Home › Security › Who was blamed for NotPetya, and what followed?
Who was blamed for NotPetya, and what followed?

Summary
A look back at the attribution of the June 2017 malware attack that hit Ukraine hardest, and the reaction in the days before 19 February 2018.
Who stood behind the NotPetya malware that struck Ukraine in June 2017? By 19 February 2018, the question had an official answer from two Western governments, and a flat denial from Moscow.
On 15 February 2018, the United Kingdom government and the United States White House accused the Russian military of being responsible for launching NotPetya. The White House described it as the most destructive and costly cyberattack in history. It said Russia would face unspecified "international consequences".
Russia denied responsibility. It dismissed the accusation as "groundless", lacking evidence, and "Russophobic".
The attack itself
The Petya-based attacks began on 27 June 2017 and swamped the websites of Ukrainian organisations, including banks, ministries, newspapers and electricity firms. Similar infections were reported in France, Germany, Italy, Poland, Russia, the United Kingdom, the United States and Australia.
ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second at about 9%. The Ukrainian government stated on 28 June 2017 that the attack had been halted.
On 30 June 2017, the Associated Press reported that experts agreed Petya had been masquerading as ransomware, while actually being designed to cause maximum damage, with Ukraine as the main target.
As of 19 February 2018, the accusation stood alongside Russia's rejection, and the nature of the promised consequences had not been spelled out.