Half a million dead windows servers are still online—and the us owns the biggest graveyard
Five hundred and eleven thousand corpses are still breathing. A UK research squad has mapped every Windows web server that reached end-of-life and immediately became a skeleton key for any halfway decent intruder. The body count, published this morning by ShadowServer, is 511,000 machines running Microsoft’s Internet Information Services without a single sanctioned patch in sight. Of those, 227,000 have also exhausted even the paid “extended support” drip feed—Microsoft’s ESU life-support cable has been yanked.
The anatomy of a forgotten server
Think of IIS as the doorman for every web request that knocks on an organisation’s digital front. When the software is current, the doorman checks IDs, frisks suspicious payloads, and keeps the lobby clean. Let the support contract lapse and the doorman becomes a cardboard cut-out: still standing, still waving visitors through, but unable to tell a guest from a gunman.
ShadowServer’s scan swept every IPv4 address on the planet last week. Any banner answering with IIS 7.5 (Windows Server 2008 R2) or older was flagged. The result is a hit list sorted by country, ASN, and—cruelly—by whether the owner ever bothered to pay for ESU. The United States tops the leaderboard with just over 100,000 of these antiques, one fifth of the global stockpile. France, Germany, Italy and Spain hoard another 46,000 among them; Europe’s economic heavyweights apparently enjoy carrying live ordnance in their public-facing pockets.

No antivirus, no perimeter, no second chance
Here is the part that keeps red-teamers awake: these boxes are invisible to file-based antivirus because the exploits they invite are often fileless. A single malicious request can coax IIS into spawning a PowerShell cradle that never touches disk. From there the attacker pivots to payroll portals, document repositories, or the domain controller next door. Ransomware crews have already automated the workflow; they merely need to pick a row from ShadowServer’s daily CSV.
Microsoft’s own figures show that a Server 2008 R2 machine that missed the January 2020 cut-off has since accumulated 262 publicly disclosed vulnerabilities, 41 of them rated “critical” and remote. Each unpatched flaw is a master key duplicated on dark-web forums for less than the price of a latte.

Why nobody pulls the plug
Legacy applications, regulatory inertia, and plain ignorance form a toxic cocktail. Hospitals still run 2008 boxes because the MRI software was never recompiled for a newer CLR. Local governments lost their only COBOL contractor in 2014 and now pray the hardware survives the next election cycle. Meanwhile, cloud migration quotes arrive stamped with six zeroes, so the server stays where it is—unloved, unpatched, and online.
ShadowServer will keep refreshing the list every 24 hours, a public shaming engine that names, shames, and geolocates. Network owners who find their IP in the feed have two choices: migrate before someone else logs in, or prepare a Bitcoin wallet and an apology template. The clock is not ticking; it already rang.