KNP Logistics: When a weak password destroys 150 years of history

Cybersecurity and operational risk management are inseparable. The KNP Logistics case demonstrates this brutally: sometimes only one weak password is enough to smoke 150 years of company history.
A historic company, a devastating attack
KNP Logistics, also known as Knights of Old, was one of the oldest transport companies in the UK. Founded over 150 years ago, he had built a solid reputation in the British logistics industry. In June 2024, everything collapsed in a few days.
A ransomware attack by the criminal group “Akira” completely paralyzed the company’s operating systems. The fleet stopped. Operations got stuck. The essential data have been encrypted and made inaccessible.
What really happened: cybersecurity and operating risk management in comparison
The attack didn’t start with a sophisticated technical flaw. Not from an obsolete system impossible to update. It started from an extremely weak password used by an employee, without any authentication to multiple factors (MFA) active.
The group “Akira” has exploited this vulnerability to encrypt all the essential data of the company — financial systems, customer databases, operational infrastructure. Backups were destroyed. The 500 truck fleet stopped completely. The estimated ransom demand was about £5 million — a figure that KNP could not afford.
As reported byThe Record, KNP declared the insolvency citing the ransomware attack as the main cause, leaving 730 employees without work.
The outcome
A year after the attack, in 2025, KNP Logistics ceased its business. Over 150 years of corporate history erased by an accident that could have been prevented by basic safety measures.
The cost of a robust password policy?
The cost of not having it? A whole company.
Management of operational risk and cybersecurity: the lesson for each company
The KNP case is not just about the transport sector. It concerns every organization that depends on digital systems — and today, in 2025, this means practically all companies.
How we analyzed in casePG& E, risk signals existed but were ignored. Even there, the cost of inaction has far exceeded that of prevention. </a>
Cybersecurity is not a technical issue for the IT department. It is a matter of corporate culture. Each employee accessing a system is a potential entry point for an attack.
A weak password. One click on a suspicious link. An open attachment without checking the sender. These are the real operational risks of the digital world.
Conclusion
KNP Logistics had passed two world wars, economic crisis, technological revolutions. He didn’t pass a weak password.
Computer risk management doesn’t start with firewalls. Start with the awareness of every person who works in the company.
