Two banks, one supplier, and a leak site that gave it away
Event dated 20 April 2026 · Published 2 September 2026 · 3 sources
Third-party risk management works one relationship at a time. An organisation lists its suppliers, assesses them, and forms a view about each. Done properly, it is genuinely useful, and it answers the question it was designed for: is this supplier acceptable?
It does not answer a different question that turns out to matter more. Not whether a supplier is acceptable, but whether the same supplier sits behind several of the things you depend on — or, at sector scale, behind several of your competitors, which is what makes an outage or a breach systemic rather than commercial.
The information is not available to the buyer
A bank can find out a great deal about a supplier's controls. What it cannot find out is the supplier's other customers, because that list is commercially sensitive and no supplier volunteers it. So the concentration risk sits in a fact that exactly one party — the supplier — can see, and that party has no incentive to publish it.
Which is why it took an extortion group's posting schedule to reveal it. That is an absurd way for a sector to learn about its own dependencies, and it is currently one of the few ways available.
Why finance specifically
Banking has spent two decades consolidating back-office functions into specialist providers, for good reasons: statement production, payment messaging and reconciliation are all better done by somebody who does nothing else. The consequence is a small number of firms handling the same function for a large number of institutions.
Regulators have noticed this in the language of operational resilience and critical third parties, which is the right frame. The gap is that the resilience conversation has largely been about outages — the provider stops working — rather than about a provider that keeps working while somebody else reads what passes through it.
What an individual institution can do
Ask directly. Concentration questions are answerable in the negotiation even when the customer list is not: whether the supplier serves competitors in the same market, whether those relationships share infrastructure, and whether an incident affecting one would involve the systems that hold your data.
None of that prevents anything. What it does is convert a dependency you did not know you had into one you can plan around — which is the difference between reading your own name on a leak site and reading it next to your competitor's.