EPISODE · Aug 23, 2026 · 16 MIN
WannaCry Explained: How One Worm Took Down the NHS in a Day
from Blue Team Academy · host Konnio Technology LLC
One piece of malware. No phishing. No user clicking anything. And on May 12, 2017, WannaCry took the UK's National Health Service offline in a single afternoon — 19,000 appointments cancelled, MRI scanners locked out, ambulances diverted.In this Breach File we walk through exactly what happened: the 59-day gap between the Microsoft patch and detonation, how the Shadow Brokers' leak of EternalBlue armed Lazarus Group to build a self-propagating cryptoworm, and how the kernel memory corruption in SMBv1 actually worked — no jargon, no glossing.Then we run it through the Threat and Control Method: Inventory, Threats, Controls, Scale — the same four-step loop we teach at Blue Team Academy for turning IT experience into blue team judgment.If you already work in IT — sysadmin, network engineer, help desk, cloud, ops — WannaCry is the clearest existing worked example of how the environments you already run get turned into weapons, and how ordinary IT hygiene applied with a defender's intent would have stopped almost all of it.━━━━━━━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━━━━━━━00:00 The Attack That Needed No Clicks00:24 Why WannaCry Still Matters01:18 Timeline of an Epidemic03:33 Lazarus Group and the Nation-State Threat05:21 How EternalBlue Actually Worked09:10 The $4 Billion Human Cost10:24 The Defense — Inventory, Threats, Controls, Scale15:11 Why This Isn't History16:03 Cybersecurity Is Not Rocket Science━━━━━━━━━━━━━━━━━━━━━━━━━━READ THE FULL BREACH FILE━━━━━━━━━━━━━━━━━━━━━━━━━━Full written breakdown with sources and code samples:https://blueteam-academy.com/breaches/wannacry-ransomware-attack-eternalblue-cryptoworm/━━━━━━━━━━━━━━━━━━━━━━━━━━BLUE TEAM ACADEMY━━━━━━━━━━━━━━━━━━━━━━━━━━We help experienced IT professionals move into defensive cybersecurity — without starting over. We teach the Threat and Control Method: a repeatable four-step decision process (Inventory → Threats → Controls → Scale) applied to real incidents like this one.Learn more: https://www2.blueteam-academy.com/from-it-to-cybersecurity/Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signupBlog: https://blueteam-academy.com/blogInstagram: @blueteamacad━━━━━━━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━━━━━━━- Microsoft Security Bulletin MS17-010 (March 14, 2017)- CISA/US-CERT Alert TA17-132A — WannaCry indicators- U.S. Department of Justice indictment of Park Jin Hyok (September 6, 2018)- UK National Audit Office — "Investigation: WannaCry cyber attack and the NHS" (October 2017)- Europol statement, May 2017 — 200,000 systems / 150 countries- MITRE ATT&CK — EternalBlue / T1210━━━━━━━━━━━━━━━━━━━━━━━━━━#Cybersecurity #BlueTeam #WannaCry #Ransomware #EternalBlue
Embed this episode
Ready to play
WannaCry Explained: How One Worm Took Down the NHS in a Day
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.