March 21, 2026, 1:13 a.m.
"On Friday, May 12, 2017, surgeries were cancelled across England, ambulance systems crashed, and hospital corridor screens filled with ransom messages. The reason: a security patch released 2 months earlier had not been installed."
WannaCry went down in history as the fastest-spreading ransomware ever. The attack that began on May 12, 2017, affected 230,000 systems in 150 countries in a single day. The most dramatic victim: England's National Health Service (NHS).
WannaCry: NHS hospitals paralyzed, surgeries cancelled
How Did WannaCry Work?
WannaCry exploited EternalBlue, a vulnerability developed and later leaked by the NSA (US National Security Agency). This vulnerability was a critical flaw in Windows' SMB (network sharing) protocol.
- Microsoft had released an emergency security patch for this vulnerability in March 2017 (MS17-010)
- WannaCry struck in May 2017 — 2 months later — targeting systems that hadn't installed this patch
- After infecting a system, it automatically spread across the entire network — no user interaction required
- It was attributed to the North Korea-linked Lazarus Group
What Happened at the NHS?
- 🔴 80 NHS trusts and 595 GP practices were affected
- 🔴 Hospitals were forced to cancel 19,000 appointments
- 🔴 Operating room screens filled with ransom messages — surgeries were halted
- 🔴 Ambulance calls had to be managed manually
- 🔴 NHS total damage: £92 million
- 🔴 NHS still had thousands of machines running Windows XP
Tragic reality: The person who stopped the attack was a security researcher. WannaCry's code contained a random domain name — the researcher purchased this domain for $10.69 and the attack automatically stopped. It was a 'kill switch'.
Impact in Turkey
WannaCry also hit Turkey. Unpatched systems were affected particularly in finance, healthcare, and public institutions. BTK issued emergency announcements on the day of the attack.
Lessons Learned
- ✅ Distinguish security patches from regular updates: Security patches must be applied IMMEDIATELY
- ✅ Legacy operating systems must be replaced: Unsupported systems like Windows XP are fatal for network security
- ✅ SMB protocol should be restricted: Unnecessary network protocols should be disabled
- ✅ Network segmentation: If one machine is compromised, only that segment should be affected, not the entire hospital network
- ✅ Patch management policy: Establish a process ensuring critical patches are applied within 48 hours
Leverage Nordis Global vulnerability scanning services to discover your security vulnerabilities.
Similar Posts