Security1 distinct publisher3 min readUpdated
Black Kite's read of 13,336 disclosed incidents puts 73% of victims in the mid-market, a share that held while volume rose 44%. The upper band is the only one shrinking.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Black Kite, a third-party risk vendor, analysed 13,336 disclosed ransomware incidents dating back to January 2023 and found that 73% of attacks in North America and Europe hit companies with $10m to $1bn in annual revenue [1][2][c5b]. That share barely moved while disclosed incident volume grew 44% between 2023 and 2025 [4], which argues the mid-market is not overflow from a saturated enterprise segment. It is the segment.
The report, published on August 18 as "Mid-Market Is the Routing Target", uses Dun & Bradstreet revenue bands: lower mid-market at $10m-$50m, core at $50m-$500m, upper at $500m-$1bn [5][7]. The lower band took the largest share of mid-market victims at 54% [8], rising from 1391 victims in 2024 to 1821 in 2025 [9]. The core band ran 40-45% of victims across the reporting period [10] and rose from 970 to 1474 [11]. Taken together those two bands went from 2361 to 3295 victims, up about 40%, with the core band growing faster (52%) than the lower band (31%) [1][3].
The upper mid-market moves the other way: 126 victims in 2023 down to 45 in 2025, a 65% decline [12]. By 2025 that leaves the $500m-$1bn band at roughly 1.4% of the lower-plus-core total [2]. The banding is coarse enough to notice: 54% for the lower band and 40-45% for the core leaves only 1-6% of mid-market victims for the upper band across the whole period [4]. One more caveat operators should apply themselves. The report was published on August 18 [5], so if the 2025 counts are partial-year, the growth in the lower and core bands is understated rather than inflated [5].
Geographically, North America accounted for 72% of incidents against Europe's 28%, with UK firms the most targeted in Europe [13]. Manufacturing was the single largest sector at 26% of mid-market victims, ahead of professional, scientific and technical services and construction [14]; Black Kite attributes this to low outage tolerance and sensitive data holdings [15]. That tracks with UK figures: Make UK reported in August that 30% of UK manufacturers had a cyber incident in the past year, directly or through their supply chain [16], and ESET data from April found 95% of affected UK manufacturers saw direct business impact and 53% took a financial loss, with supply chain disruption at 44% and missed customer or supplier commitments at 39% [17][18].
The posture side comes from Black Kite's own scan of 120,128 mid-market companies, so read it as vendor telemetry [6]. Nothing in it is exotic: 28% had at least one known exploited vulnerability [19], 55% had at least one significant patch management finding on public-facing software [20], 48% carried a disclosed vulnerability scoring 8.0 or higher on CVSS [21], 32% had a stealer log finding [22], and 47% had missing or insufficient DMARC [23]. Black Kite's own framing is capacity, not sophistication: AI is accelerating vulnerability discovery toward volumes "no small team can triage by hand" [24], and finding the exploited fraction across a company's systems and its suppliers is "exactly the work a mid-market team has little capacity to do" [25].
Watch whether the upper mid-market's 65% drop survives another year or turns out to be a disclosure artifact, since larger firms have more reason and more counsel to stay quiet [12]. Watch full-year 2025 counts against the 2361-to-3295 trajectory [1]. And watch whether third-party risk programs re-tier suppliers by revenue band rather than contract value, because on these numbers a $30m supplier is the likelier point of failure [8][9].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Black Kite analysed 13,336 disclosed ransomware incidents dating back to January 2023 for its new report.
The report found that 73% of ransomware attacks in North America and Europe hit companies with $10m-$1bn in annual revenue.
The 73% share barely moved even as the volume of incidents grew by 44% between 2023 and 2025.
The report, titled "Mid-Market Is the Routing Target", was published on August 18.
Black Kite also ran a separate security scan of 120,128 mid-market companies for the report.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Large sample, single unverified vendor source
The underlying datasets are big and specific - 13,336 disclosed incidents since January 2023 and a scan of 120,128 firms - and the article reports band definitions, shares and absolute counts that internally reconcile when re-added. But there is exactly one publisher and one primary source, no independent replication, no disclosure of how incidents were collected, and no year attached to the publication date, leaving the coverage boundary of the 2025 figures unresolved.
Observed at scale, through one vendor's lens
This is not a product-adoption story, so adoption is read as how much real-world observation stands behind it. Two substantial measured bases exist: 13,336 disclosed incidents across two-plus years and an exposure scan spanning 120,128 firms, plus two independent manufacturer datasets (Make UK, ESET) that corroborate the sector angle. It is held below high because all ransomware figures pass through a single vendor's collection method and disclosure-based counts systematically miss unreported attacks.
Framing outruns the arithmetic
Modestly overstated. The core numbers are reported straight, but the 'three-quarters target mid-market' framing supplies no denominator for how much of the company population sits in the $10m-$1bn band, so concentration is presented as attacker preference without the base rate needed to establish it. The unexplained 65% upper-band decline and the quoted claim that AI is pushing vulnerability volume beyond mid-market triage capacity - offered with no data, by a vendor selling that capacity - both push the narrative further than the evidence carries.
Vendor-authored, conclusions point at its own product
The report is produced by a third-party risk specialist, and its stated conclusion is that mid-market teams lack capacity to find exploitable vulnerabilities across their own systems and their suppliers - precisely the service such a vendor sells. The exposure scan of 120,128 firms is also the vendor's own instrumentation. That is a strong commercial alignment between findings and offering; it does not make the numbers wrong, but the selection and emphasis of which gaps to publish is not disinterested, and the coverage does not disclose the conflict.
Numbers likely sound, framing needs discounting
Confidence is moderate: the quantitative core is internally consistent and specific enough to check, and two outside datasets support the manufacturing thread, so the direction of the finding is probably right. It is capped by single-publisher, single-source provenance, a clear vendor incentive, an unresolved reporting-period boundary, and the absence of the denominator needed to convert concentration into a claim about attacker targeting.
security
Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management1 distinct publisher
build
NIST answers an NVD audit with an AI tool nobody outside NIST has seen1 distinct publisher
security
Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band1 distinct publisher
build
Buy transactional email on recovery controls, not send price1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026