Home › Security › Who answers for NotPetya? Attribution fallout in 2018
Who answers for NotPetya? Attribution fallout in 2018

Summary
A look back at the accusations against Russia's military over the June 2017 malware, and the denial that followed.
What did it mean when two Western governments named a state for a cyberattack? On 20 February 2018, the question was still live, five days after the United Kingdom government and the United States White House accused the Russian military of launching the NotPetya malware in June 2017.
The accusation and the denial
The White House described the attack as the most destructive and costly cyberattack in history and said Russia would face unspecified "international consequences". Russia denied responsibility, dismissing the accusation as "groundless", unsupported by evidence and "Russophobic".
What had happened in Ukraine
The attacks began on 27 June 2017, using Petya malware, and swamped the websites of Ukrainian organisations, including banks, ministries, newspapers and electricity firms. Infections were also reported in France, Germany, Italy, Poland, Russia, the United Kingdom, the United States and Australia. ESET estimated on 28 June 2017 that 80% of all infections were in Ukraine, with Germany second at about 9%. The Ukrainian government said that day that the attack had been halted.
On 30 June 2017, the Associated Press reported that experts agreed the malware had been masquerading as ransomware while actually being designed to cause maximum damage, with Ukraine the main target.
Why it mattered
The February 2018 statements tied a strike that hit Ukraine hardest to a named state actor, while the "international consequences" were left undefined. Moscow's flat rejection meant the dispute stood as accusation against denial.