The timing was the point. On the afternoon of Friday 2 July 2021, with IT departments across the United States emptying out for the Independence Day weekend, ransomware began arriving at small businesses through the one channel built to be trusted: the update mechanism of Kaseya VSA, a remote-management product that managed service providers use to run their customers' machines. An affiliate of the REvil gang had exploited an authentication bypass in internet-facing VSA servers, and its payload travelled disguised as an agent hotfix. Kaseya took its cloud servers offline within the hour and told every on-premises customer to pull the plug, but the encryption was already running. The company put the direct toll at fewer than 60 customers; behind them stood between 800 and 1,500 downstream businesses.
What that meant became visible in Sweden on Saturday morning, when Coop — one of the country's largest grocery chains — could not open most of its roughly 800 supermarkets because the tills and self-checkout kiosks would not start. The chain's point-of-sale systems were maintained by Visma Esscom, a Kaseya customer; all but a handful of stores stood closed through the weekend, some reopened early by taking payment through Coop's Scan & Pay phone app, and full recovery took the better part of a week. The bitter footnote came from the Netherlands: researchers at the Dutch Institute for Vulnerability Disclosure had privately reported the exploited flaws to Kaseya in early April, and patches were being tested when REvil got there first.
By Monday 5 July, REvil's leak site was offering a universal decryptor for $70 million in bitcoin — the largest publicly known ransom demand to that point — alongside a claim that more than a million systems had been encrypted, a figure that came from the attackers and was supported by no published forensics. Ransom notes on individual networks asked for about $45,000 per endpoint and $5 million per MSP, according to researchers who examined them. On 9 July President Biden telephoned President Putin and pressed him to act against ransomware groups operating from Russian territory. On 11 July Kaseya shipped its patch and began restoring its cloud service. And on 13 July REvil's dark-web infrastructure simply vanished — leak site, payment portal, everything — with no one saying why.
On 21 July Kaseya obtained a universal decryptor from what it would describe only as "a trusted third party", and on 26 July it confirmed "in no uncertain terms" that it "did not pay a ransom – either directly or indirectly through a third party". Both statements were true; neither was the whole story. In September the Washington Post reported that the third party was the FBI, which had extracted the key from REvil's own servers and then held it for roughly three weeks while planning an operation against the gang — an operation overtaken by REvil's 13 July disappearance. Emsisoft, once handed the key, reportedly turned it into a working recovery tool in about ten minutes. Schools, dental practices and small-town governments had spent those weeks rebuilding from backups, or from nothing.
A list of fifty thousand numbers
On Sunday 18 July, seventeen news organisations coordinated by Forbidden Stories, with forensics by Amnesty International's Security Lab, began publishing the Pegasus Project: reporting built on a leaked list of more than 50,000 phone numbers selected as possible surveillance targets by government clients of Israel's NSO Group. The list included more than 180 journalists and the numbers of 14 heads of state and government — Emmanuel Macron among them; the Élysée said the president changed his phone and number, and Paris prosecutors opened an investigation. The forensic core was narrower and harder: of 67 phones Amnesty examined, 37 carried traces of Pegasus, 23 of them successfully infected, with the methodology peer-reviewed by Citizen Lab. NSO disputed the premise from the first day and never stopped: the 50,000 numbers were not a list of Pegasus targets, it said, the reporting rested on "uncorroborated theories", and Macron was never a target. On 21 July the company said it would no longer answer media questions about the list at all. The technical sequel — a zero-click iPhone exploit called FORCEDENTRY — belongs to this archive's September edition.
PrintNightmare outlived its patch
The Windows Print Spooler owned the month's patching calendar. On 29 June, researchers at the Chinese firm Sangfor published proof-of-concept exploit code for what they believed was CVE-2021-1675, a spooler bug patched in June; it actually demonstrated a different, unpatched flaw. The code was deleted within hours, and forked faster. Microsoft assigned the new bug CVE-2021-34527 — PrintNightmare — on 1 July and shipped emergency out-of-band fixes on 6 and 7 July, reaching back even to Windows 7. Within a day, Will Dormann of CERT/CC and Benjamin Delpy, the Mimikatz author, showed the patch could be bypassed on systems with a common Point and Print policy enabled, leaving both privilege escalation and remote code execution alive; CISA advised disabling the spooler on domain controllers outright. On 15 July Microsoft acknowledged yet another spooler vulnerability with no patch available, and in August it changed Point and Print defaults so that installing printer drivers required administrator rights. A decades-old subsystem spent the summer being fixed in public, one bypass at a time.
