You are currently viewing 2016–2019: WannaCry, NotPetya & Mirai

2016–2019: WannaCry, NotPetya & Mirai

  • Post author:
  • Post category:Security
📋 Key Takeaways
  • The World in 2016
  • 15. The Yahoo Breaches (2013–2016 disclosed) — Three Billion Accounts
  • 16. The Ukraine Power Grid Attacks (2015 & 2016) — The First Hacker-Caused Blackouts
  • 17. The Bangladesh Bank Heist (2016) — North Korea Robs a Central Bank
  • 18. The Mirai Botnet (2016) — The Internet of Things Becomes an Army
28 min read · 5,535 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

2016–2019: WannaCry, NotPetya & Mirai

← Back to the full list · Previous: Part 3 — 2009–2015

The World in 2016

Between 2016 and 2019, three forces converged to produce the most destructive years the internet had ever seen. First, the Shadow Brokers — a still-unidentified actor — began leaking America’s own NSA hacking tools online, handing military-grade exploits to anyone with a torrent client. Second, ransomware industrialized, evolving from isolated criminal scams into a full criminal service economy with affiliates, helpdesks, and negotiation teams. Third, the Internet of Things arrived with no security at all — billions of cameras, routers, and recorders with factory passwords, connected straight to the open internet.

Into this tinderbox, nation-states threw matches: Russia’s military intelligence tested destructive attacks on Ukraine that escaped worldwide; North Korea robbed a central bank and then detonated ransomware across 150 countries. The eight stories in this part include the costliest cyberattack in history and the largest data breach in history — and the strange reality that a 22-year-old with a domain registration habit saved the UK’s health service.


15. The Yahoo Breaches (2013–2016 disclosed) — Three Billion Accounts

Attackers Russian FSB intelligence officers directing criminal hackers (per 2017 US indictments)
Target Yahoo — then the world’s largest email provider
Method Sustained network access; account-hijacking via forged cookies; mass data exfiltration
Damage All 3 billion accounts — the largest data breach in history
Cost $350M knocked off Yahoo’s sale price; a $35M SEC fine; 5 years in prison for one accomplice

How the attack unfolded

Yahoo was breached twice, catastrophically, and the full truth took four years to surface — a concealment nearly as scandalous as the hacks themselves.

The 2014 breach was, according to the US Justice Department’s March 2017 indictment, an intelligence operation brazenly staffed with criminals: two officers of Russia’s FSB — Dmitry Dokuchaev and Igor Sushchin, assigned to the cyber arm of Russia’s security service — contracted elite hacker Alexsey Belan (already on the FBI’s Most Wanted list) and, for targeted account takeovers, a young Canadian-Kazakh hacker named Karim Baratov. Belan reportedly roamed Yahoo’s network for years — accessing user databases and a management tool that could edit accounts — while the FSB officers directed him toward intelligence targets: Russian journalists critical of the Kremlin, US and Russian government officials, and employees of financial services and cryptocurrency companies. Baratov, a 22-year-old who ran a thriving business hacking specific Gmail accounts on request for paying clients, was paid to break into targeted non-Yahoo accounts whose owners had backed them up to Yahoo addresses. The thieves monetized where convenient — Belan was charged with running spam and search-engine manipulation schemes from inside Yahoo’s own infrastructure — but the crown jewels were the databases themselves: 500 million users’ names, email addresses, phone numbers, dates of birth, poorly hashed (MD5) passwords, and — fatally — unencrypted security answers.

Then it got worse. In December 2016, as Verizon was finalizing its acquisition of Yahoo, the company admitted a second, older breach: first estimated at 1 billion accounts, then corrected in October 2017 to the definitive, mind-bending figure: every one of the approximately 3 billion accounts that existed. The 2013 breach’s perpetrator has never been charged; investigators have variously described an organized criminal group with uncertain state ties. Separately, Yahoo also disclosed in 2017 that intruders had used forged session cookies — minted with stolen proprietary code — to access some 32 million accounts in 2015–2016.

