NotPetya was the 2017 malware attack designed to look like ransomware but primarily destroy data.
NotPetya displayed a ransom demand and appeared related to the Petya ransomware family, but researchers found that victims generally could not recover their data by paying. Its behavior made it effectively a destructive wiper rather than ordinary financially motivated ransomware.
The campaign began through compromised update software used by Ukrainian organizations and then spread through corporate networks. It affected shipping, pharmaceutical, manufacturing, and other international companies, producing billions of dollars in damage.
NotPetya is frequently confused with WannaCry, another fast-spreading 2017 outbreak. WannaCry encrypted files and included a payment mechanism, while NotPetya’s design and recovery limitations led many analysts to classify it as a wiper.