The shop opened on 2 May 2020, during Ramadan, when a seller calling itself ShinyHunters began leaking the user database of Tokopedia — Indonesia's largest online marketplace — first as a free sample of fifteen million rows, then as the full stock: 91 million account records for $5,000, from an intrusion the seller dated to March. Tokopedia confirmed an attempted data theft, stressing that passwords were stored encrypted. Within days the same alias was offering roughly 22 million records from the Indian learning platform Unacademy, and by 10 May the trade press counted ten further databases — Zoosk, Home Chef, Chatbooks, Minted and the Minneapolis Star Tribune among them — 73.2 million records at $500 to $3,500 apiece. Ten days in, the advertised inventory summed past 180 million rows.

What distinguished the month was not any single breach but the retailing. Earlier data thieves dumped their hauls or hawked them one-off; ShinyHunters — the name borrowed from Pokémon players who grind for rare "shiny" variants — ran a supermarket: weekly restocks, bundle pricing, free samples passed to journalists for authentication. The first week even brought a claimed cache of Microsoft source code from private GitHub repositories — a boast Microsoft never confirmed. Later in the month the shelves refilled: a reported 25 million records from the maths app Mathway at about $4,000, and 40 million from the teen polling app Wishbone — given away free, the group said, because rivals had begun reselling it. Chatbooks and Home Chef confirmed their breaches within weeks; other victims stayed silent, their customers left to learn from journalists.

The prices are the detail worth sitting with. At Tokopedia's rate, one US cent bought about 180 accounts — a name, an email address, a hashed password, the outline of a digital life. The buyers' business model explained the discount: credential stuffing, in which stolen email-and-password pairs are replayed against banking, shopping and mail services on the reliable assumption that people reuse passwords. Hashing slowed that only somewhat; weak passwords fall quickly to off-the-shelf cracking rigs. And the pandemic sharpened everything. May 2020's victims were lockdown services — groceries delivered, meals kitted, children schooled online, teenagers polling one another from their bedrooms — businesses swollen with new users at precisely the moment their customers' attention, and their own, was elsewhere.

Hindsight supplies what May 2020 lacked: an ending, and a mechanism. US prosecutors later described the machinery behind the shopfront — phishing emails steering company employees to counterfeit login pages — and counted more than 60 firms robbed under the ShinyHunters name between April 2020 and July 2021, with losses put above $6 million. It took two years for a name to be attached: in 2022 Moroccan police detained Sébastien Raoult, a French IT student in his early twenties, at Rabat airport; extradited to Seattle, he pleaded guilty and in January 2024 received three years in prison and an order to repay more than $5 million. Two co-accused stayed beyond American reach. May 2020 was the supermarket's opening month. It would not be the closing one.

Also that month · From $21m to $42m

REvil calls on Lady Gaga's lawyers

The REvil ransomware crew spent mid-May squeezing Grubman Shire Meiselas & Sacks, the New York entertainment law firm whose client roster runs from Lady Gaga to Bruce Springsteen. The gang claimed to hold 756 gigabytes of contracts, non-disclosure agreements and private correspondence, and reportedly demanded $21 million. When the firm did not pay, REvil released about 2.4 gigabytes of Lady Gaga's legal files and doubled the price to $42 million, claiming — without producing evidence — that it now held damaging material on Donald Trump, who had never been a client of the firm. The firm refused outright, calling the leak "a despicable and illegal attack by these foreign cyberterrorists" and saying the FBI had advised that paying such ransoms violates federal law; REvil answered by scheduling an auction of Madonna's files for 25 May, opening bid $1 million. Six years on: no buyer ever publicly surfaced, no Trump material ever appeared, the firm carried on with its clients' business — and REvil itself was dismantled within two years, its sites seized and alleged members arrested in Russia in January 2022.

Also that month · Stolen SSH keys, borrowed horsepower

The pandemic's supercomputers were moonlighting

On 11 May the University of Edinburgh pulled ARCHER, the UK's national academic supercomputer, offline after what it called a security exploitation of its login nodes. The same day, Germany's bwHPC consortium took five of its Baden-Württemberg clusters offline over security incidents; within the week further machines in Munich, Jülich and Dresden were disconnected, and by 16 May Switzerland's national centre CSCS had shut off external access too. The embarrassment was in the timing — several of the machines were carrying pandemic workloads, ARCHER's users among them — and in the motive, once incident responders found it. Analysis coordinated through the European Grid Infrastructure's security team, with contributions from Cado Security, described attackers hopping between systems on stolen SSH credentials, including accounts at universities in Canada, China and Poland, then planting Monero cryptocurrency miners. Machines built to model a disease had been repurposed as pocket change. ARCHER came back with every password and SSH key reset. No attribution was ever published, and six years later nobody has been charged; it remains one of the strangest unsolved episodes in these pages.

