The Attacker's View


The Perspective That Decides Who Gets Attacked

A Growing Field of Attackers: The Names Change Every Year, the Targets Do Not

Who's Leading Now

A mid-market company attacked in 2023 and attacked again in 2026 would almost certainly be facing two different groups. Of the 60 ransomware operators that claimed mid-market victims in North America and Europe during 2023, only 17 were still active in the first half of 2026. The other 43 have disappeared. Nearly half of the mid-market victims recorded in the first six months of 2026, 824 of 1,690, were claimed by groups that do not appear anywhere in the 2023 record.

The turnover is visible at the top of the list.

  • Qilin claimed 14 mid-market victims in 2023 and 303 in the first half of 2026 alone, passing through 79 in 2024 and 532 in 2025 to become the most active operator in the dataset with 928 victims. It now leads in both regions, with 196 North American and 107 European victims in the first half of 2026.
  • Akira followed a slower path to second place, moving from 93 victims in 2023 to 387 in 2025.
  • Behind them sits a group that did not exist as a meaningful presence a year ago: The Gentlemen recorded 10 mid-market victims in 2025 and 127 in the first half of 2026, third overall, with 78 of those victims in Europe.

Who's Disappeared

The exits are as abrupt as the entries.

LockBit 3.0

was the largest single threat to mid-market companies in 2023 with 391 victims. It fell to 223 in 2024, then 13 in 2025, then none at all in 2026, while a successor brand carrying the same name claimed 45 victims in the first half of the year.

RansomHub

had no mid-market victims at all in 2023, claimed 212 in 2024, and was gone by 2026. Hunters followed a similar rise and disappearance, climbing from 13 victims in 2023 to 132 in 2024, then falling to 27 in 2025 and to zero in 2026.

Black Basta

held steady across 2023 and 2024 at 149 and 158 victims before collapsing to 7 and then to none.

AlphaVM (BlackCat)

went from 198 victims to 25 and then to zero within two years.

None of these disappearances made mid-market companies safer.

Total mid-market victims rose from 2,320 in 2023 to 3,340 in 2025 while this churn was happening, and the number of distinct groups working the segment rose alongside it, from 60 to 85 to 109.

The first half of 2026 alone already carries 87 distinct names, and 30 of them are new to the dataset. The same has been true in every half-year since 2023: Roughly one in three groups active in any given period had never been seen before.

The ecosystem does not shrink when a group is dismantled or abandons its brand. Its work is redistributed, and often it is redistributed faster than the disruption removes it.

Where Groups Concentrate by Revenue


What stays constant through the turnover is who gets attacked. Every one of the twenty most active groups draws the majority of its victims from companies below $500 million in revenue, and the concentration at the top of the list has held steady, with the five largest groups accounting for between 40.3% and 50.1% of mid-market victims on a yearly basis.

Within the mid-market, groups do settle at different points on the revenue range. The median victim revenue across all mid-market victims is $46.2 million.

  • Sinobi works well below it at $25.0 million, taking 73.9% of its victims from the lower band.
  • 8Base, BianLian and INC Ransom sit in the same territory with medians between $34.6 million and $35.5 million.
  • Black Basta's median victim earned $60.7 million and 52.2% of its victims came from the core band, with Hunters ($57.0 million) and Clop ($55.2 million) close behind.
  • Clop shows the strongest pull toward the top of the segment: It accounts for 6.1% of all mid-market victims, and for 39 of the 270 victims in the upper band, which is 14.4% of that band.

This has a direct operational consequence.

A mid-market security program cannot be organized around threat actor names. Three of the five groups that led the 2023 list had left the data entirely by 2026, and 30 new names arrived in the first half of 2026 alone. What persists across every transition is the route in: Internet-facing systems that any group can find and evaluate.

What the Mid-Market Exposes From a Threat Actor’s Perspective

The ransomware data answers who was attacked. It cannot answer another important question a mid-market company actually needs answered: How does a mid-market company look to an attacker? That outside view exists whether or not a company has ever seen it and it is the point every attacker starts from.

