A Cyberweapon Escaped the NSA. Weeks Later, It Shut Down England's Hospitals.
The tool that made WannaCry spread was not built by criminals. It was built by a government that decided a flaw in nearly every Windows computer on Earth was worth keeping rather than fixing — and the
On the morning of May 12, 2017, the screens inside hospitals across England turned red. The message was identical on every one: your files have been encrypted, send $300 in Bitcoin, with a countdown clock ticking toward the moment the price doubled and then toward the moment the files were deleted for good. Staff taped handwritten signs to dead monitors and locked doors: *our computer systems are down.* Ambulances were waved off to other hospitals. Appointments stopped. Within hours, more than 200,000 machines in at least 150 countries were showing that same red screen.
The strange part was how it travelled. Nobody at those 200,000 machines had clicked anything. The malware moved on its own, jumping from computer to computer. And by that same evening it was stopped — not by a government or a security company, but by one researcher who spent about ten dollars registering a domain name. To understand how a web address halted a global attack, and why hospitals were in its path to begin with, you have to start with a decision made inside an American intelligence agency.
The ransomware was called WannaCry, and ransomware itself was old news by 2017 — malicious software that encrypts your files and demands payment for the key. The usual version arrives the usual way: someone opens a bad email attachment, and one organization’s files lock up. WannaCry broke from that in one decisive respect. It was a worm.
Most malware needs a person to make a mistake — click the link, open the file, run the program. A worm needs nothing. Once it infects one machine, it scans the network for other vulnerable machines and takes them automatically. It is the difference between a burglar, who needs someone to open a door, and a fire, which jumps from building to building on its own. A burglar robs one house at a time. A fire can take a city.
WannaCry took the NHS in hours. A third of England’s hospital trusts were hit. Five accident-and-emergency departments diverted patients elsewhere. Some 1,220 pieces of diagnostic equipment — MRI scanners, pathology systems, blood refrigerators — went dark. More than 19,000 appointments and operations were cancelled. No deaths were recorded, but the UK government’s own assessment was blunt: lives were put at risk. The worm did not discriminate by sector or border. Telefónica in Spain, Renault in France, Nissan in England — it went wherever an unpatched machine was listening.
Every Windows computer has a built-in way to share files and printers across a network — a decades-old protocol called Server Message Block, or SMB. Picture a mail slot cut into every office door: drop a document through one office’s slot and it lands in the next. SMB is always listening, the way a mail slot stays open even when nobody expects a delivery.
In 2017 there was a flaw in the slot — catalogued as CVE-2017-0144 — that let an attacker push a specially crafted message through it and run code on the machine at the other end. No username, no password, no permission of any kind. The slot was no longer just accepting documents. It was accepting instructions.
The tool that exploited that flaw was called EternalBlue, and it was not built by criminals. It was built by the United States National Security Agency. Like every major intelligence service, the NSA develops ways to break into software for surveillance work, and EternalBlue was one: a method to silently enter any unpatched Windows machine over a network.
When an intelligence agency finds a flaw in software the whole world runs, it faces a fork. It can tell the vendor, so the hole gets patched and every civilian machine is protected. Or it can keep the flaw secret and build a weapon from it, leaving those machines exposed for as long as the secret holds. EternalBlue was the second choice: the NSA found a flaw in a protocol running on virtually every Windows computer on Earth and chose to keep it. That is a defensible decision from an intelligence standpoint. It also staked the security of millions of civilian machines on a single assumption — that the weapon would never leave the building.
On April 14, 2017, the assumption failed. A group calling itself the Shadow Brokers dumped a collection of stolen NSA tools onto the open internet. EternalBlue was in it — and so was DoublePulsar, a kernel-level implant that installs itself beneath the floor the security guards patrol, in the operating-system layer most security software never inspects. Overnight, a classified capability became free attack infrastructure for anyone who could download it.
Someone did. WannaCry’s earlier versions, seen in small attacks that spring, had spread the old way, with stolen passwords. The version that detonated on May 12 had EternalBlue welded into it, so it needed neither a password nor a person — it opened the door itself. Once on a machine it encrypted the files and began scanning the local network and the open internet for any computer with port 445, the door reserved for SMB traffic, left open. Where it found an unpatched one, EternalBlue forced the door and DoublePulsar carried the ransomware through; that machine encrypted itself, raised its own red screen, and started scanning for the next. Each victim became a launch point, the spread compounding until by nightfall it had reached more than 150 countries.
Microsoft had already fixed the flaw. On March 14, 2017 — two months before the outbreak, a full month before the Shadow Brokers even leaked the exploit — it published security bulletin MS17-010, closing CVE-2017-0144 and several related holes. The fix was free. NHS Digital, responsible for cybersecurity guidance across the health service, sent trusts critical alerts in March and April urging them to install it. The warnings ran back further still: leave Windows XP, the government had told trusts as far back as 2014, since Microsoft no longer issued security updates for it — deadline April 2015.
