NotPetya Destructive Cyberattack (Jun 27 2017)
Introduction
On 27 June 2017, a destructive malware campaign now known as NotPetya began detonating across Ukraine and rapidly spread to multinational corporations worldwide. Initial reporting described it as ransomware — it displayed a ransom note demanding Bitcoin — but forensic analysis by ESET, Cisco Talos, and other firms quickly established that it had no functional decryption mechanism. It was not ransomware. It was a wiper: a weapon designed solely to destroy data and render machines unbootable.
The attack is attributed by US, UK, EU, and Australian governments to Russian GRU Unit 74455, known publicly as Sandworm. The US Department of Justice indicted six GRU officers in October 2020 by name.
The Supply-Chain Entry Point
NotPetya entered corporate networks via a trojanised software update to M.E.Doc (Me.Doc), a Ukrainian tax reporting and accounting package used by approximately 80 percent of Ukrainian businesses. The attackers had compromised M.E.Doc''s update servers weeks before the outbreak date and seeded a backdoored update to legitimate customers. This supply-chain mechanism meant that organizations with no direct relationship with the attackers received the malware through a trusted software channel — a technique later mirrored in the 2020 SolarWinds attack.
Propagation Mechanisms
Once inside a network, NotPetya used two complementary propagation tools. EternalBlue — an NSA exploit leaked by the Shadow Brokers in April 2017 and already used in the WannaCry attack of May 2017 — exploited the SMBv1 vulnerability (MS17-010) to move laterally across Windows networks. Mimikatz, an open-source credential-harvesting tool, extracted Windows login credentials from memory, allowing NotPetya to authenticate to additional machines using legitimate administrator accounts. The combination made it devastating even in environments that had partially patched EternalBlue: credentials harvested from one unpatched machine could authenticate to fully patched systems.
Global Damage
The estimated global economic damage from NotPetya exceeds $10 billion. Major victims include Maersk ($300M, which lost almost all of its Active Directory infrastructure and had to reinstall 45,000 PCs and 4,000 servers in ten days), Merck ($870M, affecting pharmaceutical manufacturing and vaccine production), FedEx/TNT ($400M, including permanent loss of some legacy systems), Mondelèz ($100M), and Saint-Gobain (€220M). Ukraine itself suffered widespread disruption to government systems, banks, media, and infrastructure.
Attribution and Legal Accountability
In February 2018, the US Cybersecurity and Infrastructure Security Agency (CISA), the UK National Cyber Security Centre (NCSC), and Five Eyes partners jointly attributed NotPetya to the Russian GRU. In October 2020, the US DOJ unsealed an indictment of six GRU Unit 74455 officers: Yuriy Andrienko, Sergei Detistov, Pavel Frolov, Artem Ochichenko, Petr Pliskin, and Anatoliy Kovalev. The indictment detailed the technical operation with granular specificity, drawing on intercepted communications and forensic evidence.
Insurance War-Exclusion Litigation
Mondelèz International sued its insurer Zurich Insurance after Zurich denied its $100M NotPetya claim under a war exclusion clause, arguing the attack constituted a "hostile or warlike action" by a sovereign state. The case attracted widespread attention from the insurance industry because its outcome would determine whether cyber incidents attributed to nation-states would be systematically excluded from commercial property coverage. The case was settled in 2022 on undisclosed terms. Subsequent years have seen Lloyd''s of London and other insurers introduce explicit state-sponsored cyberattack exclusions in cyber policies.
Verdict
NotPetya is a confirmed nation-state cyberweapon. The attribution is corroborated by multiple independent government assessments, forensic analysis from multiple private-sector firms, and a detailed criminal indictment. The claim that it was a Russian GRU operation targeting Ukraine — with collateral damage to global commerce — is not a theory: it is the documented conclusion of allied intelligence and law enforcement.
