The first 200 lines.
On the morning of May 12th,
NHS staff were about to be confronted by a major outbreak...
..as an epidemic swept like wildfire across the country.
But the disease didn't infect patients, and it wasn't biological.
Instead it attacked the central nervous system of the NHS itself.
Across the country,
computer systems were knocked out by a highly contagious computer virus.
Hello, can I speak to IT, please?
It became known as WannaCry.
There's a message on my screen, it says my files have been encrypted.
This is the story of a uniquely challenging day
for the National Health Service.
A day when the NHS itself became a patient.
It was attacked by a particularly vicious piece of computer code
which took down its networks,
its computers and anything attached to them.
And that meant patient record systems, CT scanners,
even MRI machines,
putting not just data but also patients' lives at risk.
The surgeon looked very forlorn and very sorry,
and that was when he then told me that he couldn't do the operation.
We were unable to book appointments,
we were unable to see who would be coming in tomorrow,
so we were really paralysed and at a loss of what to do.
Horizon unpicks the science behind the recent widespread cyber attack
that hit our National Health Service.
And, in his first television interview, we meet the 22-year-old
cyber security specialist who stopped it in its tracks.
I checked the message board.
There were maybe 16, 17 reports of different NHS, sort of,
organisations being hit.
And that was sort of the point where I decided, "My holiday's over,
"I've got to look into this."
The outbreak exposed a vulnerability at the heart of the NHS.
I am a doctor, and all of this is a worry.
I want to know what happens, I want to know why it happens,
and I want to know how I can protect my patients
from this new strain of infectious disease.
I found out about the attacks the way most people did,
through news reports.
Now, mercifully, the hospital that I work for wasn't affected,
but as details emerged, it became clear that colleagues all
over the NHS were getting into work that day,
setting up their computers
and being greeted with a screen that looks like this.
Now it's very polite - it tells you what it's done, it's encrypted
all of your data, tells you what you have to do, which is pay some money,
and it tells you that if you pay the money now,
you won't have to pay quite so much.
Otherwise you're going to lose everything.
On 12th May 2017, the cyber attack wrought havoc across the NHS.
It hit many hospital trusts,
and some A&E departments even closed their doors to ambulances.
Operations were cancelled.
Patients were diverted.
But the story of the virus itself
goes back far further than the events of that day.
With all outbreaks, there's always a point of origin.
A moment when the virus first emerges.
Down! Down! Hands on your head!
Down, down, down!
Cuff him!
For over 20 years,
Harold Martin worked as a contractor for US government intelligence.
On the day of his arrest, agents found stolen drives
containing more than 50 terabytes of classified data...
..allegedly including top-secret hacking tools
stockpiled by the National Security Agency.
Harold Martin's arrest followed a tweet
by a mysterious group calling themselves the Shadow Brokers.
They were offering National Security Agency hacking tools
to anyone prepared to pay the 580 million asking price.
According to reports,
once they found out about the Shadow Brokers' demands,
the NSA triggered an internal investigation and,
just a couple of weeks later, Harold Martin was arrested.
Now, there's no evidence at all
that he passed on information to the Shadow Brokers,
but, interestingly, on the hard drives in his home,
was found the hacking tool, Eternal Blue.
Now, Eternal Blue is a kind of key that allows you to prise open
the Windows 7 operating system, and it is that which allowed hackers to
cause havoc across organisations all over the world, including the NHS.
When it comes to attribution,
in other words identifying the true source of attacks,
the world in cyber is a lot more difficult than,
say for example, physical, because, you know, you can make your attack
appear to come from anywhere in the world.
So, Shadow Brokers is an anonymous entity,
we don't really know who's behind Shadow Brokers.
It's generally assumed in the security research community
that the Shadow Brokers are, in effect, an arm of the Russian state.
35 days before the cyber attack,
it was business as usual across the NHS.
But at this moment, the Shadow Brokers made a fateful decision.
With no buyer coming forward,
they dumped their trove of stolen cyber-weapons online, for free.
They were now available for anyone to use.
