The Ransomware Economy
Extortion industrialised. WannaCry in May 2017 spread on a leaked exploit and stopped hospitals; Colonial Pipeline in May 2021 interrupted fuel supply on the US east coast; ransomware-as-a-service turned all of it into a business with affiliates and support desks.
Part of Cybersecurity
16 moments in this segment.
- — The WannaCry ransom screen lock graphic. The padlock graphic from the WannaCry ransom pop-up of 12 May 2017. WannaCry used EternalBlue, an SMB exploit stolen from the NSA and dumped by the Shadow Brokers, and hit around 200,000 machines in 150 countries including large parts of the NHS. Marcus Hutchins stopped it by registering a hard-coded kill-switch domain for about ten dollars.
- — Countries hit in the first hours of WannaCry. A map of the countries affected in the first hours of WannaCry, drawn on 14 May 2017. It shows the speed a wormable exploit still had in 2017, seventeen years after ILOVEYOU.
- — BBC News on WannaCry causing global chaos. BBC News reports that tens of thousands of organisations were hit by WannaCry, which encrypted files and demanded payment of up to three hundred dollars, and that UK hospitals were among the victims, with some diverting patients. The clearest broadcast record of the attack's effect on health services.
- — Philippine television looks back at WannaCry. An ABS-CBN segment reviewing the WannaCry outbreak, which exploited a vulnerability in older versions of Windows, and what it meant for everyday computer security. A longer-form contemporaneous review rather than breaking coverage.
- — Nigerian television coverage of the WannaCry attack. Channels Television reports on WannaCry reaching about 150 countries. Coverage from outside the usual Western newsrooms, showing how globally the attack registered.
- — Journalist interviewed on CBSN during the WannaCry attack. A CBSN interview with reporter Eric Geller recorded on 12 May 2017, the first full day of the WannaCry attack. Analysis given while the scale of the incident was still unclear.
- — Bloomberg buys ransomware on the dark web. A Bloomberg investigations reporter buys ransomware on a dark-web market to show how little skill or money the criminal supply chain now requires. Documents the shift to ransomware sold as a product.
- — The Colonial Pipeline ransomware note, May 2021. A screenshot of the ransom note left on Colonial Pipeline's systems on 7 May 2021 by the DarkSide affiliate group. The company shut down 5,500 miles of fuel pipeline, causing panic buying across the US east coast, and paid about 4.4 million dollars, most of which the FBI later clawed back. It is the clearest demonstration that ransomware-as-a-service had become a national infrastructure problem.
- — A Colonial Pipeline right-of-way marker. A pipeline marker photographed weeks after the attack. It is a deliberately unglamorous image: the thing that was shut down by a compromised VPN password with no multi-factor authentication is a buried steel pipe in a field.
- — Conference talk on ransomware as a service. A recorded conference session on how ransomware became a rented service with affiliates, negotiation and support, and what that means for detection and response. A practitioner talk rather than an explainer.
- — CNBC on the group behind the Colonial Pipeline attack. TrustedSec's David Kennedy on CNBC on 12 May 2021, days after ransomware forced Colonial Pipeline to halt fuel deliveries on the US East Coast, discussing the criminal group and how such operations work. Period broadcast coverage.
- — Inside the ransomware economy on the dark web. A tour of the leak sites, forums and marketplaces that make up the ransomware criminal economy, showing how victims are named and data auctioned. Research into the infrastructure of extortion rather than a single incident.
- — Crumb's investigation into the LockBit ransomware operation. A long-form investigation into LockBit, the ransomware-as-a-service group whose affiliates hit Royal Mail and hundreds of other organisations, and into the effort to identify the people running it. It shows ransomware operating as a franchised business rather than a lone-hacker crime.
- — Cybernews on WannaCry. The 12 May 2017 WannaCry outbreak spread through a Windows SMB flaw and reached organisations in around 150 countries, including hospitals in the UK's National Health Service. The episode covers the domain registration that acted as a kill switch and stopped the spread.
- — Cybernews on the Colonial Pipeline ransomware attack. On 7 May 2021 ransomware hit the business network of Colonial Pipeline, the largest refined-fuel pipeline in the United States, and the company shut the pipeline down. The episode covers the fuel shortages and panic buying that followed and the partial recovery of the ransom payment.
- — Operation Cronos and the takedown of LockBit. How an international law-enforcement operation seized LockBit's infrastructure in February 2024 and turned the gang's own leak site into a countdown of police disclosures. The episode also covers how LockBit ran as a business, with affiliates, bug bounties and a leaderboard.

