Ransomware Hits the Mid-Market
Analytics2026-09-07, 09:57
Black Kite released a study of ransomware attacks against mid-market companies (organizations with annual revenue ranging from $10 million to $1 billion). The report is based on two datasets covering the period from 2023 through the first half of 2026: 13,336 publicly disclosed extortion cases with confirmed revenue information for the affected companies, and an analysis of the external attack surface of 120,128 mid-market organizations.
According to the study, in Europe and North America such organizations accounted for 73% of publicly disclosed ransomware attacks involving victims whose revenue could be determined.
Key figures and facts:
The share of mid-market companies among ransomware victims remains consistently around three-quarters from year to year. More than half of affected mid-market companies have revenue below $50 million, while more than a quarter operate in the manufacturing sector.
The number of externally discoverable security issues increases with company size: among organizations with revenue of $500 million–$1 billion, at least one vulnerability from the CISA KEV catalog was found in 52%, compared with 28.3% across the mid-market overall. These organizations were also more likely to have vulnerabilities rated CVSS 8.0 or higher, and the credentials associated with them were more often found in infostealer logs.
The mid-market’s challenges, however, are not limited to technical vulnerabilities; they also include limited resources for risk management. The authors cite data from another study: in 73% of companies, no more than two employees handle supplier-related risks, while half of the firms have to oversee more than 300 suppliers.
The authors explain the ransomware groups’ sustained interest in the mid-market as the result of two factors: these companies are large enough to be economically attractive to attackers, yet often have fewer resources for information security and remediating identified issues than large enterprises. At the same time, most victims are relatively small companies, even though larger organizations have the highest number of externally discoverable security issues. This shows that attack risk is determined not only by the number of vulnerabilities, but also by the scale of the business and the company’s ability to protect its infrastructure.
Vendors
Products