← Merck & Co.

2017 Merck — NotPetya worm/crypto-wiper disrupted global IT and pharmaceutical manufacturing (Jun)

2017 40.0K records affected Share on X

Data compromised

Primarily availability and operational data integrity loss; consumer HIPAA-style dossiers not the headline artifact of NotPetya

Technical writeup

Merck became one of the largest NotPetya enterprise victims on June 27, 2017, as the worm moved from poisoned M.E.Doc update channels in Ukraine to multinational networks. Subsequent litigation exhibits summarized in SecurityWeek described ~10,000 endpoints infected within 90 seconds, ballooning past 40,000 worldwide, paralyzing email, manufacturing, and R&D systems—including Gardasil 9 fill-finish lines that drew FDA attention. Insurance Business recounts how Merck pursued ~$1.4 billion in traditional property coverage, helping establish precedent that boilerplate "warlike action" exclusions often do not bar state-adjacent malware losses without clearer military nexus language.

Root cause

Supply-chain compromise of widely deployed accounting software pushing disk-encrypting/wiping malware plus aggressive lateral movement

References