Methodology
This report was assembled by the Black Kite Research Group from two independent datasets: Ransomware incident tracking across North America and Europe, and a snapshot of externally observable risk findings across the monitored mid-market population. The first establishes which companies were attacked. The second describes how companies of this size appear from the internet.
1. Market Definition
The mid-market is defined by annual revenue, following the Dun & Bradstreet revenue-based definition, with no employee-count criterion applied. Three bands are reported: Lower mid-market at $10 million to $50 million, core mid-market at $50 million to $500 million, and upper mid-market at $500 million to $1 billion. Companies below $10 million and at or above $1 billion fall outside the segment and appear in this report only where they bracket a mid-market figure for context.
2. Geographic and Temporal Scope
The study covers North America, comprising the United States and Canada, and 31 European countries: The 27 European Union member states together with the United Kingdom, Switzerland, Norway and Turkey. The ransomware data spans January 2023 to June 2026 and is analyzed across seven half-year periods.
3. Ransomware Data and Scope Filtering
The ransomware data covers publicly disclosed ransomware and data extortion incidents, retained only once an incident was marked ready for publication. Of 21,520 records, 20,411 met that condition, and 15,971 fell within the geographic scope. Of these, 13,336 carried an annual revenue figure permitting assignment to a revenue band, and 9,781 fell within the mid-market. The remainder comprised 2,931 incidents below $10 million and 624 at or above $1 billion. Shares drawn from this dataset are shares of incidents with a known revenue figure, and the denominator is stated wherever a share appears. Victim counts in this report refer to disclosed incidents.
4. Victim Counting and Period Assignment
Each incident is assigned to a period by its date of public disclosure. Where a record carried a year value inconsistent with its disclosure date, the disclosure date governs. Distinct disclosures are counted as distinct incidents, which means a company claimed by two groups on separate dates appears twice. Attacks against chains, networks or holding structures are counted as a single incident unless distinct disclosures exist.
5. Industry Classification
Industry and subindustry classifications follow the North American Industry Classification System (NAICS). Sector figures are built from the two-digit NAICS sector and subindustry analysis from the more detailed codes, so that a sector such as manufacturing is measured by its NAICS classification rather than by a broader label.
6. Population and Exposure Data
Exposure findings are drawn from a separate dataset covering 120,128 mid-market companies monitored by Black Kite across North America and Europe, comprising 41,960 in the lower band, 77,633 in the core band and 535 in the upper band. This is a snapshot taken in June 2026, so all exposure figures are point-in-time and no trend is claimed from them. This population represents the mid-market companies within Black Kite's monitored universe and is not presented as a sample of the total mid-market.
7. Vulnerabilities
Vulnerability records are restricted to disclosed vulnerabilities scored 8.0 and above on the Common Vulnerability Scoring System, so every vulnerability figure in this report describes flaws of high or critical severity.
8. Limitations
The report reflects only publicly disclosed incidents and externally observable risk indicators. Those involving smaller organizations or those resolved discreetly, go unreported.
Incidents without a revenue figure cannot be assigned to a band and are therefore excluded from all revenue-based figures in this report.