A look at the Russia-linked NotPetya cyberattack, which caused an estimated $10B+ in damages worldwide after initially targeting Ukrainian companies
Crippled ports. Paralyzed corporations. Frozen government agencies. How a single piece of code crashed the world. Tweets: @ericgeller , @wired , and @wired Tweets: Eric Geller / @ericgeller : Truly excellent @a_greenberg story about how NotPetya devastated Maersk as it ripped across the world last year. Some really fantastic anecdotes that put you right in the story. http://www.wired.com/... http://twitter.com/... @wired : In 2017, the malware NotPetya spread from the servers of a Ukrainian software firm to some of the largest businesses worldwide. The worm crippled ports, paralyzed corporations, and froze government agencies. Here's a breakdown of the approximate damages 1/ http://www.wired.com/... http://twitter.com/... @wired : “I saw a wave of screens turning black. Black, black, black. Black black black black black.” This is the untold story of NotPetya, the most devastating cyberattack in history. http://www.wired.com/... http://twitter.com/...
Context & Ripple Effects
Wired's deep dive closes the loop on a story this page has tracked since mid-2017: a worm seeded through a Ukrainian software firm's update servers that escaped its intended targets and became the costliest cyberattack on record. The piece lands after two earlier beats — Maersk's disclosure of an almost complete infrastructure overhaul covering 4,000 servers, 45,000 PCs, and 2,500 applications, and the February 2018 official attribution by the US, UK, Canada, Australia, and New Zealand pinning the attack on Russia.
What makes the retrospective matter now is the pattern it documents: a single piece of code taking out ports, corporations, and government agencies at once, with the attackers' own 100BTC ransom demand exposed early on as cover for what was really a wiper.
First-order effects
- Maersk, the most visible corporate victim, had already absorbed the direct hit — ports crippled and a global rebuild of its server, PC, and application estate — and the Wired account fixes the operational anatomy of that recovery in public record.
Second-order effects
- The joint attribution turned a technical incident into a diplomatic one, giving five governments grounds for coordinated response against Russia and raising the political cost of future destructive operations attributed to the same actor.
Third-order effects
- Google's later reporting on the Sandworm group ties NotPetya to a broader campaign spanning the Winter Olympics and French election interference, pointing toward an industry structure where state-linked destructive attacks through trusted software supply chains become a standing category of risk rather than a one-off.
The trend: State-linked cyber operations are shifting from espionage toward destructive attacks delivered through compromised software supply chains, with multinational attribution coalitions forming as the countermeasure.