Why Forensic Analysts Concluded This Was Sabotage, Not Extortion
Days after the outbreak, Kaspersky researcher Anton Ivanov and colleagues dissected the ransom mechanism itself and found it could not have worked even in principle. Genuine Petya, the 2016 ransomware family NotPetya impersonated, generated an "installation ID" that encoded real data the attacker could use to reconstruct a victim's decryption key. NotPetya's version instead produced that ID using Windows' CryptGenRandom function — pure random data with no mathematical relationship to the key actually used to scramble the machine's Master File Table. A victim who located a working payment channel, paid the full ransom, and sent the ID exactly as instructed would still receive nothing back, because there was nothing to send: the operator could not extract a real key from garbage.
That payment channel collapsed almost immediately in any case. The ransom note's sole point of contact, [email protected], was hosted by the German provider Posteo, which shut the account down early on the morning of 27 June 2017 — the same day the outbreak began — after it was flagged under routine anti-abuse procedures, before Posteo or anyone else grasped the scale of what was unfolding. From that point on, victims had no way to reach the attacker even to attempt payment. Cisco Talos reached the same "this cannot be ransomware" conclusion independently and within days of Kaspersky, examining the encryption routine rather than the mail server. Two unrelated technical teams, working from different evidence, converged on the same read: the ransom note was theater layered over a data-destruction weapon.
Corroboration Beyond the Five Eyes Statement
The February 2018 joint attribution is often cited as a single event, but the underlying corroboration is broader and came from multiple independent directions. Australia did not simply co-sign the US and UK language: Angus Taylor, then Minister for Law Enforcement and Cyber Security, stated that Australian intelligence agencies had separately assessed — in consultation with, but not solely dependent on, US and UK partners — that Russian state-sponsored actors were responsible, and that the Australian government "condemns Russia's behaviour, which posed grave risks to the global economy." A month later, the US Treasury's Office of Foreign Assets Control went beyond statements: on 15 March 2018 it sanctioned Russian entities and individuals under the Countering America's Adversaries Through Sanctions Act, explicitly naming NotPetya as "the most destructive and costly cyber-attack in history" and tying it directly to the Russian military.
Technical corroboration arrived independently of any government. Kaspersky researchers identified code-level overlaps between the ExPetr wiper and the BlackEnergy/KillDisk toolkit Sandworm had already used against Ukraine's power grid in 2015 and 2016 — matching file-extension target lists and identical shutdown command strings. Kaspersky was explicit that this alone was only a "low confidence, persistent hunch," which is itself informative: the strongest parts of the attribution case (the supply-chain forensics, the indictment's granular detail) never needed to lean on this weaker signal, and the honesty about its limits is a mark of the broader body of evidence's quality. Separately, and requiring no cooperation from Western intelligence at all, Ukrainian cyber police raided M.E.Doc developer Linkos Group on 4 July 2017 and seized servers running four-year-old, unpatched ProFTPD, Nginx, and OpenSSH, with no HTTPS or cryptographic signing anywhere on the update-delivery channel — an independent, on-the-ground confirmation of exactly the supply-chain entry point the West's forensic teams had already mapped.
The Strongest Counter-Argument — and Why It Doesn't Hold
The most substantive objection to "deliberate Russian state operation" is that NotPetya devastated major Russian companies too, including state oil giant Rosneft, Sberbank, Home Credit Bank, miner Evraz, and diagnostics firm Invitro. Skeptics ask why the Kremlin would order an attack that damages its own economy.
The objection doesn't survive contact with how the malware actually worked. NotPetya's propagation logic — EternalBlue plus harvested credentials — checks no flag for nationality; once it moved beyond the initially targeted M.E.Doc-linked Ukrainian networks, it spread through any connected Windows environment indiscriminately, including Russian firms with Ukrainian subsidiaries or shared corporate networks. A weapon can be deliberately aimed at a target and still be recklessly indifferent to where it goes after release; those are not contradictory. Analysts have also noted the pattern is not unprecedented: Russian state operations have tolerated, and at times arguably welcomed, domestic collateral damage as cover for deniability — the Kremlin's own "why would we hit ourselves" framing is precisely the rhetorical use such collateral damage serves. Most importantly, the counter-argument doesn't actually touch the evidentiary chain establishing authorship: the M.E.Doc backdoor, the wiper's technical design, and the DOJ's named-officer indictment describe who built the weapon and how it was launched — questions entirely separate from how far it later spread.
Sanctions, Insurance Precedent, and Lasting Aftermath
Merck's own insurance fight produced something Mondelez's settlement did not: an actual judicial ruling on the "act of war" question, reached on the merits rather than settled away. In January 2022, a New Jersey Superior Court held that the war exclusion in Merck's property policies — which required "hostile or warlike action ... by a government or sovereign power" — did not bar its roughly $1.4 billion NotPetya claim, because the clause's century-old language was written for concerted military action, not state-attributed malware. Insurers appealed, and New Jersey's Appellate Division affirmed Merck's win on 1 May 2023, rejecting the argument that any unfriendly government action qualifies as "hostile." With the case headed to the state Supreme Court, the two sides reached a confidential settlement in early January 2024, days before oral argument — leaving Merck's win as the operative precedent without a final high-court ruling ever being issued.
Accountability also reached the point of entry. Ukrainian officials did not treat Linkos Group solely as a victim of the same attack: a cyber police representative stated the company had been warned repeatedly by antivirus vendors about its server security and "will face criminal responsibility" for the negligence that let the backdoor persist for weeks undetected. Combined with the US Treasury's CAATSA sanctions and the DOJ's 2020 indictment, the response to NotPetya spans criminal prosecution of the alleged operators, sanctions on the state apparatus behind them, and legal accountability for the compromised software vendor whose negligence provided the door — a rare case where nearly every link in a cyberattack's chain faced some form of formal consequence.
Evidence Filters17
Five Eyes joint attribution to GRU Unit 74455 (Feb 2018)
DebunkingStrongUS CISA, UK NCSC, Australian Cyber Security Centre, and Canadian Centre for Cyber Security jointly attributed NotPetya to the Russian GRU in February 2018. The coordinated multi-government attribution reflects shared intelligence and corroborating technical evidence across allied services.
US DOJ indictment of six named GRU officers (Oct 2020)
DebunkingStrongThe US DOJ unsealed an indictment in October 2020 naming six GRU Unit 74455 officers — Andrienko, Detistov, Frolov, Ochichenko, Pliskin, and Kovalev — with granular technical detail of the NotPetya operation, including specific dates, infrastructure, and methods. Criminal indictments require prosecutorial confidence in evidentiary sufficiency.
M.E.Doc supply-chain vector forensically confirmed
DebunkingStrongESET, Cisco Talos, and multiple firms independently confirmed that NotPetya entered networks via a trojanised update to M.E.Doc Ukrainian tax software. The update servers had been compromised weeks before the June 27 detonation date. This supply-chain mechanism is technically documented with file-hash and network-traffic evidence.
EternalBlue + Mimikatz propagation documented
DebunkingStrongForensic analysis confirmed NotPetya used the NSA EternalBlue exploit (MS17-010) for lateral movement combined with Mimikatz credential harvesting. This combination allowed it to spread even to fully patched machines via harvested admin credentials — explaining why large enterprise networks with mixed patch states suffered near-total compromise.
No functional decryption mechanism — pure wiper
DebunkingStrongUnlike genuine ransomware, NotPetya had no functional decryption mechanism. The ransom note was cosmetic. Overwriting the MBR with a custom bootloader and encrypting the MFT without a retrievable key confirmed wiper intent. The ransomware disguise was designed to delay attribution and obscure the geopolitical nature of the attack.
$10B+ damages independently verified across corporate filings
SupportingStrongMaersk ($300M), Merck ($870M), FedEx/TNT ($400M), Mondelèz ($100M), and Saint-Gobain (€220M) damage figures are drawn from SEC filings, earnings calls, and audited financial disclosures — not self-serving estimates. The aggregate $10B+ figure is the most thoroughly documented economic impact of any cyberattack in history.
Ukraine targeted: primary geopolitical motive
SupportingThe M.E.Doc delivery mechanism — targeting Ukrainian tax-software users — and the timing (Ukrainian Constitution Day eve) indicate Ukraine as the primary target. The global collateral damage to multinationals with Ukrainian operations reflects poor containment design, not an intent to attack global commerce directly.
Rebuttal
The Russian government denied responsibility. The denial is inconsistent with the technical forensics, the Five Eyes attribution, and the criminal indictment. State denial is expected behaviour in nation-state cyberattack attribution and does not constitute counter-evidence.
Mondelèz v Zurich war-exclusion case: settled 2022
SupportingMondelèz sued Zurich Insurance after a $100M claim was denied under a war-exclusion clause covering "hostile or warlike action" by a sovereign state. The case — settled in 2022 on undisclosed terms — validated the legal seriousness of nation-state attribution in cyber insurance contexts and prompted industry-wide review of war exclusion language.
Merck's $1.4B NotPetya claim survives war-exclusion challenge in court
SupportingStrongA New Jersey Superior Court ruled in January 2022 that the "hostile or warlike action" exclusion did not cover NotPetya, since the clause requires actual military action; the Appellate Division affirmed in May 2023; the case settled confidentially in January 2024 before the state Supreme Court heard it.
Rebuttal
Because the case settled before the state Supreme Court ruled, Merck's win is a strong persuasive precedent within New Jersey rather than a binding nationwide one; other jurisdictions could in principle reach a different result on similar policy language.
US Treasury/OFAC sanctions (March 2018) name NotPetya directly
SupportingStrongOn 15 March 2018, Treasury's Office of Foreign Assets Control sanctioned Russian entities and individuals under the Countering America's Adversaries Through Sanctions Act, explicitly citing NotPetya as “the most destructive and costly cyber-attack in history” and attributing it to the Russian military — an economic-policy action independent of, and in addition to, the 2020 criminal indictment.
Show 7 more evidence points
Ukrainian police forensics on Linkos Group's servers independently confirm the supply-chain vector
SupportingThe 4 July 2017 raid on M.E.Doc developer Linkos Group found four-year-old unpatched ProFTPD, Nginx, and OpenSSH, with no HTTPS or code-signing on the update channel — a domestic Ukrainian forensic finding that required no Western intelligence cooperation and independently corroborates the supply-chain entry point.
Kaspersky finds low-confidence code overlap between ExPetr and Sandworm's earlier BlackEnergy/KillDisk toolkit
SupportingWeakMatching file-extension target lists and identical shutdown command strings link ExPetr to the wiper component Sandworm used against Ukraine's power grid in 2015-16; Kaspersky itself labeled this only a “low confidence, persistent hunch,” not proof on its own.
Rebuttal
Kaspersky explicitly cautions this code pattern is generic enough to appear elsewhere, so it should be read as a minor corroborating data point rather than independent proof of Sandworm authorship.
CryptGenRandom-based fake installation ID proves decryption was never possible
DebunkingStrongKaspersky researcher Anton Ivanov showed NotPetya's ransom-note installation ID was generated with Windows' CryptGenRandom function and held no relationship to the actual encryption key, unlike genuine Petya — debunking any theory that this was ordinary extortion that simply malfunctioned.
Australia's independently assessed attribution
DebunkingMinister for Law Enforcement and Cyber Security Angus Taylor stated Australian intelligence agencies reached their own conclusion, informed by but not solely dependent on US/UK input — debunking the claim that the Five Eyes attribution was a single US assessment merely echoed by allies.
NotPetya also infected major Russian companies (Rosneft, Sberbank, Evraz)
NeutralUkraine was the deliberate target, but the malware also struck Rosneft, Sberbank, Home Credit Bank, Evraz, and Invitro inside Russia — the single most-cited objection to the deliberate-state-attack reading.
Rebuttal
Analysts read this as consistent with an uncontrolled worm that does not check nationality once released via EternalBlue and harvested credentials, and note Russian state operations have previously tolerated domestic collateral damage as a deniability smokescreen. It does not contradict the M.E.Doc/GRU authorship evidence, which concerns who launched the weapon, not how far it later spread.
Global Damage Estimates Are Heavily Extrapolated From Few Firms
NeutralThe widely cited $10 billion global damage figure derives primarily from reported losses by Maersk (~$300M), Merck (~$870M), FedEx/TNT (~$400M), and Mondelez (~$100M), with the remainder estimated by extrapolation across less-reported victims. Insurance and reinsurance actuaries have noted significant methodological uncertainty in aggregating self-reported business-interruption losses across diverse sectors. The headline figure, while plausible, should be understood as an order-of-magnitude estimate rather than an audited total, and does not itself imply a broader conspiracy beyond the documented GRU Sandworm deployment.
Russian Intent: Ukraine-Targeted Operation With Collateral Global Spread
NeutralStrongThe primary NotPetya vector was M.E.Doc, Ukrainian accounting software with a near-monopoly in Ukraine's business community, strongly suggesting a Ukraine-specific initial targeting decision. The worm's self-propagating SMB component caused reckless global spread that affected Russian-owned entities (Rosneft) as well as Western firms, which is inconsistent with a designed global attack. US, UK, Australian, and Canadian government attribution to Sandworm for a Ukraine-focused operation — with collateral damage — is more precisely scoped than characterisations of NotPetya as a deliberately global infrastructure attack.
Evidence Cited by Believers7
$10B+ damages independently verified across corporate filings
SupportingStrongMaersk ($300M), Merck ($870M), FedEx/TNT ($400M), Mondelèz ($100M), and Saint-Gobain (€220M) damage figures are drawn from SEC filings, earnings calls, and audited financial disclosures — not self-serving estimates. The aggregate $10B+ figure is the most thoroughly documented economic impact of any cyberattack in history.
Ukraine targeted: primary geopolitical motive
SupportingThe M.E.Doc delivery mechanism — targeting Ukrainian tax-software users — and the timing (Ukrainian Constitution Day eve) indicate Ukraine as the primary target. The global collateral damage to multinationals with Ukrainian operations reflects poor containment design, not an intent to attack global commerce directly.
Rebuttal
The Russian government denied responsibility. The denial is inconsistent with the technical forensics, the Five Eyes attribution, and the criminal indictment. State denial is expected behaviour in nation-state cyberattack attribution and does not constitute counter-evidence.
Mondelèz v Zurich war-exclusion case: settled 2022
SupportingMondelèz sued Zurich Insurance after a $100M claim was denied under a war-exclusion clause covering "hostile or warlike action" by a sovereign state. The case — settled in 2022 on undisclosed terms — validated the legal seriousness of nation-state attribution in cyber insurance contexts and prompted industry-wide review of war exclusion language.
Merck's $1.4B NotPetya claim survives war-exclusion challenge in court
SupportingStrongA New Jersey Superior Court ruled in January 2022 that the "hostile or warlike action" exclusion did not cover NotPetya, since the clause requires actual military action; the Appellate Division affirmed in May 2023; the case settled confidentially in January 2024 before the state Supreme Court heard it.
Rebuttal
Because the case settled before the state Supreme Court ruled, Merck's win is a strong persuasive precedent within New Jersey rather than a binding nationwide one; other jurisdictions could in principle reach a different result on similar policy language.
US Treasury/OFAC sanctions (March 2018) name NotPetya directly
SupportingStrongOn 15 March 2018, Treasury's Office of Foreign Assets Control sanctioned Russian entities and individuals under the Countering America's Adversaries Through Sanctions Act, explicitly citing NotPetya as “the most destructive and costly cyber-attack in history” and attributing it to the Russian military — an economic-policy action independent of, and in addition to, the 2020 criminal indictment.
Ukrainian police forensics on Linkos Group's servers independently confirm the supply-chain vector
SupportingThe 4 July 2017 raid on M.E.Doc developer Linkos Group found four-year-old unpatched ProFTPD, Nginx, and OpenSSH, with no HTTPS or code-signing on the update channel — a domestic Ukrainian forensic finding that required no Western intelligence cooperation and independently corroborates the supply-chain entry point.
Kaspersky finds low-confidence code overlap between ExPetr and Sandworm's earlier BlackEnergy/KillDisk toolkit
SupportingWeakMatching file-extension target lists and identical shutdown command strings link ExPetr to the wiper component Sandworm used against Ukraine's power grid in 2015-16; Kaspersky itself labeled this only a “low confidence, persistent hunch,” not proof on its own.
