Security1 distinct publisher2 min readUpdated
Black Kite counted 13,336 disclosed incidents with known revenue from January 2023 to June 2026. Companies between $10M and $1B took 73%, and the share never left a three-point band.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The stable number is the one worth acting on. Black Kite's mid-market share sat inside a three-point band for the entire 42-month window [3][6], which makes it a base rate rather than a trend. Applied to the sample, 73% of 13,336 comes to roughly 9,735 mid-market victims [7], about 232 disclosed a month across the period [8].
What that share does not measure is risk per company. The count covers publicly disclosed ransomware and extortion incidents with known revenue [23], and the revenue band it uses runs from $10 million to $1 billion, a hundredfold spread [25]. Nothing in the published summary normalises by how many firms sit in each band, so the defensible reading is that this is where disclosed incidents land, not proof that a $40 million manufacturer is individually likelier to be hit than a $4 billion one. The distribution inside the band survives that caveat: more than 4,800 of those incidents fall in the $10 million to $50 million slice [21], and manufacturing alone accounts for more than 2,400 [5][22].
The entry conditions are measurable and dull. Of the 120,000-plus mid-market organisations Black Kite assessed, 54.7% had at least one significant patch-management problem on a public-facing system [9], which is more than 65,000 companies carrying a fixable gap at the internet edge [12]. More than a quarter had a vulnerability already known to be exploited in the wild [10], another 30,000 or so with a bug attackers have demonstrably used [13].
A programme built around adversary sophistication does not reach that list. Black Kite's own prescription is prioritisation, and its own figures show what prioritisation is up against: the typical vendor-risk team it describes is two people responsible for more than 300 suppliers [15], 150 each [16], with some software and services sitting outside the formal vendor inventory altogether [17]. Regulation pushes the same work downhill, with NIS2, NYCRR 500 and HIPAA all reaching supplier risk [18].
The weakest part of the analysis is the AI section. The framing is symmetrical: faster vulnerability discovery for defenders and attackers alike [19]. Symmetry is not a finding, and nothing in the incident data ties the 73% to automated discovery. The exposure figures suggest attackers have not needed the help. What the numbers describe is a target set selected by what is reachable and unpatched, which is a purchasing spec rather than a threat briefing.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion.
The figures count publicly disclosed ransomware and data-extortion incidents with known revenue, not all incidents.
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite.
The mid-market share of incidents remained between 72% and 75% throughout the period.
More than half of mid-market victims had annual revenue between $10 million and $50 million.
Manufacturing was the most affected industry, accounting for more than a quarter of mid-market victims, followed by professional, scientific and technical services and construction.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Large single-vendor dataset, disclosed scope, no corroboration
The core numbers are specific and their scope is stated: 13,336 disclosed incidents with known revenue, a named $10M-$1B mid-market definition, a 42-month window, and a separate assessment of more than 120,000 organizations. That is unusually explicit for a vendor report and the stability band (72%-75%) is a checkable consistency claim. Evidence quality is capped, though, by a single publisher relaying a single vendor's proprietary telemetry with no independent replication, no per-year absolute counts, and no base-rate adjustment for how many mid-market firms exist relative to large enterprises.
No adoption signal in supplied sources
The cluster contains research findings about victim distribution and exposure prevalence, not releases, deployments, pricing or license changes, and no disclosed usage of any product or standard. Nothing in the supplied material measures uptake, so adoption cannot be scored without inventing facts.
Targeting framing runs ahead of the disclosed-incident data
The headline framing -- attackers 'zeroing in' on the mid-market -- implies intentional targeting shift, while the data actually shows a share that has not moved for 42 months inside a population that is itself dominated by mid-market firms and filtered to publicly disclosed incidents with known revenue. The quantified findings themselves are modest and clearly bounded, and the article does state its scope limitation, so the gap is mild rather than severe. The AI-acceleration and third-party-visibility sections lean on unmeasured assertions, which widens the gap somewhat.
Vendor research aligned with third-party risk and exposure tooling
The findings originate with Black Kite, a third-party cyber risk rating vendor, and the article's conclusions -- know which systems are exposed, know which vulnerabilities are exploited, track suppliers you cannot inventory, expect customers to demand security-control evidence under NIS2, NYCRR 500 and HIPAA -- map directly onto that product category. The vendor-risk staffing anecdote (two people, 300-plus suppliers) is a classic capacity-gap framing. This is normal trade-press coverage of a vendor report rather than anything misleading, but the commercial alignment is not disclosed in the piece.
Numbers are usable directionally, single-source and unaudited
Confidence is moderate: the quantified claims are internally consistent, arithmetic on them holds, and the scope caveat is stated in the source. It is held down by single-publisher, single-vendor provenance, no adoption dimension at all, unexplained detection methodology behind the 120,000-organization assessment, and the missing base-rate control that would separate targeting from population mix.
security
Ransomware's price point is $10m to $1bn in revenue, and it is not moving1 distinct publisher
science
HIPAA Covers Less Than You Think, And "Anonymized" Is Not A Legal Shield1 distinct publisher
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 23, 2026