Expert: 'Biggest Ransomware Outbreak' Ever, Hits 60+ Countries

A cyberattack that is forcing computer owners to pay hundreds of dollars in ransom to unlock their files has hit almost every corner of the world.

    

F-Secure on Friday says it's gotten reports from more than 60 countries. Mikko Hypponen, its chief research officer, calls it "the biggest ransomware outbreak in history."

    

Security experts from Kaspersky Lab and Avast Software say Russia was the hardest hit, followed by Ukraine and Taiwan.

    

Researchers believe a criminal organization is behind this, given its sophistication.

    

Kurt Baumgartner, principal security researcher at Kaspersky, says the malware has translations in dozens of languages, such that instructions for paying the ransom are displayed in the language set for that computer.

    

He and others say the malware takes advantage of an exploit purportedly identified by the National Security Agency.

In the U.S., so far FedEx Corp. is confirming that it is suffering a malware attack.

            

A statement from the delivery company Friday said its Windows-based systems were "experiencing interference" due to malware and that it was trying to fix the issue as quickly as possible.

Microsoft has released fixes for vulnerabilities and related tools disclosed by TheShadowBrokers, a mysterious group that has repeatedly published alleged NSA software code. But many companies and individuals haven't installed the fixes yet, or are using older versions of Windows that Microsoft no longer supports and didn't fix.

    

Hospitals in the U.K. and telecommunications companies in Spain are among those hit by a "ransomware" attack that locked up computer data and demanded payment to free it. The attacks use a malware called Wanna Decryptor, also known as WannaCry.

Hospitals in London, northwest England and other parts of the country have asked patients not to come to the hospitals unless it was an emergency.

    

NHS Merseyside, which operates several hospitals in northwest England, tweeted that "following a suspected national cyberattack, we are taking all precautionary measures possible to protect our local NHS systems and services."

    

Britain's National Health Service is a great source of pride for many in the nation but has been facing substantial budget issues.

Pictures posted on social media showed screens of NHS computers with images demanding payment of $300 worth of the online currency Bitcoin, saying: "Ooops, your files have been encrypted!"

    

NHS Merseyside, which operates several hospitals in northwest England, tweeted that "following a suspected national cyberattack, we are taking all precautionary measures possible to protect our local NHS systems and services."

    

Bart's Health, which runs several London hospitals, said it had activated its major incident plan, cancelling routine appointments and diverting ambulances to neighboring hospitals.

NHS released this statement:

"A number of NHS organisations have reported to NHS Digital that they have been affected by a ransomware attack which is affecting a number of different organisations.

The investigation is at an early stage but we believe the malware variant is Wanna Decryptor. 

At this stage we do not have any evidence that patient data has been accessed. We will continue to work with affected organisations to confirm this.

NHS Digital is working closely with the National Cyber Security Centre, the Department of Health and NHS England to support affected organisations and to recommend appropriate mitigations. 

This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors.

Our focus is on supporting organisations to manage the incident swiftly and decisively, but we will continue to communicate with NHS colleagues and will share more information as it becomes available."

(The Associated Press also contributed to this report.)