This month, the Qilin ransomware group claimed an attack on Complete Packaging Solutions, a UK business services provider, threatening to leak stolen data unless a ransom is paid. It’s the latest in a run of attacks where the target isn’t a household name — it’s a supplier that quietly keeps other businesses running. That’s exactly why it matters to you, even if you’ve never heard of the company.

Qilin is a “ransomware-as-a-service” operation: the people running the software rent it out to affiliates who do the actual breaking in. That model has made it one of the most active ransomware brands of 2026, and it favours precisely the kind of mid-sized supplier that most UK SMEs depend on somewhere in their chain — packaging, logistics, payroll processing, IT support, print. None of these companies feel like “critical infrastructure,” which is exactly why they’re under-defended and exactly why attackers like them.

Why supplier breaches become your breach

If Complete Packaging Solutions holds your order data, customer addresses, or contract terms, a leak on their end can expose your business without a single one of your own systems being touched. Worse, attackers routinely use a compromised supplier’s email accounts to send convincing invoice-fraud messages to that supplier’s customers — meaning the phishing email asking you to update payment details might come from an account you’ve trusted for years.

The practical response isn’t to panic-audit every vendor overnight. It’s to know which of your suppliers actually hold sensitive data or have system access into your business, and to have a plan for what happens if one of them is breached.

Three checks worth doing this week

Map your critical suppliers. List anyone who holds customer data, financial information, or has a login into your systems. If you can’t answer “what happens if they’re hacked tomorrow” for each one, that’s a gap.

Verify payment changes out-of-band. Any request to change bank details — from a supplier or a customer — should be confirmed by phone, using a number you already have on file, not one in the email. This single habit stops most invoice fraud that follows a supplier breach.

Ask suppliers about their incident response. A short, direct question — “if you were breached, how quickly would you tell us, and what would you tell us?” — filters out suppliers who haven’t thought about it from those who have. Firms like KeepSafe specialise in monitoring exactly this kind of exposure across a business’s supplier network, flagging when a partner’s data turns up somewhere it shouldn’t.

What “ransomware-as-a-service” actually means for risk

It’s worth understanding why groups like Qilin are so prolific. Rather than one gang carrying out every attack, the core operators build and maintain the malware, then lease it to independent affiliates who handle the actual break-in, negotiation and extortion. That franchise model means dozens of loosely connected crews are running campaigns simultaneously, each hunting for the easiest available target rather than a specific industry. A packaging supplier, a bookkeeping firm, a logistics partner — none of them are targeted because of who they are, only because a login was reused, a VPN wasn’t patched, or an employee clicked the wrong link. That randomness is actually useful information: it means the basics — patching, multi-factor authentication, and staff awareness — stop the majority of these attacks before they start, regardless of how big or well-known your business is.

If you’re notified of a supplier breach

Should a supplier ever tell you they’ve been compromised, resist the urge to just note it and move on. Ask specifically whether your data was among what was accessed, request a written summary once their investigation concludes, and flag internally to anyone handling payments or customer communications with that supplier that extra vigilance is needed for the following weeks. Attackers often sit on stolen data for a while before using it, so the risk window stays open long after the initial headline fades.

The takeaway

You can’t stop your suppliers getting attacked, but you can control how exposed that leaves you. Spend twenty minutes this week identifying which vendors matter most to your data and cash flow, and make sure “verify by phone” is a habit your whole team already has — not one you’re teaching for the first time after the invoice fraud email lands.