Current Exposure
What Victims Are Still Showing Today
The aftermath shows what changed after disclosure. The signal layer shows what remains visible today.
Black Kite’s latest current-state analysis found that ransomware victims continue to carry exposure signals that are directly useful for attacker prioritization. These signals show what remains visible after the incident closes: conditions that attackers can observe, rank, and reuse.
Share of Ransomware Victims Carrying Key Exposure Signals, Current State
Patch Debt
The strongest current signal was patch debt. Nearly three in five victims (62.5%) still carried at least one medium-or-higher severity patch vulnerability. That exposure extended well into the critical range: CVSS 8.0 or higher vulnerabilities appeared in 57.7% of victims, while CVSS 9.0 or higher vulnerabilities were present in 43.5%. KEV exposure remained visible in 30.8%, meaning nearly one in three victims still carried a vulnerability known to be exploited in the wild.
Email and Identity
Email and identity adjacent exposure also remained prominent. Misconfigured DMARC records appeared in 58.9% of victims, while DKIM misconfiguration appeared in 32.1%. Stealer log findings remained visible in 29.6%. These signals matter because ransomware operators do not need a single perfect entry point. They need enough evidence that access may be available, identities may be weak, or trust controls may be incomplete.
FocusTag® Signals
FocusTag data adds a more product specific layer to this picture. FocusTag signals appeared in 18.5% of victims, and 87.1% of those signals were rated High or Very High severity. Victims carrying FocusTag signals showed an average RSI of 0.705, compared with 0.588 for those without. KEV-carrying victims showed a similar pattern, with an average RSI of 0.675 versus 0.580 for non-KEV victims.
Salesforce Aura and Salesforce Client were among the most visible CRM related signals, and a subset of victims carried both KEV and Salesforce related exposure. These differences make FocusTag and KEV useful prioritization layers, not proof of causation.
The Salesforce overlap shows that SaaS and CRM exposure can coexist with known exploited vulnerability exposure inside the same victim population, not that Salesforce was a direct compromise path.
The Supply Chain Surfaces Are Still Showing
The technology surfaces described in Chapter 06 remain directly relevant here. Email infrastructure, Salesforce and CRM integrations, remote access tools, and internet-facing applications were among the most visible technology surfaces in the current victim analysis. These are the connective tissue of modern operations, and the current signal data shows they remain exposed.
Sector context sharpens the view. Education remained one of the clearest examples of signal concentration. Even though it did not lead by victim count, it carried the weakest average RSI profile among major sectors and elevated stealer log exposure, reinforcing that ransomware risk should not be measured only by volume.
For security teams, the lesson is practical: Post-incident work should not stop at recovery. It should include a current state exposure review, because the signals described above do not disappear when the incident closes.
Next: AI didn't redefine ransomware, but it lowered the cost.
The broader ransomware market has not become autonomous. The near-term question is how AI will change the attack chain as it begins to assist and, in isolated cases, orchestrate parts of it.