The single point of failure was the posteo.de[1] account. Surely doing business over this kind of channel was doomed to fail. Infosec Twitter is alight with conspiracy theories that receiving money was the least of the attacker's concerns. I too believe that they just wanted to cause damage and piss people off in Ukraine, using the ransom functionality of the software as a front. BTW: Instead of using email, what should they be using to offer support and arrange payment? Some sort of encrypted instant messenger system?
[1]: https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa...