Back to the archive
Incident file · 2017
A.P. Moller-Maersk
Shipping · Denmark · Threat actor: NotPetya (Sandworm)
Malware
Ransom refused
- US$300
- Ransom demanded
- No
- Ransom paid
- 10 days
- Estimated downtime
- US$300m
- Est. revenue lost
What happened
Destructive wiper malware spread through a compromised Ukrainian tax software update and destroyed 49,000 laptops and 4,000 servers.
How it ended
No payment was possible — the ransom note was a cover for sabotage. Full rebuild took ten days.
Data affected
Global IT estate
Sources and further reading
Would your business survive this incident?
We stress-test detection, response and recovery so a ransom demand is never your only option.