{"id":20295,"date":"2017-05-22T16:31:11","date_gmt":"2017-05-22T16:31:11","guid":{"rendered":"https:\/\/www.legalgeek.co\/?p=20295"},"modified":"2017-05-22T16:31:11","modified_gmt":"2017-05-22T16:31:11","slug":"legal-geek-on-the-wannacry-global-hack","status":"publish","type":"post","link":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/","title":{"rendered":"Legal Geek on the WannaCry global hack"},"content":{"rendered":"<p>It\u2019s nearly 10 days after the global WannaCry hack, and at Legal Geek we\u2019re scratching our heads to work out what the real danger to emerge from this episode has really been. Is it the malware which affected 150 countries or the thinly-founded speculation and blame game which has followed?<\/p>\n<p>In light of that thought, we\u2019ve kept our summary simple.<\/p>\n<p><strong>What we know<\/strong><\/p>\n<p>On Friday 12 May, a global cyber attack spread across 150 countries affecting more than 200,000 organisations. In the UK, the attack affected 47 NHS trusts, leading to cancelled operations and people being turned away from A&amp;E. According to Moscow-based cyber security agency Kaspersky Lab, the worst affected countries were Russia, Ukraine, India, and Taiwan.<\/p>\n<p>The cyber attack deployed a variant of &#8220;WannaCry&#8221; ransomware which encrypts data, locks you out of your system, and demands a\u00a0ransom \u2013 paid in bitcoin currency \u2013 to release it.<\/p>\n<p>The attack exposed a weakness in Microsoft\u2019s Windows XP software making organisations still running Windows XP \u2013 such as the NHS in the UK \u2013 especially susceptible to attack.\u00a0<strong>We wonder if any law firms still run on Windows XP and, if they do, how well their IT Director is sleeping? \u00a0<\/strong>Especially scary when you consider cyber attacks on law firms have risen 60% in two years, according to PwC\u2019s 25th annual Law Firms Survey.<\/p>\n<p>Estimates so far place the pay-outs made at just over $70,000 \u2013 a paltry yield for the number of systems affected.<\/p>\n<p><strong>What we don\u2019t know <\/strong><\/p>\n<p>It\u2019s more than a week after the attack and SO many questions remain unanswered. Even a tech-savvy Miss Marple would be stuck for where to start. There is speculation of course, but as far as we can see there are no concrete answers to the following questions:<\/p>\n<ul>\n<li>Who did it?<\/li>\n<li>What was their motive and did they succeed?<\/li>\n<li>How was the ransomware acquired?<\/li>\n<li>Who was to blame for allowing it to happen?<\/li>\n<li>Is it over?<\/li>\n<\/ul>\n<p><strong>What people are speculating on <\/strong><\/p>\n<p>We couldn\u2019t cover this topic without highlighting the speculation, rumour and conjecture out there, but we encourage a healthy dose of scepticism to be applied to every theory.<\/p>\n<p><strong>Who did it? <\/strong><\/p>\n<p>Every organisation to offer a theory on who was behind the attack have caveated their findings with the words \u201cpreliminary\u201d, \u201ctentative\u201d or similar. BUT, fingers have been pointed in the direction of a hacker collective behind the 2014 Sony Pictures hack which was identified by US intelligence as a North Korean government operation.<\/p>\n<p>YET, chatter from US experts has also highlighted that parts of the WannaCry virus were amateurish and the payment system unsophisticated. Such a conclusion widens the net of potential hackers.<\/p>\n<p><strong>What was their motive and did they succeed?<\/strong><\/p>\n<p>If the aim of the hacking group or individual responsible was for monetary gain, then the hack failed spectacularly. Yet, if it were to cause havoc and fear across borders, it\u2019s been devastating. No one can really answer this one without speaking to the group responsible.<\/p>\n<p><strong>How<\/strong> <strong>was the ransomware acquired?<\/strong><\/p>\n<p>The hegemony around this one is that the US government had identified a weakness in Microsoft\u2019s Windows XP platform as long ago as last summer and had even developed a hacking tool to expose such a weakness. But this information was stolen by a hacking group with the theft being announced publically earlier this year. And Microsoft say that what was stolen from the US government formed the basis of this attack.<\/p>\n<p><strong>Who is to blame for allowing it to happen?<\/strong><\/p>\n<p>The blame game has seen Microsoft\u2019s President and Chief Legal Officer Brad Smith\u00a0say that the bulk of the responsibility lay with the US government for not informing Microsoft earlier about the vulnerability they had identified.<\/p>\n<p>Smith wrote in a blog post after the 12 May attack:<\/p>\n<blockquote><p>\u201cThis attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA (National Security Agency) has affected customers around the world.