The way ransomware gets covered centers on the biggest names and the highest ransoms. That framing leaves the impression that ransomware is mainly an enterprise problem. The data says otherwise.
Across three and a half years of attacks, from 2023 through the first half of 2026 in North America and Europe, roughly three in four ransomware victims with a known revenue figure were mid-market companies earning $10 million to $1 billion a year. This is the first time the Black Kite Research Group has studied the mid-market as its own segment, rather than as companies scattered through larger studies.
This report draws on two datasets. One tracks 13,336 disclosedransomware and extortion incidents with a verifiable revenue figure. The other is an external scan of 120,128 mid-market companies as they looked from the internet before any attack happened, the sameoutside-in assessment an attacker uses to pick a target.
The report follows the mid-market through three positions it holds at once: ransomware's routine target, asupplier larger customers hold accountable, and a buyer carrying its own suppliers, often hundreds, with no dedicated team to watch them. AI is accelerating vulnerability discovery faster than any small team can triage by hand. This report is your blueprint for closing that gap at a scale a mid-market security team can actually maintain.
Key Findings From the 2026 Mid-Market Ransomware Report
73% of Ransomware Attacks Target Mid-Market Companies
Black Kite's analysis of 13,336 ransomware incidents with verifiable revenue, from January 2023 to June 2026, found 73% struck companies earning $10 million to $1 billion a year. That concentration has held remarkably steady: 74.6% in 2023, 72.1% in 2024, 74.0% in 2025, and 72.3% in the first half of 2026. Total incidents grew 44% over the same window, from 2,320 in 2023 to 3,340 in 2025, and the mid-market's share of the damage never moved.
28.3% of Companies in the Dataset Already Carry a Known Exploited Vulnerability
Across 120,128 monitored companies, 33,955 carry at least one known exploited vulnerability (KEV) on an internet-facing system, a rate that climbs from 23.9% in the lower revenue band to 52.0% in the upper band, driven mostly by the larger surface area bigger companies expose, not weaker security posture.
54.7% of the Segment Runs at Least One Unpatched Public-Facing System
More than half the monitored population carries a significantpatch management finding on public-facing software, rising from 51.9% in the lower band to 75.7% in the upper band.
48.1% of Companies Monitored Carry a High or Critical Severity Vulnerability
57,740 companies, 48.1% of the monitored population, carry at least one disclosed flaw rated 8.0 or higher on the CVSS scale. Companies in this group carry a median of four such vulnerabilities, and a quarter of all vulnerabilities found across the segment score 9.5 or higher.
32.3% Already Have Credentials Circulating in Stealer Logs
For roughly one company in three, attackers don't need a vulnerability. Infostealer malware harvests browser-saved credentials and delivers them to channels where they're traded. The company that owns those credentials generally learns of it late, if at all.
Key Stats:
0%
Of ransomware victims are mid-market companies
0
Mid-market incidents recorded, 2023–H1 2026
0.0%
Carry a known exploited vulnerability
0.0%
Run an unpatched public-facing system
0.0%
Carry a high or critical severity vulnerability
0.0%
Have credentials circulating in stealer logs
Just 20%
Use AI in security operations
Ransomware Victims by Size, Region, and Sector
50.5% to 57.2% of Victims Sit in the Lower Revenue Band ($10M to $50M)
Companies earning $10 million to $50 million make up the largest slice of mid-market victims every year in the dataset. In 2024, the year law enforcement disrupted LockBit and Clop, victim counts fell in the two larger bands. Lower mid-market attacks grew 18.8% that same year, from 1,171 to 1,391.
72.4% of Victims Are North American, but Europe Is Closing the Gap
Of 9,781 mid-market incidents in the full window, 7,079 are North American and 2,702 are European, but that balance reversed sharply in the first half of 2026. European mid-market victims reached 545 in six months, a 47.3% increase year over year, while North American counts declined 10.8%. The U.S. alone accounts for 6,486 of the 9,781 victims. Black Kite's2026 Europe Cyber Risk Report covers that regional shift in full.
25.8% of Ransomware Victims Are Manufacturers
Manufacturing accounts for more mid-market victims than the next two sectors combined, 2,521 of 9,781, and its share climbed from 20.7% in 2023 to a peak of 28.0% in 2025 before easing to 27.0% in the first half of 2026.Manufacturers run some of the longest, most opaque supplier chains of any sector, where Black Kite'sransomware threat intelligence applies most directly. Professional and technical services and construction follow as the next two most exposed sectors, withhealthcare,wholesale and retail trade, andtechnology and information rounding out the top six.
928 Victims From One Group Alone, and the Roster Still Turns Over Constantly
Of the 60 ransomware operators active against the mid-market in 2023, only 17 remained active by the first half of 2026. Qilin is now the most activethreat actor in the dataset with 928 victims, passing Akira and newcomer The Gentlemen, which logged 127 victims in just six months. Roughly one in three groups active in any half-year period has never been seen before, so a program built around named adversaries has a short shelf life.
What the Mid-Market Exposes From an Attacker's Perspective
46.8% of Companies Have Not Finished Email Authentication
DMARC is missing or insufficiently configured at 46.8% of monitored companies, and DKIM at 24.2%. This is the one finding in the report that improves with company size rather than worsening, since email authentication is a matter of configuration discipline, not attack surface.
The Challenge Was Never the 48,000 Disclosed CVEs
More than 48,000 CVEs were published in 2025, but only about 800, 1.6%, were ever exploited in the wild. Black Kite'ssupply chain research narrows that further: just 58 posed a genuine threat to enterprise supply chains. That gap in scale is now a gap in speed, too.Black Kite's follow-on analysis found large enterprises using AI-powered scanning have cut detection to 14 days and remediation to 21, while mid-market vendors still average 197 days to detect a flaw and 60 to fix it. The volume was never the problem. Finding the 800 inside the 48,000 is the actual work, and it's exactly what a mid-market team has the least capacity to do.
AI Adoption Reached Every Department Except Security
Mid-market companies have adopted AI in earnest.Eurostat recorded 30.36% of mid-sized European enterprises using at least one AI technology in 2025, withOECD finding similar rates across the G7. Security is where the segment falls furthest behind.ISC2's 2025 survey found mid-sized firms using AI in security operations at just 20%, below organizations a fraction of their size. The constraint isn't access to a capable model. It's the sustained capacity to act on what it finds.
Attackers Respond to Cost as the Better-Defended Tier Hardens
Larger enterprises applying AI-driven detection raise the cost of breaching them. Black Kite'sanalysis of that widening capability gap found 36.7% of discoverable supply chain risk now sits in the long tail of mid-market and niche suppliers who can't access the same tooling. A segment that's easier to reach and slower to sort its exposure becomes the more efficient target as the tier above it hardens. The mid-market doesn't need to get more exposed to become more attractive. It only has to fall further behind.
The Mid-Market Plays Both Supplier and Buyer in the Supply Chain
Your Risk Is Now Someone Else's Third-Party Problem
Every company in this report is a supplier to someone larger and a customer of someone smaller, and in a mid-market company, both roles are usually handled by nobody in particular. The sectors that dominate the victim data, mostly manufacturing, professional services, and wholesale trade, sell to other businesses, so an attack rarely stays contained. A compromised parts supplier halts production; a breached IT services firm exposes client data and opens a route into their systems.
This is why regulation increasingly holds the larger customer accountable for its suppliers' security.The NIS2 Directive names SMEs as increasingly targeted for supply chain attacks, and its size-cap rule pulls much of this report's population into scope. In the U.S.,23 NYCRR 500 requires coveredfinancial firms to maintain writtenthird-party risk management policies with no small-firm exemption, andHIPAA holds entities responsible for a business associate's breach where reasonable diligence should have caught it. That evidence is exposure an external scan can already show, the same posture a security questionnaire only asks a company to describe.