Rebuttal
Kaspersky explicitly cautions this code pattern is generic enough to appear elsewhere, so it should be read as a minor corroborating data point rather than independent proof of Sandworm authorship.
Counter-Evidence7
Five Eyes joint attribution to GRU Unit 74455 (Feb 2018)
DebunkingStrongUS CISA, UK NCSC, Australian Cyber Security Centre, and Canadian Centre for Cyber Security jointly attributed NotPetya to the Russian GRU in February 2018. The coordinated multi-government attribution reflects shared intelligence and corroborating technical evidence across allied services.
US DOJ indictment of six named GRU officers (Oct 2020)
DebunkingStrongThe US DOJ unsealed an indictment in October 2020 naming six GRU Unit 74455 officers — Andrienko, Detistov, Frolov, Ochichenko, Pliskin, and Kovalev — with granular technical detail of the NotPetya operation, including specific dates, infrastructure, and methods. Criminal indictments require prosecutorial confidence in evidentiary sufficiency.
M.E.Doc supply-chain vector forensically confirmed
DebunkingStrongESET, Cisco Talos, and multiple firms independently confirmed that NotPetya entered networks via a trojanised update to M.E.Doc Ukrainian tax software. The update servers had been compromised weeks before the June 27 detonation date. This supply-chain mechanism is technically documented with file-hash and network-traffic evidence.
EternalBlue + Mimikatz propagation documented
DebunkingStrongForensic analysis confirmed NotPetya used the NSA EternalBlue exploit (MS17-010) for lateral movement combined with Mimikatz credential harvesting. This combination allowed it to spread even to fully patched machines via harvested admin credentials — explaining why large enterprise networks with mixed patch states suffered near-total compromise.
No functional decryption mechanism — pure wiper
DebunkingStrongUnlike genuine ransomware, NotPetya had no functional decryption mechanism. The ransom note was cosmetic. Overwriting the MBR with a custom bootloader and encrypting the MFT without a retrievable key confirmed wiper intent. The ransomware disguise was designed to delay attribution and obscure the geopolitical nature of the attack.
CryptGenRandom-based fake installation ID proves decryption was never possible
DebunkingStrongKaspersky researcher Anton Ivanov showed NotPetya's ransom-note installation ID was generated with Windows' CryptGenRandom function and held no relationship to the actual encryption key, unlike genuine Petya — debunking any theory that this was ordinary extortion that simply malfunctioned.
Australia's independently assessed attribution
DebunkingMinister for Law Enforcement and Cyber Security Angus Taylor stated Australian intelligence agencies reached their own conclusion, informed by but not solely dependent on US/UK input — debunking the claim that the Five Eyes attribution was a single US assessment merely echoed by allies.
Neutral / Ambiguous3
NotPetya also infected major Russian companies (Rosneft, Sberbank, Evraz)
NeutralUkraine was the deliberate target, but the malware also struck Rosneft, Sberbank, Home Credit Bank, Evraz, and Invitro inside Russia — the single most-cited objection to the deliberate-state-attack reading.
Rebuttal
Analysts read this as consistent with an uncontrolled worm that does not check nationality once released via EternalBlue and harvested credentials, and note Russian state operations have previously tolerated domestic collateral damage as a deniability smokescreen. It does not contradict the M.E.Doc/GRU authorship evidence, which concerns who launched the weapon, not how far it later spread.
Global Damage Estimates Are Heavily Extrapolated From Few Firms
NeutralThe widely cited $10 billion global damage figure derives primarily from reported losses by Maersk (~$300M), Merck (~$870M), FedEx/TNT (~$400M), and Mondelez (~$100M), with the remainder estimated by extrapolation across less-reported victims. Insurance and reinsurance actuaries have noted significant methodological uncertainty in aggregating self-reported business-interruption losses across diverse sectors. The headline figure, while plausible, should be understood as an order-of-magnitude estimate rather than an audited total, and does not itself imply a broader conspiracy beyond the documented GRU Sandworm deployment.
