ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Ransomware attackers are zeroing in on mid-market companies

infoRansomwareimportance 38
AI summary · glm-5.3-flash

Black Kite found mid-market firms were 73% of disclosed ransomware victims in North America and Europe from January 2023 to June 2026.

Black Kite analyzed 13,336 publicly disclosed ransomware and data-extortion incidents with known revenue between January 2023 and June 2026, finding mid-market companies (annual revenue $10M-$1B) accounted for 73% of victims in North America and Europe, consistently between 72% and 75%. Manufacturing was the most affected sector, followed by professional, scientific, and technical services and construction. Of more than 120,000 assessed mid-market organizations, 54.7% had at least one significant patch-management issue on a public-facing system, over a quarter had a known-exploited vulnerability, and nearly one-third had stealer-log credential findings.

  • 73% of disclosed ransomware/extortion incidents with known revenue hit mid-market firms; manufacturing most affected.
  • 54.7% of 120,000+ assessed mid-market organizations had patch-management issues on public-facing systems.
  • Nearly one-third of monitored organizations had stealer-log findings indicating compromised credentials.
  • Typical vendor-risk teams of two people manage 300+ suppliers, straining third-party oversight.
  • NIS2, NYCRR 500, and HIPAA push more security disclosure demands onto mid-sized vendors.
VendorsBlack Kite
Full article600 words · extracted from helpnetsecurity.com · click to collapse

Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite.

The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion. Their share of incidents remained between 72% and 75% throughout the period, showing that attacks on this part of the market are a consistent problem.

More than half of mid-market victims had annual revenue between $10 million and $50 million. Manufacturing was the most affected industry, accounting for more than a quarter of mid-market victims, followed by professional, scientific and technical services and construction.

mid market ransomware risk

Mid-market ransomware distribution by revenue segment (Source: Black Kite)

Ransomware hits smaller mid-market companies most often

Ransomware groups look for weaknesses that can provide a route into company systems. Unpatched software, known vulnerabilities and stolen login details can all give attackers an opening.

An assessment of more than 120,000 mid-market organizations found that 54.7% had at least one significant patch-management issue affecting a public-facing system. More than a quarter had a vulnerability already known to be exploited by attackers.

Stolen credentials create another route into business systems. Nearly one-third of the monitored organizations had at least one stealer-log finding, indicating credentials collected by information-stealing malware. Attackers can use stolen login details to access accounts, move through networks or prepare for further attacks.

For security teams, the challenge is deciding which weaknesses need attention first. New vulnerabilities continue to appear, while mid-sized companies may have fewer people available to investigate and fix them.

AI changes how vulnerabilities are found and exploited

AI is accelerating how software vulnerabilities are discovered and analyzed, while attackers have access to many of the same capabilities. Security teams can use AI to identify vulnerabilities faster and process large amounts of security data, while attackers can use similar tools to look for weaknesses.

This creates more work for mid-sized companies already managing large numbers of vulnerabilities with limited staff and resources. Finding a vulnerability does not automatically show how urgent it is. Teams still need to determine whether the affected system is exposed to the internet, whether attackers are exploiting the weakness and what access it could provide.

Treating every vulnerability as equally urgent is difficult when teams have thousands of potential issues to review. Knowing which systems are exposed and which weaknesses are being exploited can help determine what needs to be fixed first.

Supply chains extend the risk

Mid-sized companies are closely connected to other businesses. They may provide software, products and services to larger organizations while depending on their own suppliers, cloud platforms and technology providers.

A security incident at one company can therefore create problems elsewhere in the supply chain. A compromised supplier could expose customer data, interrupt services or give attackers another route to connected organizations.

Keeping track of these relationships can be difficult. A typical vendor-risk team described in the analysis consists of two people responsible for more than 300 suppliers. Some software and services may sit outside formal vendor inventories, leaving security teams without a complete view of third-party risk.

Regulatory requirements are putting more attention on these connections. Rules such as the EU’s NIS2 Directive and U.S. requirements including NYCRR 500 and HIPAA can require organizations to address risks linked to suppliers. Mid-sized vendors may therefore be asked to provide customers with more information about their security controls.

For smaller security teams, understanding which vulnerabilities and third-party connections create the greatest risk can help determine where limited resources should go first.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/24/black-kite-mid-market-ransomware-risk-report/