March 18, 2026, 2:35 p.m.
"On the morning of June 27, 2017, 45,000 computers of the world's largest container shipping company went offline in 10 minutes. The same message appeared on all screens: 'Your system is encrypted.'"
Maersk is the world's largest container shipping company. It transports 20 million containers annually, handling approximately 17% of global cargo traffic. In 2017, this giant became the victim of one of the largest cyberattacks in history — and it wasn't even specifically targeted.
June 27, 2017: Maersk's global network was paralyzed in 10 minutes
NotPetya: Weapon of Indiscriminate Destruction
NotPetya appeared to be ransomware — but it was actually designed for a completely different purpose. This malware, developed by a Russian-linked cyberattack group, was targeting Ukraine. However, its destruction spread worldwide.
The attack unfolded as follows: The update mechanism of M.E.Doc, an accounting software widely used in Ukraine, was compromised. With the next update, NotPetya infected all companies using the software. Among these companies was Maersk's Ukraine office.
- After the initial infection, NotPetya spread automatically across the network
- Maersk's entire global network was interconnected — and not segmented
- Within 10 minutes, 45,000 computers and 4,000 servers were destroyed
Chaos: What Happened?
- 🔴 57 ports and terminals were forced to switch to manual operations
- 🔴 Containers began piling up at the Port of Rotterdam with no knowledge of their destinations
- 🔴 The company couldn't take orders, issue invoices, or track shipments
- 🔴 For 10 days, almost nothing could be done
- 🔴 45,000 PCs and 4,000 servers across 4 continents were reinstalled to rebuild systems
Recovery: The Single Domain Controller in Ghana
The most interesting part of this story is this: All domain controllers were wiped. They needed at least one to rebuild the network. They searched — and found a domain controller in the Ghana office that had been shut down due to a power outage during the network disruption and thus escaped the attack. They flew that single machine to the UK.
Lesson: If there had been network segmentation, the attack couldn't have spread. If there had been regular backups and offline domain controller backups, recovery would have taken hours, not 10 days.
The Bill: $300 Million
- 💸 Total damage: approximately $300 million
- 💸 Lost shipping revenue, system rebuilding costs
- 💸 Maersk experienced this attack without being directly targeted — it was a victim of "collateral damage"
Lessons to Be Learned for Your Company
- ✅ Network segmentation is essential: If one office gets infected, others shouldn't be affected
- ✅ Supply chain security: Third-party software updates must be verified
- ✅ Offline backups: At least one critical system backup should be kept offline
- ✅ Incident response drills: What to do during a crisis should be rehearsed in advance
Similar Posts