A destructive piece of malware known as NotPetya spread from Ukraine to organisations around the world. Although it looked like ransomware, it was designed to destroy data, and it caused severe disruption at companies such as Maersk and Merck. Ukrainian government bodies, banks, and energy companies were among the first and hardest hit.
What happened
- The malware was initially distributed through a compromised update to M.E.Doc, accounting software widely used in Ukraine.
- It spread rapidly within networks using the EternalBlue exploit and stolen credentials.
- Victims included shipping, pharmaceutical, logistics, and food companies, with total damage estimated in the billions of dollars.
- In February 2018 the UK and US governments attributed the attack to the Russian military.
Why it mattered
NotPetya is often described as the most costly cyber attack in history, and it showed how a software supply chain compromise could spread well beyond its intended target.
Lessons for organisations
Assess supplier and software update risks, segment networks to limit spread, restrict administrative credentials, and keep tested offline backups for recovery. Plans should assume that core systems may need to be rebuilt from scratch.
Source: BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.