September 13, 2026
How a Ransomware Attack Bankrupted Knights of Old, a 158-Year-Old UK Company, in 2023
A Company That Survived Everything Except a Leaked Password and the Ransomware Attack That Followed

By David SEHYEON Baek
9 min read
A Company That Survived Everything Except a Leaked Password and the Ransomware Attack That Followed
Knights of Old was founded in 1865, the year the American Civil War ended. The Northamptonshire haulage firm outlasted two world wars, the Great Depression, the oil shocks of the 1970s, deregulation, recessions, and the near-total transformation of British freight. By 2023, its parent company KNP Logistics Group ran a fleet of roughly 500 lorries and employed more than 700 people across multiple sites in the United Kingdom.
In June 2023, someone guessed an employee's password. By September, the company no longer existed.
That sentence should unsettle every executive reading it, because nothing about KNP's fate required exotic circumstances. There was no nation-state adversary, no zero-day exploit, no insider betrayal. There was a weak, reused password on an externally accessible system, an account without multi-factor authentication, and a criminal organization that had industrialized the process of finding exactly that combination. The story of Knights of Old is not a story about technology. It is a story about how a business can be solvent on a Monday and unrecoverable by Friday, and why boards that still file ransomware under "IT risk" are misreading the nature of the threat.
How the Attack Actually Unfolded
The intruders were affiliates of Akira, a Russian-linked ransomware operation that surfaced in early 2023 and quickly built a reputation for targeting small and mid-sized companies in the UK and the United States. According to reporting by the BBC, which interviewed KNP director Paul Abbott at length, the attackers gained their initial foothold by brute-forcing a single employee's password. With no multi-factor authentication in place on the account, a correctly guessed password was the same thing as a key to the building.
What happened next is where the real lesson lies, because Akira did not simply encrypt the first machines it touched. The operators moved laterally through the network, escalated their privileges, and mapped the environment with the patience of professionals. Groups like Akira deliberately hunt for Active Directory domain controllers, because whoever controls the directory controls the company. Before triggering any encryption, the attackers located and destroyed what mattered most for KNP's survival, including the primary operational databases, live management servers, and, critically, the backup infrastructure, both the disaster recovery nodes and the secondary repositories.
Only after the escape routes were sealed did the encryption payload fire across the estate. The ransom note that greeted staff opened with a line that has since circulated widely in security circles. "If you're reading this, it means the internal infrastructure of your company is fully or partially dead," it read, before inviting the victims to keep their tears to themselves and open a constructive dialogue.
This sequencing matters for executives to understand. The attack was designed backward from KNP's recovery plan. The criminals' first objective was not to lock the data. It was to eliminate every path by which the company could refuse to negotiate.
Three Months from Breach to Administration
The encryption stopped the physical business almost immediately. Transport management systems went dark, which meant 500 lorries had no dispatching, no routing, and no delivery confirmation. Customers with supply chains to protect did what customers always do in a haulage crisis. They moved their freight to competitors, and most of that business never comes back.
But it was the second, quieter failure that killed the company. The attack also encrypted KNP's enterprise resource planning systems and its historical financial records. Management lost visibility into its own ledgers, its receivables, its payables, and its real-time cash position. A logistics firm can improvise around downed routing software for a few days with whiteboards and phone calls. No company can improvise around the inability to prove its own financial condition.
This is the mechanism that boards consistently underestimate. KNP needed emergency liquidity to survive the recovery period, and emergency liquidity comes from lenders and investors who demand current, verifiable financial statements before extending credit. With the accounting systems destroyed and the backups gone, KNP could not demonstrate its own viability as a going concern. The attackers had demanded a sum that cybersecurity analysts estimate at around £5 million, far beyond the liquid reserves of a mid-market haulier in a notoriously thin-margin industry. The company's cyber insurance policy carried a £1 million limit, a fraction of the combined cost of the ransom demand, the operational losses, and the incident response.