The disclosure story became its own landmark. Yahoo had known about the 2014 hack since 2014 and stayed publicly silent for two years while negotiating its sale. Verizon, upon learning the scale, renegotiated: a $350 million cut off the $4.83 billion deal. In 2019 the SEC fined Yahoo $35 million — the commission’s first-ever penalty against a company for failing to timely disclose a breach. CEO Marissa Mayer forfeited her annual bonus and equity award.

The damage

Three billion accounts meant every Yahoo user on Earth: passwords (weakly hashed), security answers (plain), phone numbers, birthdates. The security-answer leak was uniquely poisonous — those same “mother’s maiden name” answers unlocked other services across people’s digital lives, a gift to account-takeover criminals that keeps giving to this day.

Aftermath & lessons

  • Karim Baratov was arrested in Canada in 2017, pleaded guilty, and received five years in prison and ~$2.9 million in restitution — one of the few convictions ever obtained in a state-linked megabreach. The FSB officers were charged but remain in Russia, untouchable; Dokuchaev was reportedly arrested in Moscow in late 2016 in an unrelated treason context.
  • The case wrote the modern rulebook on breach disclosure: the Securities and Exchange Commission now treats cyber incidents as material information — discovering a breach creates a legal clock, and sitting on it costs more than the breach.
  • Architecturally, Yahoo’s fall — no ubiquitous MFA, MD5 hashes, plaintext security answers, sprawling legacy infrastructure — became the checklist of everything the industry spent the next decade fixing.

The core lesson: the largest breach in history wasn’t a single genius intrusion; it was years of quiet access to a giant that didn’t notice, didn’t disclose, and paid twice — once to the attackers, once to the market.


data-hmmnm-seam="2">

16. The Ukraine Power Grid Attacks (2015 & 2016) — The First Hacker-Caused Blackouts

Attacker Russian military intelligence (GRU) — the “Sandworm” unit; formally attributed by the US in 2020
Targets Three Ukrainian electricity distribution companies (2015); a Kyiv transmission substation (2016)
Method Spear-phishing (BlackEnergy3), credential theft, manual SCADA operation, and destructive KillDisk wipers
Damage ~230,000 people left without power mid-winter; equipment destroyed; the first confirmed cyber-caused blackouts
Cost Modest in dollars; historic in consequence — the founding events of grid cybersecurity

How the attack unfolded

On the evening of December 23, 2015, operators at three regional Ukrainian power companies watched something out of a techno-thriller: cursors moved across their screens on their own, opening breakers at substations one after another. It was no malfunction. Attackers — later attributed with high confidence to the GRU unit the industry calls Sandworm — had spent months inside the utilities’ networks, having entered through spear-phishing emails carrying the BlackEnergy3 trojan and harvesting credentials with impunity.

When the moment came, the intruders didn’t need exotic malware for the act itself: they simply logged into the companies’ remote SCADA systems with stolen credentials and manually operated the grid-switching interfaces — the same screens the operators used — tripping breakers at roughly 30 substations. Then they slammed every door behind them: launching KillDisk wipers that destroyed workstations and servers, corrupting the firmware of serial-to-ethernet gateway devices so replacements were needed (not just reimaging), and DDoS-ing the customer call centers so thousands of newly powerless households couldn’t even report the outage. Roughly 225,000–230,000 people lost electricity in the dead of a Ukrainian winter — most for one to six hours, but some remote areas for days.

One year later, almost to the day (December 17, 2016), the same attackers returned to prove a more frightening point. A single transmission substation north of Kyiv went dark for about an hour in the freezing evening — this time delivered by Industroyer (a.k.a. CrashOverride), a malware framework that autonomously speaks the legacy industrial protocols power grids run on (IEC 60870-5-101/104, IEC 61850, OPC). No hands on the keyboard at the moment of attack. Analysts concluded it was likely a test deployment — a demonstration that grid attacks could be automated — and noted Industroyer’s capability to trigger protection relays in ways that could damage equipment at scale.

The damage

The dollar cost was modest; the precedential cost was immense. These were the first confirmed instances in history of hackers causing electric blackouts. They validated every worst-case planning scenario in Western utilities, and Ukraine became — unwillingly — the world’s live laboratory of cyber-warfare. In February 2020, the US State Department formally attributed both attacks (and the 2017 NotPetya and other operations) to Russia’s GRU Main Centre for Special Technologies (unit 74455, “Sandworm”) — later sanctioned by multiple governments.