On May 12, the machines that had not applied the free patch were the machines that turned red. The ones that had were untouched.
Buried in WannaCry’s code was one odd instruction. Before encrypting anything, the malware tried to reach a specific, gibberish web address that pointed to no website. If the address answered, the malware switched itself off. If it did not, it proceeded. On the evening of May 12, a security researcher, picking through the code, saw that dead domain and registered it for $10.69. The instant it went live and began answering, every fresh copy of WannaCry that phoned home received a reply — and obeyed its own instruction to stop.
The check was almost certainly a defense against analysis. Researchers study malware by detonating it in a sandbox — a sealed environment that often fakes internet connectivity by answering every domain lookup. WannaCry’s authors appear to have built the dead domain as a tripwire: a nonexistent address that answered meant the software was being watched, so it shut down to hide. The logic held only as long as the domain stayed unregistered — and its authors assumed it always would.
The kill switch saved no one already infected — those files stayed locked — but new infections dropped to almost nothing. The firm that ran the domain as a sinkhole later estimated it absorbed 14 to 16 million further infection attempts over the next two weeks. By May 17, most NHS services were back, and Microsoft had shipped emergency patches for Windows XP and other operating systems it had officially stopped supporting years earlier.
The question of authorship took longer. In December 2017, the United States publicly attributed WannaCry to the Lazarus Group, an arm of North Korea’s Reconnaissance General Bureau, with the United Kingdom, Australia, Canada, Japan, and New Zealand concurring. The case rested on the code itself. A Google researcher, Neel Mehta, had spotted that a distinctive slice of WannaCry was identical to code in the malware that destroyed Sony Pictures’ network in 2014 — an attack long attributed to the same group. Shared cipher routines, shared data tables, shared file-deletion functions: the fingerprints matched, and reached back to Sony and forward to the 2016 theft of eighty-one million dollars from Bangladesh’s central bank.
That lineage explains the motive. Most states that run offensive cyber operations — the US, Russia, China, Israel — do it for intelligence, and avoid visibly wrecking civilian systems, because wreckage becomes a diplomatic crisis. North Korea, walled off by sanctions, uses its hackers to raise money instead: bank theft, cryptocurrency fraud, ransomware. WannaCry fit the pattern — not espionage, but a revenue operation aimed at civilians, and a dismal one at that. For all the hospitals it froze, it collected roughly $140,000 in ransom, and the NHS paid none of it. The Justice Department later charged three North Korean operatives and the Treasury sanctioned one of them; a money launderer for the group drew an eleven-year sentence. The principal defendants remain in North Korea, beyond reach.
WannaCry is what happens where two decisions to leave a known danger in place meet. The first was made in an intelligence agency that found a flaw in software the whole world runs and chose to keep it rather than fix it, betting the weapon it built would never escape. The second was made, thousands of times over, in every organization that received a free patch and a written warning and did not act on them. The first decision created the weapon. The second decided where it landed. Neither was exotic; both were the ordinary result of treating a known risk as tomorrow’s problem.
The controls that would have contained it were all on the record before May 12: patch promptly, retire operating systems too old to patch, close port 445 at the network boundary, and wall critical medical devices off from ordinary office PCs. Britain rewrote its NHS cyber playbook afterward. But the lesson underneath was never a missing control. WannaCry did not exploit a secret. It exploited the distance between a fix that already existed and the machines that never received it. That distance was measured in months for some organizations and in years for others, and a weapon built in secret found every place it was widest. A great many of those places turned out to be hospitals.
## Sources & further reading
- **UK National Audit Office** — *Investigation: WannaCry cyber attack and the NHS* (2018): the definitive account of the NHS impact, the unpatched-systems finding, and the timeline.
- **NHS England / Department of Health and Social Care** — *Lessons learned review of the WannaCry ransomware cyber attack* (February 2018): the 1,220 affected devices and the operational response.
- **UK Parliament, Public Accounts Committee** — report on the NHS and WannaCry, on patch management and legacy systems.
- **Microsoft Security Response Center** — bulletin MS17-010 (March 14, 2017) and the out-of-band *Customer Guidance for WannaCrypt attacks* (May 2017).
- **U.S. Department of Justice** — the 2018 complaint against Park Jin Hyok and the 2021 indictment of three Lazarus Group operatives, laying out the Sony–Bangladesh–WannaCry code lineage.
- **CISA / US-CERT** — technical alerts and indicators for WannaCry and North Korean cyber activity.
- **Kryptos Logic** — operator of the kill-switch sinkhole; source for the 14–16 million infection attempts absorbed.
