May 12, 2017
At around half past noon on Friday, May 12, 2017, screens across English hospitals began turning red. The message was the same everywhere: "Ooops, your files have been encrypted!" — a countdown timer, a demand for $300 in bitcoin, a threat to double the price in three days and delete everything in seven.
By mid-afternoon, hospitals were declaring major incidents. Emergency departments diverted ambulances. Radiology went dark — no access to imaging, no way to send a scan from the machine to the specialist. Pathology systems that report blood results stopped. Phone systems that ran over affected networks failed in places, so staff coordinating the response resorted to personal mobiles and, in at least one trust, runners carrying paper between departments. Surgeons canceled operations mid-list. At Barts Health in London, the largest hospital trust in the country, staff were told to shut down their computers and revert to pen and paper.
Nobody in those hospitals had been targeted. No attacker had chosen the National Health Service; that became clear only later. The NHS was collateral damage in the first global ransomware worm — a piece of self-propagating malware that in a single day infected somewhere around 200,000 to 300,000 computers across 150 countries, hitting Telefónica in Spain, Deutsche Bahn in Germany, FedEx in the United States, and factories, universities, and police departments from Brazil to China. It hit the NHS hardest among health systems not because anyone aimed at it, but because the NHS presented, at that moment, the largest connected surface of exactly the kind of machine the worm was built to eat.
EternalBlue
WannaCry's story begins at the National Security Agency.
For years, the NSA's elite Tailored Access Operations unit had held a devastating exploit for a flaw in SMBv1 — the first version of Microsoft's Server Message Block protocol, the ancient workhorse of Windows file and printer sharing. The exploit, internally codenamed EternalBlue, allowed remote code execution on an unpatched Windows machine over the network, with no user interaction whatsoever. No phishing email to click, no attachment to open. If port 445 was reachable and the machine unpatched, it could be taken.
In August 2016, a group calling itself the Shadow Brokers announced it had stolen NSA tooling and began releasing it in stages. The NSA, understanding what was coming, quietly warned Microsoft. On March 14, 2017, Microsoft shipped MS17-010, a critical patch closing the SMBv1 flaw across supported Windows versions — an unusual patch, released with conspicuous urgency and no credited discoverer. On April 14, the Shadow Brokers published EternalBlue itself, working and weaponizable, to the open internet.
The world thus had a 59-day head start. Every machine encrypted on May 12 was a machine that had gone two months without a patch flagged critical — or was running an operating system, like Windows XP, so old that no patch existed for it because Microsoft had ended support three years earlier.
Attribution for the attack itself eventually settled, with formal statements from the U.S., U.K., and allied governments and a 2018 Department of Justice indictment, on the Lazarus Group — hackers operating on behalf of North Korea. The mercenary weirdness of the operation matched the attribution: WannaCry was extortion-shaped but incompetently monetized. The payment mechanism could not reliably track who had paid, decryption frequently didn't work, and the campaign netted only on the order of $100,000–150,000 in ransoms against billions in global damage. A state actor had bolted a stolen NSA exploit onto mediocre ransomware and let it loose. Whether the intent was revenue, disruption, or a test, the effect was the same: an indiscriminate worm that treated a children's hospital exactly like a shipping company.
Why the NHS Was Hit So Hard
England's NHS in 2017 was not one organization but a federation of more than 200 hospital trusts and thousands of general practices, each responsible for its own IT, loosely overseen by the Department of Health and national bodies like NHS Digital. That structure is the first key to what happened.
WannaCry infected machines in at least 80 of England's 236 hospital trusts — about a third — plus over 600 GP practices and other organizations. Another significant fraction of trusts, though not infected, shut down email and systems as a precaution, disrupting themselves defensively. The trusts that were devastated and the trusts that were untouched were running the same national health service, treating the same kinds of patients, under the same guidance. The difference was housekeeping.
