Back to glossaryCyber

NotPetya

Destructive 2017 cyberattack attributed to Russian military intelligence, spread via Ukrainian accounting software and the trigger of the first major cyber insurance disputes.

Definition

NotPetya is a large-scale cyberattack launched in June 2017 and publicly attributed by the US, British and Australian governments to Russian military intelligence (GRU). The malware initially spread via a corrupted update to the Ukrainian accounting software M.E.Doc, before propagating through the internal networks of large multinationals by exploiting the EternalBlue vulnerability, the same used a month earlier by WannaCry. Unlike a conventional ransomware, NotPetya was a wiper disguised as ransomware: it irreversibly encrypted the master boot records of machines with no functional decryption mechanism. Its lateral propagation vector also relied on harvesting credentials from memory using the Mimikatz tool, enabling near-automatic spread across poorly segmented Windows networks. Total economic losses are estimated at more than 10 billion dollars, affecting actors such as Maersk, Merck, FedEx and Saint-Gobain. For the insurance industry, NotPetya was the watershed moment that exposed the silent cyber problem, triggering landmark disputes, notably Merck v. its insurers (1.4 billion dollars), which drove the overhaul of war exclusion clauses and the LMA 21-042 directive.

Example

Maersk, whose Windows systems were not segmented, saw all its global terminals paralyzed within hours; its emergency IT reconstruction required the replacement of 45,000 computers and 4,000 servers in ten days, at an estimated cost of 300 million dollars.

Related terms
Related articles
Also known as

NotPetya, NonPetya, M.E.Doc attack, cyberattaque GRU 2017