Dive Brief:
- Medium-sized businesses accounted for roughly three-quarters (73%) of ransomware incidents between 2023 and the first half of 2026, according to the risk management firm Black Kite.
- Manufacturing was the most targeted industry (accounting for more than 25% of those victims), and nearly 30% of mid-market organizations had at least one known exploited vulnerability, the firm said in a report published on Tuesday.
- The findings add to the challenges facing mid-market firms, which include large customers demanding accountability and a vast array of suppliers that the mid-market firms lack the personnel to hold accountable.
Dive Insight:
Mid-market firms, defined as those with annual revenue between $10 million and $1 billion, receive comparatively less attention in cybersecurity discussions than either small businesses, whose struggles and weaknesses are well understood, or large companies, whose industry importance leads to widespread media coverage when they suffer