On 31 August 2026, the Settra ransomware group listed Hatch Communications, a Leeds-based PR, social media and events agency, as a victim, with the attack itself estimated to have taken place a few days earlier. Full details of what data was taken haven’t been confirmed publicly, but the incident lands in a pattern that’s become depressingly familiar this year: attackers going after the supplier that holds your data, rather than you directly.
For UK SMEs, this matters more than a typical breach headline because of what agencies like Hatch actually hold. A PR or marketing agency working with your business doesn’t just have your logo and brand guidelines. It often has customer contact lists for email campaigns, press contacts and journalist relationships, event attendee data, social media login credentials, and sometimes access to your CRM or analytics platforms. If that agency gets breached, your customer data can be exposed without your own systems ever being touched.
Why “it’s not our breach” doesn’t hold up
Under UK GDPR, if you’re the data controller and your agency is a processor handling your customers’ personal data, you carry accountability for what happens to it, even if the agency’s servers were the ones compromised. Regulators and customers alike don’t distinguish neatly between “our breach” and “our supplier’s breach” when contact details end up for sale on a leak site. This is exactly the kind of supply-chain exposure that’s hit accountancy firms, logistics providers, and CRM vendors in recent months, and marketing agencies are a natural next target because so many hold rich, exportable customer datasets with comparatively light security investment.
What to actually check this week
Map which of your suppliers hold customer data, and how much. Most SME owners can name their accountant and their IT provider as data processors, but forget that the agency running last quarter’s email campaign still has that mailing list sitting in their systems. A short supplier audit, who has what, and why they still need it, closes gaps you didn’t know were open.
Ask for evidence, not reassurance, on data retention. If a supplier relationship ended, or a campaign is long finished, your data shouldn’t still be sitting in their systems. Ask suppliers directly when they last purged old client data, and put a retention limit in future contracts. Smallprint has ready-to-use data processing agreement templates that make this a standard clause rather than an afterthought.
Get continuous monitoring on your own exposure, not just your own network. Traditional IT security covers your systems, but a supplier breach can expose your customers’ data without ever touching your firewall. KeepSafe monitors for exactly this: your business’s name, domains and customer data surfacing in breach dumps and dark web listings, regardless of whose system leaked it.
Have a plan for the call you hope never comes. If a supplier tells you they’ve been breached and your customer data was involved, you have legal notification obligations that start ticking immediately. Knowing in advance who needs informing, the ICO, affected customers, your insurer, saves precious hours when the call actually happens.
Don’t forget the contract itself
Many SMEs sign a standard agency contract once at the start of a relationship and never look at it again, even as the scope of data shared grows over years of campaigns. If your current supplier agreements don’t specify what happens to your data when a project ends, who is liable in a breach, and what notification timeline the supplier owes you, that’s a gap worth closing before you need it, not after.
The takeaway
Every supplier holding your customer data is effectively an extension of your own security perimeter, whether you’ve thought of it that way or not. The Hatch Communications incident is a reminder that agencies, not just IT vendors, sit inside that perimeter. Audit who holds your data, insist on retention limits, and monitor for exposure you can’t otherwise see, because the next breach that hits your customers might not happen anywhere near your own systems.