;

Mid-Market Is the Routine Target

Ransomware, Third-Party Risk, and the Widening AI Gap

By The Black Kite Research Group™

This report is built to explore interactively below. For a static copy, download a PDF of this report.

Executive Summary

The way ransomware is usually described centers on the largest organizations, the incidents with the highest ransoms and the most recognizable names. That focus leaves the impression that ransomware is mainly an enterprise problem. The data points the other way, and this is the first time Black Kite has examined the mid-market as a segment in its own right rather than as a set of companies scattered through larger studies.

Across three and a half years of attacks (2023 - H1 2026) in North America and Europe, roughly three in four of the ransomware victims with a known revenue figure were mid-market companies earning between $10 million and $1 billion a year.

This report examines why the mid-market holds that position and what a company of this size can do about it. The report draws on two independent datasets: A record of 13,336 disclosed ransomware and extortion incidents with a verifiable revenue figure, showing which companies were attacked, and an external scan of 120,128 mid-market companies, showing how they looked from the internet before any attack. The second view matters because an attacker starts from the same place.

Ransomware's Default Target

of attacks hit mid-market organizations with annual revenues between $10M–1B

The report follows the mid-market through three positions it holds at once:

  • The routine target of ransomware, selected for what it exposes rather than who it is
  • A supplier whose exposure its larger customers are accountable for
  • A buyer carrying its own suppliers, often hundreds, with no dedicated team to watch them

The Gap Between Attacker and Defender Is Widening


AI is accelerating how fast new vulnerabilities are discovered, and the volume is climbing toward levels no small team can triage by hand. Only a fraction of those vulnerabilities are ever exploited, but finding that fraction across a company's own systems and its suppliers is exactly the work a mid-market team has little capacity to do.

What This Report Sets Out to Do


The chapters that follow set out that exposure and the steps that close it, on a scale that a mid-market security team can maintain rather than one that assumes an enterprise budget.

This report is also the first move in something larger. Black Kite is building for the mid-market directly, taking enterprise-level attack-surface and third-party-risk tools and sizing them for a smaller team and budget. The closing chapter shows what those tools can do today, whether a company runs them itself or has a managed security service provider (MSSP) run them on its behalf.

TABLE OF CONTENTS

01 | INTRODUCTION

Why Watching the Mid-Market Matters

02 | Who Gets Hit

Victim Profile by Size, Region, and Sector

03 | The Attacker's View

Shifting Groups, Constant Targets, and What They Already See

04 | supply chain

The Mid-Market's Hidden Role in Ecosystem Risk

05 | next steps

How to Address the Exposure Described in This Report

06 | methodology

Next: 9,781 victims. Here's who they were.

Geography, revenue, and sector all shaped who ransomware groups targeted.

NEXT PAGE