/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

US, UK, Canada, Australia, and New Zealand officially attribute 2017 NotPetya attack that targeted Ukraine and some large businesses to Russia

Eduard Kovacs / SecurityWeek :

SecurityWeek Eduard Kovacs

Context & Ripple Effects

This announcement caps a forensic arc that began months earlier, when researchers found the 'Petya' outbreak had been altered into a wiper rather than working ransomware — a tell that pointed to a nation state rather than criminals (altered to wipe system memory). Britain moved first, saying the day before that Russia was 'almost certainly responsible'; today Washington, Ottawa, Canberra and Wellington join London, turning a single government's assessment into a five-country joint attribution.

The coordination matters because NotPetya, which hit Ukrainian companies first before spreading to large businesses worldwide, caused an estimated $10B+ in damages (the damage accounting) — making this one of the costliest cyberattacks ever publicly attributed to a state.

First-order effects

  • Russia now faces formal, simultaneous public blame from five allied intelligence-sharing governments, converting what was technical inference into declared state policy.
  • The multinational businesses caught in the attack gain an official government attribution they can cite in insurance disputes, litigation, and recovery claims over their losses.

Second-order effects

  • Private-sector researchers and prosecutors can now build openly on the attribution — as Google did when it published new detail on the 'Sandworm' group behind NotPetya (Sandworm revelations), work that feeds directly into law-enforcement cases.
  • Other Western governments face pressure to join or endorse the attribution, raising the diplomatic cost for Moscow of each subsequent operation traced to the same group.

Third-order effects

  • The pattern points toward criminal indictment of state officers rather than mere statements: the DOJ later charged six Russian GRU officers for NotPetya alongside the Ukraine blackouts and election and Olympics attacks (GRU indictments), establishing prosecution as the follow-through to joint attribution.
  • Coalition attribution of this kind becomes a standing playbook — the same multi-government model reappears in later operations like the 2023 takedown of a ransomware group operating from Ukraine (the international arrest operation).

The trend: Western governments are shifting from quiet technical forensics to coordinated public attribution and eventual criminal prosecution of state-backed hacking units.