7 Companies Forced to Shut Down After a Data Breach

Yes, a data breach can shut a company down for good. It's rare, most businesses recover, but it happens. This post discusses 7 companies that didn't recover (and the lessons from each).
Share post:

Last updated: July 2026

Yes, a data breach can shut a company down for good. It’s rare, most businesses recover, but it happens. The 7 companies below didn’t make it.

Here’s the part that surprises people: they usually didn’t lose their data forever. In Sophos’s State of Ransomware 2026, only 2% of organizations that had data encrypted got nothing back at all. What kills a company is the cost and the downtime (the average recovery ran $1.7 million and about three weeks), or, in the worst cases, an attack that wiped the backups too. And most of these were already wobbling before the breach hit. The breach was the shove, not the whole story.

If you’re an especially optimistic person who tries to find the positive in negative events, you might be inclined to think of data breaches as not being particularly bad. Sure, ransomware attacks and other hacking incidents may cause companies to lose data, suffer reputational harm, and even pay fines or penalties. But at least the businesses keep operating, right?

The answer, unfortunately, is “not always.” Although many of the most infamous hacks that have taken place haven’t forced their targets to go out of business, some attacks do become existential threats that force companies to shutter. The organizations lose so much data that is critical to their operations, or face such steep financial repercussions, that they have no choice but to close entirely.

To prove the point, here’s a look at seven major hacks between 2014 and 2026 that ended in worst-case scenarios from a business perspective. As we’ll emphasize, these are also lessons in why effective data protection capabilities are so critical not just as a means of minimizing disruptions, but also of safeguarding the very viability of your business itself.

1. Stoli Group USA (2024)

Stoli Group USA, the company behind Stolichnaya vodka, filed for Chapter 11 bankruptcy on November 27, 2024. An August 2024 ransomware attack was one of the reasons it gave the court.

The attack took down the group’s ERP system, the software that runs accounting, orders, and inventory. Months later staff were still doing those jobs by hand, and the company said its systems wouldn’t be fully restored until at least Q1 2025.

The timing was brutal. Stoli was already fighting the Russian government over ownership of the brand and dealing with softer vodka sales, so it had no room to absorb another hit. Because of the breach it couldn’t even produce the financial reports its lenders required. In January 2026 the case converted to Chapter 7, the kind of bankruptcy where the company liquidates for good.

The lesson: a breach rarely kills a healthy company on its own. It’s the extra weight that sinks one already treading water. Your backup and recovery plan is what keeps a bad month from turning into the thing that ends you.

2. MediSecure breach (2024)

In July 2024, MediSecure, which provides electronic prescriptions in Australia, announced that it had experienced a breach that compromised the records of 12.9 million people – nearly half the population of the country.

According to the limited publicly available information about how the breach happened, it appears that threat actors exploited a vulnerability to plant ransomware within MediSecure’s IT estate. Then, they encrypted sensitive patient data and demanded a ransom to release it.

It’s unclear whether MediSecure actually paid the ransom, but it probably doesn’t matter much because the attackers used the stolen data to launch other attacks against individuals whose personal information they had compromised.

Following the incident, MediSecure requested a financial bailout from the Australian government, presumably to protect itself against the potential of lawsuits from affected parties seeking to hold the company responsible for the exposure of their personal information. The government declined the request, and shortly after, MediSecure entered a state called “administration” – which effectively means that it is being reorganized, and may cease operations once it finishes responding to the fallout from the breach.

The takeaway: Encrypt sensitive data – including sensitive information stored in backups, which should also be immutable to ensure that attackers can’t tamper with them. Although it’s not entirely clear whether encrypted backups would have prevented the MediSecure breach, they certainly wouldn’t have hurt. At a minimum, they would have helped ensure that if the attackers targeted backups as a way of accessing sensitive information, they wouldn’t have been able to do so without the decryption key.

3. National Public Data (2024)

In August 2024, National Public Data, which collects and processes information for background checks, announced the exposure of 2.9 billion records containing personal information associated with up to 170 million people. It appears the attack occurred because hackers located a zip file on the company’s website giving them access to its databases. Several months later, the company filed for bankruptcy and shut down due to the financial impact of the breach.

As with some other recent data breach incidents, it’s not clear that backups alone would have saved National Public Data from closing. But they would have been one key step in a broader cyber hygiene strategy that might have prevented dangerous practices like storing access credentials in zip archives.

4. Discord.io hack (2023)

In an example of an incident where a business shut down without even having its data held for ransom, Discord.io announced in August 2023 that it was ceasing operations. The announcement followed a major hacking event in which threat actors obtained access to the company’s main customer database and offered it for sale.

It’s unclear whether the database, which contained personal information about approximately 760,000 Discord.io members, was ever actually sold. Nonetheless, the company (which provided custom invitations for the Discord messaging platform, and which operated independently from Discord itself) apparently chose to shut down – presumably in a bid to avoid lawsuits linked to claims of improper management of sensitive data. In other words, Discord.io seems to have seen the writing on the wall and figured that rather than waiting to be sued into bankruptcy, it might as well just go ahead and go out of business right away.

Because this hack apparently stemmed from a compromise of a production database rather than backups, it’s not clear that stronger investment in data backup and recovery would have saved the company. Still, data protection and the ability to weather (or avoid) major hacks like this one tend to go hand-in-hand: If you take steps to back up data properly, it’s likely that you enjoy a stronger overall security posture and a higher level of business resilience, too.

