← Maersk

2017 A.P. Moller–Maersk — NotPetya destructive worm; global IT rebuild; ~$300M impact

2017 Unknown records affected Share on X

Data compromised

Primarily availability and operational data destruction; consumer PII theft not the dominant framing in primary reporting

Technical writeup

The June 2017 NotPetya self-propagation wave originating from poisoned Ukrainian tax-software channels cascaded into Maersk’s globally meshed Windows estate, encrypting tens of thousands of endpoints and servers and forcing a multi-week operational recovery narrative covered by Maersk investor communications, WIRED, and business press. The incident is canonical for supply-chain–initiated OT/IT meltdown at maritime scale rather than a consumer row-count breach.

Root cause

Destructive wiper malware spread via trusted software update paths and lateral movement across enterprise Active Directory

References