All cases

NotPetya

June 2017

Record reviewed: 2026-07

DestructivePeak: Strategic ImpactAttribution: ConfirmedMultiple SectorsCritical Infrastructure
Year
2017
Actor country
Russia
Target regions
Ukraine, Global
Unpeace score
10

Executive Summary

Destructive wiper malware disguised as ransomware, distributed via a compromised Ukrainian tax software update. Caused an estimated $10B+ in global damages, primarily affecting shipping, logistics, and pharmaceutical companies.

Why This Matters

NotPetya demonstrated that a cyber weapon aimed at one country can inflict billions in collateral damage worldwide, making it a landmark case for debating proportionality, state responsibility, and the limits of deniability in cyber conflict.

Escalation Profile

7-Dimension Profile

Escalation Ladder

Probing
Intrusion
Disruption
Degradation
Destruction
Strategic

Phases

2017-04
Intrusion

Supply chain compromise

Backdoor inserted into M.E.Doc accounting software update mechanism.

2017-06-27
Destruction

Global wiper deployment

EternalBlue + Mimikatz-based lateral movement delivered irreversible disk destruction across 65+ countries.

2017-06
Strategic Impact

Economic disruption at scale

Maersk, Merck, FedEx/TNT, and Rosneft among those crippled; global shipping delayed for weeks.

Threshold Crossings

  • First cyber operation to cause >$10B in collateral economic damage
  • Indiscriminate global propagation beyond intended target set

Restraint Factors

  • Disguised as criminal ransomware, providing deniability
  • No direct military targeting

Attribution Assessment

ConfirmedGRU (Main Intelligence Directorate)
Russia
SandwormVoodoo BearIRIDIUM
1. Technical

Threat actor mapped to Russia based on infrastructure analysis, malware attribution, and operational patterns.

Evidence: Microsoft Threat Intelligence: Petya Ransomware Attack; Andy Greenberg, Sandworm (Doubleday, 2019)

2. Political / Legal
Public AttributionIndictmentSanctions Imposed
  • Five Eyes joint attribution statement (Feb 2018)
  • US DOJ indictment of six GRU officers (Oct 2020)
  • EU sanctions against GRU entities

Sources: CISA Alert TA17-181A: Petya Ransomware; US DOJ: Six Russian GRU Officers Charged

3. Open Source
  • Andy Greenberg, 'The Untold Story of NotPetya, the Most Devastating Cyberattack in History,' Wired(2018-08-22)

Confirmed” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.

Unpeace Position

10

Unpeace Score

Composite severity rating on the peace–conflict spectrum (1–10)

Stable
Contested
Escalatory
03060100

Unpeace · score breakdown

10/10
Escalation peak6 × 1.2 = +7.2

Peak tier reached (strategic), ranked 1–6.

Threshold crossings2 × 1 = +2

Distinct escalation thresholds the operation crossed.

Governance weight4 × 0.5 = +2

Formal governance responses flagged (attribution, sanctions, indictments…).

Raw sum 11.2 → capped= 10/10

round( escalationPeak×1.2 + crossings×1 + governance×0.5 ), capped at 10. These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Entanglement · score breakdown

5/10
Sectors affected2 × 1 = +2

Distinct critical-infrastructure sectors touched.

Countries / regions2 × 1 = +2

Geographic spread of impact.

Threshold crossings2 × 1 = +2

Escalation thresholds crossed (collateral-spread proxy).

Baseline offset1 × -1 = -1

Constant offset so a single-sector, single-country event floors at 1.

Raw sum 5= 5/10

clamp( sectors + countries + crossings − 1, 1, 10 ). These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Coercive Function

Destructive

Destruction of data or systems, coercive value through denial, punishment, or deterrence signaling.

Observed coercive effects

  • First cyber operation to cause >$10B in collateral economic damage
  • Indiscriminate global propagation beyond intended target set

Entanglement Risk

Entanglement score5

Sectors affected

Multiple SectorsCritical Infrastructure

Countries / regions

UkraineGlobal

Impact summary

Irreversible disk encryption/wipe across ~2,000 organizations in 65+ countries.

Infrastructure Meaning

Malware / tooling

NotPetyaEternalBlueMimikatz

Capability profile

Irreversible disk encryption/wipe across ~2,000 organizations in 65+ countries.

4 ATT&CK techniques mapped — see ATT&CK mapping below.

Governance Analysis

Governance Flags

!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Norms invoked

  • UN GGE 2015 norm against damaging critical infrastructure
  • Due diligence obligations (Tallinn Manual Rule 6)

Policy responses

  • Five Eyes joint attribution statement (Feb 2018)
  • US DOJ indictment of six GRU officers (Oct 2020)
  • EU sanctions against GRU entities

Regulatory changes

  • Accelerated adoption of supply chain security requirements
  • Increased focus on software bill of materials (SBOM)

Governance impact assessment

Established precedent for multilateral public attribution of destructive cyber operations and highlighted supply chain risk as a policy priority.

Rules whose application to this operation is debated in the literature. These are analytical questions, not findings — the Atlas records where a case sits in legal debate, it does not adjudicate legality (see methodology §09).

Tallinn Manual 2.0

  • Rule 32, Proportionality

    $10B+ in collateral damage across 65 countries far exceeded any conceivable military advantage against Ukraine

UN Charter

  • Article 2(4), Prohibition on the Use of Force

    $10B in economic destruction without physical casualties tests whether non-kinetic harm can constitute force

Geneva Conventions / IHL

  • Principle of Proportionality

    Intended as Ukraine-targeted but caused $10B+ global damage, the clearest case of disproportionate cyber collateral

  • Precaution in Attack

    No apparent precautionary measures to limit global propagation, suggesting precaution was not adequately considered

UN GGE Voluntary Norms (2015)

  • Norm 13(f), Critical Infrastructure Protection

    Global collateral damage to critical infrastructure across 65+ countries

Explore the full Legal Mapper

Sources

Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.