Security

Marcus Hutchins, malware researcher and ‘WannaCry hero,’ sentenced to supervised release

Comment

GettyImages 831320200 1
Image Credits: Joshua Lott / Getty Images

Marcus Hutchins, the malware researcher who became known as an “accidental hero” for stopping the WannaCry ransomware attack in 2017, has been sentenced to supervised release for one year on charges of making and selling the Kronos banking malware.

Presiding Judge J. P. Stadtmueller described Hutchins, 25, as a “talented” but “youthful offender” in remarks in federal court in Milwaukee Friday.

The judge said Hutchins’ time had been served and that he will face no time in jail.

“It’s going to take the people like [Hutchins] with your skills to come up with solutions because that’s the only way we’re going to eliminate this entire subject of the woefully inadequate security protocols,” said Stadmueller.

The judge said he took into account Hutchins’ age at the time of the offenses, and gave him credit for “turning a corner” in his life before charges were brought.

Stadtmueller said his sentence is likely, however, to bar him from re-entering the United States.

Hutchins told the court he made some “bad decisions” as a teenager. “I deeply regret my conduct and the harm that was caused,” he said.

Brian Klein, a partner at Baker Marquart and one of Hutchins’ attorneys, told TechCrunch in a statement after the sentencing: “We are thrilled that the judge recognized Marcus’ very important contributions to keeping the world safe and let him go home a free man today.”

“Without precedent but more than appropriately, the judge encouraged Marcus to seek a pardon,” he added. “We plan to explore those opportunities.”

“Marcus appreciates the support he’s received from around the world the past two years,” said Klein.

Hutchins, a British citizen who goes by the online handle @MalwareTech, was arrested in Las Vegas by federal marshals in August 2017 while boarding a flight back to the U.K. following the Def Con security conference. The government alleged in an indictment that he developed Kronos, a malware that steals banking credentials from the browsers of infected computers. The indictment also accused him of developing another malware known as the UPAS Kit. Hutchins was bailed on a $30,000 bond.

Since his indictment he has been living in Los Angeles.

Hutchins initially denied creating the malware. But after prosecutors filed a superseding indictment, he later pleaded guilty to the two primary counts of creating and selling the malware. Eight remaining charges were dropped following his change in plea.

Prosecutors said Hutchins faced up to 10 years in prison and a maximum $500,000 fine.

In a statement following his guilty plea, he said he regretted his actions and accepted “full responsibility for my mistakes.”

Prosecutors said although Hutchins and an accomplice had generated only a few thousand dollars from selling the malware, Kronos allowed others to financially benefit from using the malware.

Hutchins’ indictment came four months after he was hailed as a hero for registering a domain name that stopped the spread of the WannaCry cyberattack, which knocked tens of thousands of computers offline with ransomware in a few hours.

The ransomware attack, later blamed on North Korean hackers, spread across Ukraine, Europe and the U.K., encrypting systems and knocking businesses and government departments offline. The U.K.’s National Health Service was one of the biggest organizations hit, forcing doctors to turn patients away and emergency rooms to close. Hutchins, who at the time of the attack worked for Los Angeles-based Kryptos Logic from his home in the south of England, registered the domain in an effort to understand why the ransomware was spreading. It later transpired the domain acts as a “kill switch” and stopped WannaCry dead in its tracks.

In the week after, the kill switch became the target of powerful botnets hoping to knock the domain offline and spark another outbreak.

Hutchins told TechCrunch last month that the WannaCry attack was one of the most stressful and exhausting moments in his life.

Since the attack, however, Hutchins received additional acclaim for his malware research on new infections and botnet activities. He has been praised for live-streaming his work so others can learn how to reverse-engineer malware. Many in the security community — and further afield — have called on the court to grant Hutchins clemency for his recent concerted efforts to protect users from security threats.

Prosecutors acknowledged Hutchins’ reformed character in a sentencing memo filed this week, saying Hutchins has “since made a good decision to turn his talents toward more positive ends.”

When reached, a Justice Department spokesperson deferred comment to the U.S. Attorney’s Office for the Eastern District of Wisconsin, which did not immediately comment.

The sinkhole that saved the internet

Updated to correct the spelling of the firm Baker Marquart

More TechCrunch

AI startup Anthropic is changing its policies to allow minors to use its generative AI tools — in certain circumstances, at least.  Announced in a post on the company’s official…

Anthropic now lets kids use its AI tech — within limits

Zeekr’s market hype is noteworthy and may indicate that investors see value in the high-quality, low-price offerings of Chinese automakers.

The buzziest EV IPO of the year is a Chinese automaker

Venture capital has been hit hard by souring macroeconomic conditions over the past few years and it’s not yet clear how the market downturn affected VC fund performance. But recent…

VC fund performance is down sharply — but it may have already hit its lowest point

The person who claims to have 49 million Dell customer records — Menelik — told TechCrunch that he brute-forced an online company portal and scraped customer data, including physical addresses,…

Threat actor says he scraped 49M Dell customer addresses before the company found out

The social network has announced an updated version of its app that lets you offer feedback about its algorithmic feed so you can better customize it.

Bluesky now lets you personalize main Discover feed using new controls

Microsoft will launch its own mobile game store in July, the company announced at the Bloomberg Technology Summit on Thursday. Xbox president Sarah Bond shared that the company plans to…

Microsoft is launching its mobile game store in July

Smart ring maker Oura is launching two new features focused on heart health, the company announced on Friday. The first claims to help users get an idea of their cardiovascular…

Oura launches two new heart health features

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI considers allowing AI porn

Garena is quietly developing new India-themed games even though Free Fire, its biggest title, has still not made a comeback to the country.

Garena is quietly making India-themed games even as Free Fire’s relaunch remains doubtful

The U.S.’ NHTSA has opened a fourth investigation into the Fisker Ocean SUV, spurred by multiple claims of “inadvertent Automatic Emergency Braking.”

Fisker Ocean faces fourth federal safety probe

CoreWeave has formally opened an office in London that will serve as its European headquarters and home to two new data centers.

CoreWeave, a $19B AI compute provider, opens European HQ in London with plans for 2 UK data centers

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

1 day ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses