A security guard stands outside the Telefonica headquarters in Madrid, Spain, on Friday, May 12. The Spanish government said several companies including Telefonica had been targeted in ransomware cyberattack that affected the Windows operating system of employees’ computers. (AP Photo/Paul White)

A security guard stands outside the Telefonica headquarters in Madrid, Spain, on Friday, May 12. The Spanish government said several companies including Telefonica had been targeted in ransomware cyberattack that affected the Windows operating system of employees’ computers. (AP Photo/Paul White)

Huge cyberattack forces Microsoft to offer free tech fix

By SYLVIA HUI and JIM HEINTZ / Associated Press

LONDON — Teams of technicians worked “round the clock” Saturday to restore hospital computer systems in Britain and check bank or transport services in other nations after a global cyberattack hit dozens of countries and crippled the U.K.’s health system.

The worldwide attack was so unprecedented that Microsoft quickly changed its policy and announced that it will make security fixes available for free for older Windows systems, which are still used by millions of individuals and smaller businesses.

In Russia, where a wide array of systems came under attack, officials said services had been restored or the virus contained.

ADVERTISEMENT
0 seconds of 0 secondsVolume 0%
Press shift question mark to access a list of keyboard shortcuts
00:00
00:00
00:00
 

The extortion attack, which locked up computers and held users’ files for ransom, is believed to be the biggest of its kind ever recorded, disrupting services in nations as diverse as the U.S., Russia, Ukraine, Spain and India.

Europol, the European Union’s police agency, said the onslaught was at “an unprecedented level and will require a complex international investigation to identify the culprits.”

The ransomware appeared to exploit a vulnerability in Microsoft Windows that was purportedly identified by the U.S. National Security Agency for its own intelligence-gathering purposes and was later leaked to the internet.

Before Friday’s attack, Microsoft had made fixes for older systems, such as 2001’s Windows XP, available only to mostly larger organizations that paid extra for extended technical support. Microsoft says now it will make the fixes free for everyone.

It was not yet known who perpetrated Friday’s attacks. Two security firms — Kaspersky Lab and Avast — said they had identified the malicious software behind the attack in over 70 countries, although both said the attack had hit Russia the hardest.

In Britain, the National Cyber Security Center said it is “working round the clock” with experts to restore vital health services.

British Home Secretary Amber Rudd — who was chairing a government emergency security meeting Saturday in response to the attack — said 45 public health organizations were hit, though she stressed that no patient data had been stolen. The attack froze computers at hospitals across the country, with some canceling all routine procedures. Patients were asked not to go to hospitals unless it was an emergency and even some key services like chemotherapy were canceled.

Security officials in Britain urged organizations to protect themselves from ransomware by updating their security software fixes, running anti-virus software and backing up data elsewhere.

The Russian Interior Ministry, which runs the country’s police, confirmed it was among those that fell victim to the ransomware, which typically flashes a message demanding a payment to release the user’s own data.

Ministry spokeswoman Irina Volk was quoted by the Interfax news agency Saturday as saying the problem had been “localized” and that no information was compromised. But the ministry’s website still carried a banner on Saturday afternoon saying that technical work was continuing.

A spokesman for the Russian Health Ministry, Nikita Odintsov, said on Twitter that the cyberattacks on his ministry were “effectively repelled.”

“When we say that the health ministry was attacked you should understand that it wasn’t the main server, it was local computers … actually nothing serious or deadly happened yet,” German Klimenko, a presidential adviser, said on Russian state television.

Russian cellular phone operators Megafon and MTS said some of their computers were hit and the Russian national railway system said although it was attacked, rail operations were unaffected.

Russia’s central bank said Saturday that no incidents had “compromising the data resources” of Russian banks, state news agency Tass reported.

French carmaker Renault’s assembly plant in Slovenia halted production after it was targeted in the global cyberattack. Radio Slovenia said Saturday the Revoz factory in the southeastern town of Novo Mesto stopped working Friday evening to stop the malware from spreading — and was working with the central office in France to resolve the problem.

Krishna Chinthapalli, a doctor at Britain’s National Hospital for Neurology & Neurosurgery who wrote a paper on cybersecurity for the British Medical Journal, said many British hospitals still use Windows XP software, introduced in 2001.

Security experts said the attack appeared to be caused by a self-replicating piece of software that enters companies when employees click on email attachments, then spreads quickly internally from computer to computer when employees share documents.

The security holes it exploits were disclosed several weeks ago by TheShadowBrokers, a mysterious group that has published what it says are hacking tools used by the NSA. Shortly after that disclosure, Microsoft announced that it had already issued software “patches,” or fixes, for those holes — but many users haven’t yet installed the fixes or are using older versions of Windows.

In the U.S., FedEx Corp. reported that its Windows computers were “experiencing interference” from malware, but wouldn’t say if it had been hit by ransomware.

Elsewhere in Europe, the attack hit companies including Spain’s Telefonica, a global broadband and telecommunications company.

Germany’s national railway said Saturday departure and arrival display screens at its train stations were affected, but there was no impact on actual train services. Deutsche Bahn said it deployed extra staff to busy stations to help customers, and recommended that they check its website or app for information on their connections.

Other European organizations hit by the massive cyberattack included soccer clubs in Norway and Sweden, with IF Odd, a 132-year-old Norwegian soccer club, saying its online ticketing facility was down.

Heintz reported from Moscow.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Everett Historic Theater owner Curtis Shriner inside the theater on Tuesday, May 13, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Historic Everett Theatre sale on horizon, future uncertain

With expected new ownership, events for July and August will be canceled. The schedule for the fall and beyond is unclear.

Contributed photo from Snohomish County Public Works
Snohomish County Public Works contractor crews have begun their summer 2016 paving work on 13 miles of roadway, primarily in the Monroe and Stanwood areas. This photo is an example of paving work from a previous summer. A new layer of asphalt is put down over the old.
Snohomish County plans to resurface about 76 miles of roads this summer

EVERETT – As part of its annual road maintenance and preservation program,… Continue reading

City of Everett Engineer Tom Hood, left, and City of Everett Engineer and Project Manager Dan Enrico, right, talks about the current Edgewater Bridge demolition on Friday, May 9, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
How do you get rid of a bridge? Everett engineers can explain.

Workers began dismantling the old Edgewater Bridge on May 2. The process could take one to two months, city engineers said.

Smoke from the Bolt Creek fire silhouettes a mountain ridge and trees just outside of Index on Sept. 12, 2022. (Olivia Vanni / The Herald)
County will host two wildfire-preparedness meetings in May

Meetings will allow community members to learn wildfire mitigation strategies and connect with a variety of local and state agencies.

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Helion celebrates smoother path to fusion energy site approval

Helion CEO applauds legislation signed by Gov. Bob Ferguson expected to streamline site selection process.

Vehicles travel along Mukilteo Speedway on Sunday, April 21, 2024, in Mukilteo, Washington. (Ryan Berry / The Herald)
Mukilteo cameras go live to curb speeding on Speedway

Starting Friday, an automated traffic camera system will cover four blocks of Mukilteo Speedway. A 30-day warning period is in place.

Carli Brockman lets her daughter Carli, 2, help push her ballot into the ballot drop box on the Snohomish County Campus on Tuesday, Nov. 5, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Here’s who filed for the primary election in Snohomish County

Positions with three or more candidates will go to voters Aug. 5 to determine final contenders for the Nov. 4 general election.

Former Herald writer Melissa Slager’s new book was 14-year project

The 520-page historical novel “Contests of Strength” covers the 1700 earthquake and tsunami on Makah lands.

The second floor of the Lynnwood Crisis Center on Friday, Feb. 7, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
State budget, legislation could help vacant Lynnwood Crisis Care Center

The two-year operating budget allocates $15 million to crisis centers. Another bill would streamline Medicaid contract negotiations.

Snohomish County 911 Executive Director Kurt Mills talks about the improvements made in the new call center space during a tour of the building on Tuesday, May 20, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
New 911 center in Everett built to survive disaster

The $67.5 million facility brings all emergency staff under one roof with seismic upgrades, wellness features and space to expand.

Students, educators speak out against Early Learning Center closure

Public commenters criticized Everett Community College for its handling of the closure. The board backed the move, citing the center’s lack of funding.

A ferry passes by as Everett Fire Department, Everett Police and the U.S. Coast Guard conduct a water rescue for a sinking boat in Possession Sound off of Howarth Park on Wednesday, May 21, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Recovery efforts continue Thursday for missing boaters on Possession Sound

Several agencies continue recovery efforts Thursday morning. Coast Guard suspended its search Wednesday night.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.