JBS detected an intrusion in its computer networks on Sunday 30 May 2021 and disclosed it the following day, saying servers supporting its North American and Australian IT systems had been affected. The physical consequences arrived with the working week. Shifts were cancelled at the company's Australian plants on the Monday; its Canadian beef plant at Brooks, Alberta followed; and by Tuesday 1 June all nine of its US beef plants had stopped slaughtering — the five biggest of them alone handling 22,500 cattle a day, by contemporary estimates roughly a fifth of American beef processing capacity. Nothing had been done to a cow, a hook or a blade. The kill floors stood idle because the systems that schedule, weigh, track and pay had been taken away.

Attribution arrived faster than the industry was used to, because the White House went first. On 1 June, principal deputy press secretary Karine Jean-Pierre told reporters aboard Air Force One that JBS had informed the administration of a ransom demand from a criminal organisation likely based in Russia, and that Washington was taking the matter up with Moscow directly. The FBI put a name to it the next day: REvil, also tracked as Sodinokibi, a ransomware-as-a-service operation then at the peak of its franchise. The company, meanwhile, recovered at speed. Its backup servers had not been touched, and by Wednesday 2 June JBS said the vast majority of its plants were operational — a resilience story, right up until the next announcement.

That announcement came on 9 June. JBS USA confirmed it had paid the equivalent of $11 million to the attackers — in bitcoin, its chief executive told the Wall Street Journal — and it was candid about the strangest part: the payment was made when most of its facilities were already running again. The company said it paid to mitigate any unforeseen issues and to ensure no data was exfiltrated, having found no evidence that company, customer or employee data had been compromised. "This was a very difficult decision to make for our company and for me personally," said Andre Nogueira, chief executive of JBS USA. Reporting at the time put the gang's opening demand at $22.5 million; the sum actually paid still ranked among the largest any company had publicly confirmed.

Three weeks earlier it had been fuel; now it was food. Twice in one American spring, ransomware had reached out of a corporate network and into the physical supply of something ordinary, and twice the resolution had involved millions of dollars moving to criminals. JBS could argue, reasonably, that it paid from a position of strength — plants running, backups intact — as insurance rather than surrender. But the season's lesson was already set: the category of critical infrastructure had quietly expanded to include dinner, and the company that processed a fifth of it had put the price of certainty at eleven million dollars.

Also that month · Following the money

The FBI had the key to the wallet

Two days before JBS confirmed what it had paid, the US Justice Department showed for the first time at scale that such payments could come back. On 7 June it announced the seizure of 63.7 of the 75 bitcoin Colonial Pipeline had paid the DarkSide gang in May — worth about $2.3 million on the day of seizure. The mechanism was simple to describe and has never been fully explained: investigators traced the coins across the public blockchain to a single address, and the FBI, the supporting affidavit said, possessed the private key for it. A federal court in San Francisco issued the warrant, and the department's new Ransomware and Digital Extortion Task Force executed its first clawback. The dollar figure carried its own irony — bitcoin's price had fallen by more than a third since the ransom was paid, so the recovered coins were worth less than the share of the ransom they represented. The demonstration mattered more than the sum: the money trail, it turned out, ran both ways.

Also that month · Initial access, $10

EA and the ten-dollar cookie

Electronic Arts confirmed on 10 June that intruders had taken game source code and internal tools — around 780 gigabytes, including the code behind FIFA 21 and the company's Frostbite engine — after the haul was advertised on a criminal forum. The how mattered more than the what, and it came from the attackers themselves, who described it to Vice's Motherboard: they said they had bought a stolen Slack session cookie, listed on the Genesis marketplace, for $10, used it to slip into an EA Slack workspace, then messaged IT support claiming to have lost a phone at a party and asked for a multi-factor authentication token. Support obliged. EA said no player data was accessed and that it expected no impact on its games or its business. The attackers' reported asking price of $28 million found no takers, and the following month, the extortion attempt having failed, the files were simply dumped online. By the intruders' own accounting, the whole thing had begun with the price of a sandwich.

India desk · June 2021

The CoWIN "leak" that wasn't

In June 2021 every adult in India had a reason to be on CoWIN, the government portal through which the country's Covid-19 vaccinations were booked, and every reason to fear for what it held: the Delta-driven second wave had only just receded, and a name, mobile number and identity document sat behind every appointment. So when a site calling itself Dark Leak Market claimed around 10 June to be selling the records of 150 million vaccinated Indians — names, mobile numbers, Aadhaar numbers, locations — for about $800 in bitcoin, the claim travelled fast. The Health Ministry responded the same day, saying the reports appeared on their face to be fake, that CoWIN's data sat in a secure digital environment, and that CERT-In, the national incident response agency, had been asked to investigate.

