Making Sense of the Ransomware Mess (and Planning a Sensible Path Forward)
Nolen Scaife, Patrick Traynor, Kevin R. B. Butler · IEEE Potentials · 2017
It started out as a seemingly isolated event. Reports early during the morning of 12 May 2017 talked about an unknown piece of ransomware attacking systems within the British National Health System (NHS) hospital network. Well over 50,000 NHS systems were infected, forcing affected hospitals to divert patients to other facilities. As hours passed, however, it became clear that this event was not isolated, and systems spanning more than 150 countries quickly succumbed to what would come to be known as WannaCry (which is known by multiple names including WanaCry, WannaCrypt, and WannaCrypt0r, among others.) Health care was not the only major industry impacted. As the attack continued, WannaCry also disrupted railways (e.g., Deutsche Bahn), the automotive industry (e.g., Renault rity Agency, a vulnerability that had an available patch for months prior (and multiple graduate courses in computer science and law could easily be built around this point alone). Major news outlets covered unpatched systems as the leading reason for this outbreak, and while this was a significant cause, the payload could have been any other kind of malware. The real takeaway from WannaCry is that once the ransomware had reached these systems, it successfully encrypted their data, despite having some of the best trained security staff and being protected by a wealth of traditional antivirus tools. Moreover, in the months since, we have seen at least two other significant ransomware attacks.