It began on a Friday, because these things always seem to begin on a Friday. On the morning of May 12, 2017, doctors across England looked up from their screens to find them locked. In place of patient records stood a red window with a countdown clock and a demand: $300 in bitcoin, doubling to $600 in three days, files deleted forever in seven. By lunchtime, hospital staff were turning ambulances away and writing appointments on paper. By evening, the same red window had appeared on railway departure boards in Germany, factory floors in France, telecom offices in Spain, and government desks from Russia to Romania. In roughly four hours, a piece of ransomware called WannaCry had reached more than 150 countries.
The world learned a new word that weekend. For the security profession, though, the sharpest sting was not how novel WannaCry was β it was how preventable.
The stolen key
WannaCry did not spread through clever emails or unlucky clicks. It was a worm β self-propagating, no human required β and its engine was a weapon called EternalBlue: an exploit for a flaw in Windows file-sharing (SMBv1) developed by the United States' National Security Agency and kept secret for years. In April 2017, a group calling itself the Shadow Brokers dumped EternalBlue onto the open internet as part of a cache of stolen NSA tooling.
Here is the detail that still defines the story: Microsoft had shipped the fix two months earlier. The March 2017 patch, MS17-010, closed the hole on every supported version of Windows. The eight weeks between that patch and that Friday were the whole tragedy in miniature β a global inventory of machines that nobody had gotten around to updating, plus millions more running Windows XP, three years past its retirement, for which no fix existed at all. WannaCry didn't break through the world's defenses. It walked through a door the world had been told to close.
Four hours on a Friday
The numbers from that weekend remain startling. Over 200,000 machines infected across some 150 countries. In England, at least a third of NHS hospital trusts were disrupted along with nearly 600 GP practices; around 19,000 appointments were cancelled, five hospitals diverted emergency patients, and at least 139 urgent cancer referrals had to be rebooked. TelefΓ³nica told staff in Madrid to shut down their machines and go home. Renault paused production lines; Deutsche Bahn's station displays showed the ransom note between train times; FedEx, Nissan's Sunderland plant, and Russia's interior ministry all joined the casualty list.
India escaped the worst headlines but not the worm. Police systems in Andhra Pradesh were infected, companies across several states reported hits, CERT-In pushed out urgent advisories, and the Reserve Bank directed banks to patch their ATMs β a fleet then heavily dependent on Windows XP β before switching them back on. For many Indian IT teams, WannaCry was the first time a global cyber event arrived not as news from abroad but as a Monday-morning checklist.
The ten-dollar fix
The counterattack came not from a government or a security giant, but from a 22-year-old researcher in the south-west of England, working from his bedroom. Combing through WannaCry's code that Friday afternoon, Marcus Hutchins noticed the worm checking an odd, unregistered web address β a long string of gibberish β before each infection. On instinct, he registered the domain. It cost him $10.69.
The infections began to stop. The domain turned out to be a kill switch: as long as it answered, the worm stood down. Whether it was a deliberate abort mechanism or a clumsy anti-analysis trick remains debated, but the effect was not β one researcher's ten-dollar hunch froze the fastest-moving cyber outbreak the world had seen, buying defenders the weekend they desperately needed to patch. It stands, still, as perhaps the best return on a security investment ever recorded.
A shoddy weapon with a stolen engine
Strip away the weapons-grade exploit and WannaCry was, by criminal standards, amateur work. It carried a kill switch that a stranger could trip. Its payment system couldn't reliably tell who had paid, which meant paying rarely got files back β word of that spread quickly, and victims kept their money. On many older machines it simply crashed the system instead of encrypting it. When researchers finally tallied the three hardcoded bitcoin wallets, the world's most famous ransomware attack had collected barely $142,000, from just 383 payments β pocket change against the billions in damage it caused, and against the Β£92 million cost later estimated for the NHS alone.
That mismatch β catastrophic disruption, negligible profit β was the first public clue that WannaCry wasn't ordinary crime. It looked less like a business and more like a weapon test that had slipped its leash.
The reckoning
The weekend forced conversations that had been comfortably theoretical. Microsoft took the extraordinary step of shipping emergency patches for Windows XP and other retired systems β software it had every commercial right to leave dead. Its president, Brad Smith, then published a blunt essay arguing that governments stockpiling secret vulnerabilities had to answer for what happens when those stockpiles leak, likening the episode to the military having its missiles stolen. The debate over whether states should hoard flaws or help fix them has never really closed since.
For everyone running a network, the lessons were plainer. Know what you own. Patch like it matters, because the gap between "fix available" and "fix applied" is exactly where worms live. Kill legacy protocols before they kill you. And segment your network, because the difference between one infected PC and three hundred was, for most victims, nothing more than open internal doors.
β³ Time capsule β May 2017
- Bitcoin traded near $1,750 β WannaCry's $300 ransom was about a sixth of one coin. The same coins today would be worth a small fortune, which is its own strange footnote.
- Millions of PCs worldwide β including much of India's ATM fleet β still ran Windows XP, three years after its official retirement.
- In India, UPI had just turned one, demonetisation had pushed millions into digital payments for the first time, and "cybersecurity" was about to become a household worry.
- The Nokia 3310's nostalgic relaunch was the season's feel-good tech story β a phone from an era when none of this could happen.
The last great worm
Seven months after the outbreak, the United States publicly attributed WannaCry to North Korea's Lazarus Group, and in 2018 charged a named North Korean operator β making WannaCry the first ransomware event formally laid at the feet of a state. Marcus Hutchins, briefly hounded and later celebrated, became one of the field's most respected voices. The kill-switch domain he bought for $10.69 was quietly kept alive for years, still absorbing connection attempts from unpatched machines long after the world moved on β EternalBlue's long tail showed up in network scans for the better part of a decade.
What nobody predicted: WannaCry was less a beginning than an ending. The spray-everything worm all but disappeared after 2017; the criminals studied the lesson and went the other way β quiet, targeted, human-operated intrusions against victims chosen for their ability to pay. Ransomware became the defining crime of the following decade precisely by refusing to repeat WannaCry's noisy mistakes. The defenders' lesson compounded too: the patch gap that made the outbreak possible is the same "exploitation window" that, as we wrote in our relaunch issue, has now collapsed from weeks to days. WannaCry was the moment the world learned that lesson at full volume β and the reason India's regulators, insurers, and boardrooms stopped treating patching as housekeeping and started treating it as survival.