Half a million expired windows servers sit one click from ransom
511,071 Windows web servers have reached their end-of-life and are now live on the internet without a single security patch waiting for them. A UK research group mapped every one, then watched bots start knocking.
The map that no one asked for
ShadowServer’s scanners spent months fingerprinting IIS boxes still running Server 2008, 2012, even 2003. The result is a heatmap of negligence: 227,000 machines no longer qualify for Microsoft’s Extended Security Updates, meaning zero official fixes will ever arrive. The rest cling to paid ESU keys that expire in months, not years.
United States hosts 95,000 of the walking dead—one in five worldwide. France, Germany, Italy and Spain together stack another 46,000. The numbers look abstract until you remember these boxes run payroll portals, hospital scheduling systems, municipal bill pay. Each one is a foothold.

Why iis matters more than your laptop
Internet Information Services isn’t a quaint relic; it is the front door many organisations forgot to bar. A single unpatched instance can proxy an attacker from the public web to the internal domain in three HTTP requests. Once inside, lateral movement scripts sail through Group Policy holes that were patched in 2019 but never applied here.
Fileless payloads love this scenario: no disk artefacts, only living-off-the-land binaries. A PowerShell cradle downloads Cobalt Strike straight to memory, the server continues serving cat photos, finance never gets an alert. Next stop: ransomware deployment at 3 a.m. when the American SOC is off-duty.

The extortion multiplier
Criminals aren’t targeting these servers for their data—they want the network behind them. A 2008 R2 box running a small county’s property-tax site can become the staging ground for a multi-school district siege. One compromised ESU-less server in Ohio last month led to 42 satellite clinics encrypted in 18 minutes. The ransom note arrived from that same forgotten IIS landing.
ShadowServer will keep refreshing the list, but no one is forced to look. Microsoft can’t push patches to licences it no longer supports. IT managers either pay for custom contracts, forklift the applications, or play Russian roulette with public exploits already circulating on Telegram.
The clock is not ticking—it stopped the day the last patch window closed. Every additional day online is another raffle ticket in an attacker’s lottery. And the draw happens nightly.
