SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Mid-market firms account for 73% of ransomware victims

Mid-market firms account for 73% of ransomware victims

Wed, 19th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Black Kite has published research finding that mid-market companies accounted for 73% of ransomware victims in North America and Europe. The study covered organisations with annual revenue from USD $10 million to USD $1 billion.

The findings were based on an analysis of 13,336 ransomware incidents with verifiable revenue data between January 2023 and June 2026, alongside a broader assessment of 120,128 mid-market organisations. The pattern remained steady even as incidents increased, with the share of attacks on mid-market businesses ranging from 72.1% to 74.6% over the period.

The absolute number of ransomware incidents rose 44%, from 2,320 in 2023 to 3,340 in 2025. Yet the proportion of mid-market organisations affected changed little, suggesting attackers continued to focus on companies smaller than large enterprises but still substantial enough to offer a return.

More than half of the mid-market victims identified in the study generated less than USD $50 million in annual revenue. The report divided the segment into three bands: lower mid-market at USD $10 million to USD $50 million, core mid-market at USD $50 million to USD $500 million, and upper mid-market at USD $500 million to USD $1 billion.

Sector split

Manufacturing was the most targeted industry, accounting for more than a quarter of mid-market ransomware victims. Professional, scientific and technical services followed, along with construction.

The data also pointed to a broad set of weaknesses across the organisations studied. The report found that 28.3% had at least one known exploited vulnerability, 54.7% had at least one significant patch management finding on public-facing software, and 48.1% had at least one disclosed vulnerability with a CVSS score of 8.0 or higher.

Another 32.3% had at least one stealer log finding, while 46.8% had missing or insufficient DMARC protection. These measures are often used as indicators of exposure because they can show whether attackers may have routes into systems or opportunities to misuse email domains.

The report argued that mid-market companies face pressure on two fronts. They are increasingly singled out by ransomware groups while also having to monitor cyber risk across extensive supplier networks.

That burden is heightened by the role many mid-sized businesses play in larger corporate supply chains. Companies serving bigger customers can come under scrutiny because those customers are required in some sectors and jurisdictions to assess the security posture of vendors and suppliers.

Black Kite pointed to regulation in Europe and the US, including the EU's NIS2 Directive, New York's NYCRR 500 and HIPAA, as part of that pressure. As a result, mid-market vendors may be expected to demonstrate stronger cyber controls even when they have smaller security teams and fewer resources than large enterprises.

AI gap

The report also said artificial intelligence is widening the gap between attackers and defenders. Tools that help security teams identify software flaws are also available to criminal groups, increasing the speed at which vulnerabilities are discovered and exploited.

For mid-market firms, the issue is not only exposure but capacity. The research cited published findings from ISC2's 2025 Cybersecurity Workforce Study showing that only 20% of mid-sized organisations had adopted AI tools in their security operations.

That lower adoption rate may leave many businesses trying to respond to a faster-moving threat environment with limited staff and budgets. In practice, that can make basic tasks such as identifying external weaknesses, prioritising patches and monitoring third-party risk harder to sustain.

This was the first time Black Kite had examined the mid-market as a distinct segment rather than as part of a broader sample, according to Ferhat Dikbiyik, Chief Research & Intelligence Officer, Black Kite.

"This is the first time we examined the mid-market as a segment in its own right, rather than a set of companies scattered through larger studies," Dikbiyik said.

He added that the work would continue as the company broadens its focus on the segment.

"The report is only the beginning. We're continuously expanding Black Kite with capabilities designed specifically for mid-market organizations, helping smaller security teams identify, prioritize, and reduce cyber risk without requiring enterprise-sized teams or budgets," Dikbiyik said.

The methodology combined ransomware incident tracking across North America and Europe with a snapshot of externally observable risk findings across the monitored mid-market population. One dataset established which companies were attacked, while the other showed how organisations of that size appeared from the internet.