October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

FedEx Estimates NotPetya Cost $300 Million in Fiscal Q1, Later $400 Million

FedEx did not report paying a $300 million ransom. The estimate reflected lost TNT Express revenue and IT-restoration costs after the June 2017 NotPetya attack, with the first-half impact later estimated at approximately $400 million.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—but “$300 million loss” needs a financial qualifier. FedEx said the June 27, 2017 NotPetya attack on its TNT Express subsidiary reduced fiscal first-quarter 2018 results by an estimated $300 million, or $0.79 per diluted share. The estimate mainly covered lost TNT shipment revenue and information-technology restoration costs—not a $300 million ransom payment. FedEx later estimated the impact at approximately $400 million for the first half of fiscal 2018.

What FedEx actually disclosed

In its fiscal first-quarter 2018 Form 10-Q, filed in September 2017, FedEx reported that the NotPetya incident had an estimated $300 million negative impact on results. The company quantified the effect as $0.79 per diluted share. Its filing identified two principal drivers:

  • Lower revenue because TNT Express shipments fell during the disruption.
  • Incremental costs to restore TNT information-technology systems.

The filing does not describe the $300 million as a ransom payment or as one single accounting charge. It is an estimate of how the attack affected earnings during FedEx’s first fiscal quarter of 2018. FedEx’s fiscal year ends May 31, so this quarter covered June through August 2017, rather than calendar-year “first quarter” 2017. FedEx’s Q1 Form 10-Q also said the company had no cyber or other insurance covering this attack.

Why TNT Express was the center of the incident

TNT Express, acquired by FedEx in May 2016, operated a worldwide delivery network and had operations in Ukraine. The attack began on June 27, 2017, after a compromised update mechanism for the Ukrainian tax and accounting software M.E.Doc helped distribute the malware. FedEx initially referred to the malware as “Petya” and later used “NotPetya.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The event primarily disrupted TNT’s systems and data. FedEx’s fiscal 2017 filing said TNT facilities remained operational and most services were available, but the company experienced widespread shipment delays. Invoicing and communications were impaired, and a substantial part of operations and customer service had to be handled manually. Customer-specific systems and critical business data also required restoration. FedEx’s fiscal 2017 Form 10-K described the Ukrainian software connection and the operational effects.

That scope matters: saying “FedEx was shut down” overstates the contemporaneous disclosure. FedEx said systems and data belonging to its other companies were unaffected at the time of its initial reporting. The principal financial exposure was concentrated in TNT Express, not every FedEx business unit.

What the $300 million did—and did not—mean

It was an earnings-impact estimate

The figure combined business interruption with recovery spending. Lost shipments reduced revenue, while restoration work added costs. A company can therefore suffer a very large financial hit even when it does not pay attackers anything and does not record the entire amount as a special cash charge.

It was not a reported ransom payment

FedEx’s cited filings provide no basis for saying that it paid $300 million to criminals. NotPetya displayed a ransom demand, but the FedEx estimate was tied to reduced TNT activity and IT recovery. Treating the headline number as money transferred to attackers is incorrect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It was not a confirmed customer-data breach

FedEx said no known third-party data breach or data loss had occurred at the time of its disclosures. The documented harm was systems encryption, operational disruption, delayed shipments, manual work and restoration. That does not prove that no information was ever exposed; it means FedEx’s filings did not report a known third-party breach or loss.

Why the estimate rose to approximately $400 million

FedEx’s subsequent filings measured a longer period and captured effects that continued after the initial outage. In its fiscal 2018 second-quarter Form 10-Q, the company estimated that NotPetya had reduced results by approximately $400 million during the first half of fiscal 2018. The additional impact reflected continuing shipment-volume effects and system-restoration work. The February 2018 filing said substantially all TNT services had been restored during the first quarter of fiscal 2018 and that critical operational systems and business data were restored by the second quarter.

Reporting point FedEx estimate What it covers
Fiscal Q1 2018 $300 million; $0.79 per diluted share Estimated impact on quarterly results, primarily lost TNT shipment revenue and IT-restoration costs
Fiscal first half 2018 Approximately $400 million Longer period including continuing disruption and recovery effects
Later fiscal-year comparison Approximately $400 million FedEx’s fiscal 2018 reporting continued to describe the incident at roughly this level

These figures are successive period estimates, not contradictory claims. The first number covers one quarter; the second covers two quarters. FedEx’s fiscal 2018 Form 10-K gives the annual context.

Timeline of the attack and recovery

  1. June 27, 2017: NotPetya significantly affected TNT Express operations worldwide.
  2. June 28, 2017: FedEx publicly disclosed that the incident was affecting TNT systems.
  3. September 2017: FedEx estimated a $300 million impact on fiscal first-quarter results.
  4. Early fiscal 2018: Substantially all TNT services were reported restored.
  5. Second quarter of fiscal 2018: FedEx reported restoration of critical operational systems and business data.
  6. February 2018 filing: FedEx estimated approximately $400 million of impact for the first half of fiscal 2018.

FedEx’s contemporaneous investor announcement and earnings release provide additional corporate context: the TNT disclosure and the fiscal Q1 earnings announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was NotPetya ransomware or a destructive wiper?

Both descriptions capture part of what happened. The malware presented a ransom demand and encrypted files, which explains the ransomware label. But its design made ordinary recovery and decryption unreliable. Many analysts therefore describe NotPetya as a ransomware-like wiper: a destructive attack using ransomware-style mechanics rather than a conventional extortion campaign in which victims can simply pay and retrieve their data.

CrowdStrike’s technical analysis describes several capabilities: encryption of files and the Windows Master File Table, credential theft, lateral movement using legitimate administrative tools, and propagation techniques associated with the EternalBlue vulnerability. It also documents the compromised M.E.Doc update channel and a $300-per-machine demand. CrowdStrike’s analysis explains why the malware could move rapidly through connected networks.

The distinction changes the financial interpretation. The damaging bill came from lost transactions, delayed service, manual processing, restoration labor and prolonged disruption—not from the ransom demand itself.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who was responsible?

FedEx’s filings focused on the technical incident and its business consequences; they did not make a geopolitical attribution. A later U.S. government assessment attributed NotPetya to a Russian GRU unit. An FBI official stated that attribution in 2022. The FBI statement is a subsequent government assessment, not a conclusion presented in FedEx’s 2017 earnings disclosure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the case shows about cyber risk

The TNT incident demonstrates why cyber losses often exceed a ransom demand. A logistics company depends on transaction processing, routing, communications, invoicing and customer service all operating together. When those systems fail, each day of reduced volume can compound the recovery bill.

  • Supply-chain updates need scrutiny: trusted software distribution can become an entry path.
  • Segmentation limits blast radius: a compromised endpoint or update should not provide unrestricted lateral access.
  • Credential security matters: stolen credentials can defeat perimeter controls and enable movement through the network.
  • Backups must be isolated or immutable: online backups that attackers can encrypt or delete are not dependable recovery copies.
  • Continuity planning has a financial payoff: manual workflows, alternate communications and tested customer-service procedures can reduce lost volume while systems are rebuilt.
  • Recovery objectives must be tested: Microsoft recommends immutable or offline backups and exercises tied to recovery-time objectives in its ransomware protection guidance.

FedEx’s later annual reports treat NotPetya as a historical risk disclosure, not an ongoing disruption. The fiscal 2025 filing does not establish that current FedEx systems remain affected.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.