Don’t do SECURITY. Do business SECURELY.

WannaCry ransomware spreads worldwide and disrupts the NHS

The WannaCry ransomware worm infected computers in around 150 countries and caused widespread disruption across the NHS.

The WannaCry ransomware spread rapidly around the world, encrypting files on computers running unpatched versions of Windows. In the UK it disrupted parts of the NHS, forcing hospitals to cancel appointments and divert ambulances.

What happened

  • WannaCry used EternalBlue, an exploit for a Windows flaw that Microsoft had patched two months earlier and that had been leaked by the Shadow Brokers group.
  • Europol said more than 200,000 victims in around 150 countries were affected.
  • The National Audit Office found at least 81 NHS trusts were affected and around 19,000 appointments were cancelled.
  • Security researcher Marcus Hutchins slowed the outbreak by registering a domain that acted as a kill switch, and the UK and US governments later attributed the attack to North Korea.

Why it mattered

WannaCry was a wake-up call about the cost of unpatched and unsupported systems, particularly in healthcare, and it led to major investment in NHS cyber security.

Lessons for organisations

Apply critical security updates promptly, replace unsupported software, segment networks, and keep offline backups. These are core requirements of Cyber Essentials and ISO/IEC 27001.

Source: National Audit Office

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights