Any honest account of May 2017 is mostly an account of its middle. On Friday 12 May a worm began encrypting Windows machines at a pace few working defenders had seen, and by Sunday Europol was counting more than 200,000 victims in at least 150 countries — a figure other trackers pushed towards 230,000 within days, no two tallies agreeing. In England, where the National Health Service became the outbreak's public face, the damage was measured twice: on the day, in receptionists copying patient details onto paper and ambulances diverted from five hospitals' emergency departments; and in October, when the National Audit Office counted at least 81 of 236 NHS trusts disrupted and around 19,000 appointments cancelled. This archive tells those days hour by hour in a separate restoration; this edition is for the month around them.
The chronology that mattered fitted on one calendar page. Microsoft had patched the underlying Windows file-sharing flaw in March; a group calling itself the Shadow Brokers published the NSA's exploit for it, EternalBlue, in April; the worm arrived in May, and everything afterwards was triage for that gap. On the Friday afternoon a 22-year-old researcher writing as MalwareTech registered an unregistered domain he found in the worm's code — it cost $10.69 — and new infections began aborting on contact with it. By the evening Microsoft had done something it does not do, publishing free emergency fixes for the retired Windows XP, Windows 8 and Server 2003. The feared Monday wave came smaller than predicted, in variants caught quickly, and corporate IT spent the remaining fortnight switching off SMBv1.
The argument began before the weekend ended. On 14 May Microsoft's president, Brad Smith, published a post naming the uncomfortable fact underneath the outbreak — the exploit had been developed by, and stolen from, an American intelligence agency — and asked governments to treat the attack as a "wake-up call" about stockpiling vulnerabilities rather than disclosing them to vendors. The first attribution clue arrived a day later, sideways: Neel Mehta, a Google researcher, tweeted two code fingerprints tying an early WannaCry variant to a 2015 tool from the Lazarus Group, the operation blamed for the Sony Pictures intrusion. Kaspersky called it the most significant clue yet to the worm's origins; by 22 May Symantec judged a Lazarus link "highly likely"; sceptics answered that code can be copied to mislead. North Korea's deputy ambassador to the United Nations called the connection "ridiculous".
The ending took sixteen months. On 19 December 2017 Thomas Bossert, the White House homeland security adviser, attributed WannaCry to North Korea from the press-room podium, the United Kingdom, Canada, Australia, New Zealand and Japan concurring within the day. In September 2018 the US Justice Department unsealed a 179-page criminal complaint against Park Jin Hyok, a programmer it placed inside the Lazarus operation, charging conspiracy spanning WannaCry, Sony Pictures and the Bangladesh Bank theft. Pyongyang replied that no such person existed; he has never been arrested. The worm's takings — three bitcoin wallets anyone could watch — stayed famously small, and the costs it left were counted in currencies the wallets never touched: cancelled clinics, halted production lines, and a decade of patch-management budgets approved without argument.
The app that called itself Google Docs
On the afternoon of 3 May, across newsrooms, universities and offices, Gmail users received a message from someone they genuinely knew: a document had been shared. The tell was in the recipient line — hhhhhhhhhhhhhhhh@mailinator.com, with the real targets blind-copied. The button led not to a counterfeit login page but to Google's own account screen, where a third-party app registered under the name "Google Docs" asked for permission to read, send and delete mail and to manage contacts. Nobody typed a password; the permissions were real, granted through OAuth, and each grant mailed the lure onward to the victim's whole address book. Google disabled the offending accounts, pulled the fake pages and revoked the app's tokens within about an hour, and put the affected population at fewer than 0.1 per cent of Gmail users — roughly a million people on a base of about a billion. Within weeks it had tightened its review of new apps requesting sensitive permissions, and the consent screen every cloud user now squints at owes something to that hour.
Seven hours inside OneLogin
OneLogin sold single sign-on: one company holding the keys that opened everything else its customers used. At about 2 am Pacific time on 31 May an attacker used a set of the company's AWS keys — obtained, OneLogin said, via an intermediate host at a smaller US service provider — to reach its cloud infrastructure and quietly create server instances inside the US data region. Around 9 am staff noticed unusual database activity and shut the intrusion down within minutes; it had lasted roughly seven hours. The remarkable part was the paperwork. Within days, chief information security officer Alvaro Hoyos wrote that the accessed tables held information about users, apps and various kinds of keys — and that the company could not rule out that the attacker had also obtained the ability to decrypt encrypted data. Customers received a long, unsentimental remediation list: new API credentials, new OAuth tokens, fresh certificates, forced password resets. Identity providers rarely say the worst sentence first. This one did, and the candour aged better than the breach.
