Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Ransomware's victim list barely moves: 73% of disclosed hits landed on mid-market firms

Black Kite counted 13,336 disclosed incidents with known revenue from January 2023 to June 2026. Companies between $10M and $1B took 73%, and the share never left a three-point band.

The Watch · Security desk

How we use AISend a correction

What happened

  • Black Kite says mid-sized companies took 73% of publicly disclosed ransomware and extortion incidents with known revenue in North America and Europe from January 2023 to June 2026.
  • The sample was 13,336 incidents with known revenue, with mid-market defined as $10 million to $1 billion in annual revenue.
  • That share never left the 72% to 75% range at any point in the period.
  • More than half of the mid-market victims reported annual revenue below $50 million.
  • Nearly a third of the 120,000-plus mid-market organisations monitored had at least one stealer-log finding, meaning credentials already harvested by malware.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Security spend modelled on sophisticated adversaries is being aimed at a victim population whose openings are patch state and reused passwords, which makes this a reallocation question rather than...
  • constraint A remediation queue that size cannot be worked through at this segment's headcount, so ordering by internet exposure and confirmed exploitation is the only affordable triage rule.
  • exposure Because a compromised supplier can expose customer data or open a route to connected organisations, large buyers inherit the mid-market's patch debt whether or not they audited for it.
  • precedent Supplier-risk obligations under NIS2, NYCRR 500 and HIPAA flow downhill, so hygiene evidence becomes a procurement gate that prices mid-market security from outside.

The stable number is the one worth acting on. Black Kite's mid-market share sat inside a three-point band for the entire 42-month window [4][13], which makes it a base rate rather than a trend. Applied to the sample, 73% of 13,336 comes to roughly 9,735 mid-market victims [14], about 232 disclosed a month across the period [15].

What that share does not measure is risk per company. The count covers publicly disclosed ransomware and extortion incidents with known revenue [2], and the revenue band it uses runs from $10 million to $1 billion, a hundredfold spread [12]. Nothing in the published summary normalises by how many firms sit in each band, so the defensible reading is that this is where disclosed incidents land, not proof that a $40 million manufacturer is individually likelier to be hit than a $4 billion one. The distribution inside the band survives that caveat: more than 4,800 of those incidents fall in the $10 million to $50 million slice [19], and manufacturing alone accounts for more than 2,400 [6][20].

The entry conditions are measurable and dull. Of the 120,000-plus mid-market organisations Black Kite assessed, 54.7% had at least one significant patch-management problem on a public-facing system [7], which is more than 65,000 companies carrying a fixable gap at the internet edge [16]. More than a quarter had a vulnerability already known to be exploited in the wild [8], another 30,000 or so with a bug attackers have demonstrably used [17].

A programme built around adversary sophistication does not reach that list. Black Kite's own prescription is prioritisation, and its own figures show what prioritisation is up against: the typical vendor-risk team it describes is two people responsible for more than 300 suppliers [10], 150 each [18], with some software and services sitting outside the formal vendor inventory altogether [21]. Regulation pushes the same work downhill, with NIS2, NYCRR 500 and HIPAA all reaching supplier risk [11].

The weakest part of the analysis is the AI section. The framing is symmetrical: faster vulnerability discovery for defenders and attackers alike [22]. Symmetry is not a finding, and nothing in the incident data ties the 73% to automated discovery. The exposure figures suggest attackers have not needed the help. What the numbers describe is a target set selected by what is reachable and unpatched, which is a purchasing spec rather than a threat briefing.

What to watch

  • Whether Black Kite publishes incident counts normalised per company in each revenue band, which would separate targeting from population size.
  • Whether the 72 to 75 percent band holds in disclosures after June 2026, or breaks as leak-site reporting practices change.
  • Whether NIS2 enforcement turns into contractual patch-state requirements on mid-sized suppliers rather than self-attestation.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence57
Adoption
Insufficient
Hype gap+22
Incentives68
Confidence52
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion.

  2. [2]

    The figures count publicly disclosed ransomware and data-extortion incidents with known revenue, not all incidents.

  3. [3]

    Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite.

    ReportedSupportedSource: Black Kite, reported by Help Net SecurityView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. helpnetsecurity.com

    1 article · August 23, 2026

    Ransomware attackers are zeroing in on mid-market companies

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories