Ukraine and its neighbours, explained

Advertisement

Home › Security › Who answered for NotPetya, as of 21 February 2018?

Security

Who answered for NotPetya, as of 21 February 2018?

Summary

A look back at the attribution of the June 2017 malware attack that hit Ukraine hardest, and the denial that followed.

What did governments say about NotPetya by 21 February 2018? Six days earlier, on 15 February 2018, the United Kingdom government and the United States White House had accused the Russian military of being responsible for launching the malware in June 2017.

The attack began on 27 June 2017 and swamped the websites of Ukrainian organisations, including banks, ministries, newspapers and electricity firms. Similar infections were reported in France, Germany, Italy, Poland, Russia, the United Kingdom, the United States and Australia. ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second at about 9%. The Ukrainian government stated on 28 June 2017 that the attack had been halted.

The malware had presented itself as ransomware. On 30 June 2017, the Associated Press reported that experts agreed it was designed to cause maximum damage, with Ukraine as the main target.

Washington's language and Moscow's reply

The White House called the incident the most destructive and costly cyberattack in history and said Russia would be met with unspecified "international consequences". The statement did not set out what those consequences would be.

Russia denied responsibility. It dismissed the accusation as "groundless", lacking evidence, and "Russophobic".

For Ukraine, the attribution tied the damage of June 2017 to a named state actor in the public record of two allied governments. What the promised consequences would involve remained open as of 21 February 2018.

Related analysis