The debunking was quick and instructive. Researchers, among them Rajshekhar Rajaharia, showed that the seller's site was a serial fabricator — it had previously advertised dumps from Indian organisations that were never breached — and that its listing offered a field CoWIN does not collect: the geo-location of the vaccinated. The frightening sample was not evidence of a breach but bait, and the only thing being harvested was bitcoin from whoever paid. No evidence of a CoWIN breach emerged then or later. The episode became a small classic of breach-claim hygiene — check what a system actually stores before believing what a seller says it stole — and a rehearsal for June 2023, when a Telegram bot serving genuine-looking vaccination details would put the same portal through the question again, a story told in this archive's June 2023 edition.

AI Tech desk · June 2021

Copilot moves into the code editor

GitHub spent the last day of the month redefining the text editor. On 29 June 2021 it opened a technical preview of Copilot, an "AI pair programmer" built with OpenAI on a new model called Codex, which drafted whole functions from a comment or a half-typed line inside Visual Studio Code. The preview was free and gated by a waitlist, a year ahead of the ten-dollar-a-month general release this archive records at its June 2022 desk; five years on, the assistant it introduced is simply how a great deal of the world's code gets written, licensing arguments and all. Scale supplied the month's other story. The Beijing Academy of Artificial Intelligence unveiled Wu Dao 2.0 at its annual conference in the first days of June, claiming 1.75 trillion parameters — a mixture-of-experts total that dwarfed GPT-3 on paper and is barely remembered now. More durable was the smallest release: EleutherAI's GPT-J, six billion parameters under an open licence from 9 June, an early ancestor of the open-weights movement that later reshaped the field.

Digital Guard desk · June 2021

SentinelOne takes endpoint to Wall Street

The industry's month ended on the floor of the New York Stock Exchange. On 30 June 2021 SentinelOne, the Mountain View endpoint firm that sold machine-learning detection as the successor to signatures, listed under the ticker S, pricing 35 million shares at $35 to raise roughly $1.2 billion — the largest cybersecurity flotation to date, valued near $9 billion at the offer price and about $10 billion by the first close. Endpoint protection, a category antivirus built, was now a stock-market star; the shares' later travels were rougher, but the listing fixed the sector's place alongside CrowdStrike in public-market shorthand. The stranger announcement had come at the month's start: on 1 June NortonLifeLock said Norton 360 would gain "Norton Crypto", an opt-in Ethereum miner offered as a safer alternative to the tools its own scanners routinely flagged. The raised eyebrows arrived at once; the fuller reckoning waited for January 2022, and is told in that month's edition of this archive.

⏳ Time capsule — June 2021

  • Euro 2020, postponed a year and keeping its name, kicked off in Rome on 11 June; the next evening Denmark's Christian Eriksen suffered a cardiac arrest on the pitch and was resuscitated in front of a live television audience.
  • El Salvador's legislature voted in the early hours of 9 June to make bitcoin legal tender, the first country to do so.
  • Microsoft announced Windows 11 on 24 June — the first new version of Windows in six years, released that October.
  • John McAfee, founder of the antivirus company that carried his name, died in a Spanish prison on 23 June, hours after a court approved his extradition to the United States on tax charges.
Where it stands today — 2026

The month the money moved both ways

June 2021 is the month ransom economics went public in both directions: $11 million out of JBS on the ninth, $2.3 million clawed back for Colonial on the seventh, and ransomware on the summit agenda when Biden met Putin in Geneva a week later, complete with a list of sixteen infrastructure sectors declared off-limits. REvil heard none of it. Three weeks after JBS paid, the same operation mounted the Kaseya supply-chain attack over the US Independence Day weekend, then vanished from the internet; in January 2022 Russia's FSB filmed itself raiding the gang's members, an arc this archive traces in its January 2022 edition. The clawback aged best of all. Tracing and seizing cryptocurrency became standard craft, run at growing scale through the Bitfinex recovery of 2022 and the LockBit takedown of February 2024.

The smaller stories aged just as legibly. EA's ten-dollar cookie was an early sighting of the infostealer economy that dominates initial access across this archive's later years — Genesis Market, the bazaar that sold such tokens, was itself seized by the FBI in April 2023 — and the help-desk persuasion that finished the job became a signature of the intrusions of 2022 and after. India's fake CoWIN leak began a long public education in reading breach claims, resumed in earnest during the real CoWIN scare of June 2023 and eventually framed in law by the DPDP Act. The Vault continues backwards from here: May 2021 — Colonial's month — is the next restoration, and the chain, as ever, does not shorten.