Skip to content

The Malware That Erased a Shipping Giant, and the Ghana Blackout That Saved It

In June 2017 NotPetya destroyed Maersk's network within minutes, domain controllers included. One copy survived in the Ghana office, offline after a power cut, and seeded a ten day rebuild.

Episode 143 minute read

This account concerns serious harm. It follows the official investigation record and states nothing beyond it.

Minutes to a dark network

On 27 June 2017 the malware later called NotPetya spread through corporate networks worldwide. US-CERT's alert records that its delivery mechanism was the Ukrainian tax accounting software M.E.Doc, that it encrypted the master boot record of machines where it gained administrator rights, and that files were unlikely to be restored even if a ransom were paid. Maersk confirmed the next day that it had been hit, with IT systems down across multiple sites and business units and APM Terminals affected in a number of ports.

Wired's 2018 reconstruction describes screens going black across Maersk offices and operations stopping at 17 of its 76 terminals. Maersk's chief technology and information officer later said that as many as 49,000 laptops were destroyed and 1,200 applications were inaccessible. The chairman's figure, given at Davos in January 2018, was 45,000 PCs and 4,000 servers reinstalled.

The domain controllers

Domain controllers hold a network's map: its users, permissions and structure. Wired reports that Maersk had 150 or so of them, synchronised with one another so that any could stand in for the rest, and that NotPetya wiped every one, a scenario that decentralised backup had not accounted for. A rebuild needs a clean copy of that data, and for a time it appeared there was none.

The copy in Ghana

Wired reports that one domain controller survived in a Maersk office in Ghana. Some time before the attack a blackout had knocked it offline, and it was still disconnected when the malware spread. The office's connection was too slow to transmit the backup, so a staff member flew the hard drive to Nigeria and handed it to a colleague, who carried it on to Heathrow. Wired does not name a city. Maersk's own chief information security officer, its chief technology and information officer and its former head of identity and access management have each since placed the surviving copy in Lagos, Nigeria, with a Ghana-based manager as the courier. Every account agrees on the part that matters: a West African office was offline in an outage, and its disk was carried by hand through Nigeria to the United Kingdom.

The chairman said the network of servers and PCs was rebuilt in ten days. Maersk's later accounts put full application recovery at two weeks and all laptops at four. The company's Q3 2017 report recorded a financial impact of 250 to 300 million US dollars, most of it lost business in July and August.

Isolation is the backup

Maersk's domain controllers were spread across the world, but they were all connected, and a threat that travelled over the network reached them at once. The copy that survived was the one the network could not reach. Recovery capacity should be measured by what stays intact when everything connected is lost, not by how many copies exist.

Sources

9 sources

Every figure in this article traces to one of the following: the same record the episode cites.

  1. Cyber attack update

    A.P. Møller - Mærsk A/S (archived by the Internet Archive)2017

  2. Q3 2017 report

    A.P. Møller - Mærsk A/S (archived by the Internet Archive)2017

  3. Petya Ransomware

    Cybersecurity and Infrastructure Security Agency (US-CERT Alert TA17-181A)2017

  4. The Ransomware Files, Episode 4: Maersk and NotPetya

    BankInfoSecurity (archived by the Internet Archive)2022

01Zof Console

姿勢、操作、次に注意が必要なことを 1 つの面で確認できます。

エンジニアリング、QA、SREの各チームが毎日開く認証済みのホーム。品質の姿勢、進行中の実行、モジュールごとのカバレッジ、そして次に注目すべきことが分かります。

運用上の KPI

実行数、カバレッジ、リスク

出荷先のあらゆる環境に対応します。

ワークスパイン

仕様・テスト・スケジュール

仕様から計画された回帰まで。

ガードレール

RBAC・SSO・監査

指定された人間に起因するすべての行為。

LIVE/console
Zof AI ホーム コマンド センターには、94% パスでの 12 件の実行、3 つの未解決の重大な問題、84% のカバレッジ、4 つのモジュール トレーサビリティ バー、仕様パイプライン、今後のスケジュール、アクティブ実行サイドバー付きの推奨される次のアクションが表示されます。
ホーム ビュー · チェックアウト サービス · ステージング · 製品からライブでキャプチャ。
The Malware That Erased a Shipping Giant | Zof AI