NotPetya (June 2017): How a Tax Software Update Wiped Out Global Networks
Retrospective: this article looks back at events from June 2017, written in 2026 with the benefit of hindsight.
On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to reinstall thousands of servers and tens of thousands of PCs. Pharmaceutical company Merck, logistics firm FedEx's TNT Express and many others suffered major disruption. Total damages were estimated in the billions of dollars.
How it got in
The attackers compromised the update mechanism of M.E.Doc, accounting software widely used in Ukraine. A malicious update delivered NotPetya to every organization running it — including the Ukrainian offices of global companies.
How it spread
Once inside, NotPetya used several techniques at once:
- Credential theft from memory using techniques similar to Mimikatz.
- Legitimate admin tools such as PsExec and WMI to move to other machines with those credentials.
- EternalBlue and EternalRomance SMB exploits against unpatched systems.
Shared administrator accounts and flat networks let it reach almost everything. Although it looked like ransomware, it was designed to destroy data; paying did not help. Western governments later attributed it to the Russian military.
Lessons in hindsight
- Supply-chain compromise can bypass every perimeter control you own.
- Credential hygiene limits blast radius. Shared local admin passwords and domain admins logging in everywhere let one infection become total.
- Patching alone was not enough. Fully patched machines were still compromised using stolen credentials.
- Backups must be offline or isolated. Maersk's recovery famously hinged on a domain controller that happened to be offline during a power outage.
NotPetya shaped modern thinking on identity tiering, supply-chain risk and destructive attacks — themes that run straight through SolarWinds and beyond.