AP

A massive cyberattack appears to have hit Europe, touching a number of countries, companies and public domains.

  • WPP, one of the world's largest advertising agencies confirmed on Twitter that its IT system has been affected from a possible cyberattack. Employees at Ogilvy and other WPP agencies were sent home.
  • AP reports that Ukraine's prime minister Volodymyr Groysman said the cyberattack is 'unprecedented' but that 'vital systems' haven't been affected, but Ukrainian banks and an electricity firm have been attacked. A Ukrainian official wrote on his official Facebook page that a Ukrainan airport's IT systems had also been compromised.
  • Russia's state-controlled oil company (and the world's largest publicly listed oil company by production), PAO Rosneft, said it was under a "massive hacker attack" but said its oil production hadn't been affected, per WSJ,
  • The WSJ also reports that an attack brought down computer systems across Denmark's shipping giant Maersk, which runs the world's largest container operator.
  • A large percentage of infected machines appear to be Windows 7 and 10 with a majority running 64-bit OS, according to David Kennerley at Webroot.

Daniel Smith, security researcher at Radware, tells Axios the attack is a global ransomware campaign, meaning the attackers are asking victims to forward money to be relieved. "This outbreak is leveraging the ransomware variant PETRWRAP/PETYA and spreading via the EternalBlue exploit, similar to how WannaCry spread," said Smith. "The ransom requested is $300 BTC upon infection. There is only one BTC address associated with this campaign."

What is "Petya"? A strain of attack first reported in March that reboots victims' computers, encrypts their hard drive's master file (instead of individual files) and renders their entire master hard drive inoperable. The Petya component includes many features that enable to malware to remain viable on infected systems, and the EternalBlue component enables it to proliferate through organizations that don't have the correct patches or antivirus software.

"This is a great example of two malware components coming together to generate more pernicious and resilient malware," said Phil Richards, chief information officer at Ivanti.

Timing: The attack comes just over a month after the massive WannaCry ransomware attack, conducted by a North Korean hacking group, that spread to 300,000 breaches across 150 countries. Last October, a DDOS (distributed denial of service) cyberattack shut down a huge portion of the internet. Many organizations spent countless hours trying to patch the vulnerability to the WannaCry attack and were not necessarily paying attention to other vulnerabilities in their devices, Kennerley said.

Who is responsible? Monzy Merza, head of cyber research for Splunk — a San Francisco software company that detects cyber-attacks and insider threats — speculates it might be Ukraine's neighboring countries or hackers nearby since geospatial proximity makes attacking easier. He also notes that the attackers were likely using Ukraine as a "testing ground" for future attacks.

Why it matters: Merza says people are becoming increasingly aware of these types of cyber attacks because they are starting to directly affect people outside of the cyber realm.

This story is being updated.

Go deeper

Bryan Walsh, author of Future
21 mins ago - Technology

The age of engineering life begins

Illustration: Sarah Grillo/Axios

Synthetic biology startups raised some $3 billion through the first half of 2020, up from $1.9 billion for all of 2019, as the field brings the science of engineering to the art of life.

The big picture: Synthetic biologists are gradually learning how to program the code of life the way that computer experts have learned to program machines. If they can succeed — and if the public accepts their work — synthetic biology stands to fundamentally transform how we live.

Biden will allow lobbyists to join transition team

Biden speaks at a campaign stop at Pittsburgh Union Station Wednesday. Photo: Alex Wong/Getty Images

Joe Biden's presidential transition office will allow lobbyists to help shape his potential administration, but will require them to receive a waiver to participate if they engaged in lobbying activity in the last twelve months.

Why it matters: Presidential transition teams are instrumental in establishing a new administration, and the rules that govern them are often a template for the ethics guidelines that the new administration imposes after the inauguration.

Updated 1 hour ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 5 p.m. ET: 33,799,264 — Total deaths: 1,010,381 — Total recoveries: 23,456,820Map.
  2. U.S.: Total confirmed cases as of 5 p.m. ET: 7,219,635 — Total deaths: 206,665 — Total recoveries: 2,813,305 — Total tests: 103,155,189Map.
  3. Education: School-aged children now make up 10% of all U.S COVID-19 cases.
  4. Health: The coronavirus' alarming impact on the body.
  5. Business: Real-time data show economy's rebound slowing but still going.
  6. Sports: Steelers-Titans NFL game delayed after coronavirus outbreak.