Last updated
    Marcus Hutchins

    Marcus Hutchins

    United Kingdom flagUnited Kingdom
    Celebrity

    cybersecurity researchermalware analystthreat intelligence expert

    Also known as: MalwareTech, MalwareTechBlog

    Birthday

    1994

    Birth Sign

    Capricorn

    Birthplace

    Ascot, England

    Age

    32 years old

    About

    Marcus Hutchins, born in 1994 in Ascot, England, is a British cybersecurity researcher and malware analyst. He is internationally recognized under his online handle, MalwareTech, for his work in threat intelligence and reverse engineering. As of 2026, he serves as Principal Threat Researcher at Expel, a managed detection and response firm, where he focuses on identifying and mitigating emerging cyber threats.

    Hutchins first captured global attention in May 2017 when he discovered a kill switch for the WannaCry ransomware, a move that halted one of the most devastating cyberattacks in history. His technical expertise and rapid thinking prevented billions of dollars in potential damage and saved critical infrastructure, including hospitals and government agencies, from widespread disruption.

    Beyond his work at Expel, Hutchins maintains an active online presence through his MalwareTech blog and social media channels, where he shares in-depth analyses of malware campaigns and vulnerabilities. He is also a sought-after speaker, addressing audiences on cybersecurity topics through the Harry Walker Agency. His career reflects a complex journey from a self-taught enthusiast to a leading voice in the security community.

    Early Life & Background

    Marcus Hutchins grew up in Ascot, a town in Berkshire, England, where he developed an early fascination with computers and how they could be secured. From a young age, he was drawn to understanding the inner workings of software, spending countless hours teaching himself programming and reverse engineering. This self-directed education laid the foundation for his future career in cybersecurity.

    As a teenager, Hutchins adopted the online alias MalwareTech and began blogging about malware analysis and security research. His blog, launched on malwaretech.com, quickly gained a following within the cybersecurity community for its technical depth and clarity. He covered topics ranging from Windows internals to vulnerability research, establishing himself as a knowledgeable and reliable voice long before the WannaCry incident.

    In the years leading up to 2017, Hutchins worked on various security projects, honing his skills in threat intelligence and malware analysis. He documented numerous malware campaigns, providing detailed technical write-ups that helped security professionals worldwide understand and defend against emerging threats. His reputation grew steadily, but it was his intervention during the WannaCry outbreak that would thrust him into the public eye.

    Career Growth

    Marcus Hutchins' breakthrough came in May 2017 when he discovered the kill switch for the WannaCry ransomware. While tracking the malware's spread, he noticed a hardcoded, unregistered domain in its code. Registering that domain triggered a kill switch that halted the encryption and spread of the ransomware, which had already infected over 300,000 computers across 150 countries. His swift action is widely credited with preventing catastrophic damage to hospitals, businesses, and government systems.

    Following this success, Hutchins continued his work in cybersecurity, though his trajectory took a complex turn. In August 2017, he was arrested by the FBI in Las Vegas on charges related to the creation and sale of the Kronos banking trojan, a malware designed to steal online banking credentials. In April 2019, he pleaded guilty to two charges: conspiracy and making, selling, or advertising illegal wiretapping devices. He was sentenced to time served plus one year of supervised release, avoiding additional prison time.

    After resolving his legal issues, Hutchins returned to the security field, working with various companies before joining Expel as Principal Threat Researcher. In this role, he leads threat research efforts, analyzing emerging malware and vulnerabilities. He also maintains his MalwareTech blog, which covers current events and highly technical original research, and speaks at industry events through the Harry Walker Agency.

    Career Timeline

    1994Born in Ascot, England
    Mid-2000s–2010sBegan blogging as MalwareTech, building a reputation in the cybersecurity community
    2017Discovered the WannaCry kill switch, halting a global ransomware attack
    2017Arrested by the FBI in Las Vegas on malware-related charges
    2019Pleaded guilty to two charges related to the Kronos banking trojan
    2019–2020sContinued security research and public speaking
    2025Named Principal Threat Researcher at Expel

    Public Image & Style

    Marcus Hutchins presents a complex public image shaped by his dual roles as a cybersecurity hero and a former malware creator. Following the WannaCry incident, the media celebrated him as an "accidental hero," a label that captured the public's imagination. His subsequent arrest and guilty plea added nuance, presenting him as a figure who had turned from a path of digital crime to one of defense.

    In the cybersecurity community, Hutchins is respected for his technical acumen and his willingness to share detailed research. His blog and social media presence reflect a no-nonsense, highly technical style, appealing to professionals and enthusiasts alike. He is known for breaking down complex threats in an accessible manner, making him a trusted voice in the field.

    Hutchins does not have an official fandom name, but his work has garnered a following among security researchers and tech enthusiasts who appreciate his contributions to global defense efforts. His public speaking engagements through the Harry Walker Agency further cement his reputation as a leading cybersecurity expert.

