Case file · NOTPETYA 2017

How NotPetya crippled Maersk, and the Ghana blackout that saved it

Published 2026-09-29 · 4 min read · Missing control: Offline backup of login servers

When NotPetya tore through Maersk in June 2017, the world's largest container shipping company lost roughly 150 of the servers that control every employee login. The only clean copy left was sitting in an office in Ghana, saved by a power cut that had knocked it offline before the attack.[1] This case file covers how the malware got in, how Maersk rebuilt, what it cost, and the one control that should not have been left to luck.

What happened

On June 27, 2017, a destructive piece of malware later named NotPetya began spreading from Ukraine to computers around the world.[4] It rode in on a software update for M.E.Doc, an accounting and tax program widely used by businesses in Ukraine, and at Maersk it entered through a company computer in the port city of Odessa.[3] It looked like ransomware, with a message demanding payment, but it was really a wiper: the data could not be recovered by paying.[2]

Within hours, Maersk's screens went dark across its offices and terminals. Its ships, which handle a large share of global container trade, kept sailing, but staff had to fall back on manual work, and the company later said it ran about 80% of its normal volume by hand during the recovery, with a vessel docking somewhere roughly every 15 minutes.[2]

Maersk had backups of many individual servers. What it did not have was a separate backup of its domain controllers, the servers that store every user account and password and decide who may log in to what.[1] It had about 150 of them, set up to copy one another, so when the malware wiped them all at once, the copies went too.[1] Staff finally found one survivor in Ghana, which had been disconnected by a local blackout before the attack.[1][3] Because the office's internet link was too slow to send the data, an employee flew the hard drive to Nigeria and handed it to a colleague who carried it on to London.[3]

How it worked

This was a supply chain attack: the attackers did not break into Maersk directly. They compromised the company behind a trusted Ukrainian software product and slipped their code into its update system, so customers installed it themselves as a normal update.[3] Maersk needed only one machine running that program to be exposed.

Once inside a network, NotPetya spread on its own from computer to computer and wiped each machine it reached.[2][4] The worst damage came from where it landed, not how it arrived. Because all the domain controllers were live and connected, synchronizing with each other, the malware could reach every one. A design meant to keep the login system available had no copy that was out of reach.[1]

How it was caught

There was no quiet detection here. The damage was instant and public, hitting companies, hospitals and government agencies in more than 65 countries.[2][4]

In February 2018 the UK government, backed by its National Cyber Security Centre, said the Russian military was almost certainly responsible, and the United States also attributed the attack to Russia's military intelligence.[3][5] In October 2020 the US Justice Department charged 6 officers of a Russian military intelligence unit in connection with NotPetya and other attacks. None has faced trial in the US.[4]

What it cost

Maersk rebuilt its entire network in about 10 days, reinstalling some 45,000 PCs, 4,000 servers and 2,500 applications.[2] The company put its losses at $250 million to $300 million.[1][2] Its chairman later said publicly that the company had been naive and its security only average, and that it would make security a competitive advantage.[2]

Maersk was far from alone. The Justice Department said losses at just 3 victims named in its indictment came to nearly $1 billion, and total worldwide damage has been estimated at around $10 billion.[3][4]

The missing control

The missing control: an offline backup of the login servers, kept on purpose and tested. A copy of the domain controller data that is disconnected from the network, so no malware on that network can reach it.

Maersk's recovery depended on a blackout in one office. Without that accident, the company would have had to rebuild every user account from scratch before anything else could come back.[1] An offline, regularly tested backup of the identity system would have turned a lucky break into a planned step, and would have saved days of the most critical part of the rebuild. It also would not have mattered how the malware got in.

What to do in your business

Watch the case
The blackout in Ghana that saved MaerskDrops 2026-10-30
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More backups and recovery cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Redmond Magazine: A domain controller nightmare
  2. SecurityWeek: Maersk reinstalled 50,000 computers after NotPetya attack
  3. Control Engineering: Throwback attack - how NotPetya accidentally took down global shipping giant Maersk
  4. U.S. Department of Justice: Six Russian GRU officers charged in connection with worldwide deployment of destructive malware
  5. Help Net Security: UK government officially blames Russia for NotPetya attack