Famous Cyberattacks (1)

Over the past ten years, the IT threat landscape has changed radically, marked by spectacular cyberattacks that have shaken businesses, governments and individuals. In our April articles, we look back at the most high-profile cases, which show the crucial need to keep strengthening cybersecurity, for businesses and individuals alike.
WannaCry: a ransomware with global consequences
In May 2017, WannaCry, a ransomware exploiting a vulnerability in Windows, spread at lightning speed, affecting more than 230,000 computers in 150 countries. It paralyzed hospital systems in the United Kingdom, disrupted companies such as Renault in France, and caused financial damage estimated at several billion dollars. The malware exploited a flaw leaked by a hacker group called the Shadow Brokers, using techniques developed by the NSA.
These very powerful tools, originally developed for international espionage, considerably increased the destructive capacity of ordinary cybercriminals.
AgencePDN gets pirated content removed: see our solutions by sector.
The WannaCry attack was stopped almost by accident by a British researcher who discovered a “kill switch” built into the malware. Nevertheless, the incident revealed the extent of existing vulnerabilities and underlined the crucial importance of regular updates, security backups and constant vigilance against emerging threats. Following this attack, many companies considerably tightened their patch management and system update policies, and also stepped up internal training to raise employee awareness of cybersecurity.
NotPetya: the most costly cyberattack in history
Barely a month after WannaCry, in June 2017, NotPetya struck with unmatched destructive power. Initially seen as ransomware, NotPetya turned out to be a disguised cyberattack aimed mainly at Ukraine in a particularly tense geopolitical context between Russia and Ukraine. The attack affected international companies such as Maersk, Merck, FedEx and Saint-Gobain, causing financial losses estimated at more than $10 billion.
Unlike WannaCry, NotPetya had no mechanism for recovering data, which shows that the aim of the attack was destruction rather than extortion. The event highlighted the growing political and strategic dimension of cyberattacks, pushing companies to reconsider their IT defence strategies and to treat cyber risk as a major systemic risk.
Cybersecurity awareness and investment in protection systems rose sharply after this attack, with particular emphasis on rapid threat identification and organizational resilience.

Equifax: the sensitive data of millions of people exposed
In September 2017, Equifax, one of the largest US credit agencies, revealed that it had suffered a massive data breach affecting nearly 147 million Americans. Cybercriminals exploited an unpatched Apache Struts flaw that had been known for several months before the attack, clearly demonstrating the risks of vulnerabilities and the negligence of many companies when it comes to critical updates.
The leak of sensitive information such as Social Security numbers, dates of birth, addresses and driver's licence numbers created considerable risks of identity theft and large-scale fraud. The total cost of the attack, combining fines, compensation and remedial measures, far exceeds a billion dollars.
The affair not only underlined the consequences of poor vulnerability management, but also led to significant changes in data protection legislation. In Europe, the General Data Protection Regulation (GDPR) became a model for the protection of personal information, while in the United States regulations were also tightened, requiring companies to report incidents more quickly and to strengthen their cybersecurity management.
SolarWinds: ever more sophisticated attacks
December 2020 saw the revelation of an extremely sophisticated attack against SolarWinds, an American company specialized in IT network management software.
Hackers, most likely linked to a foreign state, inserted malware called “Sunburst” into an official update of SolarWinds' Orion software, which is widely used by government agencies and companies.
This supply chain attack allowed the hackers to quietly infiltrate the networks of several critical organizations, including the US Department of the Treasury, the State Department, Homeland Security, and several large technology companies. The high level of stealth, combined with the use of advanced obfuscation techniques, allowed the hackers to remain invisible for several months, harvesting sensitive information without being detected.
SolarWinds marks a major turning point in the understanding of cyber risk linked to third-party suppliers and supply chains, pushing companies and governments to deeply rethink their risk management practices and their supplier oversight processes. The attack notably accelerated the adoption of stricter cybersecurity practices and of advanced monitoring tools to detect anomalies quickly, and reinforced the need for greater international cooperation to fight these complex and sophisticated threats.

These major cyberattacks illustrate the growing complexity and seriousness of IT threats. They highlight existing structural vulnerabilities and the vital need for a proactive cybersecurity strategy, including prevention, detection and rapid incident response.
In the second part of our article, we will look at other emblematic attacks such as Colonial Pipeline, Uber and the attacks on the Irish health system, to draw further lessons on the need for constant cyber vigilance. In the meantime, if you have a film, a series, software or an ebook to protect, don't hesitate to call on our services by contacting one of our account managers; PDN has been a pioneer in cybersecurity and anti-piracy for more than ten years, and we are bound to have a solution to help you. Happy reading, and see you soon!
Share this article