    Fame & Fandom

    Marcus Hutchins is currently the 40th most famous person in Streaming / Twitch, a position he has held steady since the previous cycle according to the iFANN Global Fame Rankings. This standing reflects his unique trajectory from a controversial figure in the digital underworld to a celebrated authority in cybersecurity, with his influence tracked across global media coverage and consumption signals worldwide. While he commands respect in high-stakes technical circles, Hutchins does not possess a traditional celebrity fandom with an official name or organized clubs like those found in pop music or sports. His supporters are primarily professionals, ethical hackers, students, and tech enthusiasts who engage through technical discussions on platforms like LinkedIn and his personal blog rather than social rituals or fan campaigns. The community operates loosely around shared professional interests, analyzing his research on malware and firmware hacking without the structured mythology of mass consumer groups. Instead of birthday billboards or charity drives, their support manifests in the amplification of his warnings regarding cyber threats and the adoption of his findings. Following his arrest, the rallying behind him was led by industry peers and media outlets arguing against overreach, rather than fans organizing grassroots movements. There are no specific inside jokes or rituals unique to this group, though they share a common language involving ransomware and botnets. The narrative surrounding him remains one of technical triumph followed by legal drama, serving as a cautionary tale and an inspiring story of redemption in the digital age.

    Interesting Facts and Legends

    Hutchins discovered the WannaCry kill switch almost by accident while tracking the ransomware's spread, noticing a hardcoded, unregistered domain that halted encryption when he registered it. His LinkedIn profile describes him as a "Cybersecurity speaker, specialist, and ex-hacker," acknowledging his past as a malware author before turning to defense. A guilty plea in 2019 to charges related to the Kronos banking trojan complicated his hero narrative, as he had created the malware years before his fame. He is based in Los Angeles for his role at Expel but remains British, running a blog that offers nuanced takes on national security and Windows internals. Beyond these facts, his legacy includes the verified incident where he inadvertently stopped a global pandemic of malware by registering a dormant domain, creating the modern archetype of the "hero hacker." Another defining chapter involves his arrest at Heathrow Airport shortly after saving the internet, which triggered immediate outrage within the tech community and sparked debates about the legal treatment of ethical hackers versus state actors. After months in detention, he reached a plea deal in 2019, transitioning from prisoner to respected industry speaker who continues to publish research on AI security and zero trust models.

    Family & Personal Life

    Marcus Hutchins is the elder son of Janet Hutchins, who has been a supportive figure in his life. He grew up in Ascot, England, with his family, though specific details about his father and siblings are not publicly documented. Hutchins maintains a relatively private personal life, and there is no public information about his current household, spouse, or children. He is based in Los Angeles for his work, but he has not shared much about his family life publicly.

    Notable Connections

    Marcus Hutchins is associated with the cybersecurity community, including organizations like Expel and the Harry Walker Agency. He is known for his collaboration with security researchers worldwide, though specific recurring collaborators are not publicly documented.

    Relationships & Dating History

    As of 2026:Single

    Marcus Hutchins has kept his personal life largely out of the public eye. There are no confirmed romantic relationships, engagements, or marriages documented in credible sources. As of 2026, he appears to be single, with no publicly reported current partner.

    Salary, Net Worth In 2026

    $2 Million

    iFANN Editorial Team estimate

    Per iFANN's editorial analysis, Marcus Hutchins' net worth stands at $2 Million as of 2026. This valuation reflects his established career trajectory following his rise to prominence in 2017. His primary income source stems from his role as Principal Threat Researcher at Expel, where senior security positions command substantial salaries. Additional revenue flows through public speaking engagements represented by the Harry Walker Agency, featuring keynote presentations at major industry events. He also maintains a personal blog and active social media channels, which may generate supplementary income through sponsorships or content monetization, though specific figures remain undisclosed. His financial growth has been steady, mirroring his evolution from a former malware creator to a leading voice in threat intelligence and mitigation.

    Awards & Accolades

    View 2 records, honours and achievements

    Known For

    WannaCry kill switch discovery

    2017 · Security researcher

    MalwareTech blog

    ongoing · Author

    Keywords

    WannaCryransomwarecybersecurityMalwareTechKronosthreat researcher

    Sources

    Quick Facts

    Profession
    Cybersecurity researcher, malware analyst
    Born
    1994
    Birthplace
    Ascot, England
    Gender
    Male
    Known for
    WannaCry kill switch
    Current role
    Principal Threat Researcher at Expel

    Personal Details

    Full Name
    Marcus Hutchins
    Education
    Self-taught in cybersecurity and reverse engineering

    Frequently Asked Questions

    How did Marcus Hutchins stop the WannaCry ransomware?
    He discovered a hardcoded, unregistered domain in the malware's code and registered it, which triggered a kill switch that halted the ransomware's encryption and spread across hundreds of thousands of computers worldwide in May 2017.
    What happened to Marcus Hutchins after WannaCry?
    He was arrested by the FBI in August 2017 for allegedly creating the Kronos banking trojan, pleaded guilty in April 2019 to conspiracy and wiretapping device charges, and received time served plus one year of supervised release.
    What is Marcus Hutchins' real name?
    His real name is Marcus Hutchins, and he operates online under the handle 'MalwareTech.'
    Is Marcus Hutchins still working in cybersecurity?
    Yes, as of 2026 he is Principal Threat Researcher at Expel, a managed detection and response firm, and continues publishing security research and speaking publicly.
    Where is Marcus Hutchins from?
    He was born in Ascot, England, and is British, though he is now based in Los Angeles, California.

    Similar People

    Join the community

    fans discussing