Europol chief says 200K computers in 150 countries were affected by WannaCry ransomware, while experts warn that new wave of attacks next week is likely
LONDON — Security experts are warning that the global cyberattack that began on Friday is likely to be magnified in the new workweek …
Context & Ripple Effects
WannaCry escalated fast: Friday's outbreak was spotted in 99 countries including the UK, US, Spain, China, and Russia, and by Sunday Europol's chief had roughly doubled the picture to 200,000 machines across 150 countries. The timing matters — the damage count landed on a weekend, with experts warning a second wave would hit when employees returned and reconnected unpatched machines.
This did not come from nowhere. A year earlier, researchers had documented ransomware volume quadrupling to about 4,000 attacks per day and shifting from personal computers toward entire networks — exactly the propagation model WannaCry demonstrated at global scale.
First-order effects
- Organizations in 150 countries spent the weekend racing to patch and isolate infected Windows machines before the workweek reopened their networks to a predicted second wave.
- Europol took on coordination of a cross-border incident response spanning far more jurisdictions than any single national cyber agency could handle.
Second-order effects
- A renewed wave on Monday would convert a consumer-and-hospital nuisance into a business-continuity crisis for firms that had not patched, forcing boards to treat ransomware as an operational risk rather than an IT ticket.
- Security vendors and managed service providers faced surging demand for emergency patching and network segmentation, repricing basic hygiene as urgent remediation.
Third-order effects
- The trajectory held: weeks later a follow-on attack reached WPP, AP Moller-Maersk, and agencies in Britain, the US, and the Netherlands, confirming that whole-network ransomware had become a recurring class rather than a one-off.
- Law enforcement adapted in kind — four years on, Europol detained 12 suspects behind ransomware operations hitting 1,800+ victims in 71 countries, signaling a durable international-policing counter-trend against industrialized ransomware crews.
The trend: Ransomware was crossing from per-machine extortion into self-spreading global network attacks, prompting both enterprise-wide defensive spending and transnational law-enforcement operations as the standing response.