The real outbreak was initially delivered through the update service of the Ukrainian M.E.Doc finance application. It then used multiple methods to spread through affected networks. Although its screen claimed to demand ransom, it did not provide a workable technical path to restore each victim's data.