AWS Backup Checklist
Fill in the gaps in your backup and DR strategy

Fortify your cloud across every critical dimension.

the disaster-proof backup & DR checklist

5. KNP Logistics / Knights of Old (2023)

KNP Logistics ran Knights of Old, a UK haulage firm that had been moving freight for 158 years. In 2023 the Akira ransomware group got in through a single weak password on one employee’s account.

Once inside, they encrypted KNP’s data and destroyed its backups, then demanded a ransom reported around £5 million. KNP didn’t have that kind of money. With no data and no recoverable backups, there was no business left to run. Around 700 people lost their jobs, roughly 500 trucks came off the road, and the company went into administration.

The story got a fresh wave of coverage in 2025 as the go-to example of how one password can end a company. But the real failure underneath it is the backups. If those had been immutable, or stored in an account the attacker couldn’t reach, KNP could have restored and kept trading.

It’s the same lesson as Code Spaces below, 9 years apart. Attackers hunt for the backups on purpose now. Backups that can be deleted are backups you can’t count on.

6. TravelEx ransomware attack (2020)

In early 2020 – as Covid-19 was spreading and most of the world was still enjoying the final weeks of “before times” – the foreign currency exchange company TravelEx experienced a ransomware attack that shut down its operations in 30 countries. The attackers demanded $6 million (some sources reported $3 million) in ransom to restore the company’s data.

The company apparently negotiated with the attackers, who agreed to settle for a payment of $2.3 million. But like the 92 percent of companies that pay ransoms without fully recovering their data, TravelEx wasn’t able to go back to normal after settling up with the hackers. Instead, it ended up restructuring, effectively going out of business.

It’s worth noting, too, that TravelEx apparently had a cyber insurance policy in place before the attack. But that was not enough to cover the serious losses it incurred from the disruption to its operations.

In the fallout of the incident, TravelEx executives stated that the company might have managed to weather the attack if not for the onset of the Covid-19 pandemic, which (by causing a major slowdown in global travel and hence in the need for foreign currency exchange) resulted in substantial revenue losses independent of those stemming from the ransomware incident. That seems plausible.

Equally plausible is that, had TravelEx backed up its data and had an effective disaster recovery plan in place before the attack, it likely could have restored its systems without paying the ransom. And perhaps then the company would have been in a better position to survive the ensuing Covid crisis.

7. Code Spaces (2014)

The Code Spaces story is one we’ve spoken about previously. Although it happened in 2014, it’s worth revisiting because it’s still just as devastating today, given how preventable the consequences of this breach were. The team at the source code hosting service woke up one morning discovering that hackers infiltrated their Amazon Web Services control panel. They then demanded a hefty ransom in exchange for returning control of their own systems. This turned into a terrifying 12-hour period as they watched their entire digital existence begin to disappear. Code Spaces discovered that the hackers implemented a DDoS attack and proceeded to infiltrate into their Amazon EC2 control panel. The hackers destroyed not just their primary data, but even their backup systems – including cross-region backups meant to be their safety net. 

When N2W customers heard about this story, many reached out as they finally understood that their data and snapshots must be stored in an entirely separate AWS account. If Code Spaces had done this, their backup data would be safe and it would have eliminated the worry that a hacked account would lead to snapshot and data deletion.

When the dust finally settled, the damage was catastrophic and the company couldn’t sustain themselves. The company never recovered, becoming a stark reminder that losing your backup data can mean losing everything.

Protecting your data (and your business)

Every company here had a backup story that went wrong, or none at all. The companies that survive ransomware mostly restore from their own backups (66% of them, per Sophos’s 2026 report). The ones on this list couldn’t.

The fix isn’t complicated:

  1. Lower your RPO. Back up often enough that losing the gap doesn’t hurt (N2W runs intervals as short as 60 seconds).
  2. Create immutable backups so ransomware can’t delete or encrypt them.
  3. Set up both cross-region backup and cross-account backup, so one stolen login can’t reach everything (that was KNP’s mistake).
  4. Write a disaster recovery plan and test the restore, not just the backup (and be sure it clones network configurations)
  5. If you run in more than one cloud, extend that plan across AWS and Azure for cross-cloud air gapping.

Breach-Proof your Backups with N2W

N2W does all of this for AWS and Azure workloads from one console. If your current setup couldn’t survive what hit the companies above, that’s the gap to close first.

Frequently Asked Questions

Can a company really shut down after a data breach?

Yes, though it’s the exception. Most companies recover. The ones that don’t usually either lost their data because the backups were destroyed too (Code Spaces, KNP Logistics), or took a financial and operational hit they were too fragile to absorb (Stoli, TravelEx).

What percentage of companies go out of business after a cyberattack?

There’s no reliable single number, and the figures you’ll see quoted vary wildly. Treat any precise stat (like “60% close within 6 months”) with suspicion, most trace back to a misquoted source. What is well documented: total closure is rare, and so is total data loss.

Do you get your data back if you pay the ransom?

Almost everyone gets their data back one way or another. In Sophos’s State of Ransomware 2026, only 2% of organizations that had data encrypted got nothing back at all. Paying the attacker is the expensive route, though: the median ransom payment was $769,000, and the average recovery bill on top of that came to $1.7 million. Most companies that recovered used their own backups (66%), not a decryptor.

How do you keep a breach from shutting your business down?

Assume attackers will reach your production data, then make sure they can’t reach your backups. Immutable backups they can’t delete, copies in a separate account or region, and a disaster recovery plan you’ve actually tested. That’s how you land in the 66% who restore from backups instead of the ones writing a $769,000 check.

You might also like