Skip to content
The Cyber Security Place

Two years without an update, one week inside, and nobody's idea of a target

Event dated 26 June 2026 · Published 2 September 2026 · 3 sources

Latvia's state-owned forestry company disclosed a ransomware attack in late June 2026 in which attackers had been inside the network for more than a week, having entered through software that had not been updated for two years. Both figures matter and the second explains the first. A system two years behind is almost never a system somebody decided not to patch. It is a system that fell off the list — no owner, no entry in the inventory, and therefore no queue position, which is also why nothing was watching it closely enough to notice a week of activity.

Forestry is a useful reminder of where the target list actually ends, which is nowhere. A state-owned timber business has no customer payment data worth reselling, no clinical records, and no obvious value to a foreign intelligence service. It was reached because it was reachable.

That is the operating model of most extortion: scanning finds what is exposed and unpatched, and the business decision about whether the victim is interesting happens afterwards, if at all. The organisations that believe themselves too dull to attack are describing a selection process that stopped existing years ago.

Two years is a specific kind of failure

A month behind is a busy team. Six months behind is a change freeze or a dependency that broke. Two years behind is a system nobody is responsible for — usually because the person who installed it left, the supplier relationship lapsed, or it was commissioned by a department that never told anybody.

Which is why exhortations to patch faster do not reach it. The queue is not the problem; the system was never in the queue. Improving how quickly items are processed does nothing for items that were never added.

A week inside says the same thing twice

Dwell time is usually read as a detection failure, and it is. But a week on a system that nobody owns is not surprising: monitoring follows the inventory too. What is not on the list is not patched, not monitored, and not investigated, and the three gaps have one cause.

That makes the inventory a security control rather than an administrative artefact, which is a hard argument to fund because it produces no alerts and blocks nothing.

The reconciliation that finds these

Compare what the scanner sees against something the scanner cannot influence: purchasing records, network address leases, cloud billing, domain registrations. The gap between those lists and the asset inventory is where two-year-old software lives.

It is dull work with no dashboard, and it is the only exercise that reliably surfaces the systems that have quietly stopped being anybody's job. Every organisation that has run it has found something, which is the strongest recommendation available.