WannaCry was ransomware that encrypted files and demanded payment in Bitcoin, but it also spread like a worm: once it reached a vulnerable Windows computer, it could seek out other vulnerable systems without anyone clicking a link. The outbreak began on May 12, 2017, even though Microsoft had released a patch for the exploited vulnerability two months earlier. That combination of encryption, automatic spread and unpatched systems made WannaCry unusually disruptive.
What was WannaCry?
WannaCry—also known as WannaCrypt, WanaCrypt0r, WCrypt and WCRY—was crypto-ransomware with worm-like network propagation. Europol described it as a crypto-ransomware variant that spread around the world beginning May 12, 2017. It encrypted files on infected computers and demanded Bitcoin, while also trying to infect other vulnerable Windows systems.
That automatic spread is the key distinction from ransomware that depends on each victim opening an attachment or following a malicious link. A person might still be involved in how the first computer was compromised, but WannaCry could move from an infected machine to other vulnerable computers over a network without another person taking that step.
How did WannaCry spread so quickly?
EternalBlue exploited a flaw in Windows SMB
WannaCry used publicly available exploit code associated with EternalBlue to target the Windows SMBv1 vulnerability CVE-2017-0145. SMB is a Windows networking protocol used for sharing files and other resources. When an unpatched system exposed the vulnerable service, the malware could exploit it and continue spreading across the network. NHS England Digital describes the propagation method as involving SMB EternalBlue and DoublePulsar.
#1 Best Overall
Microsoft’s MS17-010 security update fixed the vulnerability on March 14, 2017. Microsoft’s May 12 analysis identified unpatched Windows 7 and Windows Server 2008 or earlier systems among those targeted. The patch was therefore available before the outbreak, but many vulnerable computers remained unpatched and reachable.
Why it was a perfect storm
WannaCry brought together four conditions that amplified one another: a payload that encrypted files, a worm mechanism that did not require each victim to click, a known vulnerability with an available fix, and many older or poorly protected Windows systems. Vulnerable SMB services and legacy SMBv1 made it possible for an infection to travel between systems. The result was faster spread than a campaign relying on people to individually open malicious content.
Rank #2
How large was the outbreak?
WannaCry began on Friday, May 12, 2017. Estimates of its reach differ, so they should be read with their source and counting basis rather than treated as one definitive tally.
| Estimate | Source and qualification |
|---|---|
| More than 230,000 computers in at least 150 countries | Europol estimate cited in the NHS England lessons-learned review, published in 2017/2018. |
| More than 200,000 computers in at least 100 countries | UK House of Commons Public Accounts Committee, 2018. |
The difference between these figures reflects different counting windows and methodologies; neither should be presented without attribution.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsWhat happened to the NHS?
The NHS England lessons-learned review records the first alerts shortly after 13:00 on May 12, followed by escalation to a major incident as infections spread across NHS organizations. An OECD summary published in 2023 reports that 1% of NHS activity was directly affected, one-third of hospital trusts had operations disrupted, and 8% of NHS GP practices were infected.
Some Windows XP medical devices, including imaging and laboratory systems, were affected. The episode showed how vulnerable legacy systems can create operational risks in healthcare, where replacing or updating a device may be constrained by its role in clinical services.
Rank #4
What did the kill switch do?
WannaCry checked a hard-coded domain. On the evening of May 12, a security researcher registered that domain. Infected computers that could reach it received a response that stopped the malware from infecting additional devices. This acted as a brake on further propagation; it did not decrypt files already locked by WannaCry or repair affected computers.
Quick Recap
Best Value
How could organizations have reduced the risk?
- Install security updates promptly. Apply MS17-010 and later security updates. Microsoft also made the update broadly available for Windows XP, Windows 8 and Windows Server 2003, platforms in custom support, citing the potential impact to customers and businesses.
- Disable SMBv1 where operationally possible. Microsoft customer guidance recommends considering the blocking of legacy protocols. Check for dependencies before disabling it so that necessary services are not unexpectedly disrupted.
- Limit network exposure. Do not expose SMB or NetBIOS services unnecessarily to the internet or untrusted network segments. Restricting which systems can communicate with these services can reduce opportunities for a worm to move between devices.
- Retire or isolate unsupported systems. Replace unsupported operating systems where feasible. If legacy medical, industrial or other essential devices cannot be replaced promptly, isolate them from general-purpose networks and limit their connections to what they require.
- Prepare for recovery and disruption. Maintain tested backups and incident-response procedures. Technical containment is only part of recovery; the NHS experience also illustrates the importance of coordination and plans for maintaining services during an incident.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

