Перейти к содержимому

The Cyberattack That Wiped 40,000 Computers in 90 Seconds

TechBreaking

0:00 / 0:00

The Cyberattack That Wiped 40,000 Computers in 90 Seconds

104 просмотра · 11 дней назад
TechBreaking
43 подписчика
104 просмотра · 11 дней назад
Three hundred dollars in bitcoin: that is what every infected screen at Maersk asked for on 27 June 2017. Paying was impossible, because there was no key. It arrived as an ordinary update to a Ukrainian tax program. Nobody had to click anything. NotPetya spread from M.E.Doc's update server into Maersk, Merck, FedEx's TNT Express, Saint-Gobain and Mondelez, stealing passwords from memory so that even fully patched machines fell. The ransom key was random data. The White House and the UK blamed the Russian military in 2018, and in 2020 a US grand jury charged six GRU officers, none of whom has stood trial. The losses the companies filed themselves add up to roughly two billion dollars; the famous 10 billion dollar total is an unpublished White House assessment, reported by one magazine, and the video treats it that way. Chapters: 00:00 Cold open: the $300 ransom 00:35 Noon in Kyiv 04:00 Ninety seconds 08:22 14:02 EDT, the first warning 10:32 Ten days 14:03 Six years 17:01 Our take Reported, not documented (labelled in the video): the 10 billion dollar total (Wired, via Tom Bossert), the Ghana server story and the 45-second bank takedown (Wired). Other numbers come from the filings, court records and government documents below. Sources: DOJ indictment: https://www.justice.gov/opa/press-rel... DOJ release: https://www.justice.gov/opa/pr/six-ru... White House: https://trumpwhitehouse.archives.gov/... UK: https://www.gov.uk/government/news/fo... CISA: https://www.cisa.gov/news-events/aler... Maersk: https://investor.maersk.com/news-rele... Maersk Q2 2017: https://investor.maersk.com/static-fi... Maersk AR 2017: https://investor.maersk.com/system/fi... Merck 10-K: https://www.sec.gov/Archives/edgar/da... FedEx 10-K: https://www.sec.gov/Archives/edgar/da... Saint-Gobain: https://www.saint-gobain.com/sites/sa... Mondelez: https://www.sec.gov/Archives/edgar/da... https://www.sec.gov/Archives/edgar/da... NJ appellate opinion: https://www.njcourts.gov/system/files... https://regmedia.co.uk/2022/11/02/pac... Talos: https://blog.talosintelligence.com/wo... https://blog.talosintelligence.com/th... ESET: https://www.welivesecurity.com/2017/0... https://www.welivesecurity.com/2017/0... Kaspersky: https://securelist.com/expetrpetyanot... https://securelist.com/schroedingers-... Microsoft: https://www.microsoft.com/en-us/secur... https://www.microsoft.com/en-us/msrc/... https://blogs.microsoft.com/on-the-is... Posteo: https://posteo.de/en/blog/update-pety... Reporting: https://www.wired.com/story/notpetya-... https://www.theregister.com/2018/01/2... https://www.bleepingcomputer.com/news... https://www.theregister.com/2017/07/0... https://www.rferl.org/a/ukrainian-cyb... https://phys.org/news/2017-06-chernob... https://fortune.com/2017/07/06/the-ma... https://www.proactiveinvestors.co.uk/... https://www.cbsnews.com/news/wannacry... https://www.cybersecuritydive.com/new... https://www.insurancejournal.com/news... #NotPetya #CyberAttack #TechBreaking #Malware