The encyclopedia · Software & IT · Operational decision · 2017
NotPetya wiped Maersk's computers worldwide — and cost it up to $300M
When the NotPetya worm hit in 2017, it locked the world's largest container line out of its own systems. Terminals stalled; the cleanup cost up to $300M.
Maersk · 2017-06
What happened
A.P. Moller-Maersk, the Danish group that operates the world's largest container shipping line, was hit in late June 2017 by NotPetya, a self-spreading worm that began in Ukrainian accounting software and raced across corporate networks worldwide. At Maersk it locked employees out of the systems the company uses to run its shipping terminals around the globe.
The disruption was immediate and global. For up to two days, affected terminals could not move cargo from ship to shore; Maersk's APM terminal at Pier 400 in the Port of Los Angeles, the port's largest cargo terminal, was closed from 27 June to 1 July, leaving at least one ship waiting at anchor. With their applications and data unavailable, staff improvised using Twitter, WhatsApp and Post-It notes to keep goods moving.
Maersk said no data was lost, no workers were endangered and ships kept sailing, but the cost of stopping and then rebuilding was enormous. The company estimated the attack cost it $200 million to $300 million, and the figure climbed as the task of rebuilding its IT added more on top. Reports put the scale of the rebuild at around 50,000 computers and thousands of servers reinstalled.
There was, as a Maersk spokeswoman put it, 'no benchmark for this.' The case became the textbook example of cyber risk as operational risk: a shipping giant did not lose a single vessel, yet a single worm moving through an unsegmented network could still close terminals on multiple continents and cost a quarter of a billion dollars.
Why it happened
- NotPetya spread laterally through Maersk's network, locking the systems it uses to operate shipping terminals worldwide.
- With applications and data unavailable, terminals could not move cargo for up to two days, and major facilities like the Port of Los Angeles' largest terminal shut for days.
- The network's lack of segmentation meant one infection became a global outage rather than a contained incident.
- The cleanup — rebuilding IT and reinstalling around 50,000 computers and thousands of servers — drove the cost to an estimated $200–300 million and beyond.
The lesson
A network with no segmentation fails all at once. NotPetya spread through Maersk's systems and wiped tens of thousands of machines in minutes; resilience is built before the worm arrives, not after.
Aftermath
Maersk rebuilt its IT infrastructure from scratch and became a leading corporate voice on cyber resilience, openly detailing the cost and chaos of the attack so that other firms would prepare rather than assume they were safe. NotPetya as a whole caused an estimated $10 billion of damage across multinationals, and the Maersk case is now the standard reference for how a cyberattack on a logistics operator becomes a physical disruption to trade — and why cyber risk is priced as an operational, not merely an IT, exposure.
Sources
- Los Angeles Times — 'Cyberattack cost Maersk as much as $300 million and disrupted Port of Los Angeles', August 2017 (NotPetya, June 2017; $200–300M cost; APM Pier 400 closed 27 June–1 July; terminals stalled)
- SecurityWeek — 'Maersk Reinstalled 50,000 Computers After NotPetya Attack' (scale of the IT rebuild after the June 2017 attack)
spotted an error? The club wants to know.
More like this
Symbian had 10M+ lines of code and no one understood it — Nokia couldn't fix its own OS
Symbian was owned by 7 phone makers who couldn't agree — and the OS died of committee
Electrolux cut 3,000 jobs and its CEO left — a decade of cost-cutting ran out of road
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.