The Team Is Two, the Vendor List Is 300+
A mid-market company can carry hundreds of vendors with no dedicated team to watch them. Industry surveys find vendor risk teams of two or fewer responsible for portfolios past three hundred suppliers, a ratio that makes continuousvendor risk monitoring impossible by hand. The gap starts at the inventory itself. Vendors enter through department-level purchases and free-tier tools, and many are never recorded. Flagging exposure is only half the job. Knowing which vendors the business genuinely can't operate without isa judgment a security team can't make alone.
34% Have No Security Protocol in Place
Techaisle's research found 34% of mid-market firms have no security protocol at all, and 35% operate without a formal risk framework. Compliance fills that gap instead of security.The Cloud Security Alliance describes the problem: a questionnaire captures a single point in time, its answers are self-reported and hard to verify, and what passes today may not hold months later. It tells a company what a vendor was willing to attest to once. It doesn't show what that vendor exposes right now, and current exposure is what an attacker moving through a supply chain actually uses.
Four Shifts That Replace Point-in-Time Risk Management
Everything in this report points to the same conclusion: the exposure is measurable, the obligation is real, and the constraint is capacity. A mid-market company can see what an attacker sees and answer what a customer asks, but only with the team and budget it actually has, run directly or through a trusted MSSP partner.
Pair Every Assessment With Continuous Monitoring
An attacker selecting a target doesn't start with a questionnaire. They start with what's reachable from the internet. A point-in-time assessment is accurate the day it's taken, and the interval until the next one is exactly where new exposure appears unseen. Black Kite'scontinuous monitoring across 20 risk categories keeps that view current for the organization that owns it, between assessments, not just at one.
Treat Named Adversaries as a Moving Target, Not a Fixed Roster
Threat groups attacking the mid-market change names every few months, so preparing for a named adversary has a short useful life. TheRansomware Susceptibility Index® (RSI™) answers the question the roster can't. It's a score from 0.0 to 1.0 estimating the likelihood of a ransomware attack, combining technical exposure with factors like industry, location, and size.
Enforce Same-Day Response Inside the Window a Disclosure Opens
When a vulnerability is disclosed, a window opens between the moment a threat goes public and the moment a team acts, and attackers work inside it. Black Kite'sFocusTags® surface exactly which organizations are affected as soon as it's flagged, so the response starts while the window is still open.
Map the Vendor Ecosystem You Haven't Inventoried
Dozens of companies can sit behind a single vendor without anyone knowing it, and single points of failure stay invisible until one fails. Black Kite's Supply Chain Modulemaps Nth-party dependencies and surfaces the concentration risk that would cascade across a peer group. When a weakness turns up, Black Kite'sThe Bridge™ closes the gap between finding it and fixing it, giving vendors asset-level vulnerability intelligence and routing remediation status into one auditable view instead of scattered email threads.
How Black Kite Built the 2026 Mid-Market Ransomware Report
13,336 Ransomware Incidents Filtered From 21,520 Disclosed Records
Of 21,520 disclosed ransomware and extortion records, 20,411 were publication-ready, 15,971 fell within North America and 31 European countries, and 13,336 carried a verifiable revenue figure. Of those, 9,781 were mid-market.
120,128 Mid-Market Companies Assessed From the Outside In
Exposure findings come from a separate dataset of 120,128 mid-market companies monitored across North America and Europe: 41,960 lower band, 77,633 core, 535 upper. This is a June 2026 snapshot, so no trend is claimed from these figures.
Three Revenue Bands Define the $10 Million to $1 Billion Segment
The mid-market is defined by annual revenue only, following the Dun & Bradstreet standard, with no employee-count criterion:
Lower band is $10M–$50M,
Core band is $50M–$500M,
Upper band $500M–$1B.
Vulnerability Findings Restricted to CVSS 8.0 and Above
Vulnerability records here are limited to disclosed flaws scored 8.0 and above on the CVSS scale, so every figure reflects high or critical severity, not full disclosure volume.
See What an Attacker Sees, Before They Do
Every exposure in this report was measured from the outside, the same vantage point available to any attacker or customer right now. Black Kite puts that view in front of the team responsible for acting on it, continuously, sized for the team and budget already in place.