Increasingly Sophisticated And Damaging “NotPetya” Cyber Attack Highlights Importance Of Timely Update

King & Spalding
Contact

Last Tuesday morning, June 27, 2017, a version of the “Petya” malware attack—dubbed “NotPetya”—hit several multinational companies in a variety of industries. This is the second major cyber attack in just two months following the May 12 WannaCry attack, although NotPetya has differed in target and execution from the WannaCry incident and may provide some companies new cybersecurity lessons.

WannaCry and NotPetya both entered systems through the same Windows exploit. Microsoft had issued a patch two months before both attacks, but not all entities had updated their software. Unlike WannaCry, NotPetya compromised entire systems rather than individual files. NotPetya has been more damaging than WannaCry and is considered to be more sophisticated.

According to one security firm’s investigation, NotPetya is a “wiper,” not ransomware like WannaCry, as initially believed. A 2016 version of Petya functioned as ransomware, but the 2017 modified version (thus “NotPetya”) does permanent and irreversible damage to the disk, despite originally posing as ransomware. Some commentators believe that the appearance of ransomware was intended to suggest to the media that an independent hacker group, rather than a nation state, was behind the attack. Initially, NotPetya appeared to target Ukrainian government and commercial organizations. However, the infection has shut down ports, factories, and offices worldwide. The destructive (rather than ransom-seeking) nature of the attack emphasizes the necessity of multiple backups. Additionally, companies should be careful to layer and architect their network such that all their eggs are not in one proverbial cyber basket. The attack has also prompted businesses to seek more comprehensive cyber insurance coverage.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© King & Spalding | Attorney Advertising

Written by:

King & Spalding
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

King & Spalding on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide