Skip to main content
Back to the archive

Incident file · 2017

A.P. Moller-Maersk

Shipping · Denmark · Threat actor: NotPetya (Sandworm)

Malware
Ransom refused
US$300
Ransom demanded
No
Ransom paid
10 days
Estimated downtime
US$300m
Est. revenue lost

What happened

Destructive wiper malware spread through a compromised Ukrainian tax software update and destroyed 49,000 laptops and 4,000 servers.

How it ended

No payment was possible — the ransom note was a cover for sabotage. Full rebuild took ten days.

Data affected

Global IT estate

Would your business survive this incident?

We stress-test detection, response and recovery so a ransom demand is never your only option.