BusinessCybersecurityNewswireTechnology

Ransomware Hits Mid-Market Firms in 75% of Attacks

Originally published on: August 19, 2026
▼ Summary

– 73% of ransomware attacks in North America and Europe since 2023 hit mid-sized firms with $10m-$1bn annual revenue, with lower mid-market companies ($10m-$50m) accounting for 54% of victims.
– Victim counts rose sharply in lower and core mid-market segments between 2024 and 2025, while upper mid-market victims fell 65% from 126 to 45; North America saw 72% of incidents versus 28% in Europe.
– Manufacturing was the top target at 26% of mid-market victims, followed by professional/scientific/technical services and construction, due to low outage tolerance and sensitive data.
– Security gaps in mid-market firms included 28% with known exploited vulnerabilities, 55% with patch management issues, 48% with high-severity CVSS 8.0+ flaws, 32% with stealer logs, and 47% lacking DMARC protection.
– AI is accelerating vulnerability discovery, making manual triage increasingly difficult for small mid-market security teams, who must also monitor supplier risks.

Nearly three out of every four ransomware incidents since early 2023 have targeted mid-sized businesses, a fresh analysis from Black Kite reveals. The firm, which specializes in third-party risk, examined 13,336 publicly disclosed attacks alongside security scans of 120,128 mid-market organizations to produce its latest report, Mid-Market Is the Routing Target.

Released on August 18, the study uses Dun & Bradstreet’s revenue classifications to define the space: lower mid-market ($10m-$50m), core mid-market ($50m-$500m), and upper mid-market ($500m-$1bn). The numbers show that 73% of ransomware cases across North America and Europe struck companies earning between $10m and $1bn annually. That proportion held remarkably steady even as the total volume of incidents jumped 44% from 2023 to 2025.

Within that group, the lower mid-market absorbed the biggest blow, accounting for 54% of victims over the entire period. The absolute count in this tier climbed from 1,391 in 2024 to 1,821 in 2025. The core mid-market followed closely, representing 40% to 45% of victims each year, with numbers rising from 970 to 1,474 over the same stretch. Upper mid-market firms, by contrast, saw a sharp drop, falling from 126 incidents in 2023 to just 45 in 2025, a 65% decline.

Geography also played a role. North America hosted 72% of the attacks, while Europe accounted for the remaining 28%, with UK companies emerging as the region’s primary targets.

Manufacturing stood out as the most frequently hit sector, making up 26% of all mid-market ransomware victims. Professional, scientific, and technical services, along with construction, rounded out the top three. The appeal of manufacturers is clear: they have little tolerance for downtime and guard highly sensitive data, a combination that makes them prime candidates for extortion.

That reality is reflected in recent UK data. A Make UK survey from August found that nearly a third of British manufacturers (30%) dealt with a cyber incident in the past year, either directly or via their supply chain. ESET research from April added further weight, showing that 95% of affected manufacturers said the attack hurt their operations, and 53% reported financial losses. Supply chain interruptions (44%) and missed customer or supplier deadlines (39%) were also frequent outcomes.

Black Kite’s deep dive into the security posture of more than 120,000 mid-market firms surfaced several weaknesses that could invite compromise. Among the findings:

  • 28% had at least one known exploited vulnerability (KEV)The pressure on these organizations is only expected to intensify as artificial intelligence reshapes the threat landscape. “AI is accelerating how fast new vulnerabilities are discovered, and the volume is climbing toward levels no small team can triage by hand,” the report warns. “Only a fraction of those vulnerabilities are ever exploited, but finding that fraction across a company’s own systems and its suppliers is exactly the work a mid-market team has little capacity to do.”
(Source: Infosecurity Magazine)

Topics

ransomware targeting 98% mid-market cybersecurity 95% incident statistics 92% vulnerability management 90% security posture deficiencies 89% manufacturing sector risks 88% Supply Chain Attacks 85% geographic attack patterns 82% ai security impact 80% financial losses 78%