Russian Intent: Ukraine-Targeted Operation With Collateral Global Spread
NeutralStrongThe primary NotPetya vector was M.E.Doc, Ukrainian accounting software with a near-monopoly in Ukraine's business community, strongly suggesting a Ukraine-specific initial targeting decision. The worm's self-propagating SMB component caused reckless global spread that affected Russian-owned entities (Rosneft) as well as Western firms, which is inconsistent with a designed global attack. US, UK, Australian, and Canadian government attribution to Sandworm for a Ukraine-focused operation — with collateral damage — is more precisely scoped than characterisations of NotPetya as a deliberately global infrastructure attack.
Timeline
Shadow Brokers release EternalBlue; Microsoft MS17-010 patch already issued
The Shadow Brokers release their "Lost in Translation" dump including EternalBlue. Microsoft had patched MS17-010 on March 14, 2017 after NSA notification. Many organisations remain unpatched. The exploit becomes available to any threat actor globally.
NotPetya detonates from M.E.Doc update — spreads globally within hours
At approximately 4 p.m. Kiev time, NotPetya begins executing on machines that had received the trojanised M.E.Doc update. Within hours it has spread to Maersk, Merck, FedEx, Mondelèz, Rosneft, and hundreds of other organisations across Europe, Asia, and the Americas. Ukrainian government systems, banks, airports, and media suffer near-simultaneous disruption.
Source →Posteo shuts down the ransom-note contact email hours into the outbreak
The German provider disabled [email protected] under routine abuse procedures the same morning NotPetya detonated, before the scale of the attack was understood — permanently severing the only listed payment channel.
Source →Ukrainian police raid Linkos Group, seize M.E.Doc servers
Cyber police seized servers from Intellect Service (developer of M.E.Doc) and found years of unpatched, unsigned update infrastructure, independently confirming the supply-chain entry point.
Verdict
US CISA, UK NCSC, and Five Eyes attributed NotPetya to Russian GRU Unit 74455 (Sandworm) in February 2018. US DOJ indicted six named GRU officers in October 2020 with granular technical detail. Supply-chain entry via M.E.Doc update servers is forensically documented. $10B+ global damages are independently verified across multiple corporate disclosures. Multiple private-sector firms (ESET, Cisco Talos, CrowdStrike) independently confirm the same technical findings.
Frequently Asked Questions
Was NotPetya actually ransomware?
No. Despite displaying a ransom note demanding Bitcoin, NotPetya had no functional decryption mechanism. Forensic analysis confirmed it overwrote the master boot record and encrypted the Master File Table without any key retrieval pathway. The ransomware disguise was cosmetic — designed to delay attribution and obscure the geopolitical nature of a nation-state cyberweapon.
How did NotPetya spread so fast globally?
NotPetya entered corporate networks via a trojanised update to M.E.Doc, Ukrainian tax software used by roughly 80 percent of Ukrainian businesses. Multinationals with Ukrainian operations received the malware through their legitimate software update channel. Once inside a network, it used EternalBlue (MS17-010) and Mimikatz credential harvesting to spread laterally — including to fully patched machines via harvested admin credentials.
Why was Maersk so severely affected?
Maersk lost nearly its entire global IT infrastructure — 45,000 PCs, 4,000 servers, and its Active Directory — because NotPetya's combination of EternalBlue lateral movement and Mimikatz credential harvesting traversed its network before containment was possible. Maersk had a single surviving domain controller (in Ghana, where a power outage had taken it offline during the attack), which became the basis for a ten-day emergency restoration.
Did Merck's insurers ever have to pay out despite the act-of-war exclusion?
Sources
Show 16 more sources
Further Reading
- articleThe Untold Story of NotPetya, the Most Devastating Cyberattack in History — Andy Greenberg (2018)
- bookSandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers — Andy Greenberg (2019)
- bookSandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers — Andy Greenberg (2019)
- paperUS DOJ Indictment: Six GRU Officers Charged for NotPetya and Related Attacks — US Department of Justice (2020)
- podcastNotPetya — Jack Rhysider (Darknet Diaries), featuring Andy Greenberg
- articleNotPetya — Cyber Operations Tracker — Council on Foreign Relations