Aftermath & lessons

  • Ukraine built the playbook. Its utilities — with Western help — overhauled segmentation, defensible architectures, backup restoration, and manual-fallback operations. Those lessons were applied literally within Ukraine in later wartime attacks (2017 NotPetya, and the 2022 grid attacks during the full-scale invasion).
  • The E-ISAC/SANS report on the 2015 attack became the most-studied incident-response document in industrial cybersecurity, and versions of its recommendations now live in NERC CIP standards and every national grid-security framework.
  • The 2015 attack’s signature — long dwell time, credential abuse, manual control, destructive cleanup — is now the standard assumed threat model for OT security everywhere.

The core lesson: attackers don’t need to hack the grid’s hardware; they can simply log in as the operators. Defense means treating credentials, monitoring, and the ability to operate manually as core resilience — because Ukraine’s grid crews restored power precisely because they could still work the switches by hand.


data-hmmnm-seam="3">

17. The Bangladesh Bank Heist (2016) — North Korea Robs a Central Bank

Attacker Lazarus Group — North Korea’s state hacking unit (US charged programmer Park Jin Hyok in 2018)
Target Bangladesh Bank’s reserve account at the Federal Reserve Bank of New York
Method Long-term network compromise of the bank, then forged SWIFT payment messages
Damage $81 million stolen; an attempted $951 million narrowly averted
Cost $81 million gone (largely unrecovered); the birth of state bank robbery as a funding model

How the attack unfolded

On February 4, 2016, a Thursday before a weekend, attackers who had spent months inside Bangladesh Bank’s network — having entered through older, unpatched systems and moved laterally to the machine connected to the SWIFT interbank messaging network — began sending payment instructions to the Federal Reserve Bank of New York, where Bangladesh kept a reserve account of roughly a billion dollars. In all, they transmitted instructions for 35 transfers totaling $951 million, routing the money toward accounts they’d prepared in the Philippines and Sri Lanka: a fake “Shalika Foundation” in Colombo, and four personal accounts at a branch of the RCBC bank in Manila that had been opened days earlier with the help of a remittance insider.

The plan nearly unraveled on a typo — and survived by bureaucracy’s grace. A $20 million transfer to Sri Lanka was stopped when bank staff noticed the misspelled name “FANDATION” in the recipient’s documents and queried the payment. But the Philippines-bound instructions passed initial checks, and the weekend (in Bangladesh, Friday–Saturday) plus a subtle act of sabotage — the attackers had disabled the bank’s SWIFT transaction printers, so the paper log of the fraudulent messages wouldn’t be noticed — delayed discovery for days. By the time Bangladesh Bank, the NY Fed, and SWIFT fully compared notes, $81 million had landed in Manila.

There it was laundered with almost cinematic thoroughness: the money flowed into two Manila casinos through “junket” operators, converted into gambling chips at high-roller baccarat tables, and dissipated. About $16–18 million was later recovered in fragments from a casino and a junket broker’s estate; most of the $81 million has never been found.

Attribution pointed quickly to Lazarus Group, North Korea’s premier hacking unit: tools, infrastructure, and tradecraft matched earlier operations. In September 2018, the US Justice Department indicted Park Jin Hyok, a programmer in North Korea’s Reconnaissance General Bureau, charging him with the Bangladesh Bank heist, the Sony Pictures hack, and the WannaCry outbreak (see below) — one indictment spanning a decade of one state unit’s career. The motive was novel and consequential: with international sanctions squeezing its weapons programs, North Korea had turned to hacking as state revenue, and banks were the richest target available.

The damage

Beyond the stolen millions, the heist terrified the global financial plumbing. If attackers could forge SWIFT messages from a central bank, no correspondent relationship was safe. SWIFT responded with its Customer Security Programme — mandatory security controls and independent assessments for the 11,000+ institutions on its network — and central banks worldwide launched emergency reviews of their own operations.

