Back to blog
The Largest Cyberattacks in History

Cybersecurity · 2 October 2025

The Largest Cyberattacks in History

Adrian CosmaAuthorAdrian CosmaUNICORE Author · Digital transformation & technology

The digital landscape has shifted from a playground for amateur hackers into a geopolitical battlefield. The largest cyberattacks are evaluated by three criteria: the scale of compromised data, quantifiable economic cost, and strategic impact on critical infrastructure.

Threats have evolved from simple malware in the 1980s, such as the Morris Worm (1988), which caused millions in damages, to sophisticated nation-state espionage. The global average cost of a data breach rose to $4.88 million in 2024; for U.S. organizations, the average jumps to $10.22 million.

Acts of sabotage with the highest economic cost are not defined by victim count, but by the damage caused when operations halt.

1. NotPetya (2017): the $10 billion Maskirovka attack. It is considered the costliest global cyberattack, with ~$10 billion in damages. Attributed to Russia’s GRU, it posed as ransomware ($300 ransom) while aiming to destabilize Ukraine’s economy. It spread via compromised MeDoc software and EternalBlue (from the NSA arsenal), crippling firms like Merck with over $1.4 billion in losses.

2. WannaCry (2017): the global ransomware pandemic. The first major incident to weaponize EternalBlue at scale. It hit hundreds of thousands of computers in 150+ countries, with losses estimated at $4–8 billion. Healthcare was hit hard — the UK NHS cancelled urgent appointments. Attributed to North Korea’s Lazarus Group, with a financial motive for the regime.

Strategic sabotage and the supply-chain weapon: the most impactful attacks hit critical infrastructure or abuse third-party vendors to infect many networks at once.

3. Stuxnet (2010): the birth of physical sabotage. The first widely recognized cyberweapon built for real-world destruction. It targeted SCADA and Siemens PLCs, exploiting four zero-days, and hit configurations such as centrifuges in Iran’s nuclear program while feeding operators fake “normal” readings.

4. SolarWinds Orion (2020): an unprecedented supply-chain compromise. Attributed to Russia’s SVR, it injected SUNBURST into legitimate Orion updates. Nearly 18,000 customers installed the tainted update — access to governments, critical infrastructure, and private firms. Later attacks (Kaseya VSA 2021, MOVEit 2023 / CL0P–LEMURLOOT) confirm third-party vendors remain the weak link.

The future of threats: GenAI and deepfakes accelerate phishing and vishing — about 47% of organizations see adversarial GenAI as an urgent concern. Regulation responds: U.S. EO 14028 accelerated Zero Trust; in Europe, NIS2 (2024) requires major incidents to be reported within 24 hours, under penalty. Risk control starts with cybersecurity designed into the architecture — not bolted on at the end.

The lesson is clear: defense can no longer be static. Priority must shift from mere prevention to resilience, continuous verification of every access point, and rapid management of correlated risks — including on cloud infrastructure. At UNICORE, cybersecurity is part of the architecture — not an afterthought. Contact us for a risk review of your systems.

Frequently asked questions

What is the costliest cyberattack in history?+

NotPetya (2017) is widely considered one of the costliest global attacks, with damages estimated around $10 billion, hitting firms such as Merck and international logistics chains.

What was WannaCry?+

WannaCry (2017) was a massive ransomware campaign that exploited the EternalBlue vulnerability, affecting hundreds of thousands of systems in 150+ countries, including healthcare (NHS).

Why do supply-chain cyberattacks matter?+

Attacks like SolarWinds compromise a software vendor and spread to thousands of customers at once. The third-party link remains one of the most dangerous attack surfaces for organizations.

What does NIS2 require after a major incident?+

In Europe, NIS2 requires major incidents to be reported within short deadlines (including early notification within 24 hours), under penalty. Organizations need detection, response, and reporting processes ready in advance.

How does GenAI change the threat landscape?+

GenAI and deepfakes accelerate phishing and vishing, making attacks more convincing and faster. Defense must shift from static prevention to resilience, Zero Trust, and continuous verification.

Digital transformation never stops

Have a digital challenge? Let's turn it into a real advantage — clear consulting, an actionable plan, and a team ready to deliver.

Contact us