descendants arrived anyway.
The geopolitics aged just as predictably. Australia's unnamed "state-based actor" was an early sighting of what later editions record as routine — national advisories, joint attributions, prepositioning in critical infrastructure. India's 59-app order hardened into policy: the ban became permanent, the list grew past two hundred, and the argument it started — that where data lives is a sovereignty question — runs through this archive to the DPDP Act's passage in August 2023 and beyond; by 2025 Washington was fighting its own TikTok battle on the same ground. UCSF's ransom, paid while a reporter watched, remains the clearest small portrait of the calculation every victim makes. The Vault continues backwards from here.