The list reaches Parliament
The Pegasus Project arrived in India through The Wire, which reported some 300 verified Indian numbers in the leaked records: more than 40 journalists, two serving ministers, opposition figures including Rahul Gandhi, election strategist Prashant Kishor, former election commissioner Ashok Lavasa — and Ashwini Vaishnaw, sworn in as IT minister on 7 July, eleven days before publication. Amnesty's forensics gave India one of the project's freshest findings: Kishor's phone carried active Pegasus traces across June and July 2021, including 13 July, the day he met Rahul and Priyanka Gandhi. The first names were published on the evening of 18 July, the eve of Parliament's monsoon session, and on 19 July it fell to Vaishnaw — whose own listed number dated from before his ministership — to tell the Lok Sabha the reports were an "attempt to malign Indian democracy", arguing that presence on the list did not establish surveillance. The government maintained there had been no unauthorised interception; the opposition stalled the session day after day, and West Bengal ordered its own judicial inquiry on 26 July.
The dispute moved to the Supreme Court, and hindsight belongs to it. On 27 October 2021 the court appointed an independent technical committee overseen by former Supreme Court judge R.V. Raveendran, observing that the state does not get a "free pass every time the spectre of national security is raised". The committee reported in August 2022: of 29 phones examined, five carried malware of some kind, but nothing conclusively identified as Pegasus — and the court noted that the government had not cooperated with the inquiry. The question July 2021 put on the record, of whether an Indian agency bought and used Pegasus against Indian citizens, has never received an official answer.
AlphaFold's code, then the proteome
On 15 July 2021 DeepMind published AlphaFold 2's full methods in Nature and released the source code — the system that had all but closed the single-protein prediction problem at CASP14 the previous autumn. The same day, Science carried RoseTTAFold, from Minkyung Baek in David Baker's laboratory at the University of Washington, which approached AlphaFold's accuracy on a fraction of the computing power; the field's two leading answers arrived open and side by side. A week later, on 22 July, DeepMind and EMBL's European Bioinformatics Institute launched the AlphaFold Protein Structure Database with more than 350,000 predicted structures, covering nearly the whole human proteome and twenty other organisms from yeast to mouse. It was described, without much dissent, as AI's first unambiguous gift to science. Within a year the database held some 200 million structures — this archive's July 2022 desk records it — and in 2024 Hassabis, Jumper and Baker shared the Nobel Prize in Chemistry.
Norton and Avast confirm merger talks
Consumer antivirus spent the month arranging its own consolidation. On 14 July 2021, after the Wall Street Journal reported the negotiations, Avast's board confirmed it was in advanced discussions over a possible merger with NortonLifeLock — the Prague-based maker of free antivirus used by hundreds of millions, and the American company carrying the Norton brand. Both sides stressed that no agreement existed; one arrived on 10 August, valuing Avast at upwards of eight billion dollars and producing, in time, the company now called Gen Digital — the agreement, the September 2022 close and the November 2022 rename all sit at this archive's later desks. Microsoft, meanwhile, kept buying: RiskIQ, an attack-surface specialist, on 12 July for a reported half a billion dollars, and CloudKnox Security on 21 July. And the Kaseya intrusion on this month's cover put the managed-security industry's own tooling on trial — the update channel defenders relied upon had become the attack.
⏳ Time capsule — July 2021
- Italy beat England 3-2 on penalties at Wembley on 11 July to win the pandemic-delayed Euro 2020 final.
- Richard Branson flew to the edge of space aboard Virgin Galactic's VSS Unity on 11 July; Jeff Bezos followed on Blue Origin's New Shepard nine days later, on 20 July.
- Floods across western Germany and Belgium in mid-July killed more than 220 people — Germany's deadliest natural disaster in nearly six decades.
- The postponed Tokyo Olympics opened on 23 July in a largely empty National Stadium, with spectators barred from almost every venue.
The update and the list
Kaseya became the reference case for the software supply chain as a ransomware delivery system — a pattern this archive meets again in MOVEit's mass exploitation in 2023 and the near-miss of the XZ backdoor in 2024. REvil never recovered its July standing: it resurfaced in September 2021, was forced offline again by a multinational operation in October, and in January 2022 Russia's FSB arrested more than a dozen alleged members — cooperation that ended with the invasion of Ukraine weeks later. Yaroslav Vasinskyi, the affiliate charged over the Kaseya intrusion, was arrested crossing into Poland that October — this archive's November 2021 edition records the charges — and in May 2024 a US federal court sentenced him to 13 years and seven months. Kaseya's "we did not pay" has never needed correcting.
The Pegasus Project's afterlife ran just as long. The US Commerce Department placed NSO Group on its entity list on 3 November 2021; Apple sued the company that same month; WhatsApp's older lawsuit finally went to trial in 2025, with a jury awarding damages against NSO over the 2019 hacking of about 1,400 users. India's technical committee reported in 2022, and the question underneath it remains officially unanswered. The FBI's three quiet weeks with the REvil key hardened into a policy argument that later operations answered differently: by January 2023 the bureau was handing out Hive's keys from inside the gang's own network, and in 2024 LockBit's, seized in Operation Cronos — disruption first, prosecution when possible. July 2021 keeps turning up underneath the years that followed.