Aftermath & lessons

  • Lazarus and its affiliate crews ran the same playbook against banks and payment infrastructure in Taiwan, Ecuador, Vietnam, Mexico, India, Chile, and elsewhere — most stopped before payout, making Bangladesh the infamous exception that proved it could work.
  • The campaign scaled into cryptocurrency: United Nations experts later attributed billions of dollars in crypto-exchange thefts to North Korean groups, funding the regime’s weapons programs. The Bangladesh heist was the founding act of that economy.
  • The operational lesson — central banks now rehearse SWIFT-specific incident response, printer and terminal integrity checks included — is among the strangest audit items in modern banking.

The core lesson: when a state needs money and can’t earn it, it will steal it by code. And a heist that fails on a typo can succeed on a weekend — timing, silence, and small acts of sabotage (a disabled printer) matter as much as the exploit.


data-hmmnm-seam="4">

18. The Mirai Botnet (2016) — The Internet of Things Becomes an Army

Attackers Paras Jha, Josiah White, Dalton Norman — three young US men (plus a global criminal copycat wave)
Target Unsecured IoT devices: IP cameras, DVRs, home routers — then the internet’s DNS layer
Method Malware brute-forcing ~60 factory-default credentials and enslaving devices into a DDoS botnet
Damage A botnet of ~600,000 devices; record-setting DDoS attacks; major swaths of the US internet offline
Cost Never totaled; the October 2016 outage alone affected dozens of the world’s biggest websites

How the attack unfolded

In mid-2016, three young American men — Paras Jha, a Rutgers University student among them — wrote a small piece of malware with a simple, devastating premise. Mirai (“future” in Japanese) continuously scanned the internet for IoT devices — mostly cheap IP cameras, digital video recorders, and home routers — and attempted to log in using a hard-coded list of about 60 factory-default username/password pairs (admin/admin, root/root, and friends). Manufacturers shipped millions of such devices with credentials no user could change even if they knew, because many had no update mechanism at all. Each successfully infected device quietly joined a command-and-control army that swelled to roughly 600,000 zombie cameras and routers worldwide.

The first spectacular demonstration came on September 20, 2016, when security journalist Brian Krebs — whose reporting had recently helped take down a rival DDoS-for-hire service — was hit with a then-record flood of ~620 Gbps, among the largest attacks ever seen, more than his free protection could absorb. (Days later, the French host OVH reported Mirai peaks exceeding 1 Tbps.) Then the authors did the thing that changed internet history: on September 30, they published Mirai’s source code on a hacking forum. It remains unclear whether it was bravado, an alibi, or a gift to the copycats — but the effect was to democratize record-breaking DDoS.

The main event arrived on October 21, 2016. Mirai (in the hands of one of the original authors, per later court filings, as an apparent extortion/DDoS-for-hire operation) flooded Dyn, a company operating DNS — the internet’s phone book — for an enormous share of major websites. With DNS resolution failing, users on the US East Coast and beyond found Twitter, Netflix, Reddit, Spotify, PayPal, GitHub, Airbnb, CNN, and many others simultaneously unreachable — not because the sites were down, but because the internet couldn’t look up their addresses. It was the first time most people experienced the internet “breaking” as a single shared event; PayPal alone reported losses, and the outage rippled through commerce and media for hours. Further Mirai waves briefly degraded internet connectivity for the entire country of Liberia.

The damage

The Dyn attack’s innovation was the target: not a website, but shared infrastructure — proving that a botnet built from $60 webcams could degrade the internet experience of a continent. For the IoT industry, it was a verdict: security researchers’ years of warnings about connected-device junk were now visible to every Netflix subscriber on the Eastern Seaboard.

Aftermath & lessons

  • The three authors were caught (in part through their earlier use of botnets against Rutgers during exam-registration periods) and pleaded guilty in December 2017; Jha received prison time (six months) plus a restitution order for the Rutgers attacks, famously also working afterward with the FBI and agreeing to help combat botnets. The punishments were strikingly light relative to the global damage — a sore point in security-policy debates ever since.
  • Governments finally legislated IoT security: California’s SB-327 (the first US IoT-security law, effective 2020) and the UK’s Product Security and Telecommunications Infrastructure Act (enforced from 2024) both ban default-password shipping — closing, a decade late, the exact hole Mirai drove through.
  • Mirai’s descendants (Satori, Okiru, and endless variants) still prowl; the source-code release ensured permanent life.

