Maersk Cyber Attack: How NotPetya Crippled Global Shipping

Action: segment core services on separate networks, isolate them with offline backups, and train teams on rapid response to cut disruption when a cyber-attack hits. This approach is about reducing exposure and ensuring rapid recovery.

In the NotPetya outbreak, Maersk's core IT environment shut down to contain the spread, crippling shipping software and causing port calls to be missed or delayed. The incident impacted operations for days and triggered recovery costs reported in the hundreds of millions. It revealed how quickly a cyber-attack can cross networks and affect global trade, stressing Maersk's defences and the ability of teams to respond. A single miss in early detection can escalate fast — something we see echoed in nearly every major freight disruption we work through with carriers and terminal operators.

To prevent a repeat, run a hands-on workshop focused on incident tracking, tabletop exercises, and real-time detection. Build a cross-functional team that includes operations, IT, and security, so defences can adapt and decisions stay rapid. Track all indicators, from initial missed alerts to system isolation, and surface gaps in how teams respond so they can be fixed before a real incident hits.

Focus on Maersk's core operations: container management, cargo visibility, and customer communications. Establish offline backups for critical data, keep those backups on separate networks, and maintain a rapid restoration playbook tested against simulated disruptions. Regular drills shorten the time from detection to containment, limiting disruption for partners and customers.

The ability of teams to respond quickly shapes resilience. Share lessons with suppliers and ports so they can mirror the same defences, and use transparent tracking to measure progress across the network. This approach steadies operations during cyber-attack events and strengthens Maersk's international shipping network.

NotPetya entry points: how malware spread into Maersk networks

Isolate and segment critical networks immediately to stop the spread. The initial entry point for Maersk's NotPetya incident stemmed from a subsidiary network that received a compromised software update from a trusted vendor, enabling a destructive wiper to run. This shows how a targeted supply-chain breach can present as routine activity, and how staff activity within a trusted software line can accelerate a cyberattack across the wider environment. Early containment would have limited the blast radius.

NotPetya then moved across networks through management tools and legitimate credentials. It likely exploited a standard lateral movement path across Windows environments, using PsExec, Windows Admin Shares, and other remote techniques to reach devices and servers across a subsidiary network. When we coordinate cross-border operations for clients running multiple subsidiary entities, we see how shared credential pools and flat network architectures create exactly this kind of exposure. Tracking login and process activity in the earlier hours would have signalled abnormal behaviour and allowed quicker containment.

To defend now, implement concrete controls: enforce full network segmentation and restrict cross-network access; minimise and rotate administrative credentials; require MFA for remote login; apply strict application allowlisting and patch critical Windows vulnerabilities promptly; monitor staff activity with user and entity behaviour analytics; disable legacy protocols that enable lateral movement; ensure offline backups and regularly test recovery; isolate infected hosts and wipe them before reconnecting; run tabletop exercises with subsidiary teams so lessons are embedded in the management line; keep logs and telemetry across all networks for tracking and forensics; build a response playbook that protects operations in the event of another cyberattack.

Beyond immediate containment, strengthen resilience by aligning cybersecurity with business continuity. Maintain visibility across all subsidiaries, reduce reliance on shared credentials, and train staff to report phishing and suspicious activity. A rapid, coordinated response manages incidents more effectively across networks and produces measurable improvements in containment time and total downtime after an incident.

Immediate operational impact: outages at terminals, shipping schedules, and IT systems

Immediate operational impact: outages at terminals, shipping schedules, and IT systems

Immediately isolate the compromised network segments and switch critical operations to offline backups to prevent further spread and stabilise freight processing. Across the group, implement temporary offline workflows for terminals, inland shipping, and customer data portals, including manual reconciliation of freight movements and container bookings. This limits malware spread and preserves data integrity while responsible teams restore core systems and validate data in the affected subsidiary networks.

