Skip to content
The Cyber Security Place

Two banks, one supplier, and a leak site that gave it away

Event dated 20 April 2026 · Published 2 September 2026 · 3 sources

On 20 April 2026 the Everest group posted two US banks on its leak site on the same day, with material of the same kind — document-production data — which reporting took as pointing to a single shared supplier rather than two separate intrusions. Neither institution announced a shared dependency. The fact that both had one was inferred from the publication schedule of the people who attacked them. Two competitors, each having assessed its own suppliers independently and diligently, had bought the same concentrated risk without either being in a position to see it.

Third-party risk management works one relationship at a time. An organisation lists its suppliers, assesses them, and forms a view about each. Done properly, it is genuinely useful, and it answers the question it was designed for: is this supplier acceptable?

It does not answer a different question that turns out to matter more. Not whether a supplier is acceptable, but whether the same supplier sits behind several of the things you depend on — or, at sector scale, behind several of your competitors, which is what makes an outage or a breach systemic rather than commercial.

The information is not available to the buyer

A bank can find out a great deal about a supplier's controls. What it cannot find out is the supplier's other customers, because that list is commercially sensitive and no supplier volunteers it. So the concentration risk sits in a fact that exactly one party — the supplier — can see, and that party has no incentive to publish it.

Which is why it took an extortion group's posting schedule to reveal it. That is an absurd way for a sector to learn about its own dependencies, and it is currently one of the few ways available.

Why finance specifically

Banking has spent two decades consolidating back-office functions into specialist providers, for good reasons: statement production, payment messaging and reconciliation are all better done by somebody who does nothing else. The consequence is a small number of firms handling the same function for a large number of institutions.

Regulators have noticed this in the language of operational resilience and critical third parties, which is the right frame. The gap is that the resilience conversation has largely been about outages — the provider stops working — rather than about a provider that keeps working while somebody else reads what passes through it.

What an individual institution can do

Ask directly. Concentration questions are answerable in the negotiation even when the customer list is not: whether the supplier serves competitors in the same market, whether those relationships share infrastructure, and whether an incident affecting one would involve the systems that hold your data.

None of that prevents anything. What it does is convert a dependency you did not know you had into one you can plan around — which is the difference between reading your own name on a leak site and reading it next to your competitor's.