How Russia-linked Akira group's ransomware attack on Knights of Old in June 2023 led to the 158-year-old UK delivery firm's bankruptcy after it refused to pay
Ryan Gallagher / Bloomberg : X: @business X: @business : Major corporations get the attention in ransomware attacks. But hackers more often target small businesses, such as UK trucking company Knights of Old https://www.bloomberg.com/...
Context & Ripple Effects
This case extends a ransomware record in which attacks have disrupted British organizations and shipping operations, as in the earlier cross-border disruption affecting UK firms and Maersk. It matters because the reported victim is a long-established delivery business rather than a marquee corporation.
The Russia link also fits prior reporting that ransom payments were traced to businesses in Moscow's Federation Tower, underscoring how attacks on smaller operators can sit within a broader cross-border criminal ecosystem.
First-order effects
- Knights of Old's refusal to pay was followed by bankruptcy, turning a cyber incident into an immediate corporate failure for the delivery firm.
- Akira's attack demonstrates that a ransomware group can impose severe costs without collecting the demanded payment when the victim cannot restore operations fast enough.
Second-order effects
- Other delivery and logistics operators face stronger pressure to test restoration and continuity plans, since a disruption at one carrier can quickly become a customer-service and supplier risk.
- The case raises the value of resilience measures relative to a ransom decision: avoiding payment does not by itself avoid the commercial damage of prolonged outage.
Third-order effects
- If ransomware repeatedly disables firms that cannot or will not pay, cyber resilience will increasingly be treated as a core supply-chain survival issue, not solely an IT-security expense.
- It sharpens the policy trade-off reflected in the subsequent UK debate over restricting ransom payments: reducing criminal revenue may also leave less-resilient organizations exposed to operational collapse.
The trend: Ransomware is evolving from a data-security threat into a business-continuity risk for smaller, operationally critical companies embedded in supply chains.