Overview
NotPetya entered through a backdoored update of a Ukrainian accounting package, then propagated via EternalBlue and credential theft.\nIt was not recoverable even if a ransom was paid: the encryption destroyed data permanently.\nMaersk lost its entire global IT estate and had to rebuild hundreds of servers from a single surviving domain controller in Ghana.\nIt remains the benchmark for supply-chain destruction.
Indicators of Compromise
Signals that suggest this is present on a system.
- Petya-style boot-level encryption with no recovery path
- Mimikatz-style credential harvesting in the same burst
- Update channels from a single geographic vendor
Controls that stop it
-
Keep Tested, Offline Backups
Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.