On 27 June 2017, the shipping company Maersk — responsible for roughly a fifth of the world's container traffic — watched its entire global IT infrastructure die in under seven minutes.
Screens across offices in dozens of countries went black and came back with a demand for $300 in Bitcoin. In Maersk's terminal at Elizabeth, New Jersey, lorry drivers arrived to collect containers and found nobody could tell them which container was which. The gates closed. The same thing was happening in Rotterdam, in Mumbai, in Los Angeles.
The message on the screens said the files were encrypted and could be restored by paying. This was a lie. NotPetya was never ransomware. It was a wiper, dressed as ransomware to buy time and confuse attribution.
The poisoned update
The attack did not begin with an email. It began with a Ukrainian accounting program called M.E.Doc.
Almost any company doing business in Ukraine used it, because it was effectively required for filing taxes. Attackers had compromised the software company's update server, and pushed NotPetya out through the normal, signed, expected update channel.
This is what makes a supply chain attack so dangerous. Nothing about the delivery was suspicious. The software was legitimate, the update mechanism was the correct one, and the file arrived from the vendor's own servers. Every reasonable security instinct — do not open strange attachments, do not run unknown programs — was irrelevant, because the malicious code arrived through the trusted path.
How it moved
Once on one machine, NotPetya spread across internal networks with brutal efficiency, combining two techniques.
The first was EternalBlue, an exploit in Windows file sharing, developed by the NSA and leaked publicly by a group calling itself the Shadow Brokers two months earlier. Microsoft had already patched it — the patch was available before the attack — but a great many machines in large organisations were not updated.
The second technique is the one that mattered more, and it needed no vulnerability at all. NotPetya harvested credentials out of the memory of each machine it landed on, then used those credentials to log in to other machines legitimately, using the ordinary administrative tools Windows provides.
That combination is why patching alone did not save anyone. If a domain administrator had logged into an infected machine at any point, their credentials were now in the attacker's hands, and every fully-patched machine in the organisation would accept them. Companies that had diligently patched still lost everything, because the malware simply walked in the front door with a valid key.
The spread was effectively instantaneous. Maersk's estimate was that the network was gone in about seven minutes.
The reconstruction
Maersk lost roughly 4,000 servers, 45,000 PCs and 2,500 applications. Their Active Directory — the system that defines who exists and what they may access — was destroyed at every site simultaneously. Without it, a Windows network cannot be rebuilt; you do not know who anybody is.
They were saved by an accident. An office in Ghana had suffered a power cut during the attack, which took its domain controller offline before the malware reached it. That one surviving copy, carried physically to the recovery effort in the UK, was the seed from which the entire company's identity infrastructure was regrown.
The rebuild took around ten days of continuous work. Maersk put its own losses near $300 million. The pharmaceutical company Merck reported roughly $870 million. FedEx's European subsidiary TNT reported around $400 million. Total global damage has been estimated at approximately $10 billion, which makes NotPetya the most financially destructive cyberattack yet recorded.
The intended target was Ukraine. Everyone else was collateral damage, hit simply because they had an office there, or a subsidiary, or a supplier who did. Western governments have attributed the attack to Russian military intelligence.
What it teaches
Trust flows downhill, and you did not choose most of your suppliers' suppliers. Your security now depends on every vendor whose software auto-updates on your machines. That is not an argument against updates — unpatched systems are worse — but it is a reason to know what has permission to change itself on your systems.
Flat networks turn one compromise into total loss. NotPetya was devastating because once inside, everything was reachable from everything. Segmentation is unglamorous and it is the difference between an incident and a catastrophe.
Backups only count if they are offline. Anything reachable from the network during the attack was destroyed along with everything else. The Ghana domain controller survived precisely because it was disconnected.
Reused administrative credentials are the actual explosive. The exploit got it in the door. Harvested passwords burned the building down.
For an individual rather than a corporation, the transferable lesson is narrower but real: the same credential-reuse dynamic is what turns one breached website into a compromise of your email, and then everything your email can reset. Unique passwords per service, a password manager, and multi-factor authentication on the accounts that can reset the others. Boring, and it is the entire defence.
NotPetya is the clearest demonstration we have that in a connected economy there is no such thing as someone else's security problem. A tax program used by Ukrainian accountants stopped ships from docking in New Jersey.