Desk live·
ForensicPost
Ransomware/Analysis/File 25-1112c

The Provider Is How Small Firms Enter the Record

Twenty asset managers became visible because their provider was named. It is the second route this corpus has found by which small organisations reach the public record, and it is no more designed than the first.

Constructed geometry · not a chart of case data
TargetSmall organisations
ActorUnattributed
S. Rosler11 min readConfidence: medium2 sources reviewed

At 25-1005b this desk recorded that the JLR supply-chain firms entered the public record through proximity to a large incident, and called that a sixth route — an accident rather than a mechanism.

The MSP cases supply a seventh: shared provider compromise. Twenty asset managers and an unenumerated set of DragonForce victims became visible because a single provider was named.

It Works Better Than The Accidental Route

Proximity to a large incident requires the upstream event to be enormous. Provider compromise requires only that researchers identify the provider — which they generally do, because a shared vector is the most publishable part of the story.

So a small firm compromised through its MSP has a meaningfully higher chance of appearing in the record than one compromised directly, at identical severity.

Which Distorts The Record In A Specific Direction

If small-firm incidents become visible mainly when a provider is involved, then the visible portion over-represents provider-mediated compromise and under-represents everything else.

The national survey at 25-0615b found 84% of organisations reporting phishing as their most common attack — a direct route with no provider to name. That is the invisible majority, and this database contains almost none of it.

The Corpus Has Now Named Seven Routes

Mandatory notification, collective redress, research industry coverage, English-language publication, securities listing, proximity to a large incident, shared provider compromise.

Only the first five are mechanisms anyone designed. The last two are consequences of how research and journalism work, and they are the only ones reaching organisations below a certain size.

Graded medium: this is a structural argument about the database, extending 25-0502, 25-0924b and 25-1005b.

This is an analysis file

It extends the record-formation argument in this database using the MSP incidents above. Corrections: corrections@forensicpost.com.

Sources
  1. Qilin ransomware turns South Korean MSP breach into 28-victim Korean Leaks data heistThe Hacker News
  2. MSPs: the increasing targets in supply chain attacksMSP Channel Insights
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary