wannacry
First seen May 12, 2017Active33 claimed victims
The claims below are reproduced as posted by wannacry on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
WannaCry ransomware is a cyber attack that spreads by exploiting vulnerabilities in the Windows operating system. At its peak in May 2017, WannaCry became a global threat. Cybercriminals used the ransomware to hold an organization's data hostage and extort money in the form of cryptocurrency. WannaCry spreads using EternalBlue, an exploit leaked from the National Security Agency (NSA). EternalBlue enables attackers to use a zero-day vulnerability to gain access to a system. It targets Windows computers that use a legacy version of the Server Message Block (SMB) protocol.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| State of Connecticut (12 State Agencies, including the Department of Administrative Services) | February 23, 2018 | ransomware_live | — |
| Becker County | August 16, 2017 | ransomware_live | — |
| Murfreesboro PD and FD | July 1, 2017 | ransomware_live | — |
| Honda Motor Co. | June 19, 2017 | ransomware_live | — |
| Telkom | May 16, 2017 | ransomware_live | — |
| Rensselaer County Library | May 15, 2017 | ransomware_live | — |
| Chinese traffic police, immigration and public security bureaus | May 12, 2017 | ransomware_live | — |
| Singapore shopping mall | May 12, 2017 | ransomware_live | — |
| Russian Railways | May 12, 2017 | ransomware_live | — |
| Hitachi | May 12, 2017 | ransomware_live | — |
| Cook County | May 12, 2017 | ransomware_live | — |
| China gas stations | May 12, 2017 | ransomware_live | — |
| MediaOnline | May 12, 2017 | ransomware_live | — |
| Renault | May 12, 2017 | ransomware_live | — |
| Indian police in the state of Andhra Pradesh | May 12, 2017 | ransomware_live | — |
| Sandvik | May 12, 2017 | ransomware_live | — |
| FedEx | May 12, 2017 | ransomware_live | — |
| MegaFon | May 12, 2017 | ransomware_live | — |
| Thailand Digital Billboard | May 12, 2017 | ransomware_live | — |
| Sberbank | May 12, 2017 | ransomware_live | — |
| National Health Service (NHS) UK | May 12, 2017 | ransomware_live | — |
| Deutsche Bahn (Germany Rail Network) | May 12, 2017 | ransomware_live | — |
| Brazil's social security system | May 12, 2017 | ransomware_live | — |
| Russian Interior Ministry | May 12, 2017 | ransomware_live | — |
| Chinese Police | May 12, 2017 | ransomware_live | — |
| Nissan | May 12, 2017 | ransomware_live | — |
| Russia Central Bank | May 12, 2017 | ransomware_live | — |
| Brazil's Foreign Ministry | May 12, 2017 | ransomware_live | — |
| Petrobras | May 12, 2017 | ransomware_live | — |
| Iberdrola | May 12, 2017 | ransomware_live | — |
| Portugal Telecom | May 12, 2017 | ransomware_live | — |
| Telefonica | May 12, 2017 | ransomware_live | — |
| Bank Of China | May 12, 2017 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).