Black Kite built that view for the segment. Using only what each company exposes to the internet, Black Kite assessed 120,128 mid-market organizations across North America and Europe the way an adversary would: From the outside, looking for the way in.

The findings below are the most complete external picture of mid-market exposure Black Kite has assembled.

Two things make this view matter for a mid-market company in particular. The first is that every figure below was produced without asking a single company for anything.

The second is that watching this surface is precisely the work a mid-market security team is least equipped to do. A large enterprise assigns it to a dedicated security team with a budget; a company in this segment is often watching the surface with a handful of people, or no security staff at all, and the budget pressure decides what gets watched and what does not. The exposure is visible to everyone, and the question is who has the capacity to act on it first.

More Than One in Four Companies Is Already Exposing a Vulnerability Attackers Use


Mid-market companies carrying at least one known exploited vulnerability (KEV)

The clearest single measure in that population is the presence of a known exploited vulnerability (KEV), a flaw confirmed to be under active use.

Across the mid-market population, 33,955 companies carry at least one such flaw on an internet-facing system, which is 28.3% of the total.

The rate climbs with company size, standing at 23.9% in the lower band and 30.4% in the core band, and reaching 52.0% among upper mid-market companies.

That progression reflects arithmetic more than it reflects security practice. A company running fifteen domains, several cloud environments, and a customer portal presents more for a scanner to catalogue than a company running one website and a mail server, so the larger organization is more likely to carry at least one finding.

The Majority Run at Least One Unpatched Public-Facing System


Companies with at least one significant patch-management finding

Patch management shows the same shape at a higher level. At least one significant patch management finding on public-facing software appears at 54.7% of the monitored mid-market population.

Within the bands the figures are 51.9% for lower mid-market, 56.1% for core, and 75.7% for the upper band. The same arithmetic explained in the KEV section above also explains this climb, and it holds for every exposure finding that follows except DMARC, where larger companies actually do better.

Nearly Half the Segment Carries a Vulnerability of High or Critical Severity


Companies carrying a disclosed flaw rated 8.0+ CVSS

Counting companies with at least one unpatched system describes how widespread the problem is. The vulnerability data adds that dimension: 57,740 mid-market companies, 48.1% of the monitored population, carry at least one disclosed flaw rated high or critical, meaning a CVSS score of 8.0 or above.

Companies in that group do not typically carry one. The median is four distinct vulnerabilities and the average is six, rising from 5.1 in the lower band to 6.5 in the core band. Severity within that group sits well above the qualifying threshold, with half of all vulnerabilities found across the segment scoring 8.8 or higher and a quarter scoring 9.5 or higher, on a scale that ends at 10.

The affected share follows the pattern established by the earlier findings, running at 45.3% in the lower band and 49.4% in the core band, and reaching 66.4% within the upper band.

A Third of the Segment Has Credentials Already in Circulation


Companies with a stealer-log finding

Infostealer malware runs on an infected machine, harvests the credentials saved in its browser, and delivers them to channels where they are collected and traded. The company that owns those credentials takes no part in any step of that sequence and generally learns of it late, if at all.

Across the monitored mid-market population, 32.3% of companies carry a stealer log finding, running at 26.8% in the lower band and 35.0% in the core band, and reaching 74.2% within the upper band.

For roughly one company in three, the question of how an attacker gets in has a shorter answer than any vulnerability provides: They log in.

Nearly Half Have Not Finished Email Authentication


Companies with missing or insufficient DMARC protection

DMARC instructs receiving mail servers what to do with messages that claim to come from a company's domain and fail authentication. Without a DMARC record, or with one set to a policy that takes no action, forged mail carrying the company's name arrives at its destination like any other message.

Across the monitored mid-market population, DMARC is missing or configured with insufficient protection at 46.8% of companies.

DKIM, which signs outgoing mail so that receiving servers can confirm it has not been altered in transit, is missing or misconfigured at 24.2%.