The infected estates shared a profile. Unpatched Windows 7 machines did most of the burning — the popular memory of WannaCry as a "Windows XP incident" is largely wrong; XP machines mostly crashed rather than spread the worm — but XP's presence in the estate was symptomatic. Roughly 4 to 5 percent of NHS devices still ran XP in May 2017, years after end-of-support, much of it because of a problem unique to environments like healthcare: dependency on old software and old hardware. A £1 million MRI scanner or a pathology analyzer is bought on a 10-to-20-year lifecycle, and its control workstation runs whatever operating system the vendor certified at purchase. Upgrading the OS voids the certification, and sometimes breaks the device. Clinical applications, too, were often certified only against old browsers and old Windows builds. Trusts were not ignorant of this; they were trapped by it, and chronically underfunded for the escape. The Department of Health had been warned — by its own reviews and by the regulator — about exactly this exposure in the year before the attack, and had written to trusts in 2014 and again in March–April 2017 urging patching of the specific vulnerability. There was no mechanism to verify anyone had done it.
The second ingredient was the network. SMB worms feed on flat networks, and many trust networks were flat — a machine in an office could reach a machine in radiology could reach a machine in the lab, port 445 open all the way. Once one device on such a network was infected, the worm found the rest in minutes. The national N3 network connecting NHS organizations to each other gave it roads between institutions.
The third ingredient was the absence of anyone watching the front door. NHS Digital's assessments existed, but no trust that failed a cybersecurity inspection faced real consequence, and there was no national capability to see, in real time, that a worm was moving through the health service.
The Kill Switch
WannaCry's rampage was ended not by any government but by a 22-year-old in the south of England.
Marcus Hutchins, a self-taught malware analyst blogging as MalwareTech, obtained a sample that Friday afternoon and noticed the code querying a long, gibberish domain name — iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com — before doing anything else. The domain was unregistered. Following standard analyst practice of sinkholing malware infrastructure to observe it, he registered it for $10.69. Infections worldwide immediately began to fail.
The domain, it turned out, was a kill switch — likely an anti-analysis feature. Malware sandboxes commonly fake DNS responses, so a sample that finds a random domain "alive" can conclude it is being studied and shut down. WannaCry checked the domain; while it received no response, it spread and encrypted; once Hutchins's registration made the domain resolve, new infections went dormant. By Friday evening, hours into the outbreak, the worm's growth had been decapitated — partly by luck, partly by the instincts of one researcher, and held in place over the following days by people fighting off Mirai botnet attacks trying to knock the sinkhole domain offline and reactivate the worm.
The kill switch changed the scale of the incident. The NHS's Saturday and Sunday — staff working through the weekend, Microsoft shipping an emergency XP patch, trusts patching frantically — happened under the protection of that registered domain. Had the switch not existed, or not been found for another week, the third-of-trusts figure would look small by comparison. The version of WannaCry that hit the NHS was already a blunted one. Six weeks later, the NotPetya wiper — built on the same EternalBlue exploit, with no kill switch and no real decryption at all — showed what the unblunted version of such a weapon does, destroying Maersk's and Merck's global networks outright. Merck, a pharmaceutical company, booked roughly $1.4 billion in losses.
Fifteen months later, Hutchins was arrested by the FBI at the Las Vegas airport over malware he had written as a teenager, pleaded guilty, and was sentenced to time served by a judge who cited his WannaCry work.
The Damage
The National Audit Office and Department of Health investigations that followed produced the numbers. More than 19,000 appointments and operations were canceled in the week of the attack, including cancer referrals. Five accident-and-emergency departments diverted ambulances. The Department of Health's eventual cost estimate was £92 million — £19 million in lost output during the attack week, £73 million in IT recovery afterward — a figure most analysts consider conservative, since the NHS's data on its own disruption was poor precisely because its systems were down.
Two findings recur in healthcare incidents since.
First: no deaths were officially attributed to WannaCry. This reflects how clinical harm is measured, not how safe the event was. Attribution of clinical harm to IT outage is close to impossible with the data hospitals keep; a delayed scan or a canceled operation degrades outcomes statistically, not traceably. Later academic work on hospital cyberattacks and ransomware generally — including studies of mortality at hospitals during ransomware incidents, and the death of a patient rerouted from a ransomed Düsseldorf hospital in 2020 — has steadily eroded the assumption that these events are bloodless. WannaCry set the pattern: an official assurance that rests on an absence of measurement rather than an absence of harm.
