Case file · WANNACRY 2017

How WannaCry hit the NHS: the fix existed 2 months before the attack

Published 2026-09-29 · 4 min read · Missing control: Patch critical flaws within days

The fix for the flaw WannaCry used was published on March 14, 2017, almost 2 months before the attack that shut down parts of Britain's National Health Service.[2][4] This case file covers what happened on May 12, 2017, how the worm spread, how it was slowed almost by accident, what it cost the NHS, and the one control that would have kept it out.

What happened

On March 14, 2017, Microsoft released a security update rated critical for a flaw in the part of Windows that handles file sharing between computers on a network.[2] In the weeks that followed, NHS Digital, the health service's technology body, sent alerts urging organizations to install it.[1][5]

On Friday, May 12, 2017, ransomware later named WannaCry began spreading around the world, locking files and demanding payment in bitcoin, at first $300 and rising to $600 if victims waited.[1][4] It reached well over 200,000 computers in about 150 countries.[3][4] In England, at least 81 of 236 NHS trusts were disrupted, along with 603 primary care and other NHS organizations, including 595 GP practices.[1] Staff who could not use email fell back on personal phones and messaging apps to coordinate.[1]

That afternoon a security researcher noticed that the worm tried to contact an unregistered web address before doing its damage. He registered the address. From then on, new copies that could reach it stopped instead of encrypting files, and the outbreak slowed dramatically.[1][4] By then, the damage in the NHS was done.

How it got in

WannaCry did not need anyone to click a link. It was a worm, meaning malware that copies itself from one computer to the next on its own. It looked for Windows machines with file sharing exposed and missing the March update, and used the flaw to jump onto them.[2][4] Once inside a network, it spread to every unpatched neighbor it could reach. The NHS's shared national network helped it move between sites.[5]

The National Audit Office found that every infected NHS organization was running Windows systems that were either unpatched or so old they were no longer supported.[1] The government had asked trusts to move off older systems such as Windows XP by April 2015, and the Department of Health had been warned about cyber risk about a year before the attack.[1][6] Before May 2017, though, there was no formal way to check that trusts had acted on critical alerts.[1]

How it was caught

Nobody caught WannaCry at the front door. It announced itself with ransom screens. The spread was slowed by the researcher's registration, not by NHS defenses, and the audit office said the off switch likely prevented much wider disruption.[1]

No NHS organization paid the ransom, and the audit office found no evidence that patient data was taken.[5] Across the world, payments were small: roughly $130,000 by mid-June.[4] In December 2017, the White House publicly attributed WannaCry to North Korea, with the UK and Microsoft agreeing, and in September 2018 the Justice Department charged a North Korean programmer in connection with it.[4][7]

What it cost

NHS England estimated that more than 19,000 appointments were cancelled, and 5 emergency departments had to divert some patients elsewhere.[1] In October 2018 the Department of Health and Social Care put the total cost to the NHS at about 92 million pounds: about 19 million in lost output during the week of disruption and about 72 million in IT recovery work afterward.[3][8] Officials called it a broad estimate.[3]

The head of the audit office said the attack was relatively unsophisticated and could have been prevented by basic IT security practice.[1][5]

The missing control

The missing control: patching critical security flaws within days, with someone checking that it actually happened, and replacing systems too old to receive patches.

The fix was free and public for 59 days before the attack.[2] A worm that spreads through a known flaw can only move between machines that still have it. Every computer that installed the March update was a dead end. The alerts were sent, but nobody was required to confirm they had been acted on, and older machines that could not take the fix stayed on the network.[1]

What to do in your business

Full episode

WannaCry, start to finish: a leaked spy tool, an unapplied patch and a $10.69 off switch: the long read behind the CL11 episode, chapter by chapter.

Watch the case
The ten-dollar web address that stopped WannaCryDrops 2026-11-03
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. National Audit Office: Investigation: WannaCry cyber attack and the NHS (press release)
  2. Canadian Centre for Cyber Security: Microsoft critical security bulletins summary, March 2017
  3. ITPro: WannaCry cost the NHS 92 million pounds, report estimates
  4. Wikipedia: WannaCry ransomware attack
  5. Healthcare IT News: NHS and Department of Health warned to get their act together after NAO WannaCry report
  6. HFMA: Cyber attack hit more than a third of trusts
  7. Government Executive: North Korea was behind the WannaCry cyberattacks, says White House
  8. Public Finance: WannaCry NHS cyber attack 'cost 92m pounds'