On 4 September 2026, the ransomware group Qilin publicly claimed AP Capital Partners, a UK financial firm, as its latest victim, listing the company on its dark web leak site alongside a threat to publish stolen data if a ransom isn’t paid. It’s the same day the group also claimed a separate UK business services provider, and it follows Qilin naming an unrelated UK professional services firm earlier this same week. Three claimed UK victims from one ransomware group in a matter of days is not a coincidence, it’s a deliberate, sustained campaign, and financial and professional services firms are squarely in its sights.

Qilin has spent the past year building a reputation as one of the most active ransomware-as-a-service operations targeting the UK, including an attack that disrupted London hospitals last year. It doesn’t build every attack itself, it licenses its ransomware and infrastructure to affiliates who go hunting for targets, which is part of why claims keep landing at this pace. As with most of these leak-site listings, full details of what was actually accessed at AP Capital Partners haven’t been confirmed publicly, but the pattern of the threat, encrypt first, then threaten to publish, is well established.

Why financial and professional firms specifically

Firms in this sector are attractive to ransomware affiliates for a reason that has nothing to do with weak defences necessarily: what they hold. Financial and professional services businesses sit on client financial records, transaction histories, and often direct access into the systems of the companies they serve. A successful breach doesn’t just cost the victim firm, it potentially exposes every client relying on that firm’s data and access, which is exactly the leverage that makes ransom demands more likely to get paid.

If your business is a client of a financial adviser, accountant, or investment firm, this is also relevant to you, not just to the businesses being named. Your own data’s exposure risk now includes every third party holding it, and that risk doesn’t show up in your own security audit.

What to check this week, whichever side of the relationship you’re on

If you’re a UK financial or professional services firm: multi-factor authentication on every remote access point and email account remains the single most effective, cheapest control against the initial access methods these groups typically use. If you haven’t reviewed this in the last few months, do it this week, not after a claim with your name on it.

If you rely on a financial or professional adviser: ask them directly what access they hold to your systems and data, whether it’s still needed, and what their notification commitment is if something goes wrong on their end. A supplier who can answer that clearly is a genuinely lower-risk relationship than one who can’t.

Either way, know your 72-hour clock. UK GDPR requires notifying the ICO within 72 hours of becoming aware of a breach involving personal data. That clock starts when you find out, whether the breach happened on your systems or a supplier’s, so having a plan for who does what in that window matters regardless of where the fault sits.

Building these checks into how you select and renew supplier relationships, rather than reacting after a headline, is the more durable fix. Smallprint offers contract templates that put data access limits and breach notification commitments into supplier agreements as standard, and KeepSafe monitors for your business’s data surfacing in exactly these kinds of leak-site listings, regardless of whose system the breach happened on.

The takeaway

Nobody outside AP Capital Partners yet knows the full scope of what this incident involved, and speculating past the leak-site claim isn’t useful. What is useful is recognising the pattern: one active ransomware group has claimed three UK victims in a single week, with financial and professional services disproportionately represented. If your business sits in or depends on that sector, treat this as the prompt to check access controls and supplier commitments now, not as a story about someone else’s bad week.