To Stop a Cyberattack, Act Like It’s the Front Line
In June 2017, a cyberattack known as NotPetya unleashed unprecedented havoc across global networks, crippling infrastructure, halting business operations, and causing over $10 billion in damages worldwide.
Masquerading as ransomware, NotPetya was, in reality, a destructive wiper malware designed to obliterate data rather than extort money. Its rapid spread exposed the vulnerabilities of our interconnected digital systems and underscored the critical need for comprehensive cybersecurity strategies involving all organizational stakeholders—not just IT departments.
The Genesis of NotPetya: A Weapon Disguised as Ransomware
NotPetya appeared in Ukraine, disseminated through a compromised update of the widely used accounting software M.E.Doc. Once inside a network, it exploited the EternalBlue vulnerability—previously used in the WannaCry attack—and employed credential-stealing tools like Mimikatz to propagate rapidly across systems. Unlike typical ransomware, NotPetya lacked a functional mechanism for data recovery, rendering infected systems inoperable and causing irreversible data loss.
EternalBlue was developed by the NSA, and it was released by a hacking group known as the Shadow Brokers. This group disclosed a cache of NSA-developed exploits, including EternalBlue, which later played a significant role in cyberattacks such as WannaCry and NotPetya.
The Sandworm Connection: Cyberwarfare by State Actors
The attack was attributed to Sandworm, a cyberwarfare unit of Russia’s military intelligence agency, the GRU. A highly credible source for attributing NotPetya to Sandworm is the U.S. Department of Justice press release titled “Six Russian GRU Officers Charged in Connection with Worldwide Deployment of Destructive Malware and Other Disruptive Actions in Cyberspace.” This document details the indictment of six officers from Russia’s GRU—who have been linked to Sandworm—and outlines their involvement in cyberattacks including NotPetya.
Sandworm, also known as APT44, has a history of orchestrating significant cyberattacks, including the 2015 Ukrainian power grid blackout and interference in various international events. Their involvement in NotPetya marked a significant escalation in state-sponsored cyber aggression, blurring the lines between cybercrime and acts of war.
The Ripple Effect: Global Corporate Casualties
Maersk: The Danish shipping giant experienced a complete shutdown of its IT systems, disrupting operations at 76 ports worldwide. The company estimated losses between $200 million and $300 million..
Merck: The pharmaceutical company suffered extensive disruptions, leading to production halts and significant financial losses. Merck later secured a $1.4 billion insurance settlement after legal battles over coverage for the cyberattack.
FedEx: Its subsidiary, TNT Express, was severely affected, with some systems permanently damaged. FedEx reported losses of approximately $300 million due to the attack.
Saint-Gobain: The French construction materials company faced widespread system outages, resulting in losses estimated at $384 million.
These incidents highlighted how cyberattacks could transcend digital boundaries, causing tangible disruptions in physical operations and supply chains.
The Vulnerability of Interconnected Systems
Beyond IT: The Imperative of Organizational Resilience
Ukraine: The Epicenter and Ongoing Target
Lessons Learned and the Path Forward
The NotPetya incident serves as a stark reminder of the destructive potential of cyberattacks and the necessity for comprehensive cybersecurity strategies. Organizations must prioritize resilience, ensuring that cybersecurity measures are integrated across all levels and departments. By fostering a culture of security awareness and preparedness, businesses can better safeguard against future threats and mitigate the impact of potential attacks.
In conclusion, NotPetya was more than a cyberattack; it was a wake-up call to the vulnerabilities inherent in our interconnected digital world. By learning from this event and reinforcing our defences, we can strive to build a more secure and resilient cyber infrastructure for the future.
Why CYBER RANGES is the Preferred Choice for organizations worldwide?
Unlike some vendors that offer limited customization options, require cloud-only access, or provide less advanced attack emulation features, CYBER RANGES delivers a more adaptable and comprehensive solution.
CYBER RANGES offers:
✔ Multi-tenant, high-fidelity simulation environments
✔ Full integration of ICS/OT networks with HIL capabilities
✔ CTI-driven attack scenarios mapped to real-world threats
✔ Cloud, on-premises, and portable deployment models
✔ End-to-end cyber resilience training with automated assessment tools
✔ Military-grade security, incorporating advanced encryption protocols, secure network segmentation, compliance with NIST and ISO security standards, and hardened environments for governments, enterprises, and critical infrastructure sectors.
Experience CYBER RANGES
In an era where preemptive cybersecurity is paramount, CYBER RANGES leads the way by offering the most comprehensive, scalable, and engaging cyber range training available.
Request a demo today and see how CYBER RANGES can enhance your cybersecurity workforce, reduce risk exposure, and prepare your organization for the future of cyber warfare.

Dr. Oleksii Baranovskyi
Dr. Oleksii Baranovskyi is a distinguished figure in the field of Ukrainian Cybersecurity.
Oleksii is an accredited instructor for prestigious organizations like (ISC)2, ISACA, and EC-Council. His contributions to cybersecurity education have been honoured with international awards, underpinning his role as a global educator by EC-Council Instructor (CEI) Circle of Excellence Award in 2022 and the ISACA Educational Excellence Award in 2024. Oleksii is known for his dedication to public service in cybersecurity with trainings and educational programs, for which he has been commended with national honours acknowledged with the National Security Council order "Defender of Ukraine" in 2020 and medal of honour by State Service of Special Communication and Information Protection of Ukraine (SSSCIP) for his impact of creating and development of cyberpolice and national cybersecurity capabilities. as well as recognitions by OSCE, USAID, the National Bank of Ukraine and the National Police. Oleksii serves as forensic investigator, penetration tester and application security expert in professional companies.
For media enquiries: Marcello Hinxman-Allegri, Head of Marketing & Business Development
For industry enquiries: Michael Roncon, Head of Defense & National Security
CYBER RANGES Corp. – Quantico Cyber Range, Suite 305, 1010 Corporate Drive, Stafford, VA 22554
E-mail: contact@cyberranges.com | Web: www.cyberranges.com | Freephone: 1-800-959-0163
Learn More About Cyberdrills
CYBER RANGES has developed a strong global reputation for providing national, International, industry specific and bespoke high-fidelity Cyberdrills for multiple vertical sectors.
Free Community Scenarios
The CYBER RANGES Community is a free collaborative space for learners and professionals looking to upskill their cybersecurity prowess, start your CYBER RANGES journey here.
