What Was WannaCry? The Ransomware Worm That a $10.69 Domain Stopped
On the afternoon of Friday 12 May 2017, a 22-year-old researcher in Devon was picking apart a malware sample when he noticed it doing something odd. Before it did anything else, the code tried to reach a web address that looked like a cat had walked across a keyboard.
He checked whether anyone owned it. Nobody did. So he bought it, for $10.69, because registering the domains that malware talks to is an ordinary thing researchers do — it gives you a headcount of infected machines.
The global ransomware outbreak stopped.
Marcus Hutchins did not know he had found a kill switch, because nobody knew there was one. He was collecting telemetry. The malware had been checking whether that nonsense domain resolved as a way of working out whether it was being watched — if an address that obviously shouldn't exist answered anyway, the code assumed it was running inside a security researcher's sandbox and shut itself down rather than show its hand. Hutchins made the nonsense address answer. For everyone. At once.
It is the most valuable $10.69 anyone has ever spent, and it was an accident.
What was WannaCry?
WannaCry was a ransomware worm that spread across the internet on 12 May 2017, encrypting files on Windows machines and demanding $300 in Bitcoin to unlock them. What separated it from every ransomware campaign before it is the second word.
A worm does not need you. There is no attachment to open, no link to click, no invoice to be fooled by. WannaCry found the next machine by itself, over the network, using a stolen exploit called EternalBlue against a Windows file-sharing service listening on port 445. One unpatched laptop joining the office wifi was enough to start it.
Microsoft had shipped the fix as MS17-010 on 14 March 2017. WannaCry arrived on 12 May. Eight weeks.
How big was it, actually?
You will read that WannaCry hit 200,000 machines in 150 countries. That figure comes from a single sentence spoken by Rob Wainwright, then the director of Europol, on ITV's Peston on Sunday — two days into a fast-moving incident, with no published methodology, described in his own words as "the latest count." It was never corrected and never substantiated. It simply stuck, and it is now in every article about the attack.
The better number comes from the kill switch itself. Because every infected machine phoned that domain, whoever owned it could count them. Kryptos Logic, running the sinkhole, recorded roughly 727,000 unique IP addresses across about 90 countries, and estimated the sinkhole averted somewhere between 14 and 16 million infections and reinfections.
Unique IPs are not the same as unique machines — an office behind one address hides dozens, and dynamic addressing double-counts others. But it is a measurement rather than a guess, which is more than the famous figure can claim.
Was it because everyone was still running Windows XP?
No. This is the most persistent myth about WannaCry and it is backwards.
Kaspersky's telemetry put Windows 7 at over 98% of infections — 60.35% on 64-bit, 31.72% on 32-bit. Costin Raiu, who ran Kaspersky's global research team, described the Windows XP share as "insignificant."
Kryptos Logic then worked out why, in the lab. They tried to infect XP over the network and found that it mostly blue-screened instead. XP was too creaky to be exploited reliably; it crashed and rebooted rather than catching the worm and passing it on. If you ran the ransomware locally on an XP box it would happily encrypt your files — but XP was not what carried the outbreak. Windows 7, supported and patchable and simply unpatched, was.
Even the NHS story gets this wrong. The National Audit Office found that about 5% of the NHS estate was still on XP, and that "the majority of NHS devices infected were unpatched but on the supported Windows 7 operating system." The problem was not ancient computers. It was current computers that nobody had updated.
The ransom nobody could collect
Here is the part that should reassure you about the attackers' competence and does not.
WannaCry shipped with three hardcoded Bitcoin wallets. Each victim was randomly assigned one of the three. Bitcoin addresses do not come with names attached, so with hundreds of victims paying into three shared addresses, the operators had no reliable way of telling which payment belonged to which locked machine.
Their solution was a button in the decryptor window marked "Check Payment," which sent a request to a server where, as far as anyone can tell, a human being decided whether you had paid. It is difficult to imagine a worse-designed extortion scheme. Some victims paid and got nothing.
