How WannaCry hit the NHS: the fix existed 2 months before the attack
The fix for the flaw WannaCry used was published on March 14, 2017, almost 2 months before the attack that shut down parts of Britain's National Health Service.[2][4] This case file covers what happened on May 12, 2017, how the worm spread, how it was slowed almost by accident, what it cost the NHS, and the one control that would have kept it out.
What happened
On March 14, 2017, Microsoft released a security update rated critical for a flaw in the part of Windows that handles file sharing between computers on a network.[2] In the weeks that followed, NHS Digital, the health service's technology body, sent alerts urging organizations to install it.[1][5]
On Friday, May 12, 2017, ransomware later named WannaCry began spreading around the world, locking files and demanding payment in bitcoin, at first $300 and rising to $600 if victims waited.[1][4] It reached well over 200,000 computers in about 150 countries.[3][4] In England, at least 81 of 236 NHS trusts were disrupted, along with 603 primary care and other NHS organizations, including 595 GP practices.[1] Staff who could not use email fell back on personal phones and messaging apps to coordinate.[1]
That afternoon a security researcher noticed that the worm tried to contact an unregistered web address before doing its damage. He registered the address. From then on, new copies that could reach it stopped instead of encrypting files, and the outbreak slowed dramatically.[1][4] By then, the damage in the NHS was done.
How it got in
WannaCry did not need anyone to click a link. It was a worm, meaning malware that copies itself from one computer to the next on its own. It looked for Windows machines with file sharing exposed and missing the March update, and used the flaw to jump onto them.[2][4] Once inside a network, it spread to every unpatched neighbor it could reach. The NHS's shared national network helped it move between sites.[5]
The National Audit Office found that every infected NHS organization was running Windows systems that were either unpatched or so old they were no longer supported.[1] The government had asked trusts to move off older systems such as Windows XP by April 2015, and the Department of Health had been warned about cyber risk about a year before the attack.[1][6] Before May 2017, though, there was no formal way to check that trusts had acted on critical alerts.[1]
How it was caught
Nobody caught WannaCry at the front door. It announced itself with ransom screens. The spread was slowed by the researcher's registration, not by NHS defenses, and the audit office said the off switch likely prevented much wider disruption.[1]
No NHS organization paid the ransom, and the audit office found no evidence that patient data was taken.[5] Across the world, payments were small: roughly $130,000 by mid-June.[4] In December 2017, the White House publicly attributed WannaCry to North Korea, with the UK and Microsoft agreeing, and in September 2018 the Justice Department charged a North Korean programmer in connection with it.[4][7]
What it cost
NHS England estimated that more than 19,000 appointments were cancelled, and 5 emergency departments had to divert some patients elsewhere.[1] In October 2018 the Department of Health and Social Care put the total cost to the NHS at about 92 million pounds: about 19 million in lost output during the week of disruption and about 72 million in IT recovery work afterward.[3][8] Officials called it a broad estimate.[3]
The head of the audit office said the attack was relatively unsophisticated and could have been prevented by basic IT security practice.[1][5]
The missing control
The missing control: patching critical security flaws within days, with someone checking that it actually happened, and replacing systems too old to receive patches.
The fix was free and public for 59 days before the attack.[2] A worm that spreads through a known flaw can only move between machines that still have it. Every computer that installed the March update was a dead end. The alerts were sent, but nobody was required to confirm they had been acted on, and older machines that could not take the fix stayed on the network.[1]
What to do in your business
- Turn on automatic updates. On every Windows and Mac computer, let security updates install on their own and restart on a set schedule, such as overnight on Wednesdays.
- Set a clock for critical fixes. When a vendor labels an update critical, aim to have it on every machine within 7 days, and check a week later that it landed.
- Retire what cannot be patched. List any computer or device running software the maker no longer supports. Replace it, or at least take it off the main network.
- Close doors you do not use. Ask whoever manages your network to make sure file sharing is not open to the internet and is limited inside the office to the machines that need it.
- Keep an offline backup. Hold one copy of your important files somewhere ransomware cannot reach, and test restoring from it.
WannaCry, start to finish: a leaked spy tool, an unapplied patch and a $10.69 off switch: the long read behind the CL11 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- How a Raspberry Pi let hackers into NASA's Jet Propulsion Laboratory
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- National Audit Office: Investigation: WannaCry cyber attack and the NHS (press release)
- Canadian Centre for Cyber Security: Microsoft critical security bulletins summary, March 2017
- ITPro: WannaCry cost the NHS 92 million pounds, report estimates
- Wikipedia: WannaCry ransomware attack
- Healthcare IT News: NHS and Department of Health warned to get their act together after NAO WannaCry report
- HFMA: Cyber attack hit more than a third of trusts
- Government Executive: North Korea was behind the WannaCry cyberattacks, says White House
- Public Finance: WannaCry NHS cyber attack 'cost 92m pounds'