Ransomware attack spreads to firms and agencies in Britain, US, and Netherlands, including ad firm WPP, a US law firm, and shipping giant AP Moller-Maersk
A major ransomware attack has brought businesses to a close throughout Europe, in an infection reminiscent of last month's WannaCry attack.
Context & Ripple Effects
This is the second global ransomware wave in six weeks. In May, WannaCry hit organizations across 99 countries, and Europol's chief put the damage at 200K computers in 150 countries while warning a new wave was likely. That warning has now landed: firms and agencies in Britain, the US, and the Netherlands — including WPP, a US law firm, and AP Moller-Maersk — are shutting down under an infection The Verge describes as reminiscent of WannaCry.
The follow-up reporting matters for how this spreads: the outbreak reached 64 countries including Asia-Pacific and was traced to software from Ukrainian tax accountancy firm M.E.Doc, meaning the delivery mechanism was a trusted business-software supplier rather than a single exposed endpoint. The victim list spans advertising, shipping, law, healthcare, energy, and pharma, which is what separates this from a typical corporate breach.
First-order effects
- WPP, AP Moller-Maersk, Merck, and the other named firms face immediate operational shutdowns — for a shipping group like Maersk, halted systems mean stalled cargo movement, not just IT downtime.
- Organizations that patched after WannaCry now have proof their exposure was structural rather than one-off, since this wave arrived weeks later through a different vector.
Second-order effects
- Because the infection entered via M.E.Doc's tax-accountancy software, every firm running third-party business software must now treat its suppliers as an attack surface — vendors of widely deployed tools inherit the liability question.
- Maersk's disruption ripples into its customers' supply chains: shippers and retailers dependent on its logistics face delays they did nothing to cause, pushing cyber-risk conversations into procurement contracts.
Third-order effects
- Two global waves inside two months, with victims spanning ports, hospitals, power plants, and pharma, points to ransomware being treated as critical-infrastructure risk rather than an IT incident — the same pattern that resurfaces years later in Scattered Spider's attack on UK retailer M&S.
- If supplier-delivered infections become the norm, regulatory pressure shifts from endpoint hygiene to software supply-chain accountability, forcing vendors to answer for the security of what they distribute.
The trend: Ransomware is shifting from episodic outbreaks to a recurring global threat class that treats everyday business software as its delivery system and critical industries as its collateral.