CASE FILE
ND-2017-06
2017-06-27
TLP:CLEAR
// Cyber Incident Case File — Nation-State Destructive / Worm-Enabled Collateral Damage

MAERSK NOTPETYA ATTACK

COMPILED: 2026-09-02  |  INCIDENT DATE: 2017-06-27 (global outbreak) — Maersk recovery through ~2017-07-07  |  SOURCES: 16
Incident Type: NATION-STATE DESTRUCTIVE · WORM/SELF-PROPAGATING
Attribution: Sandworm Team / GRU Unit 74455 [HIGH]
Severity: CRITICAL
Era: 2017 (Post-ATT&CK launch)
ATT&CK Framework: Enterprise
$300M
Ceiling of Maersk's own disclosed business-interruption cost (Aug 2017)
10 DAYS
To reinstall 4,000 servers, 45,000 PCs & 2,500 apps — vs. ~6 months normal
$10B+
Total global NotPetya damage across all victims (White House assessment)
1 of ~150
Domain controllers to survive — saved by a Ghana office power outage
00
Case File Overview
Attributed Actor → Sandworm Team / GRU Unit 74455 (tracked separately as APT44) — No companion actor card on file
Incident NameMaersk NotPetya Attack
Date RangeBackdoor planted: ~mid-May 2017 · Global outbreak: 2017-06-27 · Maersk recovery: ~10 days
Incident TypeNation-state destructive attack, worm-enabled global collateral damage
Primary ActorSandworm Team (Russia, GRU Main Center for Special Technologies, Unit 74455)
Attribution Confidence[HIGH]
Primary TargetUkrainian government & economy (intended) — A.P. Møller-Maersk (collateral, this card's focus)
Victim CountMaersk globally (all business units) + 80%+ of NotPetya's ~ hundreds of other corporate/government victims worldwide
Initial Discovery2017-06-27, within hours — impact was immediately overt, not covertly discovered
Discovered ByMaersk IT staff (real-time, as systems went dark company-wide)
Dwell Time~6 weeks (M.E.Doc backdoor present before detonation) · Maersk's own network compromised same-day as outbreak
Primary Impact~$200–300M business interruption; 4,000 servers/45,000 PCs/2,500 apps rebuilt from scratch
ATT&CK FrameworkEnterprise
MITRE Campaign IDNone dedicated — tracked under Group G0034 (Sandworm Team) / Software S0368 (NotPetya)
Historical IOCsYes — infrastructure/hashes are 9 years stale; archival value only
01
Situation Overview

On June 27, 2017, a piece of malware distributed through a hijacked software update for a Ukrainian tax-accounting program detonated across the internet, self-propagating through corporate networks worldwide using leaked NSA exploits and stolen credentials. Within Ukraine it hit government ministries, banks, energy utilities, the Kyiv metro, and even the radiation-monitoring systems at Chernobyl. Outside Ukraine, it caused what the White House would later call, in its formal February 2018 attribution statement, "the most destructive and costly cyber-attack in history" — over $10 billion in global damage by U.S. government estimate (The White House, 2018). This card examines that campaign specifically through the experience of one collateral victim: A.P. Møller-Maersk, the world's largest container shipping company, whose entire global IT estate — roughly 150 countries' worth of terminals, vessels, and back-office systems running on a single flat Windows domain — was wiped in minutes because one of its business units happened to run the compromised Ukrainian tax software.

Maersk was never the intended target. The malware, publicly named NotPetya (also tracked as Petya.A, GoldenEye, ExPetr, and Nyetya across vendor reporting), was built and deployed by Russia's military intelligence directorate as an instrument aimed squarely at Ukraine, timed one day before Ukraine's Constitution Day and amid the ongoing conflict following Russia's 2014 annexation of Crimea. Its worm-like propagation mechanism, however, recognized no border and no target list: any organization anywhere in the world with a network-connected machine running the trojanized M.E.Doc update, or with an unpatched or credential-exposed machine on the same flat network as one, was fair game. Maersk's exposure came through Maersk's Ukraine-based freight-forwarding operations; from there, the malware crossed onto Maersk's single global Windows domain and detonated company-wide.

