← Merck

2017 Merck & Co. — NotPetya destructive outbreak; manufacturing disruption; multi-year insurance litigation

2017 Unknown records affected Share on X

Data compromised

Operational availability collapse dominated reporting; mass consumer PII exfiltration was not the primary public narrative

Technical writeup

The June 2017 NotPetya pseudo-ransomware wave—distributed through poisoned Ukrainian MeDoc updates and leveraging worm-like lateral movement—encrypted roughly 40,000 Merck endpoints and froze production of medicines and vaccines for weeks, with the company later citing about $1.4 billion in quantified losses and a closely watched New Jersey coverage dispute over 'hostile/warlike' exclusions. Outcomes included appellate wins for Merck on policy wording before a confidential 2024 insurer settlement, framing the case as a benchmark for systemic cyber-loss recovery.

Root cause

Supply-chain–initiated destructive malware (NotPetya) propagating across global Windows estates

References