In the space of a single week, three UK businesses turned up on ransomware leak sites, each claimed by a different gang. Displaydata, a UK technology firm, and Dotlines were both listed by the Qilin group. CGP MEP Ltd, a building services consultancy, was claimed separately by Akira. None of these are household names, none appear connected to each other, and that is exactly the point.

Ransomware coverage tends to focus on the big, dramatic breaches, retailers, airports, household brands, because those are the stories that make headlines. But the everyday reality for UK SMEs is closer to what happened this week: ordinary, mid-sized firms in ordinary sectors, hit not because anyone singled them out, but because they were reachable. Qilin and Akira are both established ransomware-as-a-service operations, meaning affiliates rent access to the malware and infrastructure, then go looking for whichever organisation has the weakest door left open. A building services consultancy is exactly the kind of target that logic produces: not glamorous, not obviously valuable, just under-defended relative to the effort required to break in.

Why “we’re too small to be a target” is the wrong lens

The instinct to assume ransomware gangs only chase big prizes is understandable, but it misreads how the economics actually work. Affiliates are not hand-picking victims for size or fame; they’re scanning for exposed VPNs, unpatched software, and weak remote access, then moving fast once they find a way in. A firm with fifty staff and a single overworked IT contractor is often an easier win than a firm with a dedicated security team, regardless of what either company does or how much data it holds. Being unremarkable is not protection.

It’s also worth being clear about what “ransomware-as-a-service” means in practice, because it changes who you’re actually up against. Qilin and Akira don’t need to employ skilled hackers to find every victim themselves. Instead, they build the malware, the negotiation infrastructure, and the leak site, then rent access to a wider pool of affiliates who go and find the targets. That model is why gangs can hit a technology firm, a logistics company, and a building services consultancy in the same week with no obvious connective thread: the affiliates are simply working through whatever list of exposed systems they’ve found that week, sector-blind and largely indifferent to who’s on the other end.

What actually reduces the odds

Patch internet-facing systems first, everything else second. VPN gateways, remote desktop, and firewall management interfaces are the entry points these gangs favour most consistently. If your IT provider hasn’t confirmed these are current in the last month, that’s the first question to ask this week.

Assume your business is being watched for leaked credentials, not just attacked directly. A meaningful share of ransomware incidents start with a password that was already sitting on a dark web dump from an unrelated breach. Continuous monitoring for exposed credentials and lookalike domains, the kind KeepSafe provides, catches this exposure before an affiliate acts on it rather than after.

Have an actual incident response plan, not just a backup policy. Backups matter, but the businesses that recover fastest are the ones that know, in advance, who calls the ICO, who calls customers, and who takes systems offline first. Writing this down when nothing is on fire takes an afternoon; figuring it out during an active breach costs days.

The takeaway

None of Displaydata, Dotlines, or CGP MEP did anything unusual to end up on a leak site this week, they were simply reachable, and that is the entire threat model most UK SMEs are operating under. The response isn’t panic, it’s ordinary maintenance treated as non-negotiable: patched systems, monitored credentials, and a plan written before it’s needed rather than during the breach itself. Three firms in one week is not an anomaly worth watching for, it’s the baseline rate, and next week’s list will have three more names on it whether or not yours is one of them.