Ukraine files much of its tax paperwork through M.E.Doc, an accounting package from the Linkos Group, a small family software firm in Kyiv. Weeks before 27 June 2017, someone slipped a backdoor into the servers that push its updates, and waited. On the morning of the 27th — the eve of Constitution Day, a national holiday — the poisoned update detonated. Banks, ministries, the Kyiv metro and Boryspil airport failed within hours; at Chernobyl, technicians fell back on hand-held counters when the automatic radiation monitors went dark. Six weeks after WannaCry, the new worm carried the same leaked EternalBlue exploit, and a credential thief besides, so a single infected office in Kyiv was enough to unlock a multinational's entire private network.

It introduced itself as ransomware. A red screen demanded $300 in bitcoin and offered a single contact address at the German mail provider Posteo — which suspended the account within hours, severing the only channel by which a victim could prove payment. Within a day, researchers at Kaspersky Lab and Comae Technologies had reached the harder conclusion: the "personal installation key" each victim was told to quote was random noise, generated for appearance, so no decryption key could ever exist. The ransom note was a costume over a wiper. Ukraine's government blamed Russia immediately — at that point a claim, not a finding — while responders settled on a name built from a negative: whatever this was, it was not Petya, the older ransomware it imitated.

At A.P. Møller-Maersk, screens began going black across the Copenhagen headquarters around lunchtime, and employees ran the corridors telling colleagues to unplug machines before it spread. A company moving roughly one seaborne container in five worldwide took bookings over WhatsApp and worked port gates by hand. As WIRED later reconstructed, the attack destroyed every one of Maersk's domain controllers except a single server in Ghana, offline that day by the luck of a local power cut; its disk was flown by relay to England to seed the rebuild. The recovery consumed ten days and replaced 4,000 servers, 45,000 PCs and 2,500 applications — work the chairman, Jim Hagemann Snabe, said would normally take six months. At Davos the following January he put the cost at $250–300 million.

The worm reached some sixty-five countries, and the bills read like an index of globalisation. The widely cited tally for Merck, whose vaccine production was interrupted, reached $870 million; FedEx put the damage to its TNT Express unit at about $400 million; Saint-Gobain, Mondelez and Reckitt Benckiser counted hundreds of millions more; a later US government assessment put the global total around $10 billion. On 15 February 2018 the White House called NotPetya "the most destructive and costly cyber-attack in history" and attributed it to the Russian military; Britain and a chorus of allies said the same. In October 2020 the United States indicted six named officers of the GRU's Unit 74455 over it. None has been arrested; all remain wanted.

Also that month · Published 12 June

The malware that spoke to the switches

The Kyiv blackout of 17 December 2016 had cut power to about a fifth of the capital for roughly an hour, and had gone unexplained ever since — assumed to be the same hands behind the 2015 attack on Ukraine's distribution grid, but not understood. On 12 June 2017 the Slovak firm ESET and the American industrial-control specialists Dragos published coordinated analyses of the reason. The malware — Industroyer to ESET, CrashOverride to Dragos — was the first ever found that speaks the grid's own languages: four industrial protocols used in transmission substations across Europe, the Middle East and Asia, addressed directly, so that opening circuit breakers required no stolen credentials and no operator's hands. Only Stuxnet had crossed from code into physical consequence before it. Dragos attributed the work to a group it called Electrum and assessed — its judgement, not an established fact — links to Sandworm and probable state support. The outage had been brief, and both firms read that brevity as the most unsettling part: an hour looked less like an attack than a test.

Also that month · 1.1 terabytes

A country's voters in an open bucket

On 12 June, the day the grid papers were published, Chris Vickery of the security firm UpGuard found an Amazon S3 storage bucket that asked him for no password. It held 1.1 terabytes compiled for the Republican National Committee by the analytics contractor Deep Root, alongside data from TargetPoint Consulting and Data Trust: names, addresses, dates of birth, telephone numbers and party registration covering about 198 million American voters — nearly the whole electorate — joined to modelled scores predicting each person's likely position on dozens of political issues. No one had hacked anything; a permissions setting had done all the work. Deep Root Analytics restricted access within two days of being notified, said the files had been exposed since a settings change on 1 June, and said it had found no evidence of access by anyone else. UpGuard published on 19 June. It was, at the time, the largest known exposure of voter data anywhere — a record set without a single exploit.

India desk · June 2017

Shrapnel at Nhava Sheva

The shot was aimed at a tax package in Kyiv; a piece of the shrapnel landed at Nhava Sheva. Gateway Terminals India — the berth at Jawaharlal Nehru Port run by APM Terminals, Maersk's ports arm — lost its systems on the night of 27 June along with the rest of the parent company, and India's busiest container port found one of its terminals unable to say what was in which box. A terminal that handled about 4,500 containers a day went manual. Gates slowed to paperwork, trucks stacked up on the approach roads, and the port authority began diverting ships and boxes to its other terminals and to APM's own Pipavav port in Gujarat while yards were found for the containers nobody could release.

