The first anyone outside T-Mobile heard of it was a listing. On 15 August 2021, Motherboard reported that a seller on a criminal forum was offering what he claimed were records on more than 100 million Americans, taken from T-Mobile's servers — with a sample of 30 million Social Security and driver's licence numbers priced at six bitcoin, then about $270,000. T-Mobile confirmed unauthorised access on 16 August, and put its first numbers to the damage on the 18th: 7.8 million current postpaid accounts and roughly 40 million former and prospective customers who had applied for credit, their names, dates of birth, Social Security numbers and licence details among the exposed fields. The company was learning the scale of its own breach roughly in step with everyone else.
The number then did what breach numbers do. On 20 August, T-Mobile added a further 5.3 million current accounts and 667,000 former customers to the count, taking the running total past 54 million current, former and prospective customers; the class-action settlement that followed would eventually define a class of roughly 76 million US residents. For about 850,000 prepaid customers, names, phone numbers and account PINs were exposed, and T-Mobile reset every one of those PINs. Payment card data, the company said, was not taken. The detail that lingered was the applicants: tens of millions of the exposed records described people who had merely asked about credit years earlier, some of whom had never been customers at all.
On 26 August the Wall Street Journal put a name to it: John Binns, a 21-year-old American living in Izmir, Turkey, who talked the newspaper through the intrusion and called T-Mobile's security "awful". By his own account — and it is his account, not published forensics — he found an unprotected router in July by scanning T-Mobile's internet addresses with a publicly available tool, followed it into a testing environment served from a Washington State data centre, and used stored credentials to reach more than a hundred servers. "Generating noise was one goal," he told the newspaper; he wanted attention for claims of harassment by the US government that he had already put into a lawsuit. T-Mobile declined to discuss the specifics of his story.
Chief executive Mike Sievert's open letter of 27 August apologised without qualification, conceding the company had not lived up to the expectations it set for itself, and announced long-term arrangements with Mandiant and with KPMG's cybersecurity practice to rebuild. By the count kept in contemporaneous coverage, this was at least the carrier's fifth disclosed security incident since 2018, and the sequel was already implicit in that arithmetic. In July 2022, T-Mobile agreed to a $350 million class settlement — second in size only to Equifax's among US data-breach cases — plus a commitment to spend an additional $150 million on security through 2023. It did not hold: six months after that settlement was filed, T-Mobile was back in these pages, disclosing another 37 million records lost through an API.
Mr. White Hat gives it back
The largest cryptocurrency theft yet recorded lasted a fortnight. On 10 August, an attacker exploited a logic flaw in Poly Network's cross-chain bridge — its manager contract could be instructed to change the keeper key that authorised transfers — and drained roughly $611 million in tokens across Ethereum, Binance Smart Chain and Polygon. Tether froze $33 million of it within hours. Poly Network's response was an open letter addressed to the thief; the thief's was a question-and-answer session embedded in transaction data, explaining the exploit had been done "for fun". Returns began on 11 August and reached about $340 million by the 13th, with the remainder parked in a wallet controlled jointly with Poly Network until 23 August, when the attacker handed over the private key to the final $141 million; the frozen Tether followed separately once released. Poly Network took to calling its adversary Mr. White Hat, transferred a $500,000 bounty and offered the post of chief security adviser. Whether this was ethics or arithmetic — every stolen token traceable, flagged by exchanges, nearly impossible to launder — was argued then and is argued still.
The bugs had been patched since spring
On 5 August, DEVCORE researcher Orange Tsai walked a Black Hat audience through ProxyShell, a chain of three Microsoft Exchange vulnerabilities that together allowed unauthenticated code execution through port 443 — the sequel to the ProxyLogon flaws that fill this archive's March edition. Microsoft had patched all three in its April and May updates, months before most administrators understood what those fixes prevented. Within days of the talk, researchers including Kevin Beaumont reported mass scanning and live exploitation against honeypots, and by the third week of August the incident-response firm Huntress had counted more than 140 distinct webshells across roughly 1,900 compromised Exchange servers. CISA issued an urgent warning on Saturday 21 August. A new ransomware family, LockFile, chained ProxyShell with the PetitPotam NTLM-relay technique to take over entire Windows domains, hitting organisations in the United States and Asia. The lesson of March had not survived to August: the servers were patched eventually, but the shells were already inside.
