Skip to content

The Malware That Erased a Shipping Giant, and the Ghana Blackout That Saved It

In June 2017 NotPetya destroyed Maersk's network within minutes, domain controllers included. One copy survived in the Ghana office, offline after a power cut, and seeded a ten day rebuild.

Episode 143 minute read

This account concerns serious harm. It follows the official investigation record and states nothing beyond it.

Minutes to a dark network

On 27 June 2017 the malware later called NotPetya spread through corporate networks worldwide. US-CERT's alert records that its delivery mechanism was the Ukrainian tax accounting software M.E.Doc, that it encrypted the master boot record of machines where it gained administrator rights, and that files were unlikely to be restored even if a ransom were paid. Maersk confirmed the next day that it had been hit, with IT systems down across multiple sites and business units and APM Terminals affected in a number of ports.

Wired's 2018 reconstruction describes screens going black across Maersk offices and operations stopping at 17 of its 76 terminals. Maersk's chief technology and information officer later said that as many as 49,000 laptops were destroyed and 1,200 applications were inaccessible. The chairman's figure, given at Davos in January 2018, was 45,000 PCs and 4,000 servers reinstalled.

The domain controllers

Domain controllers hold a network's map: its users, permissions and structure. Wired reports that Maersk had 150 or so of them, synchronised with one another so that any could stand in for the rest, and that NotPetya wiped every one, a scenario that decentralised backup had not accounted for. A rebuild needs a clean copy of that data, and for a time it appeared there was none.

The copy in Ghana

Wired reports that one domain controller survived in a Maersk office in Ghana. Some time before the attack a blackout had knocked it offline, and it was still disconnected when the malware spread. The office's connection was too slow to transmit the backup, so a staff member flew the hard drive to Nigeria and handed it to a colleague, who carried it on to Heathrow. Wired does not name a city. Maersk's own chief information security officer, its chief technology and information officer and its former head of identity and access management have each since placed the surviving copy in Lagos, Nigeria, with a Ghana-based manager as the courier. Every account agrees on the part that matters: a West African office was offline in an outage, and its disk was carried by hand through Nigeria to the United Kingdom.

The chairman said the network of servers and PCs was rebuilt in ten days. Maersk's later accounts put full application recovery at two weeks and all laptops at four. The company's Q3 2017 report recorded a financial impact of 250 to 300 million US dollars, most of it lost business in July and August.

Isolation is the backup

Maersk's domain controllers were spread across the world, but they were all connected, and a threat that travelled over the network reached them at once. The copy that survived was the one the network could not reach. Recovery capacity should be measured by what stays intact when everything connected is lost, not by how many copies exist.

Sources

9 sources

Every figure in this article traces to one of the following: the same record the episode cites.

  1. Cyber attack update

    A.P. Møller - Mærsk A/S (archived by the Internet Archive)2017

  2. Q3 2017 report

    A.P. Møller - Mærsk A/S (archived by the Internet Archive)2017

  3. Petya Ransomware

    Cybersecurity and Infrastructure Security Agency (US-CERT Alert TA17-181A)2017

  4. The Ransomware Files, Episode 4: Maersk and NotPetya

    BankInfoSecurity (archived by the Internet Archive)2022

01Zof Console

One surface for posture, operations, and what needs attention next.

The authenticated home that engineering, QA, and SRE teams open every day: quality posture, in-flight runs, coverage by module, and what needs attention next.

OPERATIONAL KPIs

  • Runs
  • Coverage
  • Risk

Live across every environment you ship to.

WORK SPINE

  • Specs
  • Tests
  • Schedules

From specification to scheduled regression.

GUARDRAILS

  • RBAC
  • SSO
  • audit

Every action attributable to a named human.

LIVE/console
Zof AI home command center showing 12 runs at 94% pass, 3 open critical issues, 84% coverage, four module traceability bars, the specification pipeline, upcoming schedules, and recommended next actions with an active-runs sidebar.
Console home · Checkout Service · Staging · captured live from the product.
The Malware That Erased a Shipping Giant | Zof AI