The government did not pretend otherwise. The shipping ministry confirmed operations were disrupted and sent the national cyber security coordinator, Gulshan Rai, to Mumbai; CERT-In issued advisories; officials stressed that the port's other terminals were running. The clearing took days of manual work, and the congestion outlasted the malware. What deserved more notice than it got was the category of the event. India had seen espionage, fraud and defacement, but this was different: military code built by one state to hurt another had knocked out a piece of Indian critical infrastructure without anyone intending it — the country's first real taste of collateral damage in someone else's cyberwar. The lesson, that India's ports and factories stood inside the blast radius of quarrels it had no part in, would be relearned more than once in the years this archive covers.

AI Tech desk · June 2017

The paper that retired recurrence

On 12 June 2017, eight researchers at Google posted a machine-translation paper to the arXiv preprint server under a title that read like a shrug: Attention Is All You Need. The architecture it proposed, the Transformer, discarded the recurrent networks that then dominated language processing and handled whole sequences through attention alone; the headline model reached state-of-the-art translation quality after about three and a half days of training on eight GPUs, a fraction of the usual cost. Few outside the field noticed that week. Nine years on there is no argument: this preprint is the most consequential AI event of 2017, the architecture beneath nearly every system the later AI desks in this archive describe — the T in the acronyms that followed. The same fortnight had a louder paper: on 5 June DeepMind posted a simple relational-reasoning module that answered questions about scenes of objects better than the humans it was measured against, and that, at the time, was the story.

Digital Guard desk · June 2017

An anti-virus becomes a suspect

The industry's own June story was geopolitical. On 28 June 2017 — the day after this edition's cover detonated — the Senate Armed Services Committee advanced a draft of America's annual defence-policy bill that would bar the Pentagon from using Kaspersky Lab software, and NBC News reported that FBI agents had visited at least a dozen of the firm's US-based employees at their homes. Kaspersky answered, as it would go on answering, that it has no ties to any government and has never helped one with cyber-espionage; its founder offered the source code for American inspection. The argument ran seven more years, through a ban across federal civilian agencies that September to the 2024 order that ended the software's sale in the United States altogether. The week's product news came from Microsoft, which said on 27 June that the Fall Creators Update would rebuild its EMET anti-exploit toolkit into Windows Defender Exploit Guard and extend Defender ATP across the stack — while NotPetya's responders circulated a humbler defence, a single read-only file that vaccinated a machine against infection.

⏳ Time capsule — June 2017

  • On 1 June Donald Trump announced from the White House Rose Garden that the United States would withdraw from the Paris climate agreement; at the time, the only other holdouts in the world were Syria and Nicaragua.
  • Amazon announced on 16 June that it would buy Whole Foods Market for $13.7 billion, its largest acquisition to that point; supermarket shares fell within minutes of the press release.
  • Pakistan beat India by 180 runs in the ICC Champions Trophy final at The Oval on 18 June — their first title in the tournament, built on an opening century by Fakhar Zaman, who had been caught early off a no-ball.
  • Wonder Woman, released in cinemas on 2 June, went on to take more than $800 million worldwide — at the time the highest-grossing live-action film directed by a woman.
Where it stands today — 2026

The template

Nine years on, June 2017 is the reference case for three arguments at once. On attribution, the February 2018 statements and the October 2020 indictment made the public naming of military hackers routine, though the six officers of Unit 74455 remain at large. On insurance, the act-of-war question took seven years to exhaust: Mondelez and Zurich settled quietly in late 2022, midway through trial, and Merck's $1.4 billion claim settled on 3 January 2024, days before New Jersey's highest court was due to hear argument — no precedent set, and the market rewrote its war exclusions anyway. And on delivery, the poisoned vendor update became the modern playbook; when SolarWinds' build system was found compromised in 2020, every post-mortem cited this month.

The wiper thread runs the length of this archive. The rehearsal ESET and Dragos described had its performance in February 2022, when the same military service put wipers into Ukrainian networks in the hours before the tanks moved, and an updated Industroyer walked back into a transmission substation that April and was caught. Maersk rebuilt, and its chairman's Davos accounting of the damage became the industry's favourite case study in resilience. India, which learned at Nhava Sheva that its infrastructure stood inside other people's blast radius, eventually wrote incident-reporting rules measured in hours. Between this edition and the three days of WannaCry in May, the summer of 2017 handed the industry its permanent vocabulary — worm, wiper, collateral.