top of page

Ransomware Now Targets the Mid-Market: 73% of Attacks

Aug 25
7 min read
mid-market-ransomware

By Yonatan Hoorizadeh, CISSP, CISM, CRISC, AAISM

Published By: Purple Shield Security

Published: August 24, 2026

Last updated: August 24, 2026


Mid-sized companies absorbed 73% of publicly disclosed ransomware and extortion incidents in North America and Europe between January 2023 and June 2026, according to Black Kite. More than half of those victims earned between $10 million and $50 million a year. That is the revenue band where full-time security leadership usually does not exist yet.

What did the Black Kite mid-market ransomware report find?


Black Kite analyzed 13,336 ransomware and data-extortion incidents with verifiable revenue across North America and Europe from January 2023 through June 2026. Companies with annual revenue between $10 million and $1 billion accounted for 73% of them. That share stayed between 72% and 75% across every half-year period in the study, which makes this a stable pattern rather than a single bad quarter.

More than half of the mid-market victims sat in the lower band, between $10 million and $50 million in annual revenue. Manufacturing was the most affected industry at more than a quarter of mid-market victims, followed by professional, scientific and technical services, and then construction.


Help Net Security reported the findings on August 24, 2026, drawing on Black Kite's study of the mid-market as a distinct target class. The same research assessed 120,128 mid-market organizations from the outside, using the view an attacker would have rather than an internal audit.


Why are ransomware groups picking companies this size?


Ransomware groups pick mid-market companies because these organizations are visible from the internet, reachable through weaknesses that are already public, and staffed too thinly to close those weaknesses quickly. Black Kite found that 54.7% of the 120,128 mid-market organizations it scanned had at least one significant patch-management problem affecting a public-facing system.


More than a quarter of those organizations carried a vulnerability already known to be exploited by attackers. That is a narrower and far more urgent category than the general vulnerability count, because it means working exploit code exists and someone is using it.


Stolen credentials open a second route. Nearly one-third of the monitored organizations had at least one stealer-log finding. A stealer log is the output of information-stealing malware sitting on an employee or contractor device, quietly harvesting saved passwords and active session cookies. Attackers buy those logs, then log in rather than break in.


None of this requires sophistication. It requires patience and a list. The uncomfortable part for a mid-market operator is that the list is generated automatically, from data that is visible to anyone who looks.


The exposure nobody owns: supplier and customer at the same time


Mid-market companies sit in the middle of other people's supply chains. They supply software, parts, and services to larger organizations while depending on their own vendors, cloud platforms, and technology providers. A single incident therefore lands in two directions at once, and in most mid-market companies neither direction has an owner.


Black Kite's report described these twin roles bluntly. The two sides, it said, are usually treated as “separate problems, handled by separate teams under separate budgets,” and in a mid-market company they are frequently handled by nobody at all.

The scale problem is concrete. The analysis described a typical mid-market vendor-risk team as two people responsible for more than 300 suppliers. Some of those suppliers never make it into a formal inventory, which means the security team cannot see the connection, let alone assess it.


Regulation is closing in on this gap from the customer side. Help Net Security noted that the EU's NIS2 Directive, along with U.S. requirements including NYCRR 500 and HIPAA, can obligate organizations to address supplier-linked risk. In practice that obligation flows downhill as contract language and security questionnaires, which is how most mid-market suppliers first discover they now need documented risk assessment services and evidence to back them up.


Does AI change the picture for smaller security teams?


AI is accelerating how software vulnerabilities are discovered and analyzed, and both sides have access to broadly similar capability. For a well-staffed enterprise security team, faster discovery is useful. For a mid-market team of two, it mostly lengthens the queue.


Finding a vulnerability does not tell anyone how urgent it is. Someone still has to determine whether the affected system is reachable from the internet, whether attackers are actively exploiting it, and what an attacker would reach next if they got through. That judgment is the scarce resource, not the scanning.


This is where AI security and vulnerability triage start to converge for smaller organizations. Treating several thousand findings as equally urgent is not a strategy. It is a way of guaranteeing that the twenty-six percent that are actively exploited get the same attention as the noise.


What a fractional CISO would actually do with this report


The 73% figure is the number getting quoted this week, but it is not the most useful one. The number that should change a decision is that more than half of the victims earned between $10 million and $50 million a year. That band is a structural gap: large enough to hold real customer data and appear in somebody else's supply chain, small enough that no one on payroll wakes up owning security.


Here is the part the coverage is underplaying. Three separate audiences are now grading these companies from the outside using nearly identical signals. Attackers scan for exposed and exploitable systems. Larger customers' vendor-risk teams request evidence of controls. Insurance underwriters assess external posture before they price the policy. None of the three calls you first, and all three are reading the same public surface.


The second thing worth naming is that this is usually framed as a resourcing problem. It is a prioritization problem wearing a resourcing costume. Two people can meaningfully defend a mid-market company. Two people cannot defend it while treating 300 suppliers and 3,000 findings as equally important. Adding headcount without adding a prioritization method just produces a larger backlog.


A useful decision rule: if your company earns between $10 million and $50 million and you sell to anyone materially larger than you, assume your security posture is already being scored by a customer you have never spoken to. Work backward from that assumption rather than waiting for the questionnaire.


When Purple Shield Security engages at this size, the first thirty days go to the external view, because that is the only view attackers, customers, and underwriters all share. A virtual Chief Information Security Officer (vCISO) is a part-time security executive who owns those calls without the cost of a full-time hire, and the first call is almost always about sequence rather than tooling.


What should a mid-market company do this week?


Five actions are worth taking in the next seven days. None of them require new spend, and all of them address the specific weaknesses the Black Kite data identified.

  1. Build an external inventory. List every system with a public IP address or public DNS record, including the ones IT does not formally own: marketing microsites, old VPN concentrators, staging environments, forgotten subdomains. The 54.7% patch-management finding lives in exactly these assets.

  2. Cross-check that inventory against CISA's Known Exploited Vulnerabilities catalog. Anything on both lists is your real queue. Everything else can wait until that queue is empty.

  3. Check for stealer-log exposure. If credentials tied to your domain are circulating, rotate them and invalidate active sessions. Then confirm that multi-factor authentication protects the identity provider itself, not just email.

  4. Tier your suppliers by blast radius. Sort them by what actually breaks if they go dark for a week or lose your data, not by contract value. Build questionnaires only for the top tier.

  5. Write down who owns each of the four items above, by name, with a date. If that assignment is ambiguous, the ambiguity is the finding.


Frequently asked questions


Does 73% mean mid-market companies are attacked more often than large enterprises?

It means they account for the large majority of publicly disclosed incidents where revenue could be verified. Black Kite's dataset covered 13,336 such incidents from January 2023 through June 2026. Large enterprises are attacked constantly, but they represent a much smaller share of the disclosed total and generally have dedicated staff to absorb the impact. The mid-market share is notable because it barely moved across seven half-year periods.

The study's floor is $10 million in annual revenue, following the Dun & Bradstreet revenue-based definition, so smaller companies were excluded from the dataset. The exposure pattern still applies. Firms under that line typically run the same internet-facing systems, sit in the same supply chains, and have even less budget assigned to security ownership. Treat the findings as directional rather than exclusionary.

Stop trying to assess all of them. Rank suppliers by what breaks if that vendor goes offline for a week or loses your data, and treat only the top tier as requiring active review. Black Kite described the two-person, 300-supplier ratio as a common mid-market pattern, which means it is the norm rather than a failure of your team. The failure would be spreading two people evenly across all 300.

They can. Help Net Security noted that these rules can require organizations to address risks linked to their suppliers, which pushes obligations downhill through customer contracts even when the supplier is not directly regulated. Most mid-market vendors encounter this first as a security questionnaire from a larger customer, not as a letter from a regulator. By then the answers are due on the customer's timeline.


Purple Shield Security works with companies in this exact revenue band, and the pattern is consistent: the security gap is rarely a missing tool, it is a missing owner. If you want an outside read on how your company looks to an attacker, a customer's vendor-risk team, and an underwriter, our risk assessment and fractional CISO services start there. You can reach the team through our cybersecurity consulting page.

 
 
bottom of page