/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A look at the Russia-linked NotPetya cyberattack, which caused an estimated $10B+ in damages worldwide after initially targeting Ukrainian companies

Crippled ports.  Paralyzed corporations.  Frozen government agencies.  How a single piece of code crashed the world. Tweets: @ericgeller , @wired , and @wired Tweets: Eric Geller / @ericgeller : Truly excellent @a_greenberg story about how NotPetya devastated Maersk as it ripped across the world last year. Some really fantastic anecdotes that put you right in the story. http://www.wired.com/... http://twitter.com/... @wired : In 2017, the malware NotPetya spread from the servers of a Ukrainian software firm to some of the largest businesses worldwide. The worm crippled ports, paralyzed corporations, and froze government agencies. Here's a breakdown of the approximate damages 1/ http://www.wired.com/... http://twitter.com/... @wired : “I saw a wave of screens turning black. Black, black, black. Black black black black black.” This is the untold story of NotPetya, the most devastating cyberattack in history. http://www.wired.com/... http://twitter.com/...

Wired Andy Greenberg

Context & Ripple Effects

Wired's deep dive closes the loop on a story this page has tracked since mid-2017: a worm seeded through a Ukrainian software firm's update servers that escaped its intended targets and became the costliest cyberattack on record. The piece lands after two earlier beats — Maersk's disclosure of an almost complete infrastructure overhaul covering 4,000 servers, 45,000 PCs, and 2,500 applications, and the February 2018 official attribution by the US, UK, Canada, Australia, and New Zealand pinning the attack on Russia.

What makes the retrospective matter now is the pattern it documents: a single piece of code taking out ports, corporations, and government agencies at once, with the attackers' own 100BTC ransom demand exposed early on as cover for what was really a wiper.

First-order effects

  • Maersk, the most visible corporate victim, had already absorbed the direct hit — ports crippled and a global rebuild of its server, PC, and application estate — and the Wired account fixes the operational anatomy of that recovery in public record.

Second-order effects

  • The joint attribution turned a technical incident into a diplomatic one, giving five governments grounds for coordinated response against Russia and raising the political cost of future destructive operations attributed to the same actor.

Third-order effects

  • Google's later reporting on the Sandworm group ties NotPetya to a broader campaign spanning the Winter Olympics and French election interference, pointing toward an industry structure where state-linked destructive attacks through trusted software supply chains become a standing category of risk rather than a one-off.

The trend: State-linked cyber operations are shifting from espionage toward destructive attacks delivered through compromised software supply chains, with multinational attribution coalitions forming as the countermeasure.