What is NotPetya?
NotPetya is destructive malware that spread worldwide from Ukraine on 27 June 2017, posing as ransomware while in fact being a wiper: encrypted systems could not be recovered, not even after paying. The attack crippled multinationals such as Maersk, Merck, Mondelez and TNT Express, and halted container terminals in the Port of Rotterdam for days. With estimated damage of 10 billion dollars, NotPetya is regarded as the costliest cyberattack to date. In 2018 the US and UK attributed the attack to the Russian military intelligence service GRU (the Sandworm group).
🗓️ How did the attack unfold?
| When | Event |
|---|---|
| Spring 2017 | Attackers gain access to the update server of M.E.Doc, Ukrainian accounting software |
| 27 June 2017 | An infected update spreads NotPetya to thousands of companies with a presence in Ukraine |
| Within hours | The malware spreads through internal networks to sites worldwide |
| July 2017 | Companies rebuild their IT environments; some terminals and plants are down for weeks |
| February 2018 | Official attribution to Russia by the US and UK |
🔧 How did NotPetya spread so quickly?
- Supply chain attack — the initial infection came through a legitimate software update
- EternalBlue and EternalRomance — vulnerabilities in Windows SMBv1, patched since March 2017
- Credential theft — using Mimikatz techniques, the malware extracted passwords from memory and used them with legitimate admin tools (PsExec, WMI)
- Flat networks — without segmentation the malware moved freely between countries, departments and IT/OT
Once inside, NotPetya overwrote the master boot record and encrypted the file table, rendering computers unusable.
🏭 What was the impact on OT and logistics?
| Organisation | Consequence |
|---|---|
| Maersk | Around 49,000 laptops and 4,000 servers unusable; terminals worldwide, including on the Maasvlakte, down for over a week |
| Merck | Production of medicines and vaccines disrupted |
| TNT Express | Parcel handling disrupted for days to weeks |
| Mondelez | Food production and distribution interrupted |
Even where OT itself was not hit, production stopped: without IT systems for planning, orders and logistics, a plant or terminal cannot run. Maersk could only restore its Active Directory thanks to a single domain controller in Ghana that happened to be offline because of a power cut.
🎯 What lessons can you draw from NotPetya?
- Patch management — the key vulnerability had been patched months earlier
- Network segmentation between IT, OT and sites, so that one infection does not hit the whole company
- Immutable and offline backups, including Active Directory
- Rehearse disaster recovery — know how long a full rebuild takes
- Supplier risk — even trusted software can arrive infected
- Least privilege for admin accounts, so stolen passwords cause less damage
🇳🇱 What did NotPetya mean for the Netherlands?
NotPetya hit the Netherlands directly through the Port of Rotterdam. The container terminals of APM Terminals, part of Maersk, on the Maasvlakte were largely at a standstill for over a week. Lorries could not collect or deliver containers, and ships were diverted. The Dutch company TNT Express, recently acquired by FedEx, also suffered severe disruption to parcel handling and customer communication.
| Effect | Consequence for the supply chain |
|---|---|
| Terminal systems unusable | No registration of incoming and outgoing containers |
| No access to bookings | Shipping lines and hauliers worked with paper and e-mail |
| Rebuilding IT | Weeks of reduced capacity |
The lesson for ports and logistics: even when cranes and vehicles work technically, operations stop as soon as the IT systems that drive logistics fail. NotPetya was therefore an important trigger for critical infrastructure policy and later legislation such as NIS2.
❓ Frequently asked questions
What is the difference between Petya and NotPetya?
Petya was ransomware from 2016 that encrypted files and released them after payment. NotPetya resembled Petya but was a wiper: the encryption could not be reversed, not even after payment. That is why the malware was named NotPetya. Its goal was destruction, not money.
How much damage did NotPetya cause?
The White House estimated the total damage from NotPetya at over 10 billion dollars, making it the costliest cyberattack to date. Maersk reported damage of 250 to 300 million dollars, and Merck and FedEx/TNT each hundreds of millions. Lengthy legal disputes with insurers followed.
Why did insurers not always pay out after NotPetya?
Some insurers refused to pay out, invoking the war exclusion, because NotPetya was attributed to a state. Mondelez and Merck challenged this. Merck won in court in 2022, a ruling upheld on appeal in 2023. The case led to new, stricter exclusions for state-sponsored cyberattacks in cyber insurance policies.
Did NotPetya also hit OT systems?
NotPetya was not specifically aimed at OT, but hit every Windows system it could reach over the network. Where IT and OT were not separated, HMIs, engineering workstations and servers in production environments were infected too. Production also stopped because IT systems for planning and logistics failed.
How do you protect against an attack like NotPetya?
Protecting against an attack like NotPetya requires timely patching, network segmentation between IT, OT and sites, limiting admin rights and offline backups, including Active Directory. Rehearsing a complete rebuild of the IT environment shows how long recovery really takes.
📌 In summary
NotPetya (2017) was a wiper disguised as ransomware that entered through an infected update and shut down companies such as Maersk worldwide, causing around 10 billion dollars in damage. The attack shows how dependent OT and logistics are on IT, and how unpatched, flat networks turn a local infection into a global one.
