Case summary
On 27 June 2017, NotPetya, a wiper disguised as ransomware, was distributed through the update server of Ukrainian accounting software M.E.Doc and paralysed global companies within hours. Estimated damage exceeded $10 billion; the US, UK and allies attributed the attack to Russian military intelligence (GRU) in 2018.
Timeline
- 2017-06-27Initial infection via an M.E.Doc update; banks, the airport and ministries hit in Ukraine.
- 2017-06-27Spread to global firms including Maersk, Merck, FedEx/TNT and Rosneft.
- 2017-06-28Analysis showed the encryption was irreversible; the goal was destruction, not ransom.
- 2017-07-04Ukrainian police seized M.E.Doc's servers.
- 2018-02-15The White House and the UK attributed the attack to the Russian military.
- 2020-10-19The US DOJ indicted six officers of GRU Unit 74455 (Sandworm).
People and connections
- Sandworm (GRU 74455)
The attributed operator unit; subject of the 2020 indictment.
- M.E.Doc
The software firm whose update channel was the supply-chain entry point.
- EternalBlue / Mimikatz
The exploit and credential tool combined for lateral spread.
- Maersk
Among the most visible victims; rebuilt 4,000 servers and 45,000 endpoints.
- Sandworm (GRU 74455) to M.E.DocCompromise of the update server (supply chain)
- M.E.Doc to MaerskSpread from a single Ukraine-office install to the global network
Findings
That the initial vector was M.E.Doc's update mechanism is verified by independent analyses.
The malware was engineered so payment could not recover data; it is classed as a wiper.
GRU attribution is supported with high confidence by a five-country joint statement and the 2020 indictment, though no court verdict exists.
Total-damage estimates ($10–12bn) rest on insurance and corporate reporting; no definitive figure exists.
Documents
- DocumentDOJ 2020 indictmentThe 50-page document charging Sandworm officers by name.
- DocumentESET Telebots analysis chainThe technical series linking NotPetya to earlier Ukraine attacks.
- MapSpread mapThe Ukraine-centred infection jumping to 65+ countries.
Sources
Locations
- Kyiv (M.E.Doc HQ)50.45°, 30.52°
- Copenhagen (Maersk HQ)55.68°, 12.57°
Researcher's note
What caught my attention here was how quickly the early ransomware label became misleading. Code overlap alone was not enough for attribution; infrastructure, targets, timing, and the later formal investigation had to be read together.
Recent checks
- 2026-05-30Source URLs checked; the NCSC attribution page had moved, archive link added.