What makes the Maersk case the canonical teaching example of NotPetya — more than Merck, more than FedEx/TNT Express, more than any of the incident's dozens of other major corporate victims — is the combination of the scale of destruction (every domain controller Maersk operated was wiped except one, saved purely by chance), the specificity of the recovery story (a hard drive physically flown out of a small West African office to rebuild the company's Active Directory), and the fact that Maersk's own leadership, notably then-Chairman Jim Hagemann Snabe, spoke publicly and in detail about the incident at forums including the World Economic Forum — producing an unusually well-documented, first-person account of what a full-enterprise wipe actually looks like from inside a Fortune Global 500 company.

Nearly a decade later, Maersk-NotPetya remains foundational reference material for business continuity planning, Active Directory security architecture, cyber insurance underwriting (via the parallel Merck and Mondelez litigation over "war exclusion" clauses triggered by the same campaign), and the broader doctrine of cyber-attack attribution, since the joint February 2018 statement by the U.S. and seven allied governments represented the most coordinated multinational attribution of a cyberattack to a nation-state that had occurred up to that point.

02
Background & Context

By mid-2017, Sandworm Team — the GRU unit publicly tracked today under a long list of vendor names (ELECTRUM, Telebots, BlackEnergy, Voodoo Bear, Iron Viking, Seashell Blizzard, and, in Mandiant's later consolidated tracking, APT44) — had already conducted two confirmed disruptive attacks on Ukraine's power grid, in December 2015 and December 2016, using the BlackEnergy and Industroyer/CRASHOVERRIDE toolsets to trigger real blackouts (MITRE ATT&CK G0034; DOJ indictment, 2020). NotPetya extended that pattern from physical infrastructure disruption to a broader, IT-centric destructive campaign, timed to detonate on June 27 — the eve of Ukraine's Constitution Day — reinforcing the assessment that the operation was a deliberate act of hybrid warfare against Ukraine rather than a financially motivated ransomware campaign that happened to spread out of control.

The entry vector exploited a specific, structural weakness in Ukraine's software ecosystem: M.E.Doc, produced by the Ukrainian company Intellect Service, was the dominant tax-filing and accounting application used by companies doing business in Ukraine, reportedly present on a substantial share of all computers in the country and used by any foreign company with a Ukrainian subsidiary or filing obligation — Maersk's Ukraine-based freight forwarding unit among them. Forensic analysis after the fact found the attackers had compromised an employee account on M.E.Doc's own update servers and distributed the backdoor through at least three tainted software updates — April 14, May 15, and June 22, 2017 — meaning it sat live in a widely-trusted update channel for roughly ten weeks before the June 27 trigger (the same channel was separately used in May 2017 to distribute an unrelated ransomware family, XData, before being repurposed for NotPetya). M.E.Doc's own server software had not been patched since 2013 — a vendor security posture ESET later described the resulting operation as exploiting "thoroughly" (ESET, TeleBots, 2017; Cisco Talos, 2017).

Maersk's own internal architecture compounded the exposure once the malware crossed onto its network. Like many large, decades-old multinational conglomerates that had grown through acquisition (Maersk's structure spans Maersk Line, APM Terminals, Damco, Svitzer, and other units), the company ran essentially all of its global Windows infrastructure — vessels, terminals, back offices, across roughly 130 countries — on a single, largely flat Active Directory domain, with limited segmentation between business units or geographies. This is precisely the condition NotPetya's propagation mechanism was engineered to exploit: once inside any part of a flat, single-domain network, credential-harvesting and SMB-exploit-driven lateral movement could reach essentially everything.

