Industry & security · Advisory

FTC Flags Rise in Vendor Ransomware Targeting SMBs

March 8, 2026Industry & securityHealthcare · Hospitality · Professional Services · Real Estate · Construction

Third-party billing and scheduling vendors were named as the most common ransomware entry point in Q1 incident reports reviewed by the FTC — a pattern researchers have flagged for two straight quarters.

For a small business the takeaway is not "audit every vendor" — it is asking which vendors have write access to customer data or payment systems, and confirming those carry their own attestation.

Why this matters for onboarding

This is the kind of signal that should raise an industry's risk tier in the questionnaire — heavy reliance on third-party billing/scheduling software is common across healthcare, home services and hospitality.

Source log
  • ftc.gov advisory — Mar 2026
  • CISA Alert AA26-xxx
FTC Flags Rise in Vendor Ransomware Targeting SMBs — CyOps News