Outages at terminals across international operations crippled crane control, yard management, and vessel loading systems. In the first 24 hours, scheduling data vanished from terminal operating and ERP systems, pushing departures and arrivals out by 12–36 hours on several routes. Some terminals experienced 1–2 day backlogs, forcing inland moves to rely on manual processes and leading to missed windows for perishable freight and time-sensitive shipments.

The group's IT systems suffered a broader impact: the network collapsed under malware pressure, affecting ERP, WMS, TMS, and linked data stores. Email, invoicing, and customer portals went offline in multiple subsidiaries, eroding visibility of data and the ability to share live freight status. Recovery required rebuilding domain controllers, reinstalling core software, and conducting strict data validation to avoid corrupted bookings or duplicate shipments. In our experience coordinating carriers through port disruptions, the loss of live freight status is often what turns a contained incident into a prolonged commercial crisis.

Recent events exposed vulnerabilities in endpoint hygiene and network segmentation. Lessons emphasise tighter segmentation, frequent backups, and tested recovery playbooks. A cross-functional workshop — covering security, operations, and commercial teams — should become a standing activity for any large group, to reduce risk across regions and subsidiaries while maintaining service levels.

To restore full capability quickly, complete a focused 72-hour plan: reimage affected endpoints, restore clean data from secure backups, and reestablish the core network with enhanced monitoring. Responsible managers should assign clear ownership to each subsidiary, set up real-time data dashboards for freight and schedule status, and run a brief data-driven drill to confirm integrity. The longer-term commitment to resilience should include updated vendor controls, refreshed access policies, and a data-driven timeline for full recovery with lessons documented from the workshop.

Direct and indirect costs: downtime, remediation, and lost revenue

Implement rapid network segmentation and offline backups within 24 hours to minimise downtime. This prevents further spread and helps international cargo and services resume quickly while access to key networks and computer systems is restored, though some systems may require staged reactivation.

Downtime costs likely ranged from 3 to 7 days for core operations, with those outages blocking access to reservation systems, tracking, and cargo movement, delaying tens of thousands of containers and reducing revenue from services. Global estimates place direct losses in the hundreds of millions of USD, commonly cited around $200–300 million, with a portion tied to remediation and the need to rebuild damaged networks and computer infrastructure.

Remediation and recovery expenses covered forensic analysis, software restoration, server rebuilds, patching, and security upgrades, plus expanded monitoring and immutable backups. Those charges likely ran from tens to low hundreds of millions, depending on the size of the network and the extent of damage, and included overtime for staff, equipment procurement, and new licences. Those steps, though demanding, reveal weaknesses in protocols and access controls that would otherwise remain hidden.

Indirect costs included lost revenue from delayed shipments, penalties, and customer churn, as well as reputational damage and higher insurance premiums. Those effects can extend for months and often exceed the initial remediation bill, especially where international customers are evaluating continuity for their own supply chains. As FreightWaves has reported in its broader coverage of cyber risk in shipping, the downstream commercial consequences of a major carrier outage tend to be underestimated until they arrive.

Recommended measures to cut exposure include: segment networks into secure zones; enforce least-privilege access; maintain offline immutable backups; deploy endpoint detection and response (EDR) and centralised logging; require MFA for all administrator access; implement application allowlisting and targeted security protocols; track cargo and service data to support rapid containment; establish an international incident playbook with clear communication for customers. Regular drills and tracking of response times reveal gaps before a real incident arrives.

Tracking post-incident metrics enables better budgeting and planning: measure time to containment, time to restore access, and revenue recovered. By tightening protocols and strengthening defences, downtime can be limited to hours rather than days, and the damage to cargo flows and services can be substantially reduced, even when those networks face another attack.

Incident response and remediation steps: containment, backups, and system restoration

Contain the breach within minutes by isolating affected segments, revoking compromised credentials, and routing work through clean, offline backups to maintain continuity and limit disruption. Immediately declare an incident and assign a responsible lead who coordinates cross-functional teams across IT, security, operations, and legal. The Maersk case shows how fast containment shapes resilience and demonstrates the value of a prepared playbook that staff can follow without hesitation. When we arrange contingency freight solutions during operational crises, the difference between teams that have rehearsed a response and those that have not is visible within the first hour.

Backups must be offline, immutable, and tested. Activate the latest clean copies to restore critical systems first, including ERP, order management, and financials. Maintain several restore points, with at least one offline copy retained for the prior year and another for peak periods. Validate data integrity with checksums and routine drills to confirm full recovery is achievable even if primary storage is compromised.

Restoration should be staged in a clean environment: bring back non-critical systems first, apply a gold image for servers, and run a malware sweep across endpoints before reintroducing them to production. Change all credentials and enforce multi-factor authentication, then reestablish connectivity through segmented networks to avoid a single point of failure. Use a controlled rollout to ensure business continuity while monitoring for latent threats that may persist in backups or dormant code.

Document lessons and share them with stakeholders through a post-event report or structured debrief. The late phase of the aftermath often reveals gaps in detection, containment, and communication; addressing those gaps strengthens resilience for future attacks, including those targeting logistics specifically. The lessons from this incident should inform your incident response playbook and be shared with external partners, so that teams stay prepared and customers see minimal disruption.

Ongoing improvement requires routine testing, technology investment, and clear responsibilities. Define who is responsible for containment, backups, and restoration, and practise with quarterly tabletop exercises. Rehearse the full continuity plan in a real-world context, analyse the aftermath, and refine processes based on measured outcomes. The result is a culture of resilience that extends beyond your own organisation into the wider shipping and technology community, turning a disruption into stronger systems and faster recovery.

Longer-term effects on the supply chain: customer trust, rerouting, and insurance considerations

Recommended action: implement a resilience framework within 90 days that aligns customer communication, operational rerouting, and cyber risk insurance. This plan connects those functions across the core of the organisation, including headquarters and regional offices.

Customer trust recovers faster when incidents are communicated with transparency. Establish a formal status email cadence and a public dashboard that shows ETA windows, current delays, and remediation steps. Those updates should be timely, factual, and easy to understand, reducing the volume of inbound inquiries and protecting the brand's reputation among international customers and partners.

Rerouting and moving goods demand a disciplined approach. Build an automated, multi-modal rerouting capability that can shift shipments between sea, air, rail, and inland networks when disruptions occur. Create a cross-functional playbook that defines where to move goods, how to reallocate capacity among suppliers, and how to quantify service level impacts in near real time. Networks increasingly rely on diversified lanes; the goal is to keep material moving with minimal delay between alerts and action. In our experience coordinating carriers across multi-modal routes, pre-negotiated capacity agreements are what separate a managed reroute from a scramble.

Insurance considerations require proactive collaboration with underwriters to map supply-chain risk to policy terms. Ensure coverage addresses business interruption caused by cyber events, data integrity issues, and supplier disruptions. Recommended features include clear triggers, regional sub-limits, and the ability to claim for rerouting costs, expedited shipping, and third-party remediation. The World Bank Logistics Performance Index has consistently highlighted how supply-chain resilience gaps affect trade costs at a systemic level — a point underwriters are increasingly factoring into pricing. This approach helps transform cyber risk from a surprise cost into a managed budget line, avoiding gaps in resilience funding.

In practice, balance transparency with protection of sensitive data. Use secure email communications for customers, establish a centralised incident response contact, and publish a concise incident summary after containment. Those steps support trust while avoiding overexposure of operational details that attackers could exploit.

To close gaps, integrate three concrete actions:

  • Implement an enhanced, end-to-end visibility layer that tracks shipments across alternate routes and flags deviations within minutes.
  • Develop international supplier contingencies, including pre-approved alternate carriers and pre-negotiated capacity pools to move goods rapidly when routes are disrupted.
  • Conduct regular insurance reviews with headquarters and regional teams, incorporating WannaCry- or similar-attack learnings into coverage and response playbooks.