Menu
Browse

Cyber Incident Victim: Bank of China

Date:

May 2017

Location:

China

Summary

The Bank of China was among numerous global entities compromised by the WannaCry ransomware attack, which exploited the EternalBlue vulnerability in unpatched Microsoft Windows systems to propagate rapidly across networks. The malware encrypted data and demanded Bitcoin payments for decryption, causing widespread operational disruptions, forced system shutdowns, and data integrity risks across critical sectors including healthcare, energy, and telecommunications. Organizations faced regulatory scrutiny, potential legal liabilities, and incurred costs for forensic investigations and recovery efforts due to the incident's scale and reliance on stolen NSA tools.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The WannaCry ransomware attack began globally on May 12, 2017, exploiting unpatched Microsoft Windows systems through the EternalBlue vulnerability—a tool allegedly stolen from the National Security Agency (NSA). Attackers deployed ransomware that encrypted files on infected machines, displaying ransom demands in Bitcoin with threats of permanent data deletion if payments weren't made within specified deadlines. The malware propagated rapidly across networks, particularly impacting organizations with outdated security patches or legacy systems. Among the confirmed affected entities were Spain's Telefonica, Russia's MEGAFON, Brazil's Petrobras and Foreign Ministry, and the United Kingdom's National Health Service (NHS), which experienced widespread operational disruptions including canceled medical procedures and emergency patient diversions.

Cyber Incident Image

Organizations responded with immediate system shutdowns to contain propagation, isolating infected devices and suspending non-critical services. Forensic teams analyzed the ransomware's behavior, identifying kill-switch domains that slowed its spread when registered. The attack compromised data integrity across energy, telecommunications, and government sectors, triggering regulatory investigations into potential negligence for unpatched systems. Legal experts noted risks of lawsuits from affected customers and employees, while operational impacts included financial losses from downtime and recovery costs. No verified reports confirmed ransom payments resulted in successful decryption, as security researchers worked to develop recovery tools from malware samples. The incident underscored systemic vulnerabilities in critical infrastructure preparedness against rapidly spreading cyber threats.

Sources
Sources available to members
1 source