Case
WannaCry ransomware attack and attribution (2017-2018)
WannaCry was a self-propagating ransomware attack that spread internationally on 12 May 2017, encrypted data and demanded payment in Bitcoin. It belongs in context because it caused economic disruption and was attributed by governments to North Korea, but the available evidence does not establish it as an economic-compellence campaign.
In England, the National Audit Office found that the attack affected at least 80 of 236 National Health Service trusts and 603 other NHS organisations. Thousands of appointments and operations were cancelled, and some patients were diverted from affected accident and emergency departments. The audit did not identify patient harm caused by the incident and did not calculate a complete financial loss.
Attribution came later. In December 2017 the British government assessed that North Korean actors known as the Lazarus Group were responsible. In September 2018 the United States charged Park Jin Hyok over a wider alleged conspiracy that included WannaCry. The complaint recorded allegations, not a conviction, and should not be used to infer a strategic economic purpose beyond the conduct alleged.
The case illustrates the boundary between cybercrime, cyber conflict and economic statecraft. Its payment demand, actual receipts, operational disruption and recovery costs are separate categories. It also demonstrates how vulnerabilities in networked infrastructure can transmit economic harm far beyond the original intrusion.
The rapid spread was not evidence that each affected organisation was individually selected. Exposure, propagation and attribution answer different questions. This is why the case should not be used to infer a North Korean choice to coerce the NHS or any other particular victim without separate evidence of targeting and purpose.
See also
Ransomware and crypto-extortion toolkits · North Korean cryptocurrency theft campaign (2017-present) · North Korea
Sources
- United Kingdom National Audit Office, Investigation: WannaCry cyber attack and the NHS, 27 October 2017.
- United States Department of Justice, North Korean regime-backed programmer charged with conspiracy to conduct multiple cyber attacks, 6 September 2018. The complaint's claims remain allegations unless separately adjudicated.
- United Kingdom Government, Foreign Office minister condemns North Korean actor for WannaCry attacks, 19 December 2017. Use for the British government's attributed assessment.
Recommended citation
Cite this entry
Tennant, James J., ed. 'WannaCry ransomware attack and attribution (2017-2018).' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/wannacry-2017/.
Suggest an edit