The WannaCry ransomware spread rapidly around the world, encrypting files on computers running unpatched versions of Windows. In the UK it disrupted parts of the NHS, forcing hospitals to cancel appointments and divert ambulances.
What happened
- WannaCry used EternalBlue, an exploit for a Windows flaw that Microsoft had patched two months earlier and that had been leaked by the Shadow Brokers group.
- Europol said more than 200,000 victims in around 150 countries were affected.
- The National Audit Office found at least 81 NHS trusts were affected and around 19,000 appointments were cancelled.
- Security researcher Marcus Hutchins slowed the outbreak by registering a domain that acted as a kill switch, and the UK and US governments later attributed the attack to North Korea.
Why it mattered
WannaCry was a wake-up call about the cost of unpatched and unsupported systems, particularly in healthcare, and it led to major investment in NHS cyber security.
Lessons for organisations
Apply critical security updates promptly, replace unsupported software, segment networks, and keep offline backups. These are core requirements of Cyber Essentials and ISO/IEC 27001.
Source: National Audit Office
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.