spreading itself within networks without relying on human activity to spread it.41 The attack was indiscriminate rather than targeted, with evidence suggesting a North Korean connection.42 The initial attacks were hindered by a 22-year-old UK security researcher—going by the name of MalwareTech for purposes of anonymity—who discovered an apparently unintentional “kill switch” to the malware.43 However, due to the relative ease of launching cyberattacks, and the great deal of money at stake, concerns persist that either attacks will be relaunched with the coded kill switch removed, or that subsequent attackers will learn from lessons from this experience.44 WannaCry is a weaponization of one of a series of system’s vulnerabilities first identified by the US National Security Agency (NSA),45 and which were stolen when the NSA was hacked46 and then leaked to the public in April 2017.47 Of that cache, it is the tool codenamed “EternalBlue” that appears to have been “the most significant factor” behind the WannaCry attack.48 Among other things, the attacks have reignited the debate over whether governments should disclose web or system vulnerabilities of which they become aware.49 The cyberattacks highlight the importance of user awareness. WannaCry appears to have capitalized upon outdated systems for which patches existed, and even to have targeted systems and sectors that might tend to run on legacy systems, such as healthcare and transport. The attacks emphasize that it is incumbent upon users—individual and institutional—to keep their systems up to date by installing the fixes—so-called “patches”— that developers, such as Microsoft or Apple, make available as they become aware of system weaknesses.51 In this instance, the attacks capitalized vulnerabilities in outdated Microsoft Window software; Microsoft had released security updates to patch this matter in April, and, responding to the attack, did so again on the day of this attack.52 As ransomware attacks grew by fifty-one percent last year,53 the threat seems unlikely to abate. “This [problem] is one in which what’s broken is the system by which we fix”, said Professor Zeynep Tufeki of the University of North Carolina.54 D. Detecting Cybercrime Detecting cybercrimes is challenging because, first, the victim may have no idea that a crime has occurred, and, second, cybercriminals are wont to operate behind multiple layers of fake identities and often operate out of nation-states having either limited cybercrime-fighting capacity, or limited interested in taking on such a fight.54 It is generally difficult to detect system security breaches before any visible damage—such as the fraudulent transferring of a victim’s funds—has been done. Moreover, much of the damage can be done simply by surveilling—for instance, in the collection of personal information or metadata for use in identity theft. Moreover, even where a breach has been identified, hackers often hide their identities through the use of various tools. Further difficulties Page 34 | Chapter 1 | § C. Challenges to Fighting Cybercrime Table of Contents

Select target paragraph3