The Update Was Real. The Company That Shipped It Wasn't the Attacker.
NotPetya proved a valid digital signature is not proof of trustworthy contents — and that the difference between a company's total collapse and its recovery can come down to a power outage nobody plan
On June 27, 2017, computers inside the shipping company A.P. Møller-Maersk began rebooting on their own. When the screens came back, each one showed the same demand: pay $300 in Bitcoin, get your files back. In the first ninety seconds, 10,000 machines were destroyed. Within five minutes the number had doubled. And the ransom note was a lie. The encryption was irreversible by design; no key existed, and no payment could undo it.
Maersk ran one of the largest shipping and logistics operations on Earth — 76 port facilities worldwide, container supply chains where a single day offline ripples through global commerce. The malware that destroyed its network did not arrive through Maersk’s own systems. It arrived through a piece of Ukrainian tax software called M.E.Doc, and to understand how, you have to start with the way software updates earn their trust.
M.E.Doc was a finance and accounting application, built by a Ukrainian company called Intellect Service and used by businesses operating in Ukraine to file taxes. It was ordinary software, the equivalent of a regional payroll platform. Maersk had operations in Ukraine, Ukrainian tax compliance required it, and so those operations ran M.E.Doc — as did thousands of other companies with Ukrainian subsidiaries or partners, multinationals whose global networks were connected, through routine business, to machines running this one piece of regional software.
A software update works like a sealed letter from a trusted sender. The seal — a digital signature called a code-signing certificate — confirms the letter came from who it claims to come from. Security systems check the seal; if it is valid, the update is installed. What the seal cannot verify is whether someone tampered with the contents before it was applied: an attacker who reaches the place where the software is assembled can insert whatever they want before it ships. The seal will be real; the contents will be whatever the attacker put there.
The attackers stole an Intellect Service employee’s credentials and used them to reach the update server, the distribution point for new M.E.Doc versions. Beginning as early as April 14, 2017, they modified those updates to include a backdoor: a hidden entrance that shipped to every customer on the normal schedule, under a valid signature, for more than two months. Every security check those customers ran came back clean. On June 27, the attackers used the backdoor to push the payload.
Once the payload landed on a single workstation, it needed credentials that would let it authenticate as a legitimate user on other machines. It had them within moments, by reading the part of the operating system’s memory where Windows keeps login information for active sessions, where credentials sit ready for use by any process with sufficient privileges. This is less cracking passwords than picking the pocket of every employee currently logged in. A machine with four active users yields four sets of credentials; a domain controller yields the keys to the entire building.
With those credentials the malware moved laterally, using two tools that exist on virtually every Windows computer: PsExec, a remote administration utility that lets an authorised user run commands on another machine, and WMI, a Windows management service that does much of the same work. Both are legitimate, present by default, and did exactly what they were designed to do: they accepted valid credentials and executed instructions. A burglar holding the building’s master key does not need to pick locks. He walks through the doors.
Where credentials were not enough, the malware went through the wall instead. Two exploits for SMBv1, a decades-old Windows file-sharing protocol — EternalBlue and the related EternalRomance — let it take machines with no username or password at all. Microsoft had published a patch for both on March 14, 2017, more than three months before the attack. Machines that had applied it were protected; machines that had not, including some running systems so old that no patch existed, were exposed.
The combination made the spread fast. Credential theft handled the well-maintained machines; EternalBlue and EternalRomance handled the neglected ones; PsExec and WMI carried the payload across every reachable subnet. No operator issued instructions between targets: each infected machine immediately scanned for the next, each new infection spawning another wave of scans — a fire jumping from floor to floor faster than anyone could close the doors. That is how 10,000 machines fell in ninety seconds.
The costume comes off
It looked like ransomware. The screen named a price, a single Bitcoin wallet, a contact email for the decryption key. But the malware had overwritten the master boot record, the index a computer reads at power-on to find everything on the drive, and destroyed the underlying file table, the structure mapping every file to its physical location. Imagine ripping the table of contents, the index, and every page number out of a book, then shuffling every page into random order. The words on each page still exist, but nobody can reconstruct the original sequence, including the person who shuffled it.
Each victim’s ransom screen displayed a unique installation identifier to send in with payment. The identifier was random, with no mathematical relationship to the encryption; no decryption mechanism existed. Paying produced nothing, because there was nothing to produce. The ransom note was a costume. Underneath it was a wiper — malware built to destroy data permanently, dressed as the kind of criminal operation that wants money.
Maersk was the most visible victim, not the only one. Merck, one of the largest pharmaceutical companies in the world, lost more than 40,000 machines; its own SEC filing reported $260 million in lost sales and $285 million in remediation costs. Production lines went dark, including Gardasil 9, the HPV vaccine recommended for adolescents across the United States — disruption severe enough that Merck borrowed doses from the CDC’s Pediatric Vaccine Stockpile while its own production recovered.
FedEx’s European subsidiary TNT Express lost $400 million and ran on manual processes for weeks. Mondelēz International, the company behind Oreo and Cadbury, reported 24,000 laptops and 1,700 servers destroyed and losses over $100 million. Heritage Valley Health System, a regional healthcare provider running eighty medical facilities, lost thousands of computers; patient lists, medical histories, and lab records became unavailable, and pre-operative work for scheduled surgeries had to be redone from scratch.
At Maersk, of 76 port terminals worldwide, the company could manage 17, and those 17 ran on paper. Employees communicated through WhatsApp and personal Gmail accounts because every corporate system was down. There was no quiet investigation period — Maersk, Mondelēz, and Nuance Communications all disclosed on June 27 itself; the destruction was too visible and simultaneous to hide. The White House later put the aggregate worldwide cost at $10 billion.
Maersk’s IT staff disconnected the entire global network within two hours of the first infection — the only way to stop the malware from reaching systems it had not yet touched. The damage was already complete: 45,000 PCs, 4,000 servers, the digital infrastructure of one of the world’s largest logistics operations. The question was whether recovery was possible at all.
In any large organisation running Windows there is a system called Active Directory, a central registry of every user, machine, and permission on the network — the master ledger of who works here and which doors they can open. The servers holding and replicating that ledger are called domain controllers. Destroy them all and you do not simply lose data; you lose the ability to rebuild, because the system that would authenticate every restored account is itself gone. Maersk’s domain controllers were synchronised and online when the malware hit, and every one was wiped.
Every one except one. Maersk operated a small office in Accra, Ghana, and at the moment the malware spread, that office was in the middle of a power outage. Its domain controller was offline and never received the payload. When the power came back, that single server held the only surviving copy of Maersk’s entire Active Directory. The machine was flown to the United Kingdom, Deloitte was brought in, and from that one server Maersk rebuilt its identity infrastructure — 4,000 servers reinstalled, 45,000 PCs reimaged, each machine rejoined and re-authenticated against the restored directory. The work took weeks. No resilient architecture had kept that server offline by design. Its survival was an accident.
The authors
On October 19, 2020, the U.S. Department of Justice indicted six officers of Unit 74455 of the GRU, Russia’s military intelligence agency — the unit security researchers know as Sandworm: Yuriy Andrienko, Sergey Detistov, Pavel Frolov, Anatoliy Kovalev, Artem Ochichenko, and Petr Pliskin. The attribution rested on a federal grand jury indictment, a criminal investigation rather than a policy announcement, supported by public statements from the UK government and the White House. Prosecutors called it the most destructive and costly cyberattack in history, and federal arrest warrants were issued for all six.
The target was Ukraine. M.E.Doc was Ukrainian software used by Ukrainian businesses, with the backdoor in place since April. But the malware did not check passports. It spread wherever an unpatched machine or a valid credential could carry it, which is how a Ukrainian tax application ended up destroying pharmaceutical production in New Jersey, shutting down shipping terminals in Rotterdam, and disrupting surgeries in Pennsylvania.
The insurance claims that followed reshaped an industry. Merck filed against its property insurers, including ACE American Insurance Company; Mondelēz filed against Zurich. Kroll examined the forensic evidence on behalf of Merck’s insurers, and both insurers invoked the same clause: the “hostile or warlike action” exclusion, a standard provision in property policies that excludes damage caused by acts of war. The argument was straightforward. A military intelligence agency of a sovereign nation had launched a destructive attack, and that, the insurers said, was war.
Neither case ended in a final verdict. Merck won real rulings: a New Jersey trial court in 2021 and the state’s appellate division in 2023 both rejected the exclusion, holding that a cyberattack on a non-military company did not meet a definition written for a world of bombs and invasions rather than malware delivered through a tax update. Then, in January 2024, before the New Jersey Supreme Court could hear the case, Merck and its insurers settled on undisclosed terms. Mondelēz’s case produced no ruling at all; it settled mid-trial in November 2022, leaving no precedent behind. The litigation still forced a rewrite: the insurance industry redrafted its cyber exclusion language, creating policy terms specifically for state-sponsored cyberattacks, terms that had not existed because the scenario had never been tested in court.
None of the controls that could have limited the damage were exotic. The patch had been available for more than three months. SMBv1, decades old and long superseded, could have been disabled entirely; Microsoft had published guidance for doing exactly that. Network segmentation could have stopped an infected workstation in Ukraine from reaching domain controllers on the other side of the world — the malware crossed those internal boundaries because they did not exist. And a single offline domain controller backup, disconnected by policy rather than by accident, would have been the difference between a recovery that took weeks and one that might never have happened. Every one of those controls was available before June 27, 2017, the earliest by more than a decade.
Some of the lesson landed. Maersk approved what internal accounts described as practically every security feature its IT team had ever requested, including multi-factor authentication and a company-wide upgrade to Windows 10. Merck built measures to speed any future recovery. Companies that had relied on single suppliers began diversifying their vendors. What remains is the shape of the attack itself: a supply chain turned into a weapon, built to destroy rather than to steal or extort. And the recovery of the largest shipping company on Earth rested, in the end, on one server in Accra that went dark at exactly the right moment, for a reason that had nothing to do with cybersecurity.
Sources & further reading
Andy Greenberg, Wired — “The Untold Story of NotPetya, the Most Devastating Cyberattack in History”
U.S. DOJ, Oct. 19, 2020 press release — indictment of six GRU Unit 74455 officers
Merck & Co. v. ACE American Insurance Co. — NJ Superior Court (2021) / NJ Appellate Division (2023) rulings; settlement reporting (Insurance Journal, Cybersecurity Dive, Jan. 2024)
Mondelēz International v. Zurich American Insurance Co. — Illinois Circuit Court, settlement reporting (Reinsurance News, The Register, Nov. 2022)
White House statement, Feb. 2018 — $10 billion global damage estimate