India desk · May 2020

Unacademy: 22 million learners on the shelf

India's entry in the ShinyHunters ledger was Unacademy, the Bengaluru education platform that lockdown had turned into one of the country's fastest-growing businesses. On 3 May 2020, researchers at the threat-intelligence firm Cyble found the company's user database on sale — advertised at 20 million accounts for $2,000, and holding, on inspection, 21,909,707 records: usernames, email addresses, hashed passwords, join dates, last logins, and flags marking which accounts belonged to staff. The freshest account in the dump dated from 26 January 2020, which suggested the intrusion itself had happened months before the sale — a distinction between attack and disclosure this archive keeps insisting on. Reports followed within days, landing in the middle of India's edtech spring, with schools shut since late March and millions of students newly online.

Unacademy's co-founder and chief technology officer, Hemesh Singh, confirmed a compromise but contested its size: the company said basic information relating to about 11 million learners had been exposed — half the seller's figure — with passwords protected by strong hashing and no financial data touched. This edition carries both numbers, because both are claims. What no one disputed was the absence of any duty to tell. In May 2020 no Indian law obliged a platform to inform its users of a breach: the six-hour CERT-In reporting rule was two years away, the Digital Personal Data Protection Act three, and nothing then in force required ringing 22 million households. The market shrugged — by September investors had valued Unacademy above a billion dollars — and the dump aged into the standing inventory of leaked Indian data that later editions of this archive keep meeting.

AI Tech desk · May 2020

GPT-3 lands quietly on arXiv

The month's most consequential release wore the plainest packaging: on 28 May 2020 OpenAI posted "Language Models are Few-Shot Learners" to arXiv — the GPT-3 paper, describing a 175-billion-parameter model, ten times the size of the largest language model then public, able to attempt translation, arithmetic or trivia from a few examples typed into its prompt, with no retraining. The hardware had been announced nine days earlier: at its Build conference on 19 May, Microsoft unveiled an Azure supercomputer assembled exclusively for OpenAI — more than 285,000 processor cores, some ten thousand graphics chips — which it reckoned among the five fastest machines then publicly disclosed. Nvidia had already set the tone on 14 May, when Jensen Huang, delivering his keynote from his own kitchen, pulled the server board of the new Ampere-generation A100 out of the oven. Six years on the lineage is plain: the A100 became the workhorse the models trained on, the paper's descendants became ChatGPT, and the partnership grew into the decade's defining commercial alliance.

Digital Guard desk · May 2020

The Snake was already loose

A month before it reached Honda's assembly lines, the Snake was already loose. In early May the operators of Snake ransomware — EKANS, in the reversed spelling many researchers used — mounted a wave of intrusions, and Fresenius, Europe's largest private hospital operator, confirmed that a computer virus had limited parts of its operations worldwide, insisting patient care continued. What earned the strain the industry's attention was its target list: analysts who took the code apart, Fortinet's among them, found it shutting down processes belonging to industrial control software before encrypting — ransomware written with factory floors in mind — and its operators now claimed to steal files before locking them. The rest of the desk's month was research: ESET described Ramsay, an espionage framework built to lift documents from air-gapped networks, found in so few victims it appeared unfinished; and on 14 May Microsoft published its trove of COVID-19-themed attack indicators for anyone to use. Snake's engagement at Honda belongs to the next edition. The specialisation outlived the strain.

⏳ Time capsule — May 2020

  • Little Richard, the rock and roll pioneer, died on 9 May, aged 87.
  • Cyclone Amphan made landfall in West Bengal on 20 May — the Bay of Bengal's first super cyclonic storm since 1999 — battering Kolkata and coastal Bangladesh.
  • George Floyd was murdered by a Minneapolis police officer on 25 May; within days, protests had spread across the United States and far beyond.
  • SpaceX's Crew Dragon Demo-2 lifted off from Florida on 30 May carrying astronauts Doug Hurley and Bob Behnken — the first crewed orbital launch from American soil since 2011.
Where it stands today — 2026

The supermarket stayed open

May 2020 is where the archive's supply side comes into focus. The ransomware economy of later years — the leak sites, the auctions, the pressure campaigns this archive traces through Colonial Pipeline, MOVEit and beyond — gets the headlines; ShinyHunters' month showed the quieter machinery underneath, where identity itself is warehoused and discounted. The REvil affair at Grubman Shire showed extortion pivoting from paralysis to publication — the leverage was not locked servers but famous names' private files, a model that had conquered the field by the time this archive reaches 2026. The supercomputer intrusions previewed a decade of stolen-credential attacks. And Unacademy opened the India desk's longest thread: enormous exposure, disputed numbers, and no law yet written to govern either.

The name is the epilogue. Sébastien Raoult went to prison; the ShinyHunters brand did not retire with him. It resurfaces in these pages giving away BigBasket's customers in April 2021, and again in 2025 and into 2026, attached to extortion campaigns against the customers of cloud platforms — a criminal marque entering its seventh year of trading. The Vault continues backwards from here, restoring the pandemic's first year month by month. Read forward, the archive keeps confirming what May 2020 first put a price on: that the cheapest commodity on the criminal market is a person.