• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

The Wannacry Cyber Attack Puts NSA Hacking Back Into Focus

By
Reuters
Reuters
Down Arrow Button Icon
By
Reuters
Reuters
Down Arrow Button Icon
May 15, 2017, 10:21 PM ET

An unprecedented global cyberattack that infected computers in at least 150 countries beginning on Friday has unleashed a new wave of criticism of the U.S. National Security Agency.

The attack was made possible by a flaw in Microsoft’s Windows software that the NSA used to build a hacking tool for its own use – only to have that tool and others end up in the hands of a mysterious group called the Shadow Brokers, which then published them online.

Microsoft President Brad Smith sharply criticized the U.S. government on Sunday for “stockpiling” software flaws that it often cannot protect, citing recent leaks of both NSA and CIA hacking tools.

“Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage,” Smith wrote in a blog post. “An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen.”

Some major technology companies, including Alphabet’s Google and Facebook, declined comment on the Microsoft statement.

But some other technology industry executives said privately that it reflected a widely held view in Silicon Valley that the U.S. government is too willing to jeopardize internet security in order to preserve offensive cyber capabilities.

The NSA did not respond to requests for comment.

The NSA and other intelligence services generally aim to balance disclosing software flaws they unearth against keeping them secret for espionage and cyber warfare purposes.

On Monday, senior administration officials defended the government’s handling of software flaws, without confirming the NSA link to WannaCry, the tool used in the global ransomware attack.

“The United States, more than probably any other country, is extremely careful with their processes about how they handle any vulnerabilities that they’re aware of,” Tom Bossert, the White House homeland security adviser, said at a press briefing on Monday.

Other tools from the presumed NSA toolkit published by the Shadow Brokers have also been repurposed by criminals and are being sold on underground forums, researchers said. But they appear to be less damaging than WannaCry. It is not known who is behind the Shadow Brokers.

Derek Manky, global security strategist at cyber security firm Fortinet, said he thinks WannaCry is probably the worst that will come from the Shadow Brokers’ publicly dumped toolkit, though the group may have held back from public revealing everything it obtained

“Out of that batch, it is probably a high-water mark,” Manky said.

“WE KNEW IT COULD BE A PROBLEM”

Security experts said the NSA had engaged in responsible disclosure by informing Microsoft of the flaw at some point after learning it had been stolen and a month before the tools leaked online.

Users who do not patch their systems and the Shadow Brokers were more directly responsible for the attack than NSA, they said.

The Department of Homeland Security began an “aggressive awareness campaign” to alert industry partners to the importance of installing the Microsoft patch shortly after it was released in March, an agency official working on the attack said.

“This one, we knew it could be a problem,” the official told Reuters.

“NSA should be embarrassed – they’ve had a lot of damaging leaks,” said James Lewis, a former U.S. official who is now a cyber expert at the Center for Strategic and International Studies. Still, he said, “Microsoft needs to admit that the 20th century is over, it’s a much more hostile environment, and that hobbling the NSA won’t make us any safer.”

For more on the ransomware attack, watch Fortune’s video:

Under former President Barack Obama, the U.S. government created an inter-agency review, known as the Vulnerability Equities Process, to determine whether flaws should be shared or kept secret.

White House cyber security coordinator Rob Joyce, who previously worked in the NSA’s elite hacking squad, told a Reuters reporter in April that the Trump administration was considering how to “optimize” the Vulnerability Equities Process, but he did not elaborate.

The White House did not respond to a request for comment about the status of the review process. A source familiar with the matter said equities meetings still take place but less frequently than they did under the Obama administration.

In Congress, Republican Senator Ron Johnson and Democratic Senator Brian Schatz are working on legislation that would codify the review process.

“We have reached a turning point where it is not sustainable for governments to think they can retain vulnerabilities for very long,” said Ari Schwartz, who oversaw technology security issues at the National Security Council during the Obama administration.

 

About the Author
By Reuters
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

A veiled Iranian woman holds her cellphone displaying a portrait of Iran's Supreme Leader, Ayatollah Ali Khamenei,
CybersecuritySecurity
Cyber retaliation from Iran is a problem for U.S. companies — ‘It’s in the hands of a 19-year-old hacker in a Telegram room,’ ex-NSA operative says
By Amanda GerutMarch 1, 2026
6 hours ago
Two girls look at a white laptop placed on a desk.
AIEducation
American schools weren’t broken until Silicon Valley used a lie to convince them they were—now reading and math scores are plummeting
By Sasha RogelbergMarch 1, 2026
8 hours ago
Big TechSocial Media
YouTube’s cofounder and former tech boss doesn’t want his kids to watch short videos, warning short-form content ‘equates to shorter attention spans’
By Marco Quiroz-GutierrezMarch 1, 2026
11 hours ago
Slack cofounder Stewart Butterfield
SuccessProductivity
Slack cofounder says workers and CEOs can get stuck doing ‘fake’ work like pre-meetings and slide shows
By Emma BurleighMarch 1, 2026
12 hours ago
heitmann
CommentaryEntrepreneurship
Here’s how to build something that lasts, from the founder of a $300 million bootstrapped company that’s been growing for 28 years straight
By Tim HeitmannMarch 1, 2026
18 hours ago
U.S. President Donald Trump delivers the State of the Union address during a joint session of Congress in the House Chamber at the Capitol on February 24, 2026 in Washington, D.C.
EnergyData centers
Your utility bills keep going up. Here’s everyone you can blame—AI data centers included
By Jordan BlumMarch 1, 2026
20 hours ago

Most Popular

placeholder alt text
Economy
Your grandparents are the reason the U.S. isn't in a recession right now. That won't last forever
By Eleanor PringleMarch 1, 2026
18 hours ago
placeholder alt text
Success
MacKenzie Scott's close relationship with Toni Morrison long before Amazon put her on the path give more than $1 billion to HBCUs
By Sasha RogelbergMarch 1, 2026
11 hours ago
placeholder alt text
Personal Finance
Trump's universal 401(k) architect on why lower-income people distrust retirement accounts: 'they want to know what the catch is'
By Jacqueline MunisFebruary 28, 2026
2 days ago
placeholder alt text
Middle East
As Iran attacks Dubai, the tax-free haven for the global elite could see 'catastrophic' fallout — 'this can also send shockwaves globally'
By Jason MaMarch 1, 2026
9 hours ago
placeholder alt text
AI
The week the AI scare turned real and America realized maybe it isn't ready for what's coming
By Nick LichtenbergFebruary 28, 2026
2 days ago
placeholder alt text
Success
Japanese companies are paying older workers to sit by a window and do nothing—while Western CEOs demand super-AI productivity just to keep your job
By Orianna Rosa RoyleFebruary 27, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.