<\/p>\n<p>\u201cRepeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the US military having some of its Tomahawk missiles stolen. And this most recent attack represents a completely unintended but disconcerting link between the two most serious forms of cybersecurity threats in the world today\u2014nation-state action and organised criminal action.\u201d<\/p><\/blockquote>\n<p><strong>Is it over?<\/strong><\/p>\n<p><u><\/u>The attack has slowed down but new forms of the malware continue to be released, according to cybersecurity company Comae Technologies, whose founder Matt Suiche has claimed to have found new variants of the malware.<\/p>\n<p>In addition, the initial attack was slowed down by a UK-based researcher finding the \u2018kill switch\u2019 for the virus and activating it \u2013 but if new variants of the virus can be created which eliminate this \u2018kill switch\u2019 the virus, in an updated form, could continue to spread.<\/p>\n<p>More worryingly though is perhaps the precedent this attack sets and the encouragement it could give to other hackers to launch a virus of their own, for whatever motive they may have, and however twisted it may be.<\/p>\n<p><strong>Learn more about cyber security at our <a href=\"https:\/\/www.legalgeek.co\/conference\/\">Legal Geek Conference.<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s nearly 10 days after the global WannaCry hack, and at Legal Geek we\u2019re scratching our heads to work out what the real danger to emerge from this episode has really been. Is it the malware which affected 150 countries or the thinly-founded speculation and blame game which has followed? In light of that thought, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":20300,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20,21],"tags":[],"class_list":["post-20295","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-read"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Legal Geek on the WannaCry global hack - Legal Geek<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Legal Geek on the WannaCry global hack - Legal Geek\" \/>\n<meta property=\"og:description\" content=\"It\u2019s nearly 10 days after the global WannaCry hack, and at Legal Geek we\u2019re scratching our heads to work out what the real danger to emerge from this episode has really been. Is it the malware which affected 150 countries or the thinly-founded speculation and blame game which has followed? In light of that thought, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\" \/>\n<meta property=\"og:site_name\" content=\"Legal Geek\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/legalgeekco\/\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-22T16:31:11+00:00\" \/>\n<meta name=\"author\" content=\"Legal Geek\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@wearelegalgeek\" \/>\n<meta name=\"twitter:site\" content=\"@wearelegalgeek\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Legal Geek\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\"},\"author\":{\"name\":\"Legal Geek\",\"@id\":\"https:\/\/www.legalgeek.co\/#\/schema\/person\/2998cc5f819a0ded226c067a6d98e53b\"},\"headline\":\"Legal Geek on the WannaCry global hack\",\"datePublished\":\"2017-05-22T16:31:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\"},\"wordCount\":887,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.legalgeek.co\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage\"},\"thumbnailUrl\":\"\",\"articleSection\":[\"News\",\"Read\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\",\"url\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\",\"name\":\"Legal Geek on the WannaCry global hack - Legal Geek\",\"isPartOf\":{\"@id\":\"https:\/\/www.legalgeek.co\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2017-05-22T16:31:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.legalgeek.co\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Legal Geek on the WannaCry global hack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.legalgeek.co\/#website\",\"url\":\"https:\/\/www.legalgeek.co\/\",\"name\":\"Legal Geek\",\"description\":\"Legal Geek organises legal technology conferences around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.legalgeek.co\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.legalgeek.co\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.legalgeek.co\/#organization\",\"name\":\"Legal Geek\",\"url\":\"https:\/\/www.legalgeek.co\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.legalgeek.co\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.legalgeek.co\/wp-content\/uploads\/2023\/02\/Legal-Geek-Hi-Res-Black-on-Transparent-1.png\",\"contentUrl\":\"https:\/\/www.legalgeek.co\/wp-content\/uploads\/2023\/02\/Legal-Geek-Hi-Res-Black-on-Transparent-1.png\",\"width\":2550,\"height\":1967,\"caption\":\"Legal Geek\"},\"image\":{\"@id\":\"https:\/\/www.legalgeek.co\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/legalgeekco\/\",\"https:\/\/x.com\/wearelegalgeek\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.legalgeek.co\/#\/schema\/person\/2998cc5f819a0ded226c067a6d98e53b\",\"name\":\"Legal Geek\",\"sameAs\":[\"https:\/\/legalgeek.co\"],\"url\":\"https:\/\/www.legalgeek.co\/author\/lovelegalinfo52\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Legal Geek on the WannaCry global hack - Legal Geek","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/","og_locale":"en_US","og_type":"article","og_title":"Legal Geek on the WannaCry global hack - Legal Geek","og_description":"It\u2019s nearly 10 days after the global WannaCry hack, and at Legal Geek we\u2019re scratching our heads to work out what the real danger to emerge from this episode has really been. Is it the malware which affected 150 countries or the thinly-founded speculation and blame game which has followed? In light of that thought, [&hellip;]","og_url":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/","og_site_name":"Legal Geek","article_publisher":"https:\/\/www.facebook.com\/legalgeekco\/","article_published_time":"2017-05-22T16:31:11+00:00","author":"Legal Geek","twitter_card":"summary_large_image","twitter_creator":"@wearelegalgeek","twitter_site":"@wearelegalgeek","twitter_misc":{"Written by":"Legal Geek","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#article","isPartOf":{"@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/"},"author":{"name":"Legal Geek","@id":"https:\/\/www.legalgeek.co\/#\/schema\/person\/2998cc5f819a0ded226c067a6d98e53b"},"headline":"Legal Geek on the WannaCry global hack","datePublished":"2017-05-22T16:31:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/"},"wordCount":887,"commentCount":0,"publisher":{"@id":"https:\/\/www.legalgeek.co\/#organization"},"image":{"@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage"},"thumbnailUrl":"","articleSection":["News","Read"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/","url":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/","name":"Legal Geek on the WannaCry global hack - Legal Geek","isPartOf":{"@id":"https:\/\/www.legalgeek.co\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage"},"image":{"@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage"},"thumbnailUrl":"","datePublished":"2017-05-22T16:31:11+00:00","breadcrumb":{"@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.legalgeek.co\/legal-geek-on-the-wannacry-global-hack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.legalgeek.co\/"},{"@type":"ListItem","position":2,"name":"Legal Geek on the WannaCry global hack"}]},{"@type":"WebSite","@id":"https:\/\/www.legalgeek.co\/#website","url":"https:\/\/www.legalgeek.co\/","name":"Legal Geek","description":"Legal Geek organises legal technology conferences around the world.","publisher":{"@id":"https:\/\/www.legalgeek.co\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.legalgeek.co\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.legalgeek.co\/#organization","name":"Legal Geek","url":"https:\/\/www.legalgeek.co\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.legalgeek.co\/#\/schema\/logo\/image\/","url":"https:\/\/www.legalgeek.co\/wp-content\/uploads\/2023\/02\/Legal-Geek-Hi-Res-Black-on-Transparent-1.png","contentUrl":"https:\/\/www.legalgeek.co\/wp-content\/uploads\/2023\/02\/Legal-Geek-Hi-Res-Black-on-Transparent-1.png","width":2550,"height":1967,"caption":"Legal Geek"},"image":{"@id":"https:\/\/www.legalgeek.co\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/legalgeekco\/","https:\/\/x.com\/wearelegalgeek"]},{"@type":"Person","@id":"https:\/\/www.legalgeek.co\/#\/schema\/person\/2998cc5f819a0ded226c067a6d98e53b","name":"Legal Geek","sameAs":["https:\/\/legalgeek.co"],"url":"https:\/\/www.legalgeek.co\/author\/lovelegalinfo52\/"}]}},"_links":{"self":[{"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/posts\/20295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/comments?post=20295"}],"version-history":[{"count":0,"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/posts\/20295\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.legalgeek.co\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/media?parent=20295"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/categories?post=20295"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.legalgeek.co\/wp-json\/wp\/v2\/tags?post=20295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}