Who Was Arrested for WannaCry? The Only Handcuffs Went on the Man Who Stopped It

The only handcuffs in the WannaCry story went on the man who stopped it, and not for WannaCry.

On 2 August 2017 Marcus Hutchins was in a lounge at the Las Vegas airport, waiting to fly home. The court record has the scene in one sentence: he "was about to embark on his journey back to the U.K." when "a federal agent and two Customs and Border Patrol officials approached him." On 12 May he had registered a domain name and a global ransomware outbreak had gone quiet.

Everyone remembers that the WannaCry hero got arrested. The part that gets dropped is what the indictment said, and the part that gets added is that it said WannaCry. It did not. The people the United States says built WannaCry have a docket of their own, and it reads very differently.

Who was arrested for WannaCry?

Nobody has been arrested for WannaCry.

Three North Korean programmers have been charged in a federal court in Los Angeles with building it. One of them has been under Treasury sanctions since 2018. The affidavit that opened the case says where he was, and it was North Korea. The one arrest in the story, the one everyone half-remembers, was for a different piece of malware, for conduct dated 2014 and 2015, and it ended with a judge sending the defendant home.

Both dockets are worth reading properly, because the popular version gets each of them wrong in a different direction.

What Marcus Hutchins was actually charged with

A federal grand jury in the Eastern District of Wisconsin indicted Hutchins on 11 July 2017, before the airport. The charges were conspiracy, fraud, and unlawfully intercepting communications, and they concerned a banking trojan called Kronos. The conduct the government alleged ran from "at some point before July 2014" to February 2015. WannaCry appears nowhere in it.

The indictment was superseded on 5 June 2018 with a ten-count version. Count Nine charged him with "lying to the FBI about whether he knew that his computer code was part of Kronos," under 18 U.S.C. § 1001(a)(2). His lawyers filed motions. On 11 February 2019 Judge J.P. Stadtmueller disposed of them in five words: "All motions will be denied."

The case never reached a jury. In April 2019 Hutchins pleaded guilty to two counts, covering Kronos and a second piece of malware called UPAS Kit. He had been facing up to a decade in prison.

What the court did with it

On 26 July 2019 Stadtmueller sentenced Hutchins, then 25, to time served and one year of supervised release. No prison. From the bench he told the defendant, "It's going to take the people…with your skills to come up with solutions," which is not the customary remark to a man who has just been convicted of writing malware. Hutchins, for his part: "I deeply regret my conduct and the harm that was caused."

That is the whole of the WannaCry arrest. A researcher was charged over code from 2014 and 2015, pleaded to two counts, and left with a year of supervision. The ransomware he stopped is not on the charge sheet. The part people remember is the airport. The part that matters is the docket.

What he had actually done on 12 May

For the record, since the two stories get fused. Kryptos Logic, the firm Hutchins worked for, put it this way in its 30 May 2017 write-up: the spread of WannaCry "came to a standstill when one of our security researchers, MalwareTech, working to collect intelligence for the Vantage Breach Intelligence Feed, registered a domain associated to the malware, ultimately triggering its 'kill switch'." The effect, in their words: "Each time WannaCry contacts the kill-switch, functionality will cease."

They also took issue with the way it was being told. "Make no mistake, this was no accident; it was just not initially assumed that the domain was a kill switch." By 30 May the sinkhole had counted approximately 727,000 unique IP addresses calling in, across 90 countries with a measurable impact, and Kryptos Logic estimated that "between 14 to 16 million infections and reinfections have been mitigated" since 12 May. The mechanics of the domain check, and why the operators built one, are in the Archive's account of WannaCry itself.

Who the United States says wrote it

On 19 December 2017 Tom Bossert stood at the White House podium and read the line: "After careful investigation, the United States is publicly attributing the massive WannaCry cyberattack to North Korea." He put the reach at "hundreds of thousands of computers" in "over 150 countries," and said the United Kingdom, Australia, Canada, New Zealand and Japan had "seen our analysis, and they join us in denouncing North Korea for WannaCry."

On the money, Bossert said something the ransomware framing tends to bury. The United States did not "really know how much money they raised." The attackers "didn't seem to architect it in the way that a smart ransomware architect would do." And: "this was a reckless attack and it was meant to cause havoc and destruction. The money was an ancillary side benefit." A ransomware worm, attributed by the White House, with the ransom described as a side effect.

London spoke the same day and used the hedged language intelligence agencies actually use. Lord Ahmad of Wimbledon, for the Foreign Office: "The UK's National Cyber Security Centre assesses it is highly likely that North Korean actors known as the Lazarus Group were behind the WannaCry ransomware campaign." Highly likely. An assessment, not a charge.

The trust count that depends on who is talking

The two December statements are also worth putting next to the audit. The Foreign Office said WannaCry "impacted 300,000 computers in 150 countries including 48 NHS trusts." The White House said "hundreds of thousands" and "over 150 countries."

The National Audit Office had already reported, on 27 October 2017, as HC 414. Its finding was that "at least 81 out of 236 trusts across England were affected," and that "a further 603 primary care and other NHS organisations were infected by WannaCry, including 595 GP practices." NHS England had identified 6,912 cancelled appointments and "estimated over 19,000 appointments would have been cancelled in total." No NHS organisation paid the ransom. And the sentence that still stands: "the Department does not know how much the disruption to services cost the NHS."

Forty-eight trusts in the Foreign Office statement of 19 December. At least eighty-one in the audit that had been on the record since 27 October. Same government, two counts, and the audited one is the larger. As for the 300,000 computers, the nearest thing to a measurement is the 727,000 unique addresses that arrived at the kill-switch domain, counted by the people who owned it. The exploit those machines were reached through has its own entry in the Archive.

The following September, the assessment became a charge.

The 179 pages

On 6 September 2018 the Justice Department unsealed a criminal complaint it had filed on 8 June in the Central District of California. It runs to 179 pages, sworn by FBI Special Agent Nathan P. Shields, and it names one man: Park Jin Hyok. Two counts. Conspiracy under 18 U.S.C. § 371, which carries up to five years, and conspiracy to commit wire fraud under 18 U.S.C. § 1349, which carries up to twenty.

Paragraph 14 is the one to read. Park was "a programmer employed by the government of North Korea," working since at least 2002 for Chosun Expo, "a North Korean government front company affiliated with one of the North Korean government's hacking organizations sometimes known as 'Lab 110.'" The affidavit does not coin a group name of its own. It borrows the private sector's: the subjects "comprise members of the 'Lazarus Group,' the name that private security researchers including Symantec, Novetta and BAE have given" to the people behind the Sony Pictures and Bangladesh Bank intrusions.

WannaCry gets one sentence in the summary. The same subjects "were also responsible for authoring the malware used in the global ransomware cyber-attack named 'WannaCry 2.0.'" The version number is doing work. The complaint connects the conspiracy to WannaCry 2.0 and to two earlier versions of the ransomware, and it is the same conspiracy that, in the same document, moved $81 million out of Bangladesh Bank in February 2016.

And then the sentence that answers this article's question. "Although PARK worked in China for at least some time between 2011 and 2013, he appears to have returned to North Korea by 2014, before the cyber-attack on SPE." The document describes itself as made "in support of a criminal complaint against and arrest warrant for PARK JIN HYOK." It asks for a warrant and, in the same affidavit, says where the man is.

The sanctions

The same day, 6 September 2018, the Treasury's Office of Foreign Assets Control designated Park and Chosun Expo Joint Venture, also known as Korea Expo Joint Venture or KEJV, under Executive Order 13722. Treasury's language is blunter than the FBI's. Park "is part of the conspiracy responsible for conducting, among others, the February 2016 cyber-enabled fraudulent transfer of $81 million from Bangladesh Bank, the ransomware used in the May 2017 'WannaCry 2.0' cyber-attack, and the November 2014 cyber-attack on Sony Pictures Entertainment." Chosun Expo was designated as "an agency, instrumentality, or controlled entity of the Government of North Korea."

A sanction is the instrument a government reaches for when the warrant is not going to be served.

The 2021 indictment

On 17 February 2021 a grand jury indictment was unsealed in Los Angeles, 33 pages this time, and the defendant list had grown. Park Jin Hyok, 36. Jon Chang Hyok, 31. Kim Il, 27. All three described as members of the Reconnaissance General Bureau, North Korea's military intelligence agency. WannaCry 2.0 is in it again. Acting United States Attorney Tracy L. Wilkison: "The scope of the criminal conduct by the North Korean hackers was extensive and long-running, and the range of crimes they have committed is staggering."

NBC News, reporting the unsealing, put the practical position in one sentence: "The prospect of any of the North Korean hackers facing justice in a U.S. court is remote at best given their role in the regime."

So the score, as the paperwork stands. Charged with WannaCry: three. Sanctioned for it: one. Arrested for it: none. Arrested in the general vicinity of it: one researcher, for something else, sentenced to time served.

The affidavit of 8 June 2018 asked for an arrest warrant for Park Jin Hyok. Paragraph 14 says where he was: home.

Written and fact-checked by a practicing senior security engineer. Published under UNHACKED, which is accountable for it. How the Archive is written.

Further reading


EXHIBIT 0002 — WANNACRY

EXHIBIT 0002 is the incident, not the court case. The patch, the port, and the date.

Most people who see it will remember the headline about the hero who got arrested. A smaller number will know what he was actually arrested for.

That's the whole idea.

View the WannaCry shirt — EXHIBIT 0002

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.