07/25/2025 | Press release | Distributed by Public on 07/25/2025 11:36
A threat actor once again proved the importance of enforcing strict password management practices by torpedoing a 158-year-old UK transportation company by hacking a password and then effectively shutting it down with ransomware.
According to published reports, the threat group Akira gained access to KNP's system in June when it was able to determine a single employee's password. Once access was gained, Akira injected ransomware, which shut down the network and encrypted access to its files and backups. Akira then demanded an estimated £5 millionransom, but this amount was beyond KNP's ability to pay, so it opted to shut down instead.
About 700 people are now out of work.
This attack reinforces the need for strong passwords and for organizations to frequently check to ensure their staffers are abiding by the rules.
Trustwave's Jason Whyte, General Manager for the Pacific, recently notedthat passwords are inherently vulnerable, but strengthening them can contribute to a robust security posture. At an organizational level, it's essential that strong password policies be provided to employees with clear instructions on password length, complexity, and expiration guidelines.
Trustwave researchers warn that an eight-character password can be cracked in under a day, and sometimes much faster, using brute-force techniques. Simply increasing the length to 10 characters can extend that brute force timeline to potentially hundreds of years. Adding length and complexity, such as uppercase and lowercase letters, numbers, and symbols, goes even further.
Of course, remembering something like "dlkjskljfo8w!$^@@" isn't easy. That's why passphrases are a smart choice. Think of a line from your favorite song, a historical quote, or even something you say to your kids, like: "Broccoliisgoodforyou".
Whyte suggests using technology to make this task easier. Complex passwords can be difficult to remember, especially when they need to be changed frequently, every 60-90 days is recommended. The solution is a password manager, which generates unique passwords for every account and securely encrypts them. This minimizes the risk of using weak or repeated passwords and ensures that employees only need to remember one strong master password.
Not sure if your password or passphrase is strong enough? Free tools like Have I Been Pwnedand other password strength checkers can estimate how long it would take to crack a password. For example, a complex passphrase like the one above could take centuries to break.
Trustwave employs a multi-faceted approach to identify and address weak passwords:
By leveraging Trustwave's cybersecurity services, organizations can significantly reduce the risk of breaches caused by weak passwords. The benefits include:
Trustwave's comprehensive cybersecurity services play a crucial role in identifying and mitigating the risks associated with weak passwords. By implementing strong password policies, conducting regular audits, and providing continuous support, Trustwave helps organizations stay one step ahead of cyber threats.
Sign up to receive the latest security news and trends straight to your inbox from Trustwave.
Stay Informed:
Sign up to receive the latest security news and trends straight to your inbox from Trustwave.
Trustwave is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.