Marcus Hutchins: The Accidental Hero Who Once Wrote the Code He Later Helped Stop
The man who halted one of history's most damaging cyberattacks spent years on the wrong side of the line first. His story is worth understanding.

Key points
- Marcus Hutchins, a British security researcher, stopped the WannaCry ransomware attack in May 2017, which had crippled hospitals and government offices across dozens of countries.
- Before becoming a defender, Hutchins wrote and sold malicious software, a period he has since described publicly as his "gray zone" years.
- He doesn't personally identify as a hacker, though he accepts the label because most people use it to describe what he once did.
- His story illustrates a divide that runs through the security industry: the skills that make someone dangerous are the same ones that make someone valuable as a defender.
Marcus Hutchins is the kind of figure the security world produces occasionally and never quite knows what to do with. Famous, genuinely, for stopping a global cyberattack almost by accident. Also a person who spent time before that moment writing malware, malicious software designed to damage systems or steal data, and selling it to others who used it for harm.
The short version: Hutchins, a self-taught British researcher working from his bedroom, registered a web address buried inside WannaCry, a strain of ransomware, meaning software that locks a victim's files and demands payment for the key, that was spreading rapidly in May 2017. That single act switched off the attack's ability to spread further. Hundreds of thousands of computers had already been hit. England's National Health Service had been forced to cancel operations and divert ambulances.
What did he actually do wrong?
Before the WannaCry moment, Hutchins wrote code that helped criminals steal banking passwords. US authorities arrested him, he pleaded guilty to two counts related to malware creation, and received a sentence of time served plus supervised release, no additional prison time.
His legal case split the security community. Many researchers pointed out that the line between writing a tool and being responsible for how others use it is genuinely blurry. Others argued that blurry or not, the harm was real.
Should you worry about the next WannaCry?
Probably, yes. WannaCry caused damage that touched ordinary people directly. Patients in England had medical appointments cancelled because hospital computers were locked. The ransomware used a stolen tool originally developed by the US National Security Agency, exploiting a flaw in older Windows systems. Microsoft had issued a patch, a software fix, weeks earlier, but many organisations hadn't applied it.
That pattern hasn't changed much. Our 3 August piece on how threats have evolved found that some of the oldest techniques still work best, largely because patching remains slow in practice. Hutchins's path from writing harmful code to stopping attacks isn't unique either. A significant number of people working in cybersecurity defence today spent time earlier in their lives operating in legal grey areas. The skills transfer completely.
His position on the label is telling. He doesn't call himself a hacker but accepts others doing so because the word is common shorthand. That careful distinction, between what a word means to you and what it signals to everyone else, is about as clean a summary of his situation as you'll find.
What this story is really about isn't redemption or even attribution. It's the unresolved question the industry keeps deferring: how do you cultivate the skills a defender needs without normalising the path that gets people there? Nobody has a clean answer. Hutchins's case just makes it harder to pretend the question doesn't exist.
If your organisation still has unpatched systems, ones that haven't received available fixes from their makers, that's where the next WannaCry finds its way in.



