May 12, 2017
WannaCry ransomware spreads worldwide
The WannaCry ransomwareMalware that encrypts files and demands payment — a major threat to businesses and hospitals. attack began on May 12, 2017 — encrypting Windows systems worldwide using an NSA-leaked EternalBlue exploit and demanding BitcoinThe first decentralized cryptocurrency — a proof-of-work blockchain without a central issuer. payments.
What it was for
WannaCry hit Britain's NHS hospitals, FedEx, and hundreds of thousands of PCs in 150 countries — many still on unpatched Windows 7. Marcus Hutchins' kill-switch domain slowed the spread. It linked nation-state exploit hoarding to criminal ransomwareMalware that encrypts files and demands payment — a major threat to businesses and hospitals. and made MS17-010 patching an emergency global priority.
Why it's here
WannaCry was the first ransomwareMalware that encrypts files and demands payment — a major threat to businesses and hospitals. wormSelf-replicating malware that spreads across networks without needing a host file. to paralyze national healthcare systems.
Why it mattered
It proved leaked government exploits could fuel criminal campaigns at planetary scale.
What it solved
Nothing until patched — unpatched SMBv1 systems were encryptable without user interaction.
Media
- ImageWannaCry ransomware attack
This SVG version is by TheAwesomeHwyh, original PNG version by User:Roke, CC BY-SA 3.0, via Wikimedia Commons
Related
- PC Cyborg AIDS Trojan — first known ransomwareDecember 1989
- NotPetya destructive malware hits global firmsJune 27, 2017
- Colonial Pipeline shut down by ransomwareMay 7, 2021