NotPetya
June 2017
Record reviewed: 2026-07
Executive Summary
Destructive wiper malware disguised as ransomware, distributed via a compromised Ukrainian tax software update. Caused an estimated $10B+ in global damages, primarily affecting shipping, logistics, and pharmaceutical companies.
Why This Matters
NotPetya demonstrated that a cyber weapon aimed at one country can inflict billions in collateral damage worldwide, making it a landmark case for debating proportionality, state responsibility, and the limits of deniability in cyber conflict.
Escalation Profile
7-Dimension Profile
Escalation Ladder
Phases
Supply chain compromise
Backdoor inserted into M.E.Doc accounting software update mechanism.
Global wiper deployment
EternalBlue + Mimikatz-based lateral movement delivered irreversible disk destruction across 65+ countries.
Economic disruption at scale
Maersk, Merck, FedEx/TNT, and Rosneft among those crippled; global shipping delayed for weeks.
Threshold Crossings
- •First cyber operation to cause >$10B in collateral economic damage
- •Indiscriminate global propagation beyond intended target set
Restraint Factors
- •Disguised as criminal ransomware, providing deniability
- •No direct military targeting
Attribution Assessment
Threat actor mapped to Russia based on infrastructure analysis, malware attribution, and operational patterns.
Evidence: Microsoft Threat Intelligence: Petya Ransomware Attack; Andy Greenberg, Sandworm (Doubleday, 2019)
- •Five Eyes joint attribution statement (Feb 2018)
- •US DOJ indictment of six GRU officers (Oct 2020)
- •EU sanctions against GRU entities
Sources: CISA Alert TA17-181A: Petya Ransomware; US DOJ: Six Russian GRU Officers Charged
- Andy Greenberg, 'The Untold Story of NotPetya, the Most Devastating Cyberattack in History,' Wired(2018-08-22)
“Confirmed” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.
Unpeace Position
Unpeace Score
Composite severity rating on the peace–conflict spectrum (1–10)
Unpeace · score breakdown
10/10Peak tier reached (strategic), ranked 1–6.
Distinct escalation thresholds the operation crossed.
Formal governance responses flagged (attribution, sanctions, indictments…).
round( escalationPeak×1.2 + crossings×1 + governance×0.5 ), capped at 10. These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.
Entanglement · score breakdown
5/10Distinct critical-infrastructure sectors touched.
Geographic spread of impact.
Escalation thresholds crossed (collateral-spread proxy).
Constant offset so a single-sector, single-country event floors at 1.
clamp( sectors + countries + crossings − 1, 1, 10 ). These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.
Coercive Function
Destructive
Destruction of data or systems, coercive value through denial, punishment, or deterrence signaling.
Observed coercive effects
- •First cyber operation to cause >$10B in collateral economic damage
- •Indiscriminate global propagation beyond intended target set
Entanglement Risk
Sectors affected
Countries / regions
Impact summary
Irreversible disk encryption/wipe across ~2,000 organizations in 65+ countries.
Infrastructure Meaning
Malware / tooling
Capability profile
Irreversible disk encryption/wipe across ~2,000 organizations in 65+ countries.
4 ATT&CK techniques mapped — see ATT&CK mapping below.
Governance Analysis
Governance Flags
Norms invoked
- •UN GGE 2015 norm against damaging critical infrastructure
- •Due diligence obligations (Tallinn Manual Rule 6)
Policy responses
- •Five Eyes joint attribution statement (Feb 2018)
- •US DOJ indictment of six GRU officers (Oct 2020)
- •EU sanctions against GRU entities
Regulatory changes
- •Accelerated adoption of supply chain security requirements
- •Increased focus on software bill of materials (SBOM)
Governance impact assessment
Established precedent for multilateral public attribution of destructive cyber operations and highlighted supply chain risk as a policy priority.
Legal Dimensions
Rules whose application to this operation is debated in the literature. These are analytical questions, not findings — the Atlas records where a case sits in legal debate, it does not adjudicate legality (see methodology §09).
Tallinn Manual 2.0
- Rule 32, Proportionality
$10B+ in collateral damage across 65 countries far exceeded any conceivable military advantage against Ukraine
UN Charter
- Article 2(4), Prohibition on the Use of Force
$10B in economic destruction without physical casualties tests whether non-kinetic harm can constitute force
Geneva Conventions / IHL
- Principle of Proportionality
Intended as Ukraine-targeted but caused $10B+ global damage, the clearest case of disproportionate cyber collateral
- Precaution in Attack
No apparent precautionary measures to limit global propagation, suggesting precaution was not adequately considered
UN GGE Voluntary Norms (2015)
- Norm 13(f), Critical Infrastructure Protection
Global collateral damage to critical infrastructure across 65+ countries
Sources
CISA Alert TA17-181A: Petya Ransomware
Microsoft Threat Intelligence: Petya Ransomware Attack
US DOJ: Six Russian GRU Officers Charged
Andy Greenberg, 'The Untold Story of NotPetya, the Most Devastating Cyberattack in History,' Wired
Andy Greenberg, Sandworm (Doubleday, 2019)
Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.
Related Cases
Viasat KA-SAT
February 2022 · Russia
Viasat KA-SAT was the clearest example yet of cyber attack as an opening act of war, with cross-border collateral damage that forced NATO and the EU to treat satellite infrastructure as a shared security concern.
Kyivstar
December 2023 · Russia
Kyivstar represented the most destructive cyber attack against a telecommunications provider during active conflict, demonstrating ICS-equivalent destructive capability against civilian communication infrastructure and disrupting life-safety warning systems.
Ukraine Grid I
December 2015 · Russia
Ukraine 2015 was the first confirmed cyber-caused power outage, turning a theoretical risk into an operational reality that reshaped how governments defend energy grids.
Ukraine Grid II
December 2016 · Russia
Industroyer represented a generational leap in ICS malware sophistication, a modular, protocol-aware weapon that signaled the industrialization of grid-targeted cyber capabilities.