03
Kill Chain Narrative Phase-by-phase account of the attack as it progressed
Software Supply Chain Compromise — M.E.Doc Backdoor BLIND
Sandworm operators compromised an employee account on the servers of Intellect Service, the Ukrainian developer of the M.E.Doc tax-accounting application, and used that access to plant a backdoor inside M.E.Doc's own software-update mechanism. The backdoor sat live, undetected, for at least six weeks before it was ever triggered — M.E.Doc's server software itself had not been patched since 2013, and the update mechanism carried no code-signing or integrity-verification step capable of catching a malicious update pushed from the vendor's own infrastructure (ESET, 2017; Cisco Talos, 2017). Because the compromise lived inside a trusted vendor's legitimate update channel rather than inside any individual victim's network, no customer of M.E.Doc — Maersk included — had any visibility into this phase at all.
A backdoored update channel inside a widely-deployed, government-adjacent piece of software gave the operators a single trigger capable of reaching an enormous, largely uncontrollable population of downstream victims simultaneously.
Trojanized Update Push & Ukraine-Wide Detonation BLIND
At approximately 10:30 GMT on June 27, 2017 — the day before Ukraine's Constitution Day — the backdoored M.E.Doc update mechanism pushed the malicious payload to every machine configured to receive automatic M.E.Doc updates. Any organization with M.E.Doc installed and update-checking enabled, anywhere in the world, received the payload within minutes of that trigger, with no user interaction required. ESET's telemetry placed roughly 80% of initial infections inside Ukraine, consistent with M.E.Doc's userbase, but the mechanism did not restrict itself geographically — any foreign entity running a Ukraine-facing business unit that used the software, including Maersk's Ukrainian freight-forwarding operation, was infected on exactly the same trigger as domestic Ukrainian victims.
The malware was now executing with local administrative context on infected machines and immediately began harvesting credentials and scanning for lateral-movement opportunities rather than waiting for further instruction — the entire remaining kill chain from this point happened automatically, with no further attacker interaction required.
Worm-Enabled Lateral Spread Into Maersk's Global Network BLIND
Once executing on an infected host, NotPetya used a modified build of the open-source credential-dumping tool Mimikatz to harvest Windows credentials cached in memory, then used those credentials — combined with the leaked NSA exploits EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0145), both released by the Shadow Brokers two months earlier — to spread over SMB to any reachable Windows host, patched or not: a host with valid cached admin credentials could be infected via PsExec or WMIC even without any exploitable vulnerability at all, meaning full patch compliance alone could not have stopped propagation once credentials were exposed anywhere on the network (Cisco Talos, 2017; CrowdStrike, 2017). Because Maersk's global IT estate sat on one largely unsegmented Active Directory domain, the malware's spread was not contained to the Ukrainian unit where it entered — contemporaneous and retrospective reporting describes the infection reaching Maersk's entire global network within minutes of first execution, a scale and speed of self-propagation that gave IT staff essentially no window in which to isolate the intrusion before impact.
With domain-wide credential reuse and unpatched SMB exposure both present somewhere on the network, the malware no longer needed to find new footholds — it had already reached every machine it would ever need to reach before the destructive payload activated.
Destructive Payload Execution — MBR/MFT Wipe Disguised as Ransomware DETECTED (instantaneously, upon activation — not before)
The payload, executed via rundll32.exe "C:\Windows\perfc.dat",#1 on infected hosts, overwrote each machine's Master Boot Record with a custom bootloader and displayed a fake CHKDSK repair screen while it encrypted the Master File Table and, on hosts where it obtained administrator rights, individual files matching a hard-coded extension list — rendering every affected machine completely unusable and demanding a $300 Bitcoin payment to a single hard-coded wallet address, with proof-of-payment instructions to email a fixed address at the German provider Posteo. Security researchers established within hours that the "ransomware" framing was a decoy: the malware generated a random installation ID with no cryptographic relationship to the actual per-victim encryption key, meaning the attackers could not have provided a working decryption key even to a victim who paid — a design choice, not a bug, that confirmed NotPetya's actual purpose was destruction, not extortion (Comae Technologies/Matt Suiche, 2017; Kaspersky, 2017). Posteo suspended the ransom-contact inbox within hours of the outbreak once it recognized its service was being used to facilitate a ransomware campaign, permanently severing the fictitious payment channel. This phase is marked "detected" in the sense that its effects were immediately and unmistakably obvious to every victim the moment it activated — there was no covert dwell time here to miss, only an instantaneous, total loss of the machine.