The core lesson: security is a systems problem — Mirai needed no exploits at all, just manufacturers who shipped passwords and users who were never given a choice. When a billion cheap devices share one flaw, the flaw is the internet’s.


data-hmmnm-seam="5">

19. WannaCry (2017) — The Ransomware That Hit 150 Countries in a Day

Attacker North Korea — Lazarus Group (formally attributed by the US, UK, and others; charged in the Park Jin Hyok indictment)
Target Unpatched Windows machines worldwide — hospitals, telcos, logistics, manufacturing
Method Ransomware worm built on the NSA’s stolen EternalBlue exploit, spreading autonomously via SMB
Damage 230,000+ computers in 150+ countries in one day; ~$4 billion estimated losses; UK NHS disrupted for weeks
Cost NHS alone: £92 million; ~19,000 appointments and operations canceled

How the attack unfolded

The road to WannaCry began inside the NSA. For years, American intelligence had quietly stockpiled a weapon: EternalBlue, an exploit against a flaw in Windows’ SMB file-sharing protocol, effective against millions of unpatched machines. In April 2017, the mysterious Shadow Brokers — who had been dripping NSA tools online since 2016 — published EternalBlue to the world. Microsoft had already issued a patch (the leak forced its hand), but on planet Earth, patching is slow: hundreds of millions of machines remained open.

On May 12, 2017, someone armed ransomware with it. WannaCry encrypted files and demanded $300–600 in bitcoin — but the truly novel feature was propulsion: it spread itself across networks like a worm, no clicks required, hopping machine-to-machine via EternalBlue. From a handful of initial infections, it exploded to over 230,000 computers in more than 150 countries within a single day. Telefonica in Spain, Germany’s Deutsche Bahn, Renault factories in France, FedEx, Russia’s interior ministry and banks (Russia was among the worst-hit countries), Taiwan’s coast guard — the world’s unpatched back office, encrypted in hours.

The defining images came from Britain’s National Health Service. At least 80 NHS trusts were disrupted: staff locked out of systems, patient records inaccessible, ambulances rerouted away from affected emergency rooms. Approximately 19,000 appointments and operations were canceled — including chemotherapy sessions — before the outbreak was contained. The UK Department of Health later put the cost to the NHS at £92 million, with the National Audit Office criticizing years of unaddressed warnings about outdated Windows estates across the health service.

Then came the twist that made the story immortal. A 22-year-old British security researcher, Marcus Hutchins (blogging as MalwareTech), began reverse-engineering samples and noticed the malware repeatedly tried to contact an odd, unregistered domain — a kill switch the authors had built in to retain an off-switch (or to detect sandbox analysis). On a hunch, Hutchins registered the domain for about $10. Every subsequent infection, finding the domain live, shut itself down — and the outbreak’s momentum collapsed within hours. A global pandemic ended, effectively, by a domain purchase. (In a bitter coda, Hutchins was arrested months later in the US over unrelated malware he’d created years earlier as a teenager; he pleaded guilty to minor charges and was sentenced to time served — the community overwhelmingly credited him as WannaCry’s savior.)

Attribution settled on North Korea’s Lazarus Group — the same unit as Sony and Bangladesh Bank — with the US government formalizing it in June 2017 and folding WannaCry into the 2018 Park Jin Hyok indictment. For all its chaos, WannaCry was a poor money-maker: barely ~$150,000 in ransoms was ever visible in its bitcoin wallets, a rounding error against $4 billion in damage. It wasn’t really about money. It was capability — demonstrated at planetary scale.

The damage

Beyond the NHS and the canceled operations, WannaCry’s deepest damage was conceptual: it merged the worm (self-spreading), the stolen state exploit (EternalBlue), and ransomware into one organism. Every “spray” ransomware crew on Earth learned the formula; six weeks later, the same exploits powered something far worse.

Aftermath & lessons

  • The Vulnerabilities Equities Process — the debate over whether governments should hoard or disclose flaws — went mainstream, with Microsoft’s president famously calling for a “Digital Geneva Convention.” WannaCry is the permanent exhibit for the hoarders’ risk: your weapon will leak, and your citizens’ hospitals will pay for it.
  • Patching finally became a board-level metric. Windows XP estates worldwide (especially in healthcare) got funded replacements — slowly.
  • The Hutchins kill-switch moment made outbreak telemetry and sinkholing a formal discipline in threat intel.

The core lesson: on an internet of unpatched networks, a state’s leaked tool + criminal monetization = global outage. And luck — a kill switch, a curious researcher — is not a strategy.


20. NotPetya (2017) — The Most Expensive Cyberattack in History

Attacker Russian military intelligence (GRU) Sandworm unit; formally attributed by the US, UK, and five allies in 2018; six GRU officers indicted in 2020
Target Ukraine — deliberately — via the M.E.Doc accounting software update channel; then the world, indiscriminately
Method Destructive wiper disguised as ransomware, spreading via EternalBlue/EternalRomance and stolen Windows credentials
Damage ~$10 billion in global losses — the costliest cyberattack ever
Cost Maersk ~$300M, Merck ~$870M+, FedEx/TNT ~$400M, Saint-Gobain ~$384M, Reckitt ~$129M, Mondelēz ~$100M+

How the attack unfolded

On June 27, 2017 — the day before Ukraine’s constitution-day holiday — computers across Ukraine began dying: at the cabinet ministry, banks, the Kyiv metro, the state post office, the Chernobyl radiation-monitoring systems, at airports and newspapers and thousands of ordinary businesses. The malware displayed a fake “ransomware” screen claiming to be Petya, an earlier criminal strain, demanding $300 in bitcoin. The disguise was skin-deep: the “payment” email address had already been shut down, and the code didn’t even track per-victim keys. Nothing could be decrypted. This was not ransomware. It was a wiper — a weapon, dressed in a criminal’s clothes.

The delivery mechanism was the genius of the operation. Ukraine’s businesses overwhelmingly used M.E.Doc, a domestic accounting suite everyone needed for local tax filings. The attackers compromised M.E.Doc’s update infrastructure and pushed their malware as a signed software update — so on June 27, thousands of Ukrainian companies voluntarily installed the attack during routine updates. From each landing point, it spread like wildfire using EternalBlue and EternalRomance (the leaked NSA exploits, same as WannaCry) plus something far more effective: credential harvesting via standard Windows admin tools (Mimikatz-style). It read passwords and session tickets from infected machines and used them to hop to every other machine those credentials touched — across trusts, into file servers and domain controllers, and out through corporate VPNs into the global offices of multinationals. Wherever a Ukrainian subsidiary existed, the fire followed the corporate network outward.

And so the world burned with Ukraine. Maersk, the world’s largest container-shipping line, lost its entire global IT estate — 49,000 laptops and 4,000 servers — within hours; terminals on multiple continents reverted to manual operations; 76 port facilities worldwide were affected. Merck, the pharmaceutical giant, lost ~30,000 computers and 7,000 servers, disrupting vaccine manufacturing (including its production of Gardasil, contributing to later shortages). FedEx’s TNT Express subsidiary was crippled in Europe. Saint-Gobain, Reckitt Benckiser, Mondelēz (its chocolate plant in Tasmania stopped), Beiersdorf, DLA Piper, WPP, Rosneft — the roll call crossed every industry and continent.

The Maersk survival story became the legend of the incident: the company’s entire Active Directory infrastructure — the master keys to its global network — was destroyed, except for one domain controller in a remote Ghana office that happened to be offline during the attack (cut off by a power outage, reportedly). That single uninfected server, flown to headquarters, became the seed from which Maersk rebuilt its global network in ten days — a herculean effort involving replacing ~45,000 PCs, with staff worldwide working around the clock.

The White House, in an unusual formal attribution in February 2018 (joined by the UK and other allies), called it “the most destructive and costly cyberattack in history” and pinned it on the Russian military — the GRU’s Sandworm, the same unit behind the Ukrainian blackouts. In October 2020, the DOJ indicted six GRU officers for NotPetya alongside other global operations. Russia, as ever, denied everything.

The damage

Total global losses were estimated by the White House at roughly $10 billion, and by insurers at more. The legal aftermath rewrote cyber-insurance: Merck’s insurers argued the “war exclusion” applied (nation-state attack = act of war); New Jersey courts ultimately sided largely with Merck in a landmark ~$1.4 billion coverage dispute, while Mondelēz’s similar claim in the UK largely failed on different policy wording. The era of asking whether “war” includes cyber-war had begun.

Aftermath & lessons

  • NotPetya proved that geography is not segmentation: an attack aimed at Ukraine destroyed global logistics because multinational networks trust their own subsidiaries. Every enterprise architecture review since includes the question: what can our regional office reach?
  • Backups must be offline and tested — thousands of companies restored in days because of good backups; Maersk survived because of one offline server and extraordinary planning.
  • The “wiper disguised as ransomware” concept forced response teams to stop assuming ransomware negotiations were an option — and taught insurers to rewrite policies.

The core lesson: the most expensive cyberattack in history wasn’t aimed at its victims at all. On a networked planet, destruction is contagious — and your disaster recovery plan is your last, best weapon.


21. The Equifax Breach (2017) — 147 Million Americans, One Unpatched Server

Attackers Four officers of China’s People’s Liberation Army (indicted by the US in February 2020)
Target Equifax — one of the three big US credit bureaus
Method Exploitation of a known Apache Struts vulnerability on an untracked web application
Damage Personal data of 147 million people — nearly every American adult with a credit file
Cost Up to $700M settlement; $1.4B+ total; careers ended; a congressional verdict of “entirely preventable”

How the attack unfolded

Equifax’s business is knowing everything about everyone’s finances — income estimates, credit lines, payment histories, Social Security numbers. In March 2017, the software world disclosed a critical remote-code-execution flaw in Apache Struts (CVE-2017-5638) and shipped a patch on March 7. Equifax’s internal procedures required patching within 48 hours. But the vulnerable Struts application was an online consumer-dispute portal that, thanks to sloppy asset inventory, nobody had flagged as running Struts — so no patch was scheduled for it. Worse, Equifax’s vulnerability scanner was silently broken: an expired digital certificate meant the scanner hadn’t reported results for months. The safety systems existed; nobody checked whether they were alive.

The attackers — later identified as four members of China’s PLA 54th Research Institute — found the hole almost immediately: forensic evidence shows they began exploiting the portal around May 13, two months after the patch existed. Over 76 days they operated at will: installing web shells for persistent access, pivoting through the network, reaching databases containing the records of 147 million people — names, Social Security numbers, birth dates, addresses, and in many cases driver’s-license numbers — plus roughly 209,000 payment cards. The data was exfiltrated in encrypted chunks over 76 days of quiet, quarterly-unmonitored traffic.

Equifax discovered the intrusion on July 29, 2017 — during a routine (rare) review of network traffic — and contained the attackers the next day. Then came the corporate failures that defined the scandal: the breach was disclosed publicly only on September 7, 2017 — and in the interval, several senior executives sold stock. An internal review cleared them of trading on knowledge of the breach, but the optics were fatal: CEO Richard Smith “retired” within weeks; the CIO and CSO departed too.

The damage

For consumers, the breach was permanent: Social Security numbers don’t get reissued, so 147 million Americans (and some Canadians/UK residents) will spend lifetimes at elevated identity-theft risk. The 2019 settlement with the FTC, CFPB, and 48 states — up to $700 million, including a $425 million consumer restitution fund (which notoriously offered alternately $125 cash or years of credit monitoring, then ran short) — is among the largest data-breach settlements in history. The GAO’s post-mortem catalogued the mundane causes: no inventory, no patch, dead scanner, no traffic monitoring — findings so damning Congress published them as a checklist for industry.

Aftermath & lessons

  • In February 2020 — a rare move against named military officers — the DOJ indicted the four PLA hackers (who remain in China). The indictment’s detail (searches, infrastructure, even taunts) made clear how methodical and state-directed the operation was.
  • Equifax became the permanent case study for asset inventory — you cannot patch what you don’t know exists — and for monitoring your monitoring (the expired certificate is the detail everyone remembers).
  • The settlement’s chaos (claim-fund shortfalls) fed lasting skepticism about “free credit monitoring” as a remedy, pushing regulators toward cash restitution models.

