12:45 23 July, 2025A weak password used by an employee led to the downfall of KNP Logistics Group, a 158-year-old transportation company in the UK. The hacker group Akira exploited this vulnerability to encrypt the company’s data, resulting in a complete business shutdown and the dismissal of about 700 employees, IT-Daily reports.
Incident Details
In 2023, hackers from the Akira group gained access to KNP Logistics’ internal systems by cracking a weak password, reportedly belonging to a high-level executive. This allowed them to deploy ransomware that encrypted critical company data, including logistics schedules, accounting records, and the client database. A ransom note left by the hackers read: “If you are reading this, your company’s infrastructure has been partially or completely destroyed… Let’s set aside the tears and grievances and begin a constructive dialogue.” Experts estimate the ransom demand at around £5 million (approximately 526.8 million rubles), which KNP was unable to pay.
KNP CEO Paul Abbott confirmed that the attack stemmed from a weak password, but the employee whose credentials were compromised had not been informed. Despite having £1 million in cyber insurance and meeting industry IT security standards, the company was unable to recover the data. The lack of reliable backups and insufficient funds to pay the ransom led to total data loss and operational paralysis. As a result, KNP—which operated a fleet of 500 trucks under the Knights of Old brand—was forced to declare bankruptcy.
Consequences and Context
The collapse of KNP Logistics is a stark example of how even large, established companies remain vulnerable to cyber threats. Founded in 1865, the company had survived two world wars and numerous economic crises, but could not recover from a cyberattack triggered by a weak password. Around 700 employees lost their jobs, while clients—including major retailers—had to seek alternative service providers. Some of KNP’s assets were sold to another retailer, saving around 170 jobs, but this was not enough to rescue the company.
According to the UK’s National Crime Agency (NCA), there were around 19,000 ransomware attacks in 2024—approximately 35 to 40 incidents per week—double the number recorded in 2023. Victims include major companies like Marks & Spencer, Co-op, and Harrods. In Co-op’s case, hackers stole data from 6.5 million customers. The UK’s National Cyber Security Centre (NCSC) notes that attacks often begin with simple vulnerabilities like weak passwords or the absence of multi-factor authentication (MFA).
Causes and Lessons
The KNP incident underscores the critical importance of basic cybersecurity measures. The key factors that led to the disaster were:
Experts such as Richard Horne, CEO of the NCSC, emphasize that hackers rarely invent new methods—they exploit known vulnerabilities. Suzanne Grimmer from the NCA noted that ransomware attacks have doubled over the past two years, and 2025 may break all records for cyber incidents. She also pointed to the rise of accessible hacking tools like plug-and-play malware, which allow even unskilled attackers to launch sophisticated assaults.
Response and Measures
Following the attack, KNP sought help from cybersecurity experts, but the data could not be recovered. The NCSC, part of GCHQ, handles major cyber incidents daily and urges companies to implement multi-layered protection, including:
KNP Director Paul Abbott now gives lectures warning other companies about the risks of cyberattacks. He advocates for a “cyber MOT” system—mandatory cybersecurity certification for businesses. The UK government is considering legislative measures, including a ban on ransom payments by public institutions and mandatory reporting of cyber incidents by private companies.
Wider Context
The collapse of KNP is part of a broader wave of cyberattacks in the UK. In addition to KNP, major retailers like Marks & Spencer (which lost £40 million per week due to a DragonForce attack), Co-op, and Harrods have been targeted by ransomware. These incidents demonstrate that cybercriminals exploit not just technical vulnerabilities but also social engineering tactics like “bluffing” or “pretexting,” where attackers pose as trusted contacts to extract access credentials. According to the NCSC, over 80% of data breaches are linked to compromised credentials, and the average cost of a cyberattack in the UK during 2023–2024 rose to £3.58 million.
The Akira group, which emerged in March 2023, has earned about $42 million from attacks on small and medium-sized enterprises in the UK and the US. Their success stems from targeting vulnerable companies and using simple methods such as password guessing and phishing.
Conclusion
The collapse of KNP Logistics Group is a tragic example of how a single vulnerability—a weak password—can destroy a 158-year-old company. The incident highlights that in the digital age, even large and established businesses are not immune to cyber threats. To prevent similar disasters, companies must implement multi-factor authentication, conduct regular employee training, and ensure robust data backups. With the number of attacks expected to rise in 2025—potentially the worst year on record for cybercrime, according to the NCA—the lessons from KNP serve as a warning to all organizations: cybersecurity is not optional—it’s essential.