Cal Leeming is someone with unique insight into the cyber underworld.
He taught himself to hack, and he started young.
When I was about nine years old,
my grandparents got me my first computer.
A proper computer.
My eyes were opened when I started using these chatrooms
and started talking to this wider audience.
People were talking about being able to share PlayStation games.
They were sharing credit card information.
Attracted to free games as an escape from his hard upbringing,
he soon graduated to something more serious.
There wasn't much money at all.
So I found myself using credit cards that I had got from hacking
to send food deliveries to the house.
So it was a mixture of 50% just utter curiosity
and wanting to learn more,
and the other 50% survival.
At the age of just 12, Cal was arrested.
He became the UK's youngest ever cybercriminal.
It was very, very traumatic.
And they sat me down and said,
"Cal, do you understand what you have done was against the law?"
My answer to them was, "All I've done was typed on a keyboard."
Because that's my mind-set, at the time.
I was like, "Why is it that I'm typing on the keyboard to
"survive and I'm now getting arrested?"
And I thought that was very unfair at the time.
Cal continued to hack until 2005,
when he was caught again for using over 10,000 stolen identities
to purchase goods worth £750,000.
Eventually, when I was 18, I handed myself in,
and the arresting officer in my case gave me a chance
to turn my life around in exchange for going to prison
for a little bit.
I owe that guy a lot.
After serving a 15-month jail sentence, he changed sides,
and now runs a cyber security firm.
Why do hackers do what they do? Why do hackers hack?
People have their own motivations for wanting to get into hacking.
Sometimes it is financial, other times criminal,
and sometimes it's just pure curiosity.
Right now we don't know who started this attack, at least not for sure.
Do you think, at any level, the people who carried out this attack
would have felt slightly appalled that this attack spilt over
into the National Health Service?
That's a difficult one to answer,
because it's not a single group that does all hacking in the world,
it's lots and lots of very tiny groups,
sometimes a single person, sometimes lots of people,
and with each group, within each environment,
you have your own set of rules,
conditions and social etiquette and all these things.
So, in some cases, yes, there are going to be some people
that are outraged, even on the criminal side, that they've...
That it went this far.
And in other cases, they might have purposefully wanted it
to go that far. It depends on the individual.
Whatever their motivation, what we know for sure is that someone
did use the alleged NSA exploit Eternal Blue
to create a devastating cyber-weapon.
Within four weeks of Eternal Blue being released,
the attack was ready.
Eternal Blue was mashed together with other pieces of malicious code
and then unleashed on the world, and it was given a name.
A security patch against Eternal Blue
had been made available by Microsoft.
But on the night before the cyber attack,
any machine that hadn't installed the update was still vulnerable...
including many in the NHS.
Infection was now just a matter of time.
On the morning of the cyber-attack,
22-year-old Marcus Hutchins was in the middle of his holiday.
If there was any surf, I might have been surfing.
It's so dynamic, the waves are never the same on two days.
Marcus works remotely for an LA-based cyber intelligence company.
I track malware. I track malicious code that affects users,
and I find ways to track and stop it.
And despite being on leave,
he was still monitoring the global malware outbreak.
I woke up, I checked the message board, there were a couple of
reports of ransomware infections, but I didn't think much of it.
From his home in Devon,
his curiosity would play a crucial role as the day's events unfolded.
In London, Patrick Ward had spent the night
in St Bartholomew's Hospital.
Like thousands of others,
in operating theatres across the country,
he was in for planned surgery,
in his case to correct a serious heart problem.
They woke me at six o'clock,
as they do in hospital,
and one of the nurses came round and shaved my chest, ready for,
obviously, the opening of the chest cavity.
I was nervous, but I was very excited, very...
confident about the operation and what was going to happen.
I'd... yeah, mentally got myself in the right place
to have open heart surgery,
and was, yeah, fantastic, ready to go.
The condition I have is hypertrophic cardiomyopathy,
which is an enlarged heart.
It means I struggle to do normal things, - walk,
I can't do any sporting activities, lifting heavy objects
No comments yet. Be the first to leave one.