Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog

A History of Notable Ransomware Attacks

AUGUST 23, 20264 MIN READ
Marshall BennettMarshall Bennett
Chat with a real personno Slack required
A History of Notable Ransomware Attacks

Key takeaways

  • WannaCry is described as the fastest-moving ransomware attack on record: in May 2017 it spread in one day to more than 150 countries and 200,000 computers, disrupting UK hospitals, FedEx, and a Renault factory.
  • The article traces ransomware evolution through four strains: GPcode (first identified in December 2004), Cryptorbit, WannaCry, and GandCrab; a key milestone was GPcode.ak in 2008 using 1024-bit RSA encryption that Kaspersky Lab could not crack.
  • WannaCry combined ransomware with a self-spreading worm built on EternalBlue, a Windows file-sharing exploit developed by the NSA and later exposed in a public leak.
  • GandCrab is highlighted for popularizing the ransomware-as-a-service model, with CSIS adviser James Andrew Lewis noting groups like REvil lease infrastructure through affiliate schemes, subscription models, online forums, and even 24/7 technical support.
  • The company case studies emphasize common entry points: Coca-Cola investigated but never confirmed a 2022 Stormous data-theft claim, while Ingram Micro’s 2025 attack reportedly began with one stolen VPN credential and affected about 42,000 people.
  • The core defensive lessons are to patch known vulnerabilities quickly, maintain offline backups, verify requests before handing over credentials or changing wire instructions, and train employees to spot the messages that often start ransomware incidents; Dr. Josephine Wolff specifically recommends offline backups so systems can be restored without paying a ransom.

How two decades of digital extortion shaped the defenses businesses use today. Compiled by Adaptive Security, the team helping organizations recognize these attacks before they start.

In May 2017, a single piece of malicious code spread to more than 150 countries in one day. Hospitals across the United Kingdom canceled surgeries. FedEx paused shipments. A Renault factory in France stopped its assembly line. The code was called WannaCry, and it remains the fastest moving ransomware attack on record.

WannaCry did not appear out of nowhere. It capped more than a decade of ransomware evolution, and every major incident since has borrowed something from the code and the companies that came before it. Here is that history, told in two parts: the strains that built the playbook, and the companies that lived through it.

The Strains That Built the Playbook

Ransomware started as a curiosity and grew into a global industry in a little over twenty years.

GPcode, first identified in December 2004, spent several years in a back-and-forth with researchers who cracked its earlier, weaker encryption. That changed with a 2008 variant called GPcode.ak, which used 1024-bit RSA encryption strong enough that Kaspersky Lab, the firm racing to break it, could not.

  • Cryptorbit rode the wave CryptoLocker started in 2013, showing that a bitcoin address and a group of people willing to click on a fake update were enough to build a working ransomware strain.
  • WannaCry paired a ransomware payload with a self-spreading worm built on EternalBlue, an exploit for a Windows file-sharing vulnerability that the National Security Agency developed and later lost to a public leak. Within a single day, Europol reported the worm had reached more than 150 countries and 200,000 computers.
  • GandCrab took the furthest step, renting its code out to affiliates and inventing the ransomware-as-a-service model that funds a large share of today's attacks.

“RaaS involves criminal organizations such as REvil leasing out their expertise and infrastructure to other criminals,” said James Andrew Lewis, senior adviser in the Economic Security and Technology Department at the Center for Strategic and International Studies. “Ransomware groups are known to offer 24/7 technical support, subscription models, affiliate schemes, and online forums, just like legitimate online companies,” he said.

Each of these four strains has its own story and its own lesson:

When the Target Has a Household Name

Strains of ransomware are one half of this story. The other half is what happens when that code lands inside a company whose name everyone already knows.

  • Coca-Cola faced its first widely reported ransomware claim in 2022, when a group calling itself Stormous said it had stolen company data, a claim Coca-Cola investigated but never confirmed.
  • Then Coca-Cola dairy brand, Fairlife, confirmed a different outcome four years later, in the summer of 2026.
  • Ingram Micro, one of the largest technology distributors in the world, spent days working through a 2025 attack that traced back to one stolen VPN credential and ended up touching the personal information of about 42,000 people.

Those three incidents get their own full stories too:

What Ties It Together

Every strain and every confirmed incident in this history got in somewhere: an unpatched server, a leaked exploit, a stolen credential, or a person who clicked, answered, or trusted the wrong message. The technology behind each of those openings keeps improving. Closing all four, not just the easiest one to talk about, is the work in front of every security team.

“There's still a tremendous amount we don't know about the ransomware landscape,” said Dr. Josephine Wolff, associate professor of cybersecurity policy at The Fletcher School at Tufts University and a faculty associate at Harvard's Berkman Klein Center. Wolff has also been direct about what does work. “Make sure you have lots of offline backup,” she said. “If all of your data is encrypted, you can reboot your systems without paying a ransom.”

None of this is a mystery, even though it is hard, ongoing work.

  • Patch known vulnerabilities quickly.
  • Keep backups attackers cannot reach.
  • Verify who is asking before a credential or a wire transfer changes hands.
  • Prepare people for the message that starts the next attempt, since that is still how a large share of these stories begin.

Ransomware has a twenty-year head start. The response to it is finally catching up. This is the work Adaptive Security does with organizations every day: turning ransomware history into training that sticks and defenses built for how these attacks begin.

Get started with Adaptive Security

Get started

Human security for the AI era.