Unable to pay, unable to restore, and unable to borrow, KNP watched its fixed obligations pile up against zero revenue. Payroll, fuel, vehicle leases, and facility costs do not pause for a cyber incident. By September 2023, less than three months after the intrusion, KNP Logistics Group entered administration under FRP Advisory. Roughly 700 people lost their jobs. A brand that had carried freight through three centuries was gone, with only isolated subsidiary assets salvaged through pre-pack sales.
The Numbers Say This Was Not an Outlier
It is tempting for executives to read the KNP story as an extreme case, the corporate equivalent of a lightning strike. The data says otherwise. Roughly nine in ten ransomware victims are organizations with fewer than a thousand employees, because criminal groups have learned that mid-market firms combine genuine operational complexity, lean security staffing, and real money. They are, from the attacker's perspective, the optimal ratio of effort to payout.
The economics are brutal at every stage. According to Sophos's annual State of Ransomware research, median ransom payments have climbed past the million-dollar mark, with average demands running around two million, and average recovery costs, excluding any ransom paid, running between roughly 1.5 million and 2.7 million dollars depending on the year measured. IBM's Cost of a Data Breach research puts the fully loaded cost of a ransomware incident above five million dollars once lost business and customer churn are counted. Typical downtime runs three weeks before basic operations resume, and full recovery routinely stretches past a hundred days.
Two figures deserve particular board attention. First, backup infrastructure is now targeted in the overwhelming majority of ransomware attacks, and in roughly three quarters of those cases the attackers succeed in compromising at least some of it. KNP's experience was not bad luck. It was the standard playbook working as intended. Second, paying does not buy peace. A large majority of organizations that pay a ransom are attacked again, and according to industry surveys, most who pay still see their stolen data leaked anyway, which brings regulatory exposure under regimes like GDPR on top of everything else.
Run those numbers against a typical SME balance sheet and the conclusion writes itself. Three weeks of zero revenue against continuing fixed costs, plus a seven-figure recovery bill, exceeds the annual operating profit of most mid-market companies. Ransomware does not need to bankrupt a firm directly. It merely needs to drain the cash faster than the company can rebuild, and the insolvency process handles the rest.
Why Spending on IT Did Not Save Them
Here is the uncomfortable part of the KNP story for any board that believes it has this covered. The company was not negligent in the way that word is usually meant. It reportedly spent around £100,000 a year on IT, maintained an internal technical team, and held international data security accreditations. By the standards most executives apply, KNP was doing the responsible things.
The failure was one of allocation, not effort. General IT expenditure is not the same thing as security control hygiene, and accreditation is not the same thing as protection. A company can modernize its infrastructure, migrate to the cloud, and pass its audits while a single internet-facing account sits exposed without multi-factor authentication. That one gap is worth more to an attacker than every pound spent elsewhere, because the modern credential economy is built to exploit it. Infostealer malware families such as RedLine and Raccoon harvest passwords from infected personal devices and browsers by the million, and the results are traded openly on criminal forums. Where reuse is common and MFA is absent, a purchased or brute-forced password becomes a legitimate login that trips no alarms.
The second allocation failure was architectural. KNP's network, like most mid-market networks, appears to have been essentially flat, meaning that an attacker who compromised one low-level account could traverse the environment, reach domain administration, and touch the backup systems. Segmentation is unglamorous and shows up in no marketing brochure, which is precisely why it is chronically underfunded, and precisely why it decides outcomes.
What the Insurance Policy Could Not Do
Boards often treat cyber insurance as the backstop that makes residual risk acceptable. The KNP collapse shows the limits of that assumption with unusual clarity, and it is worth walking through why a £1 million policy provided so little protection against a £5 million problem.
The first limit is arithmetic. Policy limits and sub-limits are frequently calibrated to premiums rather than to a company's actual maximum foreseeable loss, and sub-limits for extortion payments, business interruption, or data restoration often cap out well below the headline figure. The second limit is contractual. Insurers have tightened their warranty and exclusion clauses considerably, and coverage increasingly depends on provable, continuous compliance with baseline controls such as universal MFA, endpoint detection and response, and segregated backups. A firm that lets those controls lapse can find its claim voided at the exact moment it matters.