Within Maersk, this phase executed near-simultaneously across the company's entire global Windows estate — by the time any single business unit's IT staff recognized what was happening, the same destruction was already underway everywhere else in the company at once.
Maersk-Wide Operational Collapse & the Ghana Domain Controller DETECTED (by the victim, in real time)
Within roughly seven minutes of first detonation inside Maersk's network, by the account Chairman Jim Hagemann Snabe later gave publicly at the World Economic Forum in Davos and that Andy Greenberg's subsequent reporting corroborated in detail, Maersk's entire global IT infrastructure had gone dark — every one of the company's roughly 150 domain controllers wiped, taking with them the Active Directory data needed to authenticate and rebuild any of the company's 4,000 servers or 45,000 endpoints. Terminal operations halted at 76 ports Maersk-affiliated operators controlled worldwide, including major hubs at Los Angeles, Rotterdam, and Mumbai's Jawaharlal Nehru Port; ship-to-shore communications and container-booking systems went down company-wide. Frantic calls to data centers around the world eventually turned up exactly one surviving domain controller — in a small Maersk office in Ghana, which by pure chance had lost power and been disconnected from the network in the hours before the malware reached it, preserving the only intact copy of the company's Active Directory data left anywhere in the organization. Because the connection out of Ghana was too slow to transfer the several-hundred-gigabyte backup electronically in any workable timeframe, a Maersk staffer physically carried the drive to the airport, and the data was relayed onward by air to the company's technology recovery hub in Maidenhead, UK, where engineers used it as the seed to rebuild the company's entire identity infrastructure from scratch. Over the following ten days — a rebuild Snabe stated would normally take around six months — Maersk's IT organization reinstalled all 4,000 servers, 45,000 PCs, and roughly 2,500 applications, restoring core operations; Maersk's own public disclosures placed the resulting financial impact at $200–300 million in lost business, contributing to a $264 million net loss for the quarter in which the attack occurred (Maersk, Aug. 2017 trading update; Reuters, CNBC, Computer Weekly, 2017).
04
TTPs — MITRE ATT&CK Mapping Enterprise Framework — forward-mapped (post-dates ATT&CK's 2015 launch)
Initial Access
T1195.002
Supply Chain Compromise: Compromise Software Supply Chain
Backdoor planted in M.E.Doc's legitimate update mechanism via a compromised employee account on the vendor's own servers — the explicit technique MITRE ATT&CK attributes to Sandworm Team for this operation.
Execution
T1218.011
System Binary Proxy Execution: Rundll32
Main payload executed via rundll32.exe "perfc.dat",#1 on infected hosts, a technique consistently documented across vendor forensic writeups.
Credential Access
T1003.001
OS Credential Dumping: LSASS Memory
Modified open-source Mimikatz build embedded in the payload harvested plaintext/hashed Windows credentials from memory on each newly infected host.
Lateral Movement
T1210
Exploitation of Remote Services
EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0145) SMB exploits — leaked by the Shadow Brokers — used to spread to unpatched hosts regardless of credential exposure.
Lateral Movement
T1021.002
Remote Services: SMB/Windows Admin Shares
Harvested credentials used with PsExec-style remote execution over admin shares, propagating even to fully patched hosts that shared a network with a compromised, credential-exposed machine.
Lateral Movement
T1047
Windows Management Instrumentation
WMIC invoked with harvested credentials as an alternate remote-execution path alongside PsExec, documented in Talos and CrowdStrike technical breakdowns.
Defense Evasion
T1070.001
Indicator Removal: Clear Windows Event Logs
Malware cleared Application, Security, System, and Setup event logs and the NTFS USN change journal on infected hosts prior to triggering the destructive payload, hindering post-incident forensic reconstruction.
Impact
T1561.002
Disk Wipe: Disk Structure Wipe
Custom bootloader overwrote the Master Boot Record; Master File Table encrypted with no recoverable key relationship to the victim, rendering the technique functionally destructive rather than reversible.
Impact
T1486
Data Encrypted for Impact
Individually encrypted files on hosts with elevated privileges, masquerading as conventional ransomware to delay recognition of the payload's true destructive intent.
Impact
T1657
Financial Theft (adapted: Fraudulent Extortion Demand)
$300 BTC ransom demand functioned as misdirection rather than a genuine monetization goal — a single hard-coded wallet address and an email channel that was severed by the provider within hours confirm no functioning payment-to-decryption pipeline ever existed.
05
Defender Post-Mortem What was missed, when, and why
SUPPLY CHAIN TRUST
MISSED — ARCHITECTURAL
Maersk had no visibility into, or control over, the security posture of a third-party Ukrainian tax vendor its local subsidiary was legally required to use — a dependency essentially invisible to corporate IT risk management until it detonated. No amount of Maersk-side detection could have caught this phase; the failure point sat entirely inside M.E.Doc's own infrastructure.
NETWORK SEGMENTATION
MISSED — ARCHITECTURAL
Maersk's global IT estate ran on a single, largely flat Active Directory domain spanning roughly 130 countries and dozens of business units acquired over decades — the single largest structural factor in why an infection entering through one small Ukrainian unit reached the entire global company within minutes rather than remaining contained.
BACKUP ARCHITECTURE
MISSED — ARCHITECTURAL
The single most consequential control gap in this incident. Maersk's domain-controller backups were themselves network-connected and were destroyed by the same propagation wave as the production systems they were meant to protect — the company came within one lucky, unrelated power outage in Ghana of losing its Active Directory identity data entirely, with no accessible offline or immutable copy anywhere in the organization.
DESTRUCTIVE-PAYLOAD ACTIVATION
UNMISSABLE — NOT A DETECTION FAILURE
Once triggered, the payload's effects were instantaneous and total; no plausible detection or SOC-alerting capability of the era could have intervened between activation and impact on an individual host. The only leverage point that mattered was everything upstream of this moment — patching, segmentation, and credential hygiene — not detection at the point of destruction.
POST-INCIDENT
LESSON ADOPTED
Maersk undertook a large-scale post-incident overhaul of its IT architecture and security investment, publicly discussed by Chairman Jim Hagemann Snabe; the incident became a widely cited catalyst for enterprise adoption of offline/immutable Active Directory backup practices specifically, cited repeatedly in identity-security vendor guidance (e.g., Semperis, 2020/2021) as the canonical cautionary example of why domain-controller backups must be isolated from the production network they protect.
POST-INCIDENT
LESSON ADOPTED
CISA/US-CERT's contemporaneous alert (TA17-181A / ICS-ALERT-17-181-01C) reinforced urgency around applying MS17-010, disabling SMBv1 entirely, and blocking TCP 139/445 at network boundaries — guidance that, alongside the same EternalBlue exploit's role one month earlier in WannaCry, accelerated industry-wide SMBv1 deprecation efforts that continued for years afterward.
06
Technical Artifacts Malware, tools, CVEs, IOCs
NotPetya (aka Petya.A, GoldenEye, ExPetr, Nyetya)
Wiper disguised as ransomware [HISTORICAL — Limited detection utility]
Core payload, distributed as perfc.dat, executed via rundll32.exe "C:\Windows\perfc.dat",#1. Overwrites the Master Boot Record with a custom bootloader, encrypts the Master File Table, and on hosts with elevated privileges encrypts individual files by extension. Displays a forged CHKDSK screen during MFT encryption to delay victim recognition. Confirmed non-recoverable by design — the victim installation ID has no cryptographic relationship to the actual encryption key.
EternalBlue / EternalRomance (CVE-2017-0144 / CVE-2017-0145)
Leaked NSA SMBv1 remote-code-execution exploits [HISTORICAL — Limited detection utility]
Publicly released by the Shadow Brokers in April 2017; the same EternalBlue exploit had been used one month earlier by WannaCry. Enabled NotPetya to spread to unpatched Windows SMB hosts regardless of credential exposure. Patched by Microsoft's MS17-010 (March 2017), meaning both outbreaks targeted organizations that had not applied an already-available patch.
Modified Mimikatz Build
Credential-harvesting component [HISTORICAL — Limited detection utility]
Custom-compiled variant of the open-source Mimikatz tool embedded directly in the NotPetya payload, used to extract plaintext and hashed Windows credentials from LSASS memory on each newly infected host, feeding the PsExec/WMIC lateral-movement stage.
M.E.Doc Update Backdoor
Software supply-chain implant [HISTORICAL — Limited detection utility]
Backdoor implanted in Intellect Service's M.E.Doc tax-software update mechanism via a compromised employee account on the vendor's own servers; present at least six weeks before the June 27, 2017 trigger. This was the sole confirmed initial-access vector for the global campaign — no other simultaneous infection vector has been documented in public reporting.
⚠ All IPs and domains defanged. Reconstruct before use in detection tooling.
⚠ HISTORICAL IOCs — These artifacts are archival. Infrastructure has long since rotated and this malware is broadly detected by any current-generation AV/EDR signature set. Use for research and retrospective analysis only.
TypeValue / DescriptionSourceDate
FILEC:\Windows\perfc.dat (primary payload DLL, no file extension executed via rundll32 export #1)Cisco Talos, ESET2017-06-27
EXEC PATTERNrundll32.exe "C:\Windows\perfc.dat",#1Cisco Talos, Microsoft MSTIC2017-06-27
EMAIL (extortion contact)wowsmith123456[at]posteo[.]net — suspended by provider within hours of outbreakBleepingComputer, Motherboard/Vice2017-06-27
BTC WALLET1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX8 — single hard-coded address for the entire global campaignBleepingComputer, Fortune2017-06-27/28
CVECVE-2017-0144 (EternalBlue) / CVE-2017-0145 (EternalRomance) — patched by MS17-010Microsoft, MITRE CVE2017-03-14
NOTENo specific vendor-published file hashes (MD5/SHA) are reproduced in this card. Contemporaneous hash-based IOC packages were published by ESET, Kaspersky, and Microsoft at the time of the outbreak — see References for original vendor advisories rather than a value transcribed here from memory.
07
Consequences Strategic · Technical · Legal/Regulatory
⬡ Strategic / Geopolitical
On February 15, 2018, the United States, United Kingdom, Australia, Canada, Denmark, Estonia, Lithuania, New Zealand, and Norway issued coordinated statements formally attributing NotPetya to the Russian military — at the time, the broadest multinational cyberattack attribution ever conducted, treated by policy analysts as an early test case for collective attribution as a norm-enforcement tool. The operation also demonstrated a strategic vulnerability the Kremlin's own economic sphere shared with the rest of the world: NotPetya's uncontained spread inflicted significant collateral damage on Russian entities including oil major Rosneft and steelmaker Evraz, an outcome widely read as evidence the weapon's blast radius exceeded even its operators' apparent intent.
⬡ Technical / Capability
NotPetya established, in a single incident, that a wiper disguised as ransomware — combining a software supply-chain trigger with leaked-exploit-plus-credential-harvesting worm propagation — could achieve total, simultaneous compromise of a multinational enterprise's entire IT estate in minutes, independent of that organization's individual patch compliance, so long as credential reuse existed anywhere on a flat network. It remains a frequently cited reference point for why "we patch everything" is an insufficient defense on its own against lateral movement chains that route around unpatched hosts via valid credentials.
⬡ Legal / Regulatory
Maersk's own ~$200–300M impact was disclosed directly as an unmitigated business-interruption cost in its own quarterly trading update rather than pursued through public first-party insurance litigation; public reporting does not document a comparable war-exclusion coverage dispute specific to Maersk. The same campaign, however, produced two of the most closely watched cyber-insurance disputes in the industry's history: Merck & Co. prevailed against Ace American Insurance in New Jersey courts (ruling January 2022, affirmed on appeal 2023) after insurers invoked a policy's "act of war" exclusion, a dispute ultimately resolved by confidential settlement in January 2024 rather than further appeal to the state supreme court; reported claim figures vary by outlet and by point in the litigation timeline ($870M in early filings, $1.3B in 2019-era reporting, $1.4B at the litigation/settlement stage, and $700M in at least one settlement-era headline) — presented here as a range rather than a single resolved number, since no source reviewed reconciles the spread. Mondelez International separately settled a parallel dispute with Zurich Insurance in November 2022 over a claim reported as "$100M+" in some outlets and $188M in others (likely reflecting claim-denial amount vs. total business loss respectively), without a public ruling or precedent. Together these cases materially reshaped how war-exclusion language is drafted and litigated across the cyber-insurance industry.
08
Attribution
ATTRIBUTION CONFIDENCE: HIGH
Attributed ToSandworm Team (GRU Unit 74455 / Main Center for Special Technologies)
SponsorRussian Federation — GRU (military intelligence)
Formal AttributionYes — joint statement, US + 7 allied governments, 2018-02-15
IndictmentsYes — US DOJ, W.D. Pa., 2020-10-19: Yuriy Andrienko, Sergey Detistov, Pavel Frolov, Anatoliy Kovalev, Artem Ochichenko, Petr Pliskin
Companion Actor CardNone on file — see Section 00
Primary EvidenceMalware code-lineage overlap with prior Sandworm operations; DOJ indictment names Pliskin specifically as a NotPetya malware developer; US Treasury CAATSA/EO 13694 sanctions, March 2018
Competing HypothesesNone substantive in public record — attribution is not contested among Western governments or major vendors; some early (June–July 2017) reporting briefly entertained a purely criminal ransomware hypothesis before technical analysis ruled it out
What Would Change AssessmentCredible alternative claim of authorship, or documented evidence the M.E.Doc backdoor and destructive payload were developed/deployed by an unrelated actor exploiting Sandworm's established access