BlackMatter names Pine Labs
The ransomware listing that mattered most to Indian banking that month appeared in the second week of August, when BlackMatter — the group newly assembled from the remains of DarkSide, which had shut the Colonial Pipeline in May — added Pine Labs to its leak site. Pine Labs is not a household name, but its card machines sit on shop counters across the country, carrying payments for a large share of organised retail. The gang claimed to hold roughly 100 gigabytes of company data, and threat-intelligence firm Cyble, reporting on 11 August, said the published proof set contained agreements between Pine Labs and multiple Indian banks alongside financial documents and employee details. Press accounts of how many records were involved varied between publications by an order of magnitude, which is reason enough for this archive to decline to settle on a number.
Pine Labs disputed nearly all of it. Chief technology officer Sanjeev Kumar said the company's platforms remained secure and PCI-DSS compliant, that "all customer data is safe", and that the published material appeared to be legal business contracts from 2014; the company said it was investigating whether a laptop or a server had been the source. No regulator required it to say more. In August 2021 India had no general breach-notification obligation — CERT-In's six-hour reporting mandate was eight months away, the DPDP Act two years — so the public record of the episode consists of the gang's claims, one vendor's analysis and a denial. BlackMatter itself did not see out the year, announcing a shutdown in November 2021 under law-enforcement pressure; later editions of this archive trace its lineage into ALPHV/BlackCat.
Codex arrives, and a robot dances
On 10 August, OpenAI opened a private beta for the Codex API, giving developers direct access to the model that turns plain-English instructions into working code — an improved descendant of the system behind GitHub's Copilot preview, fine-tuned on billions of lines of public source code and strongest in Python. Nine days later Tesla held its first AI Day, pitched openly as a recruiting exercise, and unveiled the D1, a 7-nanometre chip meant to power Dojo, the training computer that would digest camera footage from the company's cars. The evening's stranger announcement was the Tesla Bot, a humanoid robot represented on stage by a dancer in a spandex suit — the detail everyone remembers. Read from 2026, the ledger is uneven: Codex's descendants made conversational programming ordinary, and OpenAI revived the name for its coding agent in 2025, while the bot became Optimus and Dojo was wound up in August 2025, Musk conceding its second generation was "an evolutionary dead end".
Norton and Avast agree to combine
The month's real industry news was a merger announced on 10 August: NortonLifeLock and Avast confirmed a cash-and-stock deal valuing the Prague-based firm at between $8.1 billion and $8.6 billion, depending on the mix Avast's shareholders elected. The logic was scale: Avast brought roughly 435 million users gathered around a free product, NortonLifeLock its smaller paying base built on identity protection, and together the companies claimed more than 500 million users and some $280 million in annual cost synergies. The combined business would be dual-headquartered in Tempe and Prague and listed on Nasdaq, ending Avast's run on the London Stock Exchange; the announcement itself surprised nobody, following weeks of publicly confirmed talks. Nothing about it moved quickly: Britain's competition regulator took the deal through an in-depth review before clearing it, completion waited until 12 September 2022, and that November the merged company renamed itself Gen Digital — an arc this archive's 2022 desks follow to its close.
⏳ Time capsule — August 2021
- The Taliban entered Kabul on 15 August as the Afghan government collapsed; the United States completed its withdrawal on 30 August, ending a 20-year war.
- Lionel Messi, released by Barcelona after 21 years because the club could not afford to register him, signed for Paris Saint-Germain on 10 August.
- The pandemic-delayed Tokyo Olympics closed on 8 August, a Games held a year late and almost entirely without spectators.
- Charlie Watts, the Rolling Stones' drummer for 58 years, died on 24 August, aged 80.
The month nobody picked a lock
Nothing in this edition required breaking anything: an exposed router, bugs patched months earlier, a contract doing what it was written to do. Every thread runs forward through the archive. T-Mobile paid its $350 million, spent its promised $150 million, returned to these pages in January 2023 with 37 million records lost through an API, and settled with the FCC in 2024 for $31.5 million — half fine, half compelled security spending. John Binns was arrested in Turkey in May 2024, and that November was named alongside Connor Moucka in the American indictment over the Snowflake account thefts. Poly Network's record survived seven months, until the Ronin bridge lost more the following March; nobody gave that money back, and by Bybit in 2025 the sums had more than doubled.
The quieter stories aged just as predictably. ProxyShell settled into criminal toolkits for years, and Exchange's run of catastrophes continued through the Storm-0558 cloud-key theft of 2023. Apple's plan to scan photos on its customers' phones, announced that 5 August, was paused within a month under protest from researchers and abandoned outright by the end of 2022. And the gap the Pine Labs episode exposed — a payments company able to answer a ransomware claim with a denial and owe nobody an explanation — closed slowly, through CERT-In's six-hour rule in 2022 and the DPDP Act in 2023, both covered elsewhere in this magazine. The Vault continues backwards from here, and the doors keep turning out to have been open.