
WannaCry
The Ransomware That Held the World Hostage
By Shane Larson · Digital Outlaws
About This Book
On the afternoon of May 12, 2017, a twenty-two-year-old named Marcus Hutchins was sitting in his bedroom in a small seaside town in the west of England, doing what he did most days: picking apart malware for a living. A nasty new piece of ransomware was tearing across the world that Friday — it had already frozen hospitals across the National Health Service — and Hutchins had gotten hold of a sample to study. Poking through its guts, he noticed something odd. Before doing its damage, the malware kept trying to reach a particular web address: a long, meaningless string of characters that no one had ever registered.
On a hunch, following a routine researcher's habit, Hutchins registered the domain himself. It cost him $10.69. He did not fully understand, in that moment, what he had done. What he had done was flip a hidden switch inside the worm that told it to stop. Across the planet, WannaCry's spread slammed to a halt. A self-taught kid and an eleven-dollar domain registration had just thrown an emergency brake on one of the worst cyberattacks in history — one that all the assembled machinery of governments and security firms had not managed to stop.
That is the kind of story WannaCry is: enormous stakes turning on tiny, almost accidental human moments. And it gets stranger from there.
A Weapon That Came Home
The most unsettling fact about WannaCry is that the criminals who unleashed it did not build its most dangerous part. The engine that let the malware spread across the globe in a single afternoon — jumping from computer to computer on its own, with no one clicking anything — was a cyber-weapon built by the United States National Security Agency.
Years earlier, the NSA had found a flaw in software that runs on nearly every Windows computer on earth, and instead of warning Microsoft so it could be fixed, the agency kept the flaw secret and turned it into a weapon, code-named EternalBlue. Then it lost control of it. In 2016 and 2017, a mysterious group calling itself the Shadow Brokers began dumping the NSA's stolen cyber-arsenal onto the public internet, and in April 2017 it released EternalBlue itself — free, for anyone in the world to pick up. Weeks later, someone wrapped it around a piece of ransomware and pointed it at the world. A weapon built by the American government to spy on its enemies ended up locking the files of British nurses and Spanish office workers and Russian train dispatchers.
And here is the quiet tragedy under the drama: it never should have worked. When the NSA's tools were compromised, Microsoft was tipped off, and in March 2017 — two full months before the attack — it issued a free patch that closed the hole EternalBlue relied on. Any computer that installed it was immune. But hundreds of thousands of organizations hadn't. They were running old, unpatchable systems; they had medical machines certified only for ancient software; they couldn't take critical systems offline; they were understaffed and running on the oldest instinct of all — if it works, don't touch it. So WannaCry found a world full of doors that could have been bolted for free, and walked right through them. The fix existed. The world didn't use it. It is the single most repeated and least-learned lesson in all of cybersecurity, and this book keeps returning to it.
Why I Wrote This
I write the Digital Outlaws series, and my background is in engineering the kinds of systems that attacks like WannaCry target. That shapes how I approached this one. The WannaCry story has been told in fragments — a headline about the NHS here, a profile of Marcus Hutchins there, a technical write-up of EternalBlue somewhere else — but I'd never seen it assembled into a single coherent narrative that a general reader could follow from the stolen weapon all the way to the ransomware epidemic it launched. And the technical heart of it, the part that actually explains why one weekend went so wrong, is exactly the part most accounts either fumble or skip.
I wanted to write the version I wished existed: one that explains EternalBlue, the worm mechanism, and the patching failures precisely and in plain language, while keeping the human beings — the NHS staff working by candlelight on pen and paper, the Shadow Brokers in their shadows, Marcus Hutchins in his bedroom — at the emotional center. WannaCry has been sensationalized and oversimplified for years. I think the honest, well-paced, technically grounded account is more gripping than the myth, and it carries a warning we still haven't heard.
Frequently Asked Questions
Do I need a technical background to follow it?
No. Everything technical — EternalBlue, the worm, the kill switch, the patching problem — is explained in plain language for a smart general reader. If you remember the 2017 headlines and want to finally understand what actually happened, this is written for you.
Is it a how-to for hacking or making ransomware?
Absolutely not. It's history and journalism about events of extensive public record. It explains what happened and why it mattered at the level a good documentary would — no exploit code, no attack recipes, nothing you could misuse. Understanding a crime is not the same as committing one.
How does WannaCry connect to your other books?
It's a crossroads of the Digital Outlaws series. It pays off the stolen-state-weapon thread from Stuxnet and Zero Day, and it shares the North Korean Lazarus Group with The Sony Hack and The Bangladesh Bank Heist. You can read it entirely on its own, but series readers will see the threads converge.
What really happened to Marcus Hutchins?
He stopped WannaCry with the kill switch, was hailed as a hero, and was then arrested in August 2017 for banking malware he'd helped create years earlier as a teenager. He eventually pleaded guilty and was sentenced to time served — no prison — and has since had a legitimate, respected security career. The book treats his story with nuance, holding the heroism and the wrongdoing in the same frame.
Was anyone actually harmed by the NHS attack?
The disruption was severe and well-documented — thousands of appointments and operations cancelled, ambulances diverted, staff locked out of records. The book is precise about what the record does and doesn't establish about ultimate patient outcomes, and handles the human cost soberly rather than sensationally.
If You Liked This, You Might Like
- Stuxnet — The origin of the stolen-state-weapon thread WannaCry pays off: nation-state code built to sabotage the physical world.
- The Sony Hack — The same actor, North Korea's Lazarus Group, in the attack that first put it on the map.
- The Morris Worm — The first great self-spreading worm, decades before WannaCry proved how far the idea could go.
- Operation Aurora — State-sponsored intrusion and the blurring line between espionage and attack.
The heist that shares WannaCry's North Korean culprit is The Bangladesh Bank Heist, and the deeper history of the stockpiled exploits behind it runs through Zero Day.
The fix existed. The warning was delivered as loudly as history ever delivers one. This is the story of the weekend the world got a preview of the ransomware age — and how much of the warning we failed to hear.
Part of the Digital Outlaws series.
What You'll Learn
- The Shadow Brokers and the theft of the NSA's cyber-arsenal — and why the leak still isn't fully solved
- EternalBlue explained in plain language: how a hoarded government exploit became a self-spreading weapon
- The patch that existed for two months, and the deep reasons the world left it on the shelf
- The hour-by-hour spread across 150+ countries, and the human cost inside the NHS
- The $10.69 kill switch and the bedroom researcher who found it by accident
- The strange economics — billions in damage, roughly $140,000 collected — and what that failure revealed
- The forensic trail to North Korea's Lazarus Group, the same actor behind Sony and the Bangladesh Bank heist
- The hero-with-a-past arc of Marcus Hutchins, arrested three months after saving the world
- The ransomware epidemic WannaCry previewed — NotPetya, Colonial Pipeline, and the industry that followed
New Cybersecurity History releases and free chapters — no spam, unsubscribe anytime.
More in Digital Outlaws
View series →More in This Genre
View all →