Attribution here rests on a substantially stronger evidentiary base than most nation-state cyber incidents reach: a coordinated, multi-government formal statement naming the Russian military specifically; a detailed criminal indictment naming six individual GRU officers with role-specific allegations (Pliskin credited with developing NotPetya components, alongside his and Andrienko's separate work on Olympic Destroyer); Treasury sanctions applied under a named legal authority; and technical continuity between NotPetya's tradecraft and Sandworm's well-documented prior Ukrainian power-grid attacks. No companion threat-actor profile card exists yet in this repository for Sandworm Team / GRU Unit 74455 / APT44 — a gap worth closing given the group's broader operational history extends well beyond this single incident (Ukraine grid attacks 2015–2016, Olympic Destroyer 2018, ongoing Ukraine-conflict operations tracked into the 2020s).

09
Historical Significance

Maersk-NotPetya endures as a teaching case for a reason distinct from most incidents in this repository: it is not primarily a story about a detection failure, but about what happens when detection is irrelevant — when a destructive payload's activation and its impact are the same instant, and every meaningful defensive decision had to have already been made beforehand. That reframing is itself the case's central lesson for defenders: patch management, network segmentation, and offline backup architecture are not merely best practices among many, but the entire available defense against a category of attack where there is no detection window to exploit once the payload fires.

The incident is also the canonical real-world illustration of why domain-controller backup isolation matters specifically, not backups in general — Maersk had backups, and lost them anyway, because they were reachable from the same network the malware was already spreading across. The company's survival hinged on an unrelated, unplanned power outage in a small West African office, a fact identity-security practitioners have cited for years since as the sharpest available argument for offline, immutable backup of directory-services infrastructure in particular.

Beyond its technical lessons, the incident helped establish coordinated multinational attribution as a functioning diplomatic tool: the February 2018 joint statement by nine governments set a template later incidents' attributions would follow, and the subsequent named indictment of individual GRU officers — with specific malware-development roles alleged — pushed nation-state cyber accountability further toward individualized, evidence-based legal action than prior incidents had achieved. Finally, through the parallel Merck and Mondelez litigation the same campaign generated, NotPetya reshaped how the insurance industry drafts and defends war-exclusion clauses against cyber losses — a regulatory and contractual legacy still actively cited in cyber-insurance underwriting discussions today.

10
References URLs are NOT defanged — navigate directly
Wired
Accessed: 2026-09-02
CONTEMPORANEOUS-ADJACENT REPORTING — 2018-08-22
The White House
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2018-02-15
MITRE ATT&CK
Accessed: 2026-09-02
MITRE ATT&CK
Accessed: 2026-09-02
CISA / US-CERT
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2017-07-01 (updated through 2018)
ESET (WeLiveSecurity)
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2017-06-30
ESET (WeLiveSecurity)
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2017-07-04
Insurance Journal
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2022-11-23
Cisco Talos
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2017-06-27
CNBC
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2017-08-16
Bleeping Computer
Accessed: 2026-09-02
CONTEMPORANEOUS-ADJACENT REPORTING — 2019-01
The Record (Recorded Future News)
Accessed: 2026-09-02
BleepingComputer
Accessed: 2026-09-02
CONTEMPORANEOUS REPORTING — 2017-06-28