Second: the NHS was saved substantially by clinicians' capacity to degrade gracefully. Medicine, unlike claims processing, has a manual mode: doctors and nurses reverted to paper charts, verbal orders, hand-carried results, and clinical judgment without decision support. It worked, imperfectly, for days. Every year since, that fallback thins — staff who trained on paper retire; workflows are built assuming the EHR; the paper forms no longer exist. WannaCry's least transferable asset was a 2017 workforce that still remembered how to run a hospital without computers.
Lessons
WannaCry has been studied more than any other healthcare cyber incident, but several of its lessons are commonly misremembered.
Patching is an organizational capability. Every infected NHS machine was missing a two-month-old critical patch. But trusts failed to patch because patching a hospital is hard — clinical systems certified against specific builds, devices that cannot be rebooted mid-care, no maintenance windows in a 24/7 ward, no staff. The real lesson is that an organization must know its estate (many trusts could not enumerate their own devices), know what it cannot patch, and compensate for the unpatchable with isolation.
Segment as if the perimeter is already lost. The worm's speed inside trusts was a property of flat networks, not of the exploit. A hospital where the MRI console, the pathology lab, and the finance office cannot reach each other's port 445 has the same vulnerable machines and a fraction of the blast radius. After 2017, network segmentation of legacy and clinical-device networks became the canonical compensating control for the unpatchable — the acknowledgment that in healthcare, some machines will always be old, and the design must assume it.
Being untargeted is not protection. Hospitals had long comforted themselves that they were unattractive targets. WannaCry demonstrated that a worm does not read mission statements. Indiscriminate, self-propagating attacks select for the softest connected estates, and healthcare's economics — long device lifecycles, thin IT budgets, 24/7 availability pressure — systematically produce soft estates.
Guidance without enforcement does not change behavior. The Department of Health had warned, assessed, and written letters. Nothing compelled action, and no one verified it. The post-WannaCry reforms — the Cyber Essentials requirements, CareCERT alerts with mandatory response, board-level accountability for cyber risk in trusts, England's central Cyber Security Operations Centre, and the application of the NIS Regulations to health as critical infrastructure — all encode the same correction: security guidance to autonomous units must come with inspection and consequence.
The exploit supply chain is a policy problem. WannaCry ran on a weapon developed by the NSA, stolen from the NSA, and published to the world — with the patch arriving only when theft made disclosure unavoidable. The incident put the "vulnerabilities equities" debate into public view: a government that stockpiles an exploit in SMBv1 is betting that no one else will find or steal it, and every hospital running Windows is unknowingly underwriting that bet. Microsoft's president Brad Smith made the point sharply that week, comparing the theft to "the U.S. military having some of its Tomahawk missiles stolen." No hospital CISO can patch geopolitics; the sector learned it was downstream of it.
Resilience depends on the fallback. The trusts that coped best were not those with the best security but those that could operate degraded — paper processes rehearsed, downtime procedures printed, staff drilled. "Business continuity" had been a fire-and-flood exercise; WannaCry made cyber-downtime drills a standard of care. But the manual fallback decays as digitization deepens: fewer staff are trained on paper each year, so the drills matter more even as they get harder to run.
The NHS spent the following years and several hundred million pounds on the remediation program — Windows 10 migrations funded centrally, a national contract with Microsoft, segmentation projects, the security operations center. When the next waves came for healthcare — Ryuk and Conti against American hospital chains in 2020, the Irish Health Service Executive's catastrophic Conti infection in 2021, and the vendor-side collapse chronicled in the opening chapter — the NHS was not spared, but it was never again the worst-hit health system in the world on a single day.
One distinction remained, and no remediation program could change it. WannaCry is the clearest natural experiment the field has: one worm, one day, one health service, two hundred trusts operating under identical national policy — some crippled, some untouched, sorted by the state of their patching, their networks, and their preparedness. The two-thirds of NHS trusts that came through that Friday unscathed are the standing evidence against the claim that the damage elsewhere couldn't have been helped.