Hackers are using EternalBlue vulnerability discovered by NSA and an exploit released by Shadow Brokers to infect unpatched Windows computers with WannaCry
A new strain of ransomware has spread quickly all over the world, causing crisis in National Health Service hospitals and facilities around England …
Context & Ripple Effects
WannaCry is the first mass deployment of EternalBlue, an NSA-built Windows exploit that the Shadow Brokers leak put into any hacker's hands. Within days it had crippled National Health Service hospitals across England, forcing cancelled procedures and diverted ambulances.
The blast radius kept growing after this story: researchers found EternalBlue had already powered a quieter, possibly larger crypto-mining campaign (Adylkuzz), Eset and Recorded Future flagged a Petya variant reusing the same exploit weeks later, and by 2018 Wired called the leaked tool a go-to for hackers because so many machines stayed unpatched.
First-order effects
- Unpatched Windows users — most visibly NHS hospitals in England — face immediate encryption of files and disrupted care, with no fix available until machines are patched or taken offline.
- Attribution pressure lands on North Korea: NSA and Britain's National Cyber Security Centre later linked the attack to the Lazarus hacking group, turning a criminal incident into a state-actor case.
Second-order effects
- EternalBlue stops being a one-off weapon and becomes commodity infrastructure — copycat campaigns like the Petya variant fold the same exploit into new ransomware that also harvests passwords from infected systems.
- Organizations that skipped patching become repeat targets: two years on, the same leaked exploit is paralyzing American city governments including Allentown, San Antonio, and Baltimore.
Third-order effects
- The leak establishes a lasting pattern: once a stockpiled government exploit escapes, it outlives its original owner and shifts the burden of defense onto every unpatched machine worldwide.
- Sustained exploitation of a single leaked vulnerability pushes patching discipline and disclosure policy toward the center of national security debates, since civilian infrastructure — hospitals, then city networks — absorbs the cost of intelligence-agency tooling.
The trend: Leaked nation-state exploits are becoming durable criminal infrastructure, with each unpatched population converting a single intelligence-agency tool into years of ransomware campaigns.