2017 A.P. Moller–Maersk / Maersk Line — NotPetya wiper; global booking & terminal IT meltdown (Jun)
Data compromised
Primarily availability destruction of IT and operational-technology support layers; incident-class espionage/exfiltration was not the centerpiece relative to mass wiper damage
Technical writeup
Container-shipping giant A.P. Moller–Maersk was among the largest corporate victims of the June 2017 NotPetya self-spreading destructive malware campaign traced in public reporting to poisoned M.E.Doc updates and subsequent lateral movement across global enterprises. Maersk Line bookings, APM Terminals port systems, and group email/Active Directory infrastructure were knocked offline for days to weeks; Maersk later described rebuilding on the order of tens of thousands of endpoints. This row keys to the `maersk-line` directory slug as the consumer-facing shipping brand most often named in coverage, while impact was group-wide.
Root cause
NotPetya pseudo-ransomware / wiper outbreak propagating into Maersk’s global Windows estate (sector attribution and tradecraft summarized in McAfee/USG and press post-mortems)