Home › Security › Who was blamed for the NotPetya cyberattack?
Who was blamed for the NotPetya cyberattack?

Summary
A look back at the attribution of the June 2017 malware that struck Ukraine, and Russia's rejection of it, as of 18 February 2018.
Who stood behind the NotPetya malware that hit Ukraine in June 2017? On 18 February 2018, that question was at the centre of an international dispute, three days after the United Kingdom government and the United States White House accused the Russian military of launching it.
The accusations were made on 15 February 2018. The White House described the attack as the most destructive and costly cyberattack in history and said Russia would face unspecified "international consequences". Moscow denied responsibility, dismissing the accusation as "groundless", lacking evidence and "Russophobic".
What the attack was
The wave of attacks using Petya malware began on 27 June 2017 and swamped the websites of Ukrainian organisations, including banks, ministries, newspapers and electricity firms. Infections were also reported in France, Germany, Italy, Poland, Russia, the United Kingdom, the United States and Australia.
ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second at about 9%. The Ukrainian government stated that day that the attack had been halted. By 30 June 2017, as the Associated Press reported, experts agreed that Petya was masquerading as ransomware while actually being designed to cause maximum damage, with Ukraine as the main target.
Where things stood
As of 18 February 2018, the public positions were set: London and Washington attributing the attack to the Russian military, and Russia rejecting the claim outright. The nature of the promised consequences had not been specified.