Exploit used. i think if i could, i'd rather instead of directly answering that and can't speak to how we do or don't do our business as a government in that regard. i'd like to instead point out that this was a vulnerability exploit as one part of a much larger tool that was put together by the culpable parties and not by the u.s. government. this was not a tool developed by the nsa to hold randsome data. this was a tool developed by parties, potentially criminals of foreign nation have put together in such a way so that there are deliberate phishing e-mail, put it in embedding documents and ...