The leaked NSA exploit EternalBlue is being used by hackers to paralyze American cities like Allentown, San Antonio, and most recently Baltimore
For nearly three weeks, Baltimore has struggled with a cyberattack by digital extortionists that has frozen thousands of computers …
Context & Ripple Effects
The Baltimore attack is the third act of a two-year arc. The exploit entered the wild when the Shadow Brokers released the NSA-built EternalBlue, powering the WannaCry outbreak that hit unpatched Windows machines worldwide in May 2017. A year later Wired reported it had become a go-to tool for hackers precisely because so many machines were never patched — and Allentown and San Antonio had already demonstrated the municipal playbook.
Baltimore is now the case study in what happens when a city ignores that history: three weeks in, utilities billing, phone, and email remain offline, and experts told the Washington Post that victims like Baltimore still haven't taken basic measures against an exploit that has been public since 2017 two years after it first leaked.
First-order effects
- Baltimore is directly absorbing the damage: thousands of frozen computers, core services like utilities billing and email down for weeks, and an estimated $10M cleanup bill on top of $8M in deferred or lost revenue from unprocessed payments.
- Digital extortionists now have a proven, repeatable template — Allentown, San Antonio, then Baltimore — for holding city governments hostage with a single leaked exploit.
Second-order effects
- Every other US city running unpatched Windows infrastructure faces pressure to fund emergency patching and network segmentation, shifting municipal IT from backlog item to budget line before they become the next Baltimore.
- Ransomware operators gain pricing power over municipalities specifically because recovery costs — Baltimore's $10M-plus figure — routinely exceed ransom demands, making payment look rational to desperate city officials.
Third-order effects
- If the pattern holds, the NSA's exploit stockpiling faces renewed scrutiny: weapons built in secret escaped via the Shadow Brokers leak and are now a standing tax on American local government, strengthening the argument for disclosing vulnerabilities to vendors rather than hoarding them.
- Municipal ransomware is consolidating into a structural cost of governance — cities that don't treat patching as critical infrastructure will keep paying, either in cleanup bills or ransoms, on a predictable cycle.
The trend: Leaked NSA cyberweapons are turning municipal ransomware into a recurring, budgetable cost of American city government, with each unpatched victim funding the next attacker's playbook.