Back to glossaryCyber

WannaCry

Global ransomware of May 2017 exploiting the EternalBlue vulnerability to spread automatically across unpatched networks.

Definition

WannaCry is a worm-type ransomware that spread from 12 May 2017 by exploiting the EternalBlue vulnerability in Windows SMBv1, an exploit developed by the NSA and released by the Shadow Brokers group weeks earlier. Unlike conventional ransomware requiring human interaction, WannaCry spreads autonomously from machine to machine across networks whose systems had not applied the MS17-010 patch published by Microsoft in March 2017. Within hours, more than 200,000 systems in 150 countries were affected, including the British NHS, Spanish telecoms and car factories in France and Romania. The attack was attributed to the Lazarus group, linked to North Korea, with estimated global economic damage exceeding four billion dollars. For cyber risk models, WannaCry is the canonical example of a wormable attack whose kinetics resemble a digital pandemic: loss correlation is near-perfect across vulnerable networks, making any pooling mechanism inoperative. This attack vector constitutes a reference scenario in most cyber PML models.

Example

In the United Kingdom, NHS hospitals had to turn away A&E patients and cancel thousands of planned operations following WannaCry. The cost of the disruption to the NHS alone was estimated at 92 million pounds sterling, of which 19 million was directly linked to disruptions and 73 million to subsequent remediation measures.

Related terms
Related articles
Also known as

WCry, WannaCrypt