The core lesson: the breach that exposed half a country required zero genius — just an unpatched server nobody knew about and a broken scanner nobody checked. Boring discipline is the whole game.


22. The Marriott/Starwood Breach (2014–2018) — Four Years Inside the World’s Hotels

Attacker China’s Ministry of State Security (per US officials)
Target Starwood Hotels’ reservation database (Sheraton, Westin, W, St. Regis, Le Méridien) — acquired by Marriott in 2016
Method Long-implanted espionage access in the booking platform, undetected for four years
Damage Up to ~383 million guest records, including 5.25 million unencrypted passport numbers
Cost £18.4M UK fine; massive class actions; the defining M&A cyber-due-diligence case

How the attack unfolded

In November 2018, Marriott made a disclosure that stunned the travel world: the guest reservation database of its Starwood brands — compromised since 2014. The intrusion predated Marriott’s $13.6 billion acquisition of Starwood (2016) by two years. In other words, Marriott had bought a breach: state-sponsored intruders were already living inside the asset, and nobody had looked.

The attackers — US officials later told reporters they belonged to or worked with China’s Ministry of State Security — had planted deep access in Starwood’s guest reservation and loyalty systems, the databases that know who sleeps where, when, with whom, paid by which card, headed to which meeting. For four years they quietly harvested: names, mailing addresses, phone numbers, email addresses, dates of birth, gender, arrival/departure details, guest preferences, loyalty numbers — and, most painfully, passport numbers and travel itineraries. The final accounting (revised downward from the initial 500 million): records affecting up to 383 million guests, including 5.25 million unencrypted passport numbers and about 8.6 million payment cards (mostly encrypted, with a smaller active-card subset).

The espionage value is obvious in hindsight: hotel records are a counterintelligence goldmine — they reveal the movements of government officials, business executives, and intelligence officers, and the meetings between them. Security analysts noted that the data could be cross-referenced to detect patterns of diplomatic or covert travel — precisely the category of intelligence a foreign service prizes. (Reporting around the case suggested US agencies had even warned about Chinese collection via hospitality data in earlier cases.)

Marriott’s discovery came via a database-query alert in September 2018 — an anomalous query someone finally noticed — followed by forensic investigation and the November disclosure, initially estimating 500 million guests (later refined). The company’s response — forcing password resets, phasing out Starwood systems, offering monitoring — was costly and mostly well-regarded, but the central fact was unanswerable: the intruders had owned the database for four years, and everything in it had to be assumed collected.

The damage

The UK’s Information Commissioner’s Office (Marriott’s European operations put it under GDPR) announced intent to fine up to £99 million under the new regulation — one of GDPR’s first mega-fines — ultimately issuing £18.4 million in 2020, citing mitigation and cooperation. Class actions in the US and elsewhere dragged on for years. But the case’s lasting impact was on mergers and acquisitions: Marriott had acquired Starwood’s breach along with its brands, and there was no recourse that undid the data loss. Deal-makers rewrote playbooks accordingly.

Aftermath & lessons

  • M&A cyber due diligence became standard: acquisitions now routinely include compromise assessments of the target’s environment — operating on the assumption that the target may already be hacked — with specific representations, escrows, and post-close hunts.
  • The breach highlighted consolidation risk: Marriott’s post-merger migration concentrated years of guest data from multiple brands into shared systems — creating exactly the aggregated intelligence trove an adversary wants.
  • GDPR’s global reach was confirmed: a US company’s European guests’ data brought European regulators, and European fines, into an American breach.

The core lesson: when you acquire a company, you acquire its intruders. Four years of quiet access turned a $13.6 billion acquisition into the largest known exposure of travelers’ identities — and proved, again, that detection time, not prevention, is the metric that decides everything.


Next in the series: Part 5 — 2020–2021: SolarWinds, Colonial Pipeline & the ransomware wave →

data-hmmnm-seam="end">