A single compromised password was all it took for a ransomware gang to dismantle KNP, a 158-year-old British transport company, leaving 700 employees without jobs.
The attack is part of a surge in cybercrime targeting UK businesses, with major firms like M&S, Co-op, and Harrods also falling victim in recent months. The chief executive of Co-op confirmed last week that all 6.5 million of its members had their data stolen in a separate breach.
KNP, which operated 500 lorries under the brand Knights of Old, had complied with industry IT standards and held cyber insurance. Yet hackers from the group Akira infiltrated its systems by guessing an employee’s password, encrypting critical data and locking internal operations.
The ransom note demanded payment to restore access but did not specify an amount—specialists estimated it could have been as high as £5 million. Unable to pay, KNP lost all its data and collapsed.
Paul Abbott, a director at KNP, revealed he never told the employee their weak password likely triggered the company’s downfall. “Would you want to know if it was you?” he asked.
The UK faces an escalating ransomware crisis, with the National Cyber Security Centre (NCSC) handling major attacks daily. Richard Horne, NCSC’s CEO, warns that businesses must strengthen their defenses. Hackers exploit vulnerabilities with alarming ease, often targeting companies during weak moments. While the agency works to intercept attacks before ransomware deploys, resources are stretched.
Exact figures are scarce since companies aren’t required to report attacks, but government estimates suggest 19,000 ransomware incidents struck UK businesses last year. Industry research indicates the average ransom demand is £4 million, with a third of victims paying.
The National Crime Agency (NCA) reports that hacking incidents have nearly doubled in two years, reaching 35-40 per week. Suzanne Grimmer, who leads an NCA cyber unit, warns 2024 could be the worst year on record. Criminals are using low-tech tactics, such as phishing IT help desks, to breach systems.
James Babbage, NCA’s Director General for Threats, notes a new generation of hackers, many groomed through gaming, are exploiting social engineering to bypass security. Once inside, they deploy ransomware purchased on the dark web. “It’s a national security threat,” Babbage said.
Parliament’s Joint Committee on National Security Strategy has warned of a potential “catastrophic ransomware attack at any moment.” The government is considering banning public bodies from paying ransoms and may require private firms to report attacks and seek approval before paying.
Paul Abbott, now an advocate for cybersecurity reform, argues businesses should undergo mandatory “cyber MOTs” to prove IT resilience. Meanwhile, cyber specialist Paul Cashmore, who worked with KNP’s insurers, says many firms quietly pay ransoms to avoid collapse—fueling the criminal cycle.
“This is organised crime,” Cashmore said. “There’s very little progress in catching the perpetrators, but the damage is devastating.” As ransomware evolves, the message is clear: businesses must prioritize cybersecurity—or risk becoming the next KNP.
Source:BBC

