Half a million dead windows servers are still online—and attackers are already knocking
511,000 Microsoft web servers that reached end-of-life are still answering HTTP requests, and 227,000 of them no longer receive even the paid Extended Security Updates. A UK research group mapped every one, then published the coordinates so the rest of us can watch the clock tick.
The map is the attack plan
ShadowServer’s scanner found Internet Information Services boxes running Windows Server 2008 R2, 2012, even 2003, in 192 countries. The United States hosts 20 % of the total—one abandoned server for every 650 Americans. France keeps 15,122; Germany 14,570; Italy 10,448; Spain 6,317. Each IP is indexed, searchable, and—because the banner never lies—already loaded into adversarial automation.
IIS is the doorman: it takes every packet, decides what to serve, and often sits on the same subnet as payroll, CRM, or medical imaging. When the doorman’s badge expires, the building’s elevators still work; you just need the right forged pass. Exploit code for CVE-2015-1635, CVE-2017-7269, and a dozen other aged wounds is one search away. No zero-day required—just patience and a list.

No patch, no ransom note—yet
Without ESU, the next bug won’t get a fix; it will get a blog post, a shodan query, and a Bitcoin address. Ransomware crews already favor legacy IIS because lateral movement is trivial: the same account that spins up ASP.NET often has domain admin tokens lying in memory. One foothold on a forgotten HR portal and the entire forest is suddenly negotiable.
ShadowServer’s data drops every 24 hours. That means today’s 227,000 unpatched targets could be 225,000 tomorrow—or 200,000 next month—if someone bothers to pull the plug. The rest will stay online until the power dies or the adversary arrives. Odds are the adversary arrives first.