Seventeen million rows for a thousand dollars
On 18 May 2017 Zomato, then India's largest restaurant platform, published a security notice admitting that about 17 million user records — email addresses and hashed passwords — had been copied from its database. The company had not caught the intrusion; it had caught the advertisement. A vendor using the handle nclay had listed the database on a dark-web marketplace for about $1,000 in bitcoin, samples included, and the security site HackRead reported the listing that morning. Zomato reset passwords, logged every user out, and was careful with one distinction that held up: payment card data lived in a separate, PCI-compliant vault and was not touched. It described the stolen hashes as one-way; researchers who later indexed the dump identified salted MD5, which commodity hardware guesses at billions of tries a second. The ending was stranger than the theft: contacted by the company, the seller asked not for money but for a paid bug-bounty programme for security researchers.
Zomato promised one, the listing came down — the destruction of all copies was, and remains, the seller's claim — and the company moved its bounties to a paid footing on HackerOne. The same fortnight, WannaCry's confirmed Indian footprint stayed modest and municipal: computers in eighteen police units across five Andhra Pradesh districts, from Chittoor to Srikakulam, reported infected on 13 May; four machines in a village panchayat office in Wayanad, Kerala; at least six offices of West Bengal's state electricity distributor, serving around eight lakh households, showing the $300 demand. The Centre's assessment — isolated incidents in Kerala, Andhra Pradesh, Maharashtra and West Bengal, no serious impact — held, and CERT-In's critical alerts that week reached desks that had never read one before.
Three games in Wuzhen, then retirement
At the Future of Go Summit in Wuzhen, from 23 to 27 May, DeepMind's AlphaGo beat Ke Jie, the 19-year-old world number one, in all three games — the first by half a point, a system optimising for certainty of victory rather than margin — while running on a single machine with four of Google's TPU chips. Ke Jie wept at the close; DeepMind retired AlphaGo from competitive play at the summit's end and published 50 of its self-play games for professionals to study. The chips had already had their own launch: at I/O in Mountain View on 17 May, Sundar Pichai announced Google.ai, AutoML — neural networks learning to design other neural networks — and the second-generation TPU, rated at 180 teraflops a board, 64 boards to a pod, 1,000 of them offered free to researchers. Nine years on, both halves aged into fact: within months a successor taught itself Go from nothing but the rules, and the TPU line still trains Google's frontier models.
Signatures at speed, adware at scale
For the vendors, the outbreak on this edition's cover meant a weekend of engineering at speed: Microsoft pushed a Windows Defender detection for the worm out on 12 May itself, and its guidance pages soon listed matching signature names from Symantec, Trend Micro, ESET and the rest of the industry. The quieter endpoint news that month was Android's. At I/O on 17 May Google announced Play Protect, always-on malware scanning for any phone carrying the Play store, saying its systems already scanned more than 50 billion apps a day. Eight days later Check Point showed what years of scanning had missed: Judy, auto-clicking adware inside 41 apps from the Korean developer Kiniwini, some resident on Google Play for years, silently loading hidden pages and clicking advertisements for revenue. Check Point put the possible spread between 8.5 and 36.5 million users — headlines carried the top figure — and Google removed the apps once notified. The design proved durable: quiet ad fraud, not ransom notes, became mobile malware's steadiest business over the decade that followed.
⏳ Time capsule — May 2017
- On 7 May Emmanuel Macron defeated Marine Le Pen in the French presidential run-off with about 66 per cent of the vote, becoming, at 39, the youngest president in the republic's history.
- Chelsea clinched the Premier League title on the evening of Friday 12 May — the outbreak's first day — beating West Bromwich Albion 1–0 with a late Michy Batshuayi goal.
- Bitcoin crossed $2,000 for the first time on 20 May, having begun the year below $1,000; it would near $20,000 by December.
- Just after midnight on 31 May the US president tweeted "Despite the constant negative press covfefe" and nothing more; the post lasted about six hours, the word considerably longer.
The loudest lesson
Nine years on, WannaCry reads less like a chapter of ransomware history than its hinge. The loud, indiscriminate worm all but retired with 2017; what replaced it was patient, targeted and vastly more expensive, and this archive follows that line through May 2021, when a single ransom note emptied petrol stations across the American Southeast. SMBv1 is disabled by default everywhere now, though EternalBlue still answers scans from forgotten corners of old networks, and the kill-switch domain was kept alive for years, absorbing the calls of machines nobody ever patched. For the outbreak itself, hour by hour — the wards, the domain, the weekend — read the full special restoration.
The month's smaller stories aged into standards. Consent-screen phishing — the fake Google Docs trick of asking politely for real permissions — became a fixture of the following decade's cloud intrusions, and the app-verification walls every developer now climbs date from that week's embarrassment. OneLogin's worst-case candour, unusual in 2017, is roughly what regulators now require: seventy-two hours under GDPR, six under India's CERT-In directions. Zomato honoured the bounty promise, listed on India's exchanges in 2021 and trades today under the name Eternal. And May 2017 kept one secret: on the 13th, while every headline was red, someone stepped through an unpatched Apache Struts server into Equifax and stayed all summer. This archive reaches that story in September.