The ransom note itself is worth reading for the tone. "You only have 3 days to submit the payment. After that the price will be doubled." "If you don't pay in 7 days, you won't be able to recover your files forever." And, extraordinarily: "We will have free events for users who are so poor that they couldn't pay in 6 months." There is no evidence the seven-day deletion was ever implemented, or that the charitable offer was ever honoured.
The three wallets took in about 52 bitcoin — roughly $140,000 — against damage counted in the billions. The funds sat untouched for three months and were emptied in the early hours of 3 August 2017, then pushed through a mixer.
What happened to the NHS
The UK National Audit Office investigated and published in October 2017. The findings, which are the only figures worth quoting on this:
- At least 81 of England's 236 NHS trusts were affected — 37 infected and locked out of devices, 44 disrupted without infection.
- 595 GP practices and 603 primary care and other NHS organisations were hit.
- 6,912 appointments were recorded as cancelled; the NAO estimated the true figure including knock-on effects at over 19,000.
- 1,220 pieces of diagnostic equipment were infected.
- Five hospitals had to divert emergency ambulances elsewhere.
No NHS organisation paid the ransom. No patient data was stolen. No deaths were attributed to the attack. And the NAO's conclusion was blunt: NHS Digital had warned organisations in March and April 2017 to apply exactly this patch, and they had not.
The NAO also noted that the Department "does not know the cost of the disruption to services." Nobody counted the diverted ambulances.
Who did it
On 19 December 2017 the United States publicly attributed WannaCry to North Korea, with Homeland Security Advisor Thomas Bossert saying the attribution followed "careful investigation" and naming the UK, Australia, Canada, New Zealand and Japan as joining the assessment. The UK's National Cyber Security Centre used its own hedged language: it assessed as "highly likely" that the Lazarus Group was responsible.
In September 2018 the US Department of Justice unsealed a criminal complaint against Park Jin Hyok, a North Korean programmer alleged to have worked for a front company tied to military intelligence, charging him in connection with WannaCry, the 2014 Sony Pictures attack and the $81 million Bangladesh Bank theft.
Worth being honest about the sequence: before the governments spoke, the public technical evidence was thin. Symantec had found only what it called two "loose" links — some shared code and some co-located tooling — and said explicitly that these did "not indicate a definitive link." The confident attribution came from intelligence, not from code anyone outside government could check.
A postscript about Marcus Hutchins
In August 2017, three months after stopping WannaCry, Hutchins was arrested in Las Vegas as he left DEF CON.
The charges had nothing to do with WannaCry. They concerned banking malware he was alleged to have written years earlier, as a teenager, before he became a defensive researcher. He pleaded guilty to two counts in 2019 and was sentenced to time served — no prison time. The judge weighed the earlier conduct against what he had done in May 2017.
It is a strange coda, and it gets misremembered constantly as "the guy who stopped WannaCry was arrested for WannaCry." He was not.
Why it still matters
WannaCry is the reason patching stopped being an IT housekeeping task and started being a board-level conversation. It demonstrated, in a single Friday afternoon, that the gap between a patch shipping and a patch being installed is a window somebody else can climb through — and that the window can be eight weeks wide in organisations that keep people alive.
It also broke the comfortable assumption that ransomware is a thing that happens to careless individuals. WannaCry did not care how careful you were. It did not need you to do anything at all.
And it ended, not because of a coordinated international response, but because one researcher spent ten dollars on a domain name to satisfy his curiosity.
Further reading
- National Audit Office — Investigation: WannaCry cyber attack and the NHS (HC 414, October 2017). The definitive account of the UK impact.
- Kryptos Logic — WannaCry: Two Weeks and 16 Million Averted Ransoms Later (May 2017). The sinkhole data, from the people who ran it.
- Marcus Hutchins — How to Accidentally Stop a Global Cyber Attacks. His own write-up, published while it was still happening.
- Kaspersky Securelist and Secureworks CTU — the technical teardowns.
EXHIBIT 0002 — WANNACRY
We put it on a shirt. The patch, the port, and the eight weeks in between.
Most people who see it will recognise a word from a news cycle they half remember. A smaller number will look at the details and know exactly which Friday this was.
That's the whole idea.