Roughly 98% of computers affected by WannaCry ransomware were running Windows 7, according to data released by Kaspersky Lab
Windows XP was ‘insignificant,’ researchers say — One week after it first hit, researchers are getting a better handle on how the WannaCry ransomware spread so quickly …
Context & Ripple Effects
The working assumption after WannaCry hit was that Windows XP's huge installed base was the fuel; Kaspersky Lab's telemetry flips that story, showing roughly 98% of affected machines ran Windows 7 while XP was 'insignificant.' That matters because Microsoft had already broken precedent with out-of-band security updates for long-unsupported versions like XP and Server 2003, yet the actual victim pool sat on a still-supported OS.
The finding lands alongside a free decryption tool for un-rebooted XP, 7, and 2003 machines, which together reshape both who is at risk and what victims can do about it without paying.
First-order effects
- Enterprises running Windows 7 — not laggards on XP — become the urgent patching population, since the dominant victim platform was still within Microsoft's support window.
- Victims with infected machines that haven't been rebooted gain a no-cost recovery path via the decryption tool, undercutting the ransom's leverage.
Second-order effects
- Microsoft faces continued pressure to service end-of-life Windows: weeks later it patched three more flaws affecting XP and Server 2003 it had initially declined to fix (ZDNet coverage), extending an emergency posture into routine practice.
- Security teams re-rank risk from 'oldest OS' to 'most-deployed under-patched OS,' shifting audit and patch budgets toward mainstream fleets like Windows 7.
Third-order effects
- The legacy-exposure pattern recurs: by 2019 Microsoft was again warning of a WannaCry-like exploit targeting old Windows versions over the RDS protocol and shipping preemptive patches, suggesting vendors will be pulled into indefinite extended support for abandoned platforms.
- If ransomware keeps monetizing unpatched mainstream installs rather than museum-piece ones, patch-discipline requirements harden from best practice toward procurement and regulatory baseline for large networks.
The trend: Ransomware impact is driven less by the oldest operating systems than by the most widely deployed under-patched ones, forcing Microsoft into a standing cycle of emergency patches for software it has already retired.