The listing went up on Breach Forums on 30 June 2022 and was being reported around the world by 4 July. A seller using the handle ChinaDan offered what they described as twenty-three terabytes taken from the Shanghai National Police database — names, addresses, birthplaces, resident identity card numbers, mobile numbers, photographs and police case records — covering, they claimed, one billion Chinese residents. The asking price was ten bitcoin, roughly $200,000 at the exchange rate of the week. Attached to the post was a sample of about 750,000 records, which was the only part of the claim anyone outside China could actually test, and the part that made the rest of it credible.

The verification is worth being precise about, because the headline number never was. Journalists including the Wall Street Journal's Karen Hao and Rachel Cheung of VICE World News took phone numbers out of the sample and rang them; the people who answered confirmed that the names, identity numbers and addresses recorded against them were correct. That establishes that the sample was genuine police data, and it establishes nothing else. No independent party ever counted a billion records, no full copy was ever examined outside the forum, and no buyer was ever confirmed. This archive reports the scale as the seller's claim — corroborated at the edges, never at the centre — and the phrase "largest ever" as a description of that claim.

What the seller appears to have done, on the available evidence, was not break in. Researchers at LeakIX traced the exposure to an unprotected Kibana dashboard on port 5601 sitting in front of an Elasticsearch cluster running version 5.5.3, a release with no authentication of its own, hosted on an Alibaba Cloud endpoint and reachable from the open internet since roughly the end of 2020. Security Discovery had recorded the cluster in April 2022. In mid-June someone reached it, destroyed data and left a ransom note, which is the ordinary fate of an open Elasticsearch instance. Binance's chief executive suggested credentials had been published in a developer's blog post on the Chinese platform CSDN; other researchers disputed that explanation. LeakIX recorded Alibaba making private or shutting down the exposed 5.5.3 Kibana servers on 1 July.

Then nothing happened. Weibo censored discussion of the leak inside China; the administrators of Breach Forums pulled the listing on 8 July and asked their sudden influx of Chinese users to stop posting in Chinese characters. Bloomberg's questions to the Cyberspace Administration of China and to the Shanghai police went unanswered. Four years later no Chinese authority has acknowledged the breach, which means that not one of the people whose identity card number sat in that index has ever been formally told. The only institution able to confirm or deny the largest data claim ever made has never said a word about it.

Also that month · A country's front desk

Albania switched off its own state

On 15 July 2022 Albania's National Agency for Information Society took the e-Albania portal and a string of government websites offline, describing a synchronised and sophisticated attack originating outside the country. The timing mattered locally in a way the outage figures do not capture: on 1 May the government had closed most in-person administrative counters and moved the great majority of public services onto the portal, so switching it off removed the state's front desk rather than its website. A group calling itself HomeLand Justice claimed the operation. A joint CISA and FBI advisory published on 21 September 2022 attributed it to Iranian state actors and laid out a timeline worse than the disruption suggested — initial access roughly fourteen months earlier through an internet-facing SharePoint server, CVE-2019-0604, then lateral movement and credential harvesting through May and June 2022, then a file encryptor and a version of the ZeroCleare wiper, with anti-Mujahideen-e-Khalq messages left on desktops. On 7 September Prime Minister Edi Rama severed diplomatic relations with Iran and gave its embassy staff twenty-four hours to go, the first known case of a country breaking off relations over a cyberattack. Iran denied involvement.

Also that month · Who answers for a breach

Uber admits the cover-up

On 22 July 2022 the US Attorney's Office for the Northern District of California announced a non-prosecution agreement with Uber, under which the company accepted responsibility for concealing the November 2016 breach in which attackers copied records on approximately 57 million users along with about 600,000 driver's licence numbers. The admitted facts are the uncomfortable part. Uber personnel did not report the breach to the Federal Trade Commission while the FTC had an open investigation into the company's data security, and the six-figure payment made to the two men who took the data was routed through Uber's bug bounty programme in exchange for non-disclosure agreements. Prosecutors credited the change of leadership in late 2017 and the new team's decision to investigate and disclose. The agreement was tied to the separate prosecution of Joe Sullivan, Uber's chief security officer at the time, who went to trial that September, was convicted on 5 October 2022 of obstruction of proceedings and misprision of a felony, and was sentenced in May 2023 to three years' probation. The company was not charged. The security executive was.

India desk · July 2022

A booking site, a deadline, and no law

Cleartrip, the travel booking company owned by Flipkart, emailed customers on 18 July 2022 to tell them of what it called "a security anomaly that entailed illegal and unauthorised access" to part of its internal systems. The company did not itemise what had been taken: aside from "some details which are a part of your profile", it said, no sensitive information pertaining to the account had been compromised, and it asked customers to reset their passwords as a precaution. The disclosure followed screenshots circulated by the security researcher Sunny Nehra showing company files listed for sale on a private forum, some timestamped as recently as June. Cleartrip did not dispute that an intrusion had occurred and said it had brought in a leading external forensics partner, but it did not say it had notified CERT-In — Nehra reported the incident to the agency himself — and it declined to say when the intrusion began or how many customers were involved, which is why 18 July, the disclosure date, is the only firm date here.

The regulatory backdrop was heavier than the incident. CERT-In's directions of 28 April 2022 had taken effect on 27 June, introducing a six-hour deadline for reporting listed incidents, 180 days of logs held within India, and five-year retention of subscriber records by data centres, cloud providers and VPN services. On the day they came into force CERT-In pushed the compliance date to 25 September for micro, small and medium enterprises and for those service providers. Several consumer VPN companies did not wait: ExpressVPN, Surfshark and NordVPN each withdrew their physical Indian servers by late June, offering Indian addresses from machines hosted abroad instead. July 2022 therefore opened with India's first hard breach-reporting clock running, part of the privacy industry gone, and no data protection statute at all — the Personal Data Protection Bill of 2019 was withdrawn from Parliament on 3 August, sixteen days after Cleartrip's email.

AI Tech desk · July 2022

The month the image generators arrived

Two image generators reached the public eight days apart. Midjourney, run through a Discord server, entered open beta on 12 July 2022; on 20 July OpenAI moved DALL·E 2 into a paid beta, inviting one million people from its waitlist and pricing the output in credits — fifty free the first month, fifteen a month thereafter, $15 for 115 more — an early sketch of what a market for generated images would look like. Within weeks a Midjourney render had taken first prize in the Colorado State Fair's digital-art category, and the argument it started has not ended. The month's quieter releases wore better. BLOOM, a 176-billion-parameter multilingual model built in the open by the BigScience collaboration, arrived the same day as Midjourney's beta — the largest open multilingual model of its day, and an ancestor of today's open-weights lineage. And on 28 July DeepMind and EMBL's European Bioinformatics Institute expanded the AlphaFold database to over 200 million predicted structures — nearly every catalogued protein known to science, and the work that won Demis Hassabis and John Jumper the 2024 Nobel Prize in Chemistry.

Digital Guard desk · July 2022

Macros blocked, unblocked, blocked again

The month's most consequential endpoint decision was a reversal of a reversal. In February 2022 Microsoft had said Office would block VBA macros in files downloaded from the internet by default, a change the security industry had wanted for years — macros having carried malware since the nineties. In early July the company quietly paused the rollout, citing user feedback; after two weeks of criticism it reinstated the block, rolling out again from 27 July. It stuck, and attackers spent the next year migrating to shortcut files, ISO archives and OneNote attachments instead. The industry news was reorganisation and consolidation. Sophos announced X-Ops on 20 July, folding SophosLabs, Sophos SecOps and Sophos AI into a single cross-domain unit — the byline its research has carried since, including the 2024 Pacific Rim account of a years-long contest with Chinese intruders on its own firewalls. And in mid-July the US Justice Department closed its antitrust review of Google's $5.4 billion purchase of Mandiant, clearing a September completion and, in time, a place at the centre of Google's security business.

⏳ Time capsule — July 2022

  • Shinzo Abe, Japan's longest-serving prime minister, was shot and killed on 8 July while delivering a campaign speech outside a station in Nara.
  • Protesters occupied Sri Lanka's President's House in Colombo on 9 July; Gotabaya Rajapaksa left the country and his resignation took effect on 14 July.
  • The first full-colour image from the James Webb Space Telescope was released on 11 July, with the rest of the opening set following the next day.
  • Britain passed 40°C for the first time on 19 July, with 40.3°C recorded at Coningsby in Lincolnshire.
Where it stands today — 2026

The breach nobody admitted

Shanghai is the clearest early example of a pattern this archive keeps returning to: the largest exposures are rarely break-ins. A dashboard with no password, in front of a database with no authentication, produced on the seller's account more personal records than any intrusion in history, and the same shape recurs in June 2025's sixteen-billion-credential compilation, where the frightening number turned out to be an aggregation of material already lying open. What makes July 2022 different is the ending. Most breaches in these pages eventually produce a regulator, a fine, a hearing or at minimum a notification letter. This one produced silence, and silence is not a remedy.

The two briefs went the other way. Albania's July outage ended with a NATO member expelling another state's diplomats over a cyberattack, and with an advisory showing the intruders had been inside for more than a year — the template for the state-against-civilian-infrastructure stories that fill this archive from the 2024 telecom intrusions onward. Uber's agreement ended with a chief security officer convicted, which changed how incident response is written down everywhere: every disclosure decision since has been taken by people who know what happened to Joe Sullivan. Three institutions faced the same question in July 2022 — what do we say, and to whom. Only two of them were ever made to answer it.