Risk register · entry
Q3 · EngineeredNotPetya (Maersk)
A Ukrainian tax update froze a fifth of world shipping. One server in Ghana had lost power and survived.
Tightly coupled systems where one small fault cascades and takes down the whole machine.
Why this quadrant
The malware arrived through the auto-update channel of one Ukrainian accounting package and then moved by itself across flat Windows networks, so a tax client in Kyiv took down a Danish shipping company that was never a target. Maersk's domain controllers were synchronised so they could back each other up, which meant they were wiped together. 76 port terminals stopped and 45,000 endpoints were destroyed. The blast radius was set by the coupling, not by anyone's choice of victim.
The record
- Maersk put its own losses from the June 2017 NotPetya attack at USD 250-300 million; its first public guidance, given by CEO Soren Skou on 16 August 2017, was a negative results impact of USD 200-300 million.high
- The attack forced Maersk to halt operations at 76 port terminals worldwide, hitting Maersk Line, APM Terminals and Damco.certain
- Maersk reinstalled 4,000 servers, 45,000 PCs and 2,500 applications in ten days, work chairman Jim Hagemann Snabe said would normally take six months.certain
- Maersk kept running manually through the outage and took only a roughly 20 per cent drop in volumes.high
- The White House stated on 15 February 2018 that the Russian military launched NotPetya, 'causing billions of dollars in damage across Europe, Asia, and the Americas'; the widely-cited global figure of more than USD 10 billion is an estimate attributed to then-Homeland Security Adviser Tom Bossert, not a figure published by the White House.medium
Sources
The newsletter
One risk story a week, taken apart the way this one was: what was known, what was ignored, and which quadrant it really belonged to.
No spam, one email a week.