Man who fought off NHS cyber attack to appear in US court

Marcus Hutchins wanted to remain anonymouse following the cyber attack.
Marcus Hutchins wanted to remain anonymouse following the cyber attack.
Share this article

The British computer expert who helped shut down a world-wide cyber attack that crippled the NHS was due to appear in a US court charged with creating software that harvested banking details.

The British computer expert who helped shut down a world-wide cyber attack that crippled the NHS will appear in a US court on Friday charged with creating software that harvested banking details.

Marcus Hutchins, from Ilfracombe, Devon, will face a judge in Las Vegas accused of six counts of creating and distributing the malware known as Kronos.

READ MORE: 13 NHS health boards in Scotland affected by cyberattack

Officials said after the 23-year-old’s arrest by the FBI on Wednesday that he was indicted by a grand jury in the Eastern District of Wisconsin in relation to charges in the year leading up to July 2015.

Hutchins, also known as MalwareTech, was hailed a hero in May this year when he found a “kill-switch” that slowed the effects of the WannaCry “ransomware” virus that hit more than 300,000 computers in 150 countries.

The investigation predates that attack and is completely unrelated, officials said.

The indictment says Hutchins created the Kronos malware before conspiring with another defendant, whose name has been redacted, to advertise and sell it on internet forums.

In August 2014 the unnamed defendant sold the software for 2,000 dollars (£1,522) in a digital currency in June 2015, the legal document adds.

Hutchins’ mother, Janet Hutchins, said it was “hugely unlikely” that her son was involved because he has spent “enormous amounts of time and even his free time” combating such attacks.

She said she is “outraged” by the charges and has been “frantically calling America” trying to contact her son.

READ MORE: NHS cyber attack: Criminals will be brought to justice

A friend from the IT security industry, who spoke on the condition of anonymity, said Hutchins was arrested in McCarran International Airport after he tried to fly back from the Def Con hacking conference.

The Electronic Frontier Foundation, a San Francisco-based digital rights group, said it is “deeply concerned” and has reached out to Hutchins.

Naomi Colvin, from civil liberties campaign group Courage, echoed the foundation and praised Hutchins’ earlier work.

She said: “In May this year, WannaCry malware closed hospitals in the UK, becoming the first ransomware attack to represent an actual threat to life.

“In halting the spread of WannaCry before the US woke up, MalwareTech did the world an enormous service - and to American businesses in particular.”

Ms Colvin said he had been detained for 24 hours before information was released about his arrest and said he has still not been allowed to contact his family or lawyers.

“The US treats hackers far worse than other countries do, with much longer prison sentences, a dearth of vital health care and rampant solitary confinement,” she said.

The Foreign Office said it is supporting Hutchins’ family and is in contact with authorities in Las Vegas while the National Cyber Security Centre also said it was “aware of the situation”.

Hutchins appeared in the Las Vegas court on Thursday but the hearing was adjourned to be continued the following day.