Skip to content

Security1 publisher3 min readPublished

Ransomware's price point is $10m to $1bn in revenue, and it is not moving

Black Kite's read of 13,336 disclosed incidents puts 73% of victims in the mid-market, a share that held while volume rose 44%. The upper band is the only one shrinking.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Black Kite analysed 13,336 disclosed ransomware incidents dating back to January 2023 for its new report.
  • The report found that 73% of ransomware attacks in North America and Europe hit companies with $10m-$1bn in annual revenue.
  • The 73% share barely moved even as the volume of incidents grew by 44% between 2023 and 2025.
  • The report, titled "Mid-Market Is the Routing Target", was published on August 18.
  • Black Kite is a third-party risk specialist.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Black Kite, a third-party risk vendor, analysed 13,336 disclosed ransomware incidents dating back to January 2023 and found that 73% of attacks in North America and Europe hit companies with $10m to $1bn in annual revenue [1][2][c5b]. That share barely moved while disclosed incident volume grew 44% between 2023 and 2025 [4], which argues the mid-market is not overflow from a saturated enterprise segment. It is the segment.

The report, published on August 18 as "Mid-Market Is the Routing Target", uses Dun & Bradstreet revenue bands: lower mid-market at $10m-$50m, core at $50m-$500m, upper at $500m-$1bn [5][7]. The lower band took the largest share of mid-market victims at 54% [8], rising from 1391 victims in 2024 to 1821 in 2025 [9]. The core band ran 40-45% of victims across the reporting period [10] and rose from 970 to 1474 [11]. Taken together those two bands went from 2361 to 3295 victims, up about 40%, with the core band growing faster (52%) than the lower band (31%) [1][3].

The upper mid-market moves the other way: 126 victims in 2023 down to 45 in 2025, a 65% decline [12]. By 2025 that leaves the $500m-$1bn band at roughly 1.4% of the lower-plus-core total [2]. The banding is coarse enough to notice: 54% for the lower band and 40-45% for the core leaves only 1-6% of mid-market victims for the upper band across the whole period [4]. One more caveat operators should apply themselves. The report was published on August 18 [5], so if the 2025 counts are partial-year, the growth in the lower and core bands is understated rather than inflated [5].

Geographically, North America accounted for 72% of incidents against Europe's 28%, with UK firms the most targeted in Europe [13]. Manufacturing was the single largest sector at 26% of mid-market victims, ahead of professional, scientific and technical services and construction [14]; Black Kite attributes this to low outage tolerance and sensitive data holdings [15]. That tracks with UK figures: Make UK reported in August that 30% of UK manufacturers had a cyber incident in the past year, directly or through their supply chain [16], and ESET data from April found 95% of affected UK manufacturers saw direct business impact and 53% took a financial loss, with supply chain disruption at 44% and missed customer or supplier commitments at 39% [17][18].

The posture side comes from Black Kite's own scan of 120,128 mid-market companies, so read it as vendor telemetry [6]. Nothing in it is exotic: 28% had at least one known exploited vulnerability [19], 55% had at least one significant patch management finding on public-facing software [20], 48% carried a disclosed vulnerability scoring 8.0 or higher on CVSS [21], 32% had a stealer log finding [22], and 47% had missing or insufficient DMARC [23]. Black Kite's own framing is capacity, not sophistication: AI is accelerating vulnerability discovery toward volumes "no small team can triage by hand" [24], and finding the exploited fraction across a company's systems and its suppliers is "exactly the work a mid-market team has little capacity to do" [25].

Watch whether the upper mid-market's 65% drop survives another year or turns out to be a disclosure artifact, since larger firms have more reason and more counsel to stay quiet [12]. Watch full-year 2025 counts against the 2361-to-3295 trajectory [1]. And watch whether third-party risk programs re-tier suppliers by revenue band rather than contract value, because on these numbers a $30m supplier is the likelier point of failure [8][9].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories