Marcus Hutchins: The Accidental Hero Who Once Wrote the Code He Later Helped Stop
The man who halted one of history's most damaging cyberattacks spent years on the wrong side of the line first. His story is worth understanding.

Key points
- Marcus Hutchins, a British security researcher, is best known for stopping the WannaCry ransomware attack in May 2017, which had crippled hospitals, banks, and government offices across dozens of countries.
- Before becoming a defender, Hutchins wrote and sold malicious software, a period he has since described publicly as his "gray zone" years.
- Hutchins does not personally identify as a hacker, though he accepts the label because most people use it to describe what he once did.
- His story illustrates a divide that runs through the security industry: the skills that make someone dangerous are the same skills that make someone valuable as a defender.
Marcus Hutchins is the kind of figure the security world produces occasionally and never quite knows what to do with. He is famous, genuinely famous, for stopping a global cyberattack almost by accident. He is also a person who, before that moment, spent time writing malware, which is malicious software designed to damage systems or steal data, and selling it to others who used it for harm.
Security Week has covered his story in depth. The short version is this: Hutchins, a self-taught British researcher working from his bedroom, registered a web address buried inside WannaCry, a strain of ransomware, meaning software that locks a victim's files and demands payment for the key, that was tearing through the internet in May 2017. That single act switched off the attack's ability to spread further. Hundreds of thousands of computers had already been hit. The National Health Service in England had been forced to cancel operations and divert ambulances.
What did he actually do wrong?
Before the WannaCry moment, Hutchins wrote code that helped criminals steal banking passwords. He was later arrested by US authorities, pleaded guilty to two counts related to malware creation, and received a sentence of time served plus supervised release. No prison time beyond what he had already spent.
His legal case split opinions sharply inside the security community. Many researchers pointed out that the line between writing a tool and being responsible for how others use it is genuinely blurry. Others argued that blurry or not, the harm was real.
Does any of this matter to ordinary people?
Yes, for two reasons.
First, WannaCry caused real damage to real people. Patients in England had medical appointments cancelled because hospital computers were locked. The ransomware used a stolen hacking tool, originally developed by the US National Security Agency, that exploited a flaw in older Windows systems. Microsoft had issued a patch, meaning a software fix, weeks earlier, but many organisations had not applied it.
Second, Hutchins's path from writing harmful code to stopping attacks is not unique. A significant number of people working in cybersecurity defence today spent time earlier in their lives operating in legal grey areas. The skills transfer completely.
His position on the label is telling. He does not call himself a hacker. He accepts others calling him one because the word is common shorthand. That careful distinction, between what a word means to you and what it signals to everyone else, is about as clean a summary of his situation as you will find.
If you were affected by WannaCry or a similar attack: check that your organisation applies software updates promptly. Unpatched systems, ones that have not received available fixes from their makers, remain the single most reliable way ransomware finds a way in.



