
What happened
On 27 June 2017, destructive malware now known as NotPetya spread through networks in Ukraine and then into companies across Europe, Asia and the Americas. According to CISA's Petya Ransomware alert, the outbreak began inside the update mechanism of M.E.Doc, Ukrainian tax-accounting software whose developer had been compromised as early as April 2017. The malware then spread on its own using a credential-theft tool and two leaked exploits, moving across Windows file-sharing without further attacker involvement, before encrypting each machine's master boot record. CISA's alert notes the encryption could not reliably be reversed, which is why NotPetya is described as a wiper disguised as ransomware.
On 15 February 2018, the United Kingdom's Foreign Office publicly attributed the attack to the Russian military, describing the release as reckless and indiscriminate and stating it caused hundreds of millions of pounds of damage across Europe. CISA's alert records that US guidance was updated the same day to reflect a matching White House statement.
Confidence and limits
The technical account rests on a government alert drawing on vendor and incident-response analysis; it does not name every affected organisation or state a global damage total. The attribution to the Russian military is a formal determination made by two allied governments on the same day, a stronger form of accusation than an unattributed vendor report, but still a state assessment rather than a criminal conviction. This article does not describe any later criminal charges filed elsewhere, since those records were not reviewed here.
Why it mattered
NotPetya is one of the clearest early cases of a destructive attack propagating through a trusted software update rather than a phishing email or exposed server. The M.E.Doc compromise meant companies with no direct relationship to Ukraine were infected simply because they, or a subsidiary, used routine accounting software. That dependency chain, more than the malware's sophistication, is why supply chain entered wide security use years before the SolarWinds compromise, and why the incident is still cited when assessing risk from third-party software you do not control.
Defensive takeaway
Segment networks so that a single compromised update channel or workstation cannot reach backups, domain controllers and unrelated business units by design, and confirm that offline or immutable backups exist for systems that would be catastrophic to lose to a wiper rather than to encryption you could pay to reverse.
- Which third-party software on your network can push updates automatically, and what could an attacker do if that update channel were compromised?
- Could a single set of stolen administrative credentials move an attacker from one business unit or subsidiary into your entire network?
- If every writable copy of a critical system's data were destroyed today, what is your actual, tested recovery time?
NotPetya's damage came less from a novel exploit than from ordinary trust: in a software vendor, in flat internal networks, and in the assumption that ransomware means an attacker wants to be paid. Reading it only as a Ukraine story, or only as a Russia story, misses the more durable lesson about how far a single compromised update can travel.
Segment networks so a single compromised update channel cannot reach backups and unrelated business units, and confirm offline backups exist for systems a wiper, not just ransomware, could destroy.
A US technical alert and a UK government statement, issued independently, corroborate the propagation method and the state attribution respectively; neither document supplies a global damage total or details of any later criminal case.
Sources & reading trail
Describes the wiper's propagation via a compromised M.E.Doc update, credential theft and leaked exploits, and records the later US attribution to the Russian military.
government-primary · Source published: 1 July 2017 · Retrieved: 16 September 2026
UK government's formal public attribution of the June 2017 NotPetya attack to the Russian military and description of its indiscriminate impact.
government-primary · Source published: 15 February 2018 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.