The NotPetya cyber attack of 2017 is widely described as the most destructive cyberattack in history. It began as a strike on Ukraine, then tore through global companies in a matter of hours. Damage estimates reach around $10 billion across organizations in roughly 65 countries.
Years later, its lessons still matter. This guide explains what happened, how the malware spread, who was responsible, and what your business should do differently today.
Table of Contents
- What Was the NotPetya Cyber Attack of 2017
- NotPetya Cyber Attack Timeline
- How the NotPetya Cyber Attack Spread
- NotPetya vs Petya vs WannaCry
- Why NotPetya Was a Wiper, Not Ransomware
- Who Was Behind the NotPetya Cyber Attack
- The Real Cost of the NotPetya Cyber Attack
- How Maersk Recovered
- The Insurance Fallout
- 7 Lessons From the NotPetya Cyber Attack
- Could Another NotPetya Cyber Attack Happen
- Common Misconceptions
- Frequently Asked Questions
- Test Your Own Resilience
What Was the NotPetya Cyber Attack of 2017
NotPetya was destructive malware that surfaced on June 27, 2017. It looked like ransomware, with a ransom note and a payment demand. In reality, it was built to destroy data, not to earn money.
The name came from researchers who wanted to separate it from the older Petya ransomware family. Although the two share some code, their goals were completely different.
The NotPetya cyber attack hit Ukraine first. Government ministries, banks, metro systems, and even the radiation monitoring system at the Chernobyl plant were affected. Then it spread far beyond Ukraine’s borders.
NotPetya Cyber Attack Timeline
| Date | What Happened |
|---|---|
| June 27, 2017 | Malware spreads through a compromised software update in Ukraine |
| Within hours | Global companies including Maersk, Merck, and TNT Express go offline |
| June 28 to July 2017 | Researchers conclude the malware is a wiper, not real ransomware |
| February 2018 | US and UK governments publicly attribute the attack to Russia |
| October 2020 | The US Department of Justice indicts six Russian military intelligence officers |
The speed is what stunned defenders. Maersk’s network was reportedly crippled within minutes, with the damage complete in about an hour.
How the NotPetya Cyber Attack Spread
The entry point was a supply chain compromise. Attackers abused the update mechanism of M.E.Doc, a widely used Ukrainian tax accounting program. Customers trusted the update, so they installed it.
Once inside a network, the malware moved on its own. It combined a leaked exploit targeting a Windows file sharing weakness, known as EternalBlue, with stolen credentials. That pairing let it hop from machine to machine without any user clicking anything.
This is why the NotPetya cyber attack behaved like a worm rather than a classic virus. If you want a quick refresher on the difference, the distinction between a trojan horse and a worm comes down to self replication. A worm spreads by itself, and NotPetya did exactly that.
Two failures made the spread possible: unpatched systems and flat networks. Where those existed, the malware crossed entire organizations in minutes.
NotPetya vs Petya vs WannaCry
These three names get mixed up constantly. Here is how they differ:
| Feature | Petya | WannaCry | NotPetya |
|---|---|---|---|
| Year | 2016 | May 2017 | June 2017 |
| Goal | Extortion | Extortion | Destruction |
| Spread method | Phishing | Worm using EternalBlue | Supply chain plus EternalBlue and stolen credentials |
| Recoverable by paying | Sometimes | Sometimes | No |
WannaCry drew huge public attention in May 2017 and remains one of the most searched attacks of that year. NotPetya arrived roughly six weeks later and reused the same class of Windows weakness.
The key difference is intent. WannaCry wanted money. The NotPetya cyber attack wanted damage.
Why NotPetya Was a Wiper, Not Ransomware
Real ransomware needs a working way to give files back once the victim pays. NotPetya did not have one. The encryption routine destroyed the information needed for recovery.
That means paying the ransom accomplished nothing. Even victims who wanted to pay could not get their data back.
This matters for how we talk about the incident. Calling it ransomware understates what it was. It was a disguised sabotage operation, which is why defenders now plan for wipers separately from ransomware.
Your ransomware protection plan should assume that some attacks will never offer a decryption path. Tested backups become the only reliable recovery route.
Who Was Behind the NotPetya Cyber Attack
US and UK authorities attributed the attack to Sandworm, a unit of Russia’s military intelligence agency, the GRU. In October 2020, the US Department of Justice charged six GRU officers in connection with NotPetya and other destructive operations.
The Kremlin has denied involvement. Western governments rejected that denial and described the campaign as reckless and unprecedented in scale.
Prosecutors argued the malware was aimed at Ukraine but caused enormous collateral damage worldwide. You can read the government’s account in the US Department of Justice announcement.
The Real Cost of the NotPetya Cyber Attack
The financial impact is hard to pin down, because indirect losses are difficult to measure. Still, reported figures show the scale:
| Organization | Estimated Impact |
|---|---|
| Maersk | $200 million to $300 million |
| FedEx (TNT Express) | About $400 million |
| US shoreside business impact | Nearly $1 billion |
| Global total | Around $10 billion |
Merck, the pharmaceutical company, was also badly hit. The global figure is an estimate, and different sources vary. What no one disputes is that the NotPetya cyber attack cost more than almost any cyber incident before it.
How Maersk Recovered
Maersk became the defining case study. The shipping giant lost its Active Directory domain controllers, the servers that control who can log in to nearly everything.
It reportedly took about nine days to rebuild that core identity system. Maersk’s security chief later stressed that organizations should aim for far faster recovery.
One widely reported detail stands out. A single domain controller in Ghana survived because a power outage had taken it offline when the malware struck. That accident helped Maersk rebuild.
The lesson is uncomfortable. Recovery depended partly on luck, not planning. A modern disaster recovery plan should never rely on that.
The Insurance Fallout
The NotPetya cyber attack also reshaped cyber insurance. Insurers argued that policy war exclusions applied because the attack was attributed to a nation state.
Mondelez filed a claim with its insurer Zurich, which denied coverage on that basis. That dispute became one of the most closely watched legal battles in the industry. Merck pursued a similar fight with its own insurers.
The result was a wave of policy rewrites. Many insurers now use much more specific language about state backed attacks. Businesses should review their own wording carefully rather than assuming coverage.
7 Lessons From the NotPetya Cyber Attack
- Patch management is not optional. The spread relied on a known, fixable weakness. Prompt patching would have blocked a large share of infections.
- Segment your network. Flat networks let malware travel freely. Network segmentation limits how far an infection can run.
- Protect Active Directory. Losing identity infrastructure paralyzes everything. Keep isolated, tested recovery copies.
- Vet software supply chain trust. A trusted update was the delivery vehicle. Software supply chain security means monitoring what your vendors push into your environment.
- Keep offline, tested backups. No malware protection strategy is 100 percent effective. Backups you have never restored are a hope, not a plan.
- Rehearse incident response. Teams that practiced recovery rebuilt faster. Run tabletop exercises before an attack, not during one.
- Read your cyber insurance policy. Understand war and state actor exclusions before you need to claim.
Each of these lessons is measurable in your own environment. A structured vulnerability assessment and penetration testing engagement is the fastest way to find out which ones you are failing today.
Could Another NotPetya Cyber Attack Happen
Yes, and the ingredients are still common. The same threat group has continued deploying wipers since 2017, including attacks tied to the war in Ukraine that caused spillover damage in other countries.
Supply chain compromise also remains a favored tactic, because it lets attackers reach thousands of victims through one trusted channel. Small and mid sized businesses are exposed too, since they often lack dedicated security teams.
For smaller organizations, the basics matter most. Strong cybersecurity best practices for SMBs, including patching, backups, and access controls, remove the easiest paths an attacker would use.
Common Misconceptions
- “NotPetya was ransomware.” It only pretended to be. Recovery through payment was not possible.
- “Only Ukrainian companies were targets.” Ukraine was the intended focus, but the malware spread globally in hours.
- “Antivirus alone would have stopped it.” Once inside, the spread used legitimate credentials and network protocols. Layered defenses were needed.
- “This only affects large enterprises.” Any organization with flat networks and unpatched systems shares the same weakness.
- “It was a one off event.” Its techniques, supply chain abuse and worm-like movement, continue to appear in modern attacks.
Frequently Asked Questions
What was the NotPetya cyber attack?
It was a destructive malware outbreak that began on June 27, 2017, disguised as ransomware but designed to permanently destroy data.
Who was responsible for NotPetya?
The US and UK governments attributed it to Sandworm, a unit within Russia’s GRU military intelligence agency. The US indicted six officers in 2020, and Russia has denied involvement.
How much damage did NotPetya cause?
Estimates reach roughly $10 billion globally. Maersk reported losses of $200 million to $300 million, and FedEx estimated about $400 million.
How did NotPetya spread so quickly?
It entered through a compromised software update, then moved between computers using a Windows exploit and stolen credentials, requiring no user action.
What is the difference between NotPetya and WannaCry?
WannaCry was extortion focused and aimed at money. NotPetya was designed to destroy data, and paying could not recover files.
Could files be decrypted after NotPetya?
In general, no. The malware did not preserve the information needed for recovery, so restoring from backups was the only reliable option.
How did Maersk recover?
Maersk rebuilt its infrastructure over about nine days, starting with its Active Directory, and was helped by one surviving domain controller in Ghana.
Was NotPetya considered an act of war by insurers?
Some insurers argued it fell under war exclusions after government attribution to Russia. Those arguments led to major legal disputes, including Mondelez against Zurich.
Could a NotPetya style attack happen again?
Yes. Unpatched systems, flat networks, and supply chain trust gaps still exist in many organizations, and state backed wiper campaigns have continued.
How can I check whether my business is exposed?
A security risk assessment and penetration test shows where an attacker could enter and how far they could travel inside your network.
Test Your Own Resilience
Understanding the NotPetya cyber attack is useful. Knowing whether your own network could survive one is what actually protects you.
Our team tests the same weaknesses that made NotPetya possible: unpatched systems, flat networks, weak credentials, and fragile recovery plans.