DMARC failure stands at 47.6% in the lower band and 46.4% in the core band, dropping to 31.0% within the upper band, and DKIM failure follows the same shape at 23.6%, 24.5%, and 16.3%. This is the exception flagged earlier: DMARC and DKIM failure both fall as company size increases, because email authentication comes down to configuration discipline, not footprint.

None of these findings required a breach to discover, a budget to run, or a large team to read. They are the product of an external scan, which is why they sit within reach of the companies they describe rather than beyond it.

Seeing an entire segment from the outside is also where a tool built for these companies would have to start. That same picture is not the company's alone. Every enterprise it sells to can run the same scan against it, and a growing number of them are now required to, held accountable by regulation for the security of their suppliers.

The AI-Driven Gap Between Exposure and Capacity

The exposure in the preceding section is measured against today's conditions. Those conditions are about to change, and the direction of the change works against a company that defends itself with a small team.

More Disclosures, Few That Matter

Artificial intelligence is accelerating the discovery of software vulnerabilities, and the same tools that help a company find flaws in its own systems are available to attackers, a trend that's hardest to keep up with for a small security team.

New vulnerabilities are now surfacing faster than any manual process was built to handle. In 2025, more than 48,000 vulnerabilities were disclosed across the software the world runs on. As AI-assisted discovery becomes routine, that annual figure is widely expected to climb into the hundreds of thousands.

The volume itself is not the whole problem. What makes it dangerous is how few of those vulnerabilities actually matter, and how hard the few are to find in the many. Of those 48,000 disclosed vulnerabilities in 2025, roughly 800, about 1.6%, were actually exploited by attackers in the wild. Black Kite's own supply chain research narrows the point further: Of the full year's disclosures, only 58 posed a genuine threat to enterprise supply chains. The challenge was never the 48,000. It is finding the 800, and then the far smaller number of those that touch a specific company or its suppliers, before an attacker reaches them first.

The Challenge Was Never the 48,000

CVEs

➔

Exploited

➔

Supply Chain Threats

Same Tools, Different Capacity to Use Them

Sorting a flood of disclosures down to the few that matter, continuously, across a company's own systems and every supplier it depends on, is compute-intensive and labor-intensive work. A large enterprise can fund it, staffing a dedicated function and paying for the processing that automated triage at this scale requires. A mid-market company competes for the same talent and the same capacity from a fraction of the budget, and usually without a dedicated security team at all.

The published research shows mid-market companies lagging in AI adoption for security overall. Mid-market companies have adopted AI in earnest, at rates a tier below the largest enterprises: Eurostat recorded 30.36% of medium-sized European enterprises using at least one AI technology in 2025, with the OECD finding a similar level across G7 economies.

Where they fall furthest behind is security. ISC2's 2025 survey found firms in the middle of the size range using AI in their security operations at 20%, below organizations a fraction of their size, and of every AI use case Eurostat tracks, security shows the widest gap between midsize and large firms.

Mid-Market Has Adopted AI. Just Not for Security.

of mid-sized European enterprises use at least one AI technology (Eurostat, 2025)

of mid-market firms use AI in their security operations (ISC2, 2025)

The segment is putting AI into the work that earns revenue and leaving it out of the work that defends it, and the reason is the same constraint: The tools that make discovery cheap for everyone do not make defending against it cheap for a team this size, and access to a capable model does not close the gap, because the constraint is the sustained capacity to act on what the model finds, not the model itself.

Attackers Respond to Cost

As larger enterprises apply these same techniques to find and close their vulnerabilities earlier, before software reaches production, the cost of breaching them rises. Attackers respond to cost. A segment that is easier to reach, and less equipped to sort its exposure quickly, becomes relatively more attractive as the better-defended tier hardens.

The mid-market does not have to become more exposed in absolute terms to become a more efficient target; it only has to fall further behind the tier above it.

Next: 300+ vendors, 2 people to watch them.

You're not just a target. You're somebody else's third party, and you have third parties of your own.

PREVIOUS
NEXT