NotPetya malware halts Maersk and APM Terminals port operations
NotPetya malware halts Maersk and APM Terminals port operations. The disruption ran from 2017-06-27 (27 June 2017) to 2017-07-03 (week of 3 July 2017), affecting Los Angeles-Long Beach, New York-New Jersey, Rotterdam, Mumbai-Jawaharlal Nehru. No measured effect is published for this event; the effect section explains why.
Key facts
- Started
- 2017-06-27 (27 June 2017)
- Ended
- 2017-07-03 (week of 3 July 2017)
- Status
- ended
- Type
- Cyber incident
- Severity
- 3 Significant
- Scope
- global
- Chokepoints
- None
- Lanes
- None
- Countries
- Denmark, United States, Netherlands, India
- Confidence
- medium: The start date and the affected terminals are reported consistently by two trade outlets and by Wired, and the attribution is official, but no statement by Maersk about its own operations could be retrieved and the end of the disruption is given only as more than a week.
- First reported
- 2017-06-28 (28 June 2017)
- Severity basis: Measured effects are not available for 2017, so severity rests on the non measured criterion of simultaneous stoppages at terminals in several regions, reported at 17 of the operator's 76 terminals.
What happened
On 2017-06-27 (27 June 2017) the NotPetya malware disabled the information systems of A.P. Moller-Maersk, stopping gate, crane and booking operations at container terminals run by its APM Terminals unit. Trade press reported closures or suspended gate operations the following day at Pier 400 in Los Angeles, at Elizabeth in New Jersey, at Rotterdam, at Jawaharlal Nehru near Mumbai and at other terminals, with 17 of the operator's 76 terminals affected. Terminals returned to normal working over more than a week. On 2018-02-15 (15 February 2018) the United Kingdom said the Russian military was responsible, and the White House issued a statement the same day attributing the attack to the Russian military. The malware spread from compromised Ukrainian accounting software.
Measured effect
No measured effect is published for this event. The event predates the daily series we use, which begin on 2019-01-01 (1 January 2019).
IMF PortWatch daily data starts on 2019-01-01, so no effect can be measured for a 2017 event.
Timeline
- The NotPetya malware disables Maersk systems. Gate and terminal operating systems stop at APM Terminals facilities, and trucks queue outside the Elizabeth terminal in New Jersey. [s3]
- Trade press reports closures or suspended gate operations at Pier 400 in Los Angeles, Elizabeth in New Jersey, Rotterdam, Jawaharlal Nehru near Mumbai and further terminals, and says Maersk could not accept electronic bookings. [s1] [s2]
- Terminals worldwide return to normal working more than a week after the infection, according to Wired. [s3]
- The United Kingdom attributes the attack to the Russian military, and the White House issues a statement attributing it to the Russian military the same day. [s4] [s5]
Cause
The United Kingdom government said the Russian military was responsible for the NotPetya attack of June 2017, and the White House attributed the attack to the Russian military on the same day. Reporting traces the initial spread to compromised Ukrainian accounting software. Attributed by: Foreign and Commonwealth Office and the White House. [s3] [s4] [s5]
Resolution
2017-07-03 (3 July 2017): Maersk rebuilt its systems and worked with manual processes in the meantime. Terminals around the world resumed normal working more than a week after 2017-06-27. [s3]
Corrections
No corrections to this record as of 2026-09-16 (16 September 2026).
Sources
- [s1] gCaptain, Maersk-Operated Port Terminals, Booking System Crippled by Cyber-Attack, published 2017-06-28 (28 June 2017), accessed 2026-09-15. Archived copy. (press)
- [s2] The Maritime Executive, Maersk's Cargo Operations Hit Hard by Cyberattack, published 2017-06-28 (28 June 2017), accessed 2026-09-15. Archived copy. (press)
- [s3] Wired, The Untold Story of NotPetya, the Most Devastating Cyberattack in History, published 2018-08-22 (22 August 2018), accessed 2026-09-15. Archived copy. (press)
- [s4] Foreign and Commonwealth Office, Foreign Office Minister condemns Russia for NotPetya attacks, published 2018-02-15 (15 February 2018), accessed 2026-09-15. Archived copy. (official)
- [s5] The White House, Statement from the Press Secretary, published 2018-02-15 (15 February 2018), accessed 2026-09-15. Archived copy. (official)