Cyberattack

Port or tanker

NotPetya — Maersk port logistics and Rosneft systems disrupted

27 June 2017

Global campaign (marker at Maersk headquarters, Copenhagen, Denmark)

55.6800, 12.5900

Loading free detailed map…

What happened

The destructive NotPetya malware spread from a compromised Ukrainian accounting-software update into organizations worldwide. A.P. Moller–Maersk said applications and data became unavailable across its global network, significantly interrupting Maersk Line, APM Terminals and Damco and forcing manual workarounds; vessels remained controllable and Maersk estimated a US$200–300 million financial impact. Rosneft also reported a large-scale attack on its servers, but said oil production continued. This aggregate record captures the campaign's direct energy-logistics and oil-sector impact rather than counting every affected non-energy company as a separate incident.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Port or tanker
Current temperature
Loading…
Latitude
55.6800°
Longitude
12.5900°

Attribution

Attributed to Russian military

The United Kingdom and allied governments attributed the destructive NotPetya operation to the Russian government, specifically the Russian military. Russia denied responsibility.

Sources

  1. Foreign Office Minister condemns Russia for NotPetya attacksUK Foreign & Commonwealth Office and NCSC · Incident reporting
  2. A.P. Moller–Maersk 2017 Annual ReportA.P. Moller–Maersk · Operational and financial impact
  3. Rosneft suffers powerful cyber attack; oil production unaffectedReuters, via Business Standard · Oil-sector impact and production-status corroboration