Security1 publisherNot yet confirmed elsewhere2 min readPublished
Ransomware's victim list barely moves: 73% of disclosed hits landed on mid-market firms
Black Kite counted 13,336 disclosed incidents with known revenue from January 2023 to June 2026. Companies between $10M and $1B took 73%, and the share never left a three-point band.
The Watch · Security desk
What happened
- Black Kite says mid-sized companies took 73% of publicly disclosed ransomware and extortion incidents with known revenue in North America and Europe from January 2023 to June 2026.
- The sample was 13,336 incidents with known revenue, with mid-market defined as $10 million to $1 billion in annual revenue.
- That share never left the 72% to 75% range at any point in the period.
- More than half of the mid-market victims reported annual revenue below $50 million.
- Nearly a third of the 120,000-plus mid-market organisations monitored had at least one stealer-log finding, meaning credentials already harvested by malware.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Security spend modelled on sophisticated adversaries is being aimed at a victim population whose openings are patch state and reused passwords, which makes this a reallocation question rather than...
- constraint A remediation queue that size cannot be worked through at this segment's headcount, so ordering by internet exposure and confirmed exploitation is the only affordable triage rule.
- exposure Because a compromised supplier can expose customer data or open a route to connected organisations, large buyers inherit the mid-market's patch debt whether or not they audited for it.
- precedent Supplier-risk obligations under NIS2, NYCRR 500 and HIPAA flow downhill, so hygiene evidence becomes a procurement gate that prices mid-market security from outside.
The stable number is the one worth acting on. Black Kite's mid-market share sat inside a three-point band for the entire 42-month window [4][13], which makes it a base rate rather than a trend. Applied to the sample, 73% of 13,336 comes to roughly 9,735 mid-market victims [14], about 232 disclosed a month across the period [15].
What that share does not measure is risk per company. The count covers publicly disclosed ransomware and extortion incidents with known revenue [2], and the revenue band it uses runs from $10 million to $1 billion, a hundredfold spread [12]. Nothing in the published summary normalises by how many firms sit in each band, so the defensible reading is that this is where disclosed incidents land, not proof that a $40 million manufacturer is individually likelier to be hit than a $4 billion one. The distribution inside the band survives that caveat: more than 4,800 of those incidents fall in the $10 million to $50 million slice [19], and manufacturing alone accounts for more than 2,400 [6][20].
The entry conditions are measurable and dull. Of the 120,000-plus mid-market organisations Black Kite assessed, 54.7% had at least one significant patch-management problem on a public-facing system [7], which is more than 65,000 companies carrying a fixable gap at the internet edge [16]. More than a quarter had a vulnerability already known to be exploited in the wild [8], another 30,000 or so with a bug attackers have demonstrably used [17].
A programme built around adversary sophistication does not reach that list. Black Kite's own prescription is prioritisation, and its own figures show what prioritisation is up against: the typical vendor-risk team it describes is two people responsible for more than 300 suppliers [10], 150 each [18], with some software and services sitting outside the formal vendor inventory altogether [21]. Regulation pushes the same work downhill, with NIS2, NYCRR 500 and HIPAA all reaching supplier risk [11].
The weakest part of the analysis is the AI section. The framing is symmetrical: faster vulnerability discovery for defenders and attackers alike [22]. Symmetry is not a finding, and nothing in the incident data ties the 73% to automated discovery. The exposure figures suggest attackers have not needed the help. What the numbers describe is a target set selected by what is reachable and unpatched, which is a purchasing spec rather than a threat briefing.
What to watch
- Whether Black Kite publishes incident counts normalised per company in each revenue band, which would separate targeting from population size.
- Whether the 72 to 75 percent band holds in disclosures after June 2026, or breaks as leak-site reporting practices change.
- Whether NIS2 enforcement turns into contractual patch-state requirements on mid-sized suppliers rather than self-attestation.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence57
- Adoption
- Insufficient
- Hype gap+22
- Incentives68
- Confidence52
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion.
- [2]
The figures count publicly disclosed ransomware and data-extortion incidents with known revenue, not all incidents.
- [3]
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite.
- [4]
The mid-market share of incidents remained between 72% and 75% throughout the period.
- [5]
More than half of mid-market victims had annual revenue between $10 million and $50 million.
- [6]
Manufacturing was the most affected industry, accounting for more than a quarter of mid-market victims, followed by professional, scientific and technical services and construction.
- [7]
An assessment of more than 120,000 mid-market organizations found that 54.7% had at least one significant patch-management issue affecting a public-facing system.
- [8]
More than a quarter of the assessed mid-market organizations had a vulnerability already known to be exploited by attackers.
- [9]
Nearly one-third of the monitored organizations had at least one stealer-log finding, indicating credentials collected by information-stealing malware.
- [10]
A typical vendor-risk team described in the analysis consists of two people responsible for more than 300 suppliers.
- [11]
Rules such as the EU's NIS2 Directive and U.S. requirements including NYCRR 500 and HIPAA can require organizations to address risks linked to suppliers, and mid-sized vendors may be asked to provide customers with more information about their security controls.
- [12]
The mid-market band spans a hundredfold range of revenue.
- [13]
The observation window from January 2023 to June 2026 inclusive is 42 months.
- [14]
The 73% share implies roughly 9,735 mid-market incidents within the sample.
- [15]
That works out to about 232 disclosed mid-market incidents per month across the window.
- [16]
The patch-management rate implies more than 65,000 organizations with at least one such issue on a public-facing system.
- [17]
The known-exploited share implies more than 30,000 organizations carrying a vulnerability attackers are known to use.
- [18]
That staffing works out to at least 150 suppliers per person.
- [19]
More than 4,800 of the mid-market incidents fall in the $10 million to $50 million revenue slice.
- [20]
Manufacturing accounts for more than 2,400 of the mid-market incidents in the sample.
- [21]
Some software and services may sit outside formal vendor inventories, leaving security teams without a complete view of third-party risk.
- [22]
AI is accelerating how software vulnerabilities are discovered and analyzed, and attackers have access to many of the same capabilities as defenders.
- [23]
Mid-sized companies may have fewer people available to investigate and fix vulnerabilities, and knowing which systems are exposed and which weaknesses are being exploited helps determine what to fix first.
- [24]
A compromised supplier could expose customer data, interrupt services or give attackers another route to connected organizations.
Sources
1 independent publisher whose own reporting we read for this story.
- helpnetsecurity.comRansomware attackers are zeroing in on mid-market companies
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- RansomwareFollow
- Third-Party and Supply Chain RiskFollow
- Mid-Market SecurityFollow
- Security and Supplier-Risk RegulationFollow
- Vulnerability ManagementFollow
- Credential Theft and Stealer LogsFollow
Entities
- Black KiteFollow
- Help Net SecurityFollow
- NIS2 DirectiveFollow
- NYCRR 500Follow
- HIPAAFollow