Roughly 98% of computers affected by WannaCry ransomware were running Windows 7, according to data released by Kaspersky Lab
Windows XP was ‘insignificant,’ researchers say — One week after it first hit, researchers are getting a better handle on how the WannaCry ransomware spread so quickly …
Context & Ripple Effects
The working assumption after WannaCry hit was that the outbreak fed on abandoned machines — hence Microsoft's emergency updates for Windows XP and Server 2003. Kaspersky Lab's telemetry cuts against that story: roughly 98% of infected computers were running Windows 7, an operating system still in mainstream support, while XP's share was 'insignificant.'
That reframes the incident from a legacy-OS cautionary tale into a patching-discipline failure on current fleets. It also lands mid-response: researchers have published a [[a:919113|decryption tool that recovers files on XP, 7, and 2003 machines that have not been rebooted]], giving victims a recovery path while the attribution picture settles.
First-order effects
- Organizations running unpatched Windows 7 — not XP holdouts — are the population actually exposed, which redirects remediation and audit effort toward supported-but-unpatched estates.
- Microsoft's out-of-band patches for end-of-life systems address a smaller slice of the risk than the emergency response implied, since the dominant victim platform was already covered by existing updates.
Second-order effects
- Microsoft faces sustained pressure to keep patching unsupported OSes beyond the one-off emergency release — a pressure it conceded weeks later when it fixed three additional flaws affecting Windows XP and Windows Server 2003 it had initially declined to patch.
- Security teams and insurers can now price Windows 7 unpatched rate as the primary WannaCry-style risk metric, shifting vendor conversations away from 'upgrade off XP' toward patch cadence on in-support fleets.
Third-order effects
- If the pattern holds, end-of-life does not end attack surface: vendors get pulled into recurring ad-hoc support for dead platforms, as Microsoft's later warning of a WannaCry-like exploit spreading via the RDS protocol against older Windows versions shows the cycle repeating two years on.
- Ransomware economics favor targeting large installed bases regardless of support status, making fleet-wide patch latency — not OS vintage — the structural control that matters.
The trend: WannaCry marks the point where ransomware's blast radius is set by unpatched mainstream platforms rather than abandoned ones, forcing vendors into open-ended maintenance of officially unsupported software.