At least 45,000 hackers have unleashed thousands of ransomware attacks that are targeting organizations around the world Friday. The hack has disrupted services at hospitals, financial institutions and many others.

Security firm Kaspersky Lab has recorded thousands of attacks in 74 countries in the past 10 hours. Most of the attacks have targeted Russia. Exports say, WannaCry ransomware infects computers even without the vulnerability, EternalBlue is “the most significant factor” in the global outbreak.

Advertisement

What is it?

The ransomware, called “WannaCry,” locks down all the files on an infected computer and asks the computer’s administrator to pay in order to regain control of them. Researchers say it is spreading through a Microsoft Windows exploit called “EternalBlue,” which Microsoft released a patch for in March. A hacking group leaked the exploit in a trove of other National Security Agency spy tools last month.

“Effected machines have six hours to pay up, and every few hours the ransom goes up,” said Kurt Baumgartner, the principal security researcher at Kaspersky Lab. “Most folks that have paid up appear to have paid the initial $300 in the first few hours.”

Sixteen National Health Service (NHS) organizations in the UK have been hit, and some of those hospitals have canceled outpatient appointments and told people to avoid emergency departments if possible. Spanish telecom company Telefónica was also hit with the ransomware.

Spanish authorities confirmed the ransomware is spreading through the EternalBlue vulnerability and advised people to patch.

“It is going to spread far and wide within the internal systems of organizations — this is turning into the biggest cybersecurity incident I’ve ever seen,” UK-based security architect Kevin Beaumont said.

VIA