The third limit is the one that ended KNP, and no policy wording can fix it. Insurance reimburses money. It cannot reconstitute destroyed data. When the operational and financial records are gone and the backups are gone with them, cash flow stops immediately, while claims settle on a timescale of months. A payout that arrives after the administrators do is an asset of the estate, not a lifeline for the business. Insurance is a component of resilience, never a substitute for it.
Building a Company That Can Survive Its Worst Day
The single most important structural defense to emerge from cases like KNP is immutability. Because attackers now treat backup destruction as a standard pre-encryption step, any backup that can be reached, altered, or deleted using stolen administrative credentials must be assumed lost on the day of the attack. Connected offsite mirrors and cloud sync do not meet the bar, because they obey whoever holds the keys, including the intruder.
The current best-practice standard is often described as the 3–2–1–1–0 architecture, and it translates into plain business language easily. Keep three copies of critical data. Store them on two different types of media so a single technology failure cannot destroy everything. Hold one copy offsite, beyond the reach of a physical disaster. Hold one copy that is immutable or physically air-gapped, written in a form that no user, no administrator, and no API call can modify or delete during its retention period. And verify restorations continuously until the error count is zero, because a backup that has never been tested is a hope, not a plan. The immutable copy is the piece that changes the negotiation. When a clean recovery path is mathematically guaranteed to exist, the attacker's leverage collapses, and a ransom demand becomes an inconvenience rather than an existential ultimatum.
Above the technical layer sits governance, and here the framing has to change. Frameworks such as NIST's ransomware risk management profile for the Cybersecurity Framework 2.0 give boards a structured way to connect technical controls to solvency outcomes, but the essential shift is conceptual. The right question for a board is not whether the company complies with a security standard. It is how many days of total financial blackout the company can absorb before it can no longer make payroll, and whether its capital reserves, credit facilities, and insurance limits are calibrated against that number rather than against an arbitrary policy figure. Quantitative modeling of maximum foreseeable loss belongs in the same board pack as currency and interest-rate exposure.
Crisis governance deserves rehearsal too. In the event, technical responders and forensic specialists will fight the fire, but the survival of the company will be decided elsewhere, in conversations with lenders about bridge financing, with major clients about continuity, and with regulators about notification obligations. Directors who meet their bank for the first time on day three of a blackout, with no financial statements to show, are negotiating from the position KNP found itself in. Directors who have pre-arranged emergency credit terms and rehearsed a thirty-day loss of all financial systems are negotiating from somewhere far stronger.
The Directives Worth Acting on This Quarter
The practical agenda that falls out of the KNP case is short enough to fit on one page of a board pack. Mandate multi-factor authentication on every account, every remote access portal, and every SaaS environment, with no exceptions granted for seniority or convenience, since exceptions are precisely where attackers look first. Fund and deploy an immutable backup tier under the 3–2–1–1–0 model, with automated restore testing treated as a compliance obligation rather than an aspiration. Commission a bi-annual review of the cyber insurance program that reads the warranties as carefully as the limits, and confirms that the company's actual technical configuration satisfies every condition of coverage on every day of the policy period. And run a full tabletop simulation of a thirty-day financial blackout, with the finance function and the board in the room, so that emergency liquidity is arranged before it is needed rather than begged for after.
None of this is beyond the reach of a mid-market company. Every element costs less than a fraction of the recovery bill from a single successful attack, and immeasurably less than the outcome at KNP.
Knights of Old survived for 158 years because generations of its leaders managed the risks of their eras, from horse-drawn freight to motorways to globalized supply chains. The risk of this era is that a company's entire operational and financial existence now lives in systems that can be destroyed remotely, by strangers, in hours. The firms that endure the next 158 years will be the ones whose boards treat that fact not as a technology problem delegated downward, but as a solvency exposure owned at the top.