This week, the ransomware group Qilin added a UK-based professional services firm to its dark web leak site — the standard opening move in a ransomware-as-a-service extortion playbook, used to pressure a victim into paying before any stolen data gets published. As is typical with these listings, the full details are still thin: no confirmed ransom figure, no public statement yet on exactly what was accessed. But the incident itself is a useful, timely prompt, because Qilin has spent the past year building a track record that UK businesses should recognise, including a ransomware attack that disrupted hospitals across London last year.

Why a “professional services” target should worry more than one company

Qilin runs a recruitment model, not a single hacking crew — it licenses its ransomware to affiliates who go looking for targets, and consultancies, accountants, and IT support firms are increasingly attractive ones. Not because they’re poorly defended necessarily, but because of what they hold: client data, system access credentials, financial records, and often direct network connections into the businesses they serve. Breach one consultancy and an attacker doesn’t just get that firm’s data — they potentially get a foothold into every client relying on that firm’s access.

This is the same pattern behind several recent UK incidents where an attack on an accountant or a logistics provider rippled out to their clients, not just the company named in the headline. If your business uses an outside firm for IT support, accounting, HR, or compliance — and almost every SME does — that firm’s security posture is, functionally, part of your own.

Questions worth asking your suppliers this week

What access do they actually have, and does it need to be permanent? A consultancy that only needs quarterly access to your accounts shouldn’t have a standing login that works all year round. Time-limited or on-request access closes a door that doesn’t need to stay open.

Do they use multi-factor authentication on anything touching your systems? This is the single most effective, cheapest control against exactly this kind of attack, and it’s reasonable to ask a supplier to confirm it’s in place before you hand over access.

What’s their notification commitment if something goes wrong on their end? UK GDPR gives you 72 hours to notify the ICO once you’re aware of a breach involving personal data — but that clock doesn’t start until you find out. A supplier who commits contractually to telling you quickly, not eventually, protects your own compliance position as much as theirs.

Building this into how you choose suppliers, not just react to breaches

The instinct after a story like this is to review the supplier relationship in question and move on. A more durable approach is treating basic security questions as a standard part of onboarding any new consultancy, IT provider, or software vendor — the same way you’d check references or insurance. Smallprint offers straightforward contract templates that build data protection and access commitments into supplier agreements from the start, rather than discovering the gaps after something’s gone wrong.

The takeaway

Nobody yet knows the full extent of what this particular breach involved, and speculating beyond the leak-site listing isn’t useful. What is useful is the reminder it offers: your business’s exposure to ransomware isn’t limited to your own systems. If an outside firm has access to your data or your network, their security is your risk too — and this week is as good a time as any to ask them a few direct questions about it.

None of this requires a big compliance programme to get started. A short supplier checklist, a five-minute conversation at your next renewal, and a written commitment to be told quickly if something goes wrong will cover most of the risk that a story like this points to. The businesses that get caught out badly by supply-chain breaches are almost always the ones that never asked the question in the first place, not the ones whose supplier turned out to have a perfect answer.