2017 Merck & Co. — NotPetya destructive outbreak; manufacturing disruption; multi-year insurance litigation
Data compromised
Operational availability collapse dominated reporting; mass consumer PII exfiltration was not the primary public narrative
Technical writeup
The June 2017 NotPetya pseudo-ransomware wave—distributed through poisoned Ukrainian MeDoc updates and leveraging worm-like lateral movement—encrypted roughly 40,000 Merck endpoints and froze production of medicines and vaccines for weeks, with the company later citing about $1.4 billion in quantified losses and a closely watched New Jersey coverage dispute over 'hostile/warlike' exclusions. Outcomes included appellate wins for Merck on policy wording before a confidential 2024 insurer settlement, framing the case as a benchmark for systemic cyber-loss recovery.
Root cause
Supply-chain–initiated destructive malware (NotPetya) propagating across global Windows estates