Yes—but “$300 million loss” needs a financial qualifier. FedEx said the June 27, 2017 NotPetya attack on its TNT Express subsidiary reduced fiscal first-quarter 2018 results by an estimated $300 million, or $0.79 per diluted share. The estimate mainly covered lost TNT shipment revenue and information-technology restoration costs—not a $300 million ransom payment. FedEx later estimated the impact at approximately $400 million for the first half of fiscal 2018.
What FedEx actually disclosed
In its fiscal first-quarter 2018 Form 10-Q, filed in September 2017, FedEx reported that the NotPetya incident had an estimated $300 million negative impact on results. The company quantified the effect as $0.79 per diluted share. Its filing identified two principal drivers:
- Lower revenue because TNT Express shipments fell during the disruption.
- Incremental costs to restore TNT information-technology systems.
The filing does not describe the $300 million as a ransom payment or as one single accounting charge. It is an estimate of how the attack affected earnings during FedEx’s first fiscal quarter of 2018. FedEx’s fiscal year ends May 31, so this quarter covered June through August 2017, rather than calendar-year “first quarter” 2017. FedEx’s Q1 Form 10-Q also said the company had no cyber or other insurance covering this attack.
Why TNT Express was the center of the incident
TNT Express, acquired by FedEx in May 2016, operated a worldwide delivery network and had operations in Ukraine. The attack began on June 27, 2017, after a compromised update mechanism for the Ukrainian tax and accounting software M.E.Doc helped distribute the malware. FedEx initially referred to the malware as “Petya” and later used “NotPetya.”
#1 Best Overall
The event primarily disrupted TNT’s systems and data. FedEx’s fiscal 2017 filing said TNT facilities remained operational and most services were available, but the company experienced widespread shipment delays. Invoicing and communications were impaired, and a substantial part of operations and customer service had to be handled manually. Customer-specific systems and critical business data also required restoration. FedEx’s fiscal 2017 Form 10-K described the Ukrainian software connection and the operational effects.
That scope matters: saying “FedEx was shut down” overstates the contemporaneous disclosure. FedEx said systems and data belonging to its other companies were unaffected at the time of its initial reporting. The principal financial exposure was concentrated in TNT Express, not every FedEx business unit.
What the $300 million did—and did not—mean
It was an earnings-impact estimate
The figure combined business interruption with recovery spending. Lost shipments reduced revenue, while restoration work added costs. A company can therefore suffer a very large financial hit even when it does not pay attackers anything and does not record the entire amount as a special cash charge.
It was not a reported ransom payment
FedEx’s cited filings provide no basis for saying that it paid $300 million to criminals. NotPetya displayed a ransom demand, but the FedEx estimate was tied to reduced TNT activity and IT recovery. Treating the headline number as money transferred to attackers is incorrect.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →It was not a confirmed customer-data breach
FedEx said no known third-party data breach or data loss had occurred at the time of its disclosures. The documented harm was systems encryption, operational disruption, delayed shipments, manual work and restoration. That does not prove that no information was ever exposed; it means FedEx’s filings did not report a known third-party breach or loss.
Why the estimate rose to approximately $400 million
FedEx’s subsequent filings measured a longer period and captured effects that continued after the initial outage. In its fiscal 2018 second-quarter Form 10-Q, the company estimated that NotPetya had reduced results by approximately $400 million during the first half of fiscal 2018. The additional impact reflected continuing shipment-volume effects and system-restoration work. The February 2018 filing said substantially all TNT services had been restored during the first quarter of fiscal 2018 and that critical operational systems and business data were restored by the second quarter.
Rank #3
| Reporting point | FedEx estimate | What it covers |
|---|---|---|
| Fiscal Q1 2018 | $300 million; $0.79 per diluted share | Estimated impact on quarterly results, primarily lost TNT shipment revenue and IT-restoration costs |
| Fiscal first half 2018 | Approximately $400 million | Longer period including continuing disruption and recovery effects |
| Later fiscal-year comparison | Approximately $400 million | FedEx’s fiscal 2018 reporting continued to describe the incident at roughly this level |
These figures are successive period estimates, not contradictory claims. The first number covers one quarter; the second covers two quarters. FedEx’s fiscal 2018 Form 10-K gives the annual context.
Timeline of the attack and recovery
- June 27, 2017: NotPetya significantly affected TNT Express operations worldwide.
- June 28, 2017: FedEx publicly disclosed that the incident was affecting TNT systems.
- September 2017: FedEx estimated a $300 million impact on fiscal first-quarter results.
- Early fiscal 2018: Substantially all TNT services were reported restored.
- Second quarter of fiscal 2018: FedEx reported restoration of critical operational systems and business data.
- February 2018 filing: FedEx estimated approximately $400 million of impact for the first half of fiscal 2018.
FedEx’s contemporaneous investor announcement and earnings release provide additional corporate context: the TNT disclosure and the fiscal Q1 earnings announcement.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsWas NotPetya ransomware or a destructive wiper?
Both descriptions capture part of what happened. The malware presented a ransom demand and encrypted files, which explains the ransomware label. But its design made ordinary recovery and decryption unreliable. Many analysts therefore describe NotPetya as a ransomware-like wiper: a destructive attack using ransomware-style mechanics rather than a conventional extortion campaign in which victims can simply pay and retrieve their data.
Rank #4
CrowdStrike’s technical analysis describes several capabilities: encryption of files and the Windows Master File Table, credential theft, lateral movement using legitimate administrative tools, and propagation techniques associated with the EternalBlue vulnerability. It also documents the compromised M.E.Doc update channel and a $300-per-machine demand. CrowdStrike’s analysis explains why the malware could move rapidly through connected networks.
The distinction changes the financial interpretation. The damaging bill came from lost transactions, delayed service, manual processing, restoration labor and prolonged disruption—not from the ransom demand itself.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Who was responsible?
FedEx’s filings focused on the technical incident and its business consequences; they did not make a geopolitical attribution. A later U.S. government assessment attributed NotPetya to a Russian GRU unit. An FBI official stated that attribution in 2022. The FBI statement is a subsequent government assessment, not a conclusion presented in FedEx’s 2017 earnings disclosure.
Best Value
What the case shows about cyber risk
The TNT incident demonstrates why cyber losses often exceed a ransom demand. A logistics company depends on transaction processing, routing, communications, invoicing and customer service all operating together. When those systems fail, each day of reduced volume can compound the recovery bill.
- Supply-chain updates need scrutiny: trusted software distribution can become an entry path.
- Segmentation limits blast radius: a compromised endpoint or update should not provide unrestricted lateral access.
- Credential security matters: stolen credentials can defeat perimeter controls and enable movement through the network.
- Backups must be isolated or immutable: online backups that attackers can encrypt or delete are not dependable recovery copies.
- Continuity planning has a financial payoff: manual workflows, alternate communications and tested customer-service procedures can reduce lost volume while systems are rebuilt.
- Recovery objectives must be tested: Microsoft recommends immutable or offline backups and exercises tied to recovery-time objectives in its ransomware protection guidance.
FedEx’s later annual reports treat NotPetya as a historical risk disclosure, not an ongoing disruption. The fiscal 2025 filing does not establish that current FedEx systems remain affected.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




