Menu
Browse

Feofania

Primary URL Location Industry
Undetermined
Country Ukraine
Technology Icon
Technology
Profile

Feofania, also known by its alias, is an organisation headquartered in Ukraine. It came to public attention because of its connection to a significant cyber incident that occurred in 2017. The organisation’s name appears in reports linking it to the supply chain of a widely used tax accounting software package in the region.

On 27 June 2017 a ransomware attack was launched that initially spread through a compromised update mechanism of that tax accounting software. The malware deployed was a modified variant of Petya, designed to irreversibly encrypt files and disrupt systems. The attack primarily targeted Ukrainian critical infrastructure, including banks, government ministries, energy firms and transportation networks. Radiation monitoring systems at a nuclear facility were taken offline as part of the disruption. The incident also affected multinational corporations through their interconnected networks in Ukraine. Security analysts assessed the malware’s primary intent as destructive rather than financially motivated. Evidence pointed to state‑sponsored involvement, with attribution investigations linking the activity to advanced persistent threat actors previously observed in operations against Ukrainian infrastructure. The attack caused billions of dollars in damages across numerous international organisations.

These facts establish Feofania as an entity associated with a notable cyber event that had both national and global repercussions. The organisation’s headquarters in Ukraine situates it within the geopolitical context of the incident. No further details about its size, product portfolio, ownership structure or subsidiaries are provided in the available source material.

Incidents
Linked incidents available to members
1 incident