Ukraine and its neighbours, explained

Advertisement

Home › Security › Who answered for NotPetya, and what followed?

Security

Who answered for NotPetya, and what followed?

Summary

A look back at the day the UK and US governments publicly blamed the Russian military for the 2017 malware attack that hit Ukraine hardest.

What did it mean when two governments named the Russian military as the author of NotPetya? On 15 February 2018, the United Kingdom government and the United States White House did exactly that, attributing the June 2017 malware launch to Russia's armed forces.

The White House described the operation as the most destructive and costly cyberattack in history and said Russia would face unspecified "international consequences". No measures were spelled out.

Moscow rejected the accusation. Russia denied responsibility and dismissed the claim as groundless, unsupported by evidence and "Russophobic".

The attack being attributed

The malware, a variant of Petya, began spreading on 27 June 2017. It swamped the systems of Ukrainian organisations, including banks, ministries, newspapers and electricity firms. Infections were also reported in France, Germany, Italy, Poland, Russia, the United Kingdom, the United States and Australia.

ESET estimated on 28 June 2017 that 80% of infections were in Ukraine, with Germany second at about 9%. The Ukrainian government said that day that the attack had been halted. By 30 June 2017, the Associated Press reported that experts agreed Petya was posing as ransomware while actually being designed to cause maximum damage, with Ukraine the main target.

What the day settled

The statements of 15 February 2018 moved the matter from technical analysis to public attribution by two governments, and they met a flat denial from Russia. The promised consequences remained undefined on that date.

Related analysis