Back to the case archive

File 2017/007, Documented event

NotPetya attack

Kyiv, Ukraine (global spread), June 2017

Case summary

On 27 June 2017, NotPetya, a wiper disguised as ransomware, was distributed through the update server of Ukrainian accounting software M.E.Doc and paralysed global companies within hours. Estimated damage exceeded $10 billion; the US, UK and allies attributed the attack to Russian military intelligence (GRU) in 2018.

Timeline

  1. 2017-06-27Initial infection via an M.E.Doc update; banks, the airport and ministries hit in Ukraine.
  2. 2017-06-27Spread to global firms including Maersk, Merck, FedEx/TNT and Rosneft.
  3. 2017-06-28Analysis showed the encryption was irreversible; the goal was destruction, not ransom.
  4. 2017-07-04Ukrainian police seized M.E.Doc's servers.
  5. 2018-02-15The White House and the UK attributed the attack to the Russian military.
  6. 2020-10-19The US DOJ indicted six officers of GRU Unit 74455 (Sandworm).

People and connections

  • Sandworm (GRU 74455)Organisation

    The attributed operator unit; subject of the 2020 indictment.

  • M.E.DocOrganisation

    The software firm whose update channel was the supply-chain entry point.

  • EternalBlue / MimikatzObject

    The exploit and credential tool combined for lateral spread.

  • MaerskOrganisation

    Among the most visible victims; rebuilt 4,000 servers and 45,000 endpoints.

  • Sandworm (GRU 74455) to M.E.DocCompromise of the update server (supply chain)
  • M.E.Doc to MaerskSpread from a single Ukraine-office install to the global network

Findings

Every finding lists its source and date. Interpretation stays in the researcher's note.

  • That the initial vector was M.E.Doc's update mechanism is verified by independent analyses.

    VerifiedSource: ESET, Cisco Talos and Ukrainian police2017-07
  • The malware was engineered so payment could not recover data; it is classed as a wiper.

    VerifiedSource: Kaspersky and Matt Suiche analyses2017-06
  • GRU attribution is supported with high confidence by a five-country joint statement and the 2020 indictment, though no court verdict exists.

    ProbableSource: DOJ indictment2020-10
  • Total-damage estimates ($10–12bn) rest on insurance and corporate reporting; no definitive figure exists.

    ContestedSource: White House estimate2018-02

Documents

Sources

  1. The Untold Story of NotPetya

    WIRED (Andy Greenberg), 2018, In-depth investigation

    Open source
  2. Six Russian GRU Officers Charged

    US Department of Justice, 2020, Official indictment

    Open source
  3. NotPetya technical analysis

    ESET WeLiveSecurity, 2017, Technical analysis

    Open source
  4. Statement on NotPetya attribution

    White House / NCSC, 2018, Official attribution statement

    Open source

Locations

  • Kyiv (M.E.Doc HQ)50.45°, 30.52°
  • Copenhagen (Maersk HQ)55.68°, 12.57°

Researcher's note

Interpretation: NotPetya is the teaching case for attribution methodology: technical evidence (code overlap, infrastructure), contextual evidence (targeting, timing) and formal process (indictment) must be read as three separate layers. The early mislabelling as 'ransomware' shows why first reports should be marked as provisional assessments.

Recent checks

  1. 2026-05-30Source URLs checked; the NCSC attribution page had moved, archive link added.