On June 27, 2017, a software update pushed through M.E.Doc - Ukrainian accounting software used by approximately 80% of Ukrainian businesses for tax filings - began encrypting hard drives. The malware called itself "Petya" but was not Petya. Security researchers quickly named it "NotPetya" to distinguish it from the ransomware it superficially resembled. NotPetya was not ransomware. It was a wiper disguised as ransomware - a cyberweapon designed to destroy data without any possibility of recovery. The ransom demand displayed on encrypted screens was theater. There was no working decryption mechanism. There never was.
What followed in the next 24 hours was the most destructive cyberattack in history by direct financial impact. NotPetya spread from Ukraine using EternalBlue (the same NSA exploit used by WannaCry six weeks earlier) combined with a credential-stealing module that extracted Windows account hashes from memory and used them to propagate laterally across corporate networks without any user interaction. The malware hit shipping giant Maersk, pharmaceutical company Merck, FedEx subsidiary TNT Express, construction company Saint-Gobain, food company Mondelez, advertising holding company WPP, and thousands of other companies. Total losses exceeded $10 billion.
The M.E.Doc Supply Chain Attack
M.E.Doc was the entry point. The software had an auto-update feature; attackers (later attributed to Sandworm, a Russian GRU Unit 74455 operation) had compromised M.E.Doc's update infrastructure months before the June 27 deployment. The backdoor inserted into M.E.Doc's update system gave Sandworm persistent access to any machine running the software and the ability to push arbitrary code as a software update.
When Sandworm pushed NotPetya through the M.E.Doc update on June 27, every machine running M.E.Doc that accepted the update received the malware simultaneously. Because M.E.Doc was essentially mandatory for Ukrainian businesses conducting tax compliance, the initial infection was enormous: Ukrainian government ministries, banks, airports, the Kyiv metro system, state power company Ukrenergo, and thousands of private businesses all received the update and began encrypting simultaneously.
The intent was clearly to cause maximum disruption in Ukraine. But NotPetya didn't stay in Ukraine. The propagation mechanisms - EternalBlue for unpatched SMBv1 systems, and credential-based lateral movement using extracted NTLM hashes - spread the malware to any machine reachable from an infected network, regardless of geographic location. Companies with even modest connectivity to Ukrainian offices or subsidiaries found the malware spreading through their global networks. This was the mechanism by which NotPetya became a global incident rather than a Ukraine-specific attack.
Maersk: Reinstalling an Empire in 10 Days
A.P. Moller-Maersk is the world's largest container shipping company, handling approximately 20% of global ocean container freight. NotPetya reached Maersk through its Ukrainian operations. The malware spread across Maersk's global network within minutes, taking down approximately 45,000 PCs and 4,000 servers across 130 countries. Maersk's port operations worldwide stopped. Ships at sea could still sail, but the logistics and booking systems that coordinated container movements were gone.
Maersk's recovery became one of the most documented disaster recovery operations in corporate history. The company had to reinstall its entire IT infrastructure from scratch. They needed to restore their Active Directory. By a near-miraculous accident of timing, one AD domain controller in Ghana had been offline during the attack because of a local power outage - and came back online after NotPetya had finished spreading. That single surviving domain controller, in Ghana, contained the directory information needed to rebuild Maersk's global AD forest. The company flew a team to Accra to recover it.
The reinstallation required 45,000 new PCs, 4,000 servers, and 2,500 applications in approximately 10 days - with Maersk employees working around the clock and hundreds of IT staff volunteering to participate. Maersk's CEO later said the Ghana domain controller "was a savior." The total cost to Maersk was approximately $300 million. The incident triggered a comprehensive rebuild of Maersk's IT security architecture, including network segmentation, endpoint security, and backup systems that hadn't existed before.
Attribution and Geopolitical Context
NotPetya was deployed on June 27, 2017 - the day before Ukraine's Constitution Day, a national holiday. The timing, the M.E.Doc delivery mechanism, and the primary targeting of Ukrainian infrastructure all pointed to Russian state involvement from early in the investigation. In February 2018, the US, UK, Australian, Canadian, and other governments formally attributed NotPetya to Sandworm, identifying it as an operation by the GRU's Main Centre for Special Technologies (GTsST), Unit 74455.
The same group - Sandworm - was responsible for the 2015 and 2016 Ukraine power grid attacks, the Olympic Destroyer malware at the 2018 Pyeongchang Olympics, and the Industroyer2 attack on Ukraine's power grid in April 2022. The pattern represents Russia's ongoing use of destructive cyber operations as an instrument of its campaign against Ukraine, with collateral damage to global companies treated as acceptable or even desired.
In October 2020, the DOJ indicted six Russian GRU officers in connection with NotPetya, the 2018 Olympic Destroyer attack, and other operations. The individuals named - Yuriy Andrienko, Sergei Detistov, Pavel Frolov, Anatoliy Kovalev, Artem Ochichenko, and Petr Pliskin - were alleged to be members of Unit 74455 operating under GRU Center 16 and Center 74455. No extraditions were expected; the indictments were primarily a public attribution and naming action.