File 2017/007, Documented event
NotPetya attack
Kyiv, Ukraine (global spread), June 2017
Case summary
On 27 June 2017, NotPetya, a wiper disguised as ransomware, was distributed through the update server of Ukrainian accounting software M.E.Doc and paralysed global companies within hours. Estimated damage exceeded $10 billion; the US, UK and allies attributed the attack to Russian military intelligence (GRU) in 2018.
Timeline
- 2017-06-27Initial infection via an M.E.Doc update; banks, the airport and ministries hit in Ukraine.
- 2017-06-27Spread to global firms including Maersk, Merck, FedEx/TNT and Rosneft.
- 2017-06-28Analysis showed the encryption was irreversible; the goal was destruction, not ransom.
- 2017-07-04Ukrainian police seized M.E.Doc's servers.
- 2018-02-15The White House and the UK attributed the attack to the Russian military.
- 2020-10-19The US DOJ indicted six officers of GRU Unit 74455 (Sandworm).
People and connections
- Sandworm (GRU 74455)Organisation
The attributed operator unit; subject of the 2020 indictment.
- M.E.DocOrganisation
The software firm whose update channel was the supply-chain entry point.
- EternalBlue / MimikatzObject
The exploit and credential tool combined for lateral spread.
- MaerskOrganisation
Among the most visible victims; rebuilt 4,000 servers and 45,000 endpoints.
- Sandworm (GRU 74455) to M.E.DocCompromise of the update server (supply chain)
- M.E.Doc to MaerskSpread from a single Ukraine-office install to the global network
Findings
Every finding lists its source and date. Interpretation stays in the researcher's note.
That the initial vector was M.E.Doc's update mechanism is verified by independent analyses.
The malware was engineered so payment could not recover data; it is classed as a wiper.
GRU attribution is supported with high confidence by a five-country joint statement and the 2020 indictment, though no court verdict exists.
Total-damage estimates ($10–12bn) rest on insurance and corporate reporting; no definitive figure exists.
Documents
- DocumentDOJ 2020 indictmentThe 50-page document charging Sandworm officers by name.
- DocumentESET Telebots analysis chainThe technical series linking NotPetya to earlier Ukraine attacks.
- MapSpread mapThe Ukraine-centred infection jumping to 65+ countries.
Sources
The Untold Story of NotPetya
Open sourceSix Russian GRU Officers Charged
Open sourceNotPetya technical analysis
Open sourceStatement on NotPetya attribution
Open source
Locations
- Kyiv (M.E.Doc HQ)50.45°, 30.52°
- Copenhagen (Maersk HQ)55.68°, 12.57°
Researcher's note
Interpretation: NotPetya is the teaching case for attribution methodology: technical evidence (code overlap, infrastructure), contextual evidence (targeting, timing) and formal process (indictment) must be read as three separate layers. The early mislabelling as 'ransomware' shows why first reports should be marked as provisional assessments.
Recent checks
- 2026-05-30Source URLs checked; the NCSC attribution page had moved, archive link added.

