NotPetya: The Costliest Cyberattack in History Disguised as Ransomware
In 2017, NotPetya exited a Ukrainian accounting program and paralyzed global corporations, causing $10 billion in losses. The story of a weapon that only pretended to be a ransom.
- AUTHOR
- Karol Rapacz / Penetration Tester (OSCP, PNPT)
- PUBLISHED
- 6 July 2026
- READING TIME
- 14 min read
- TOPIC
- History
On June 27, 2017, on the eve of Ukraine’s Constitution Day, something started shutting down computers across the country. ATMs stopped working, cash registers in stores froze, employees stared at screens demanding ransom. Within hours, the wave spread across borders and hit global corporations - a shipowner controlling a fifth of the world’s maritime transport, a pharmaceutical giant, a food manufacturer, logistics companies. By the time it was over, losses had reached approximately ten billion dollars, making NotPetya the costliest cyberattack in history. And the most perverse thing is that the attack that looked like ordinary ransomware was not ransomware at all. It was a weapon designed to destroy - disguised as a common criminal.
Poisoned update
NotPetya’s story begins not with a phishing email, but with something we all trust most: software updates. The attackers took over the update mechanism of M.E.Doc - a popular Ukrainian accounting and tax settlement program used by virtually every company operating in Ukraine. They injected malicious code into a legitimate update, which the program automatically downloaded and ran.
This is a textbook supply chain attack: instead of attacking thousands of companies individually, it was enough to compromise one trusted supplier through which the malware reached all of them at once. In an instant, thousands of organizations “invited” NotPetya in, performing a routine, trusted act.
A weapon perfect for spreading
Once NotPetya entered the company’s network, it unleashed hell with deadly efficiency because it combined several techniques into one self-replicating machine:
- EternalBlue. The same leaked NSA exploit that powered WannaCry allowed NotPetyi to jump from machine to machine without human intervention.
- Credential theft. NotPetya extracted passwords from infected computers and used them to legally log in to subsequent ones - so even patched machines went down if there was at least one entry point in the network.
- Administrative Tools. Used Windows’ built-in, legitimate management mechanisms to spread, making it difficult to detect.
This combination caused NotPetya to pass through large, flat corporate networks like a wildfire through a dry forest. The entire company could have collapsed in a few minutes.
A ransom that couldn’t be paid
A ransom demand in Bitcoin appeared on infected screens - it looked like classic ransomware. But it was a masquerade. Researchers quickly discovered that NotPetya had no mechanism for data recovery. The damage was irreversible: the malware did not encrypt data in order to restore it for a ransom, but rather permanently destroy it (it was a so-called wiper). The “contact” address and payment ID were dummies.
This was key evidence of the true nature of the attack. Since the data could not be recovered for any money, money was not the goal. The goal was destruction. The ransom demand was just a disguise to hide the fact that we were dealing with an act of cybersabotage and not a financial crime.
A blow to Ukraine that hit the world
The attack was clearly aimed at Ukraine - hence the choice of Ukrainian accounting software as the entry point and the timing just before a public holiday. Analyses by multiple governments and researchers attributed it to Russian military intelligence, specifically the group known as Sandworm, as part of the ongoing conflict.
But cyber weapons do not respect borders. Malware designed to cause havoc in Ukraine escaped and hit international companies that had even one computer connected to a Ukrainian network. A Danish shipping company lost operational capabilities worldwide and had to rebuild thousands of servers and tens of thousands of computers. According to the well-known account, recovery depended on a single surviving domain controller in Ghana, where a power outage had kept it offline. An American pharmaceutical company lost the ability to manufacture some medicines. The losses spread globally as a side effect of an attack aimed at one country.
Why NotPetya is a lesson of the times
NotPetya combines several of the most important truths of modern security into one story:
- The supply chain is the shortest route to everyone at once. You don’t have to attack thousands of companies - just compromise one supplier they trust. This is a lesson that the world has learned many times since.
- Sabotage can masquerade as crime. “Ransomware” can be a costume for a state operation. Not every ransom note is what it seems.
- Flat networks are deadly. Credential theft plus self-replication means one entry point = entire organization. Segmentation is not a luxury, it is a requirement for survival.
- Collateral damage is real. In a connected world, a weapon aimed at one adversary hits others. Your company may fall victim to an attack that was not directed at you.
Lessons for companies
- Treat suppliers as part of your attack surface. Updates and integrations are a trust that can be abused - we write about systematic assessment in vendor risk management.
- Segment and restrict credentials. Prevent one infected host from seeing and logging in to your entire network. Limit administrative accounts and their scope.
- Patch and disable obsolete protocols. EternalBlue still worked because SMBv1 was still alive. Dead protocols are worm fuel.
- Destruction-resistant backups. What matters with wiper is whether you have offline, tested copies that cannot be reached by malware - 3-2-1 strategy. The history of a shipowner has shown that sometimes the entire company hangs on one surviving copy.
Summary
NotPetya is the story of how a single-country attack unleashed by a poisoned update to a regular accounting program turned into the costliest cyber disaster in history - ten billion dollars in losses spread across global corporations that “only” had an office in Ukraine. It pretended to be ransomware, but you couldn’t pay the ransom because it was never about money - it was about destruction. This is the purest lesson of several truths at once: the supply chain is the shortest route to everyone, flat networks die in minutes, and cyber weapons do not respect borders. In a connected world, someone else’s war can become your crisis.
Want to test whether your network could survive an attack spreading like NotPetya - from vendor risk to segmentation and copy resiliency? Contact us - audits and penetration testing show these paths before an attacker does.
Frequently asked questions (FAQ)
Was NotPetya ransomware? It looked like ransomware — it displayed a ransom demand in bitcoin — but it wasn’t. It had no working data recovery mechanism; he destroyed them permanently (he was a wiper). The ransom demand was a camouflage to hide that the goal was not money but destruction. This is an act of cyber sabotage disguised as a financial crime.
How did NotPetya spread if there was a patch for EternalBlue? Because he didn’t rely solely on EternalBlue. He also stole passwords from the memory of infected machines and used them to legally log in to subsequent ones - thanks to this, even fully patched computers were destroyed if there was at least one entry point in the same flat network. It was the combination of exploit, credential theft, and administrative tools that made it so effective.
Why did the attack on Ukraine hurt companies around the world? Because the entry point was accounting software used in Ukraine, but the malware spread through global corporate networks. Every international company with at least one connected computer in Ukraine allowed NotPetya into its global infrastructure. Cyber weapons know no boundaries - collateral damage has spread across the globe.
How to protect yourself against NotPetya attacks? Four things are key: treating vendors and updates as part of the attack surface (vendor risk assessment), network segmentation and limiting the scope of administrative credentials, quick patching and disabling of outdated protocols, and offline, tested, destruction-proof backups. They decide whether an incident means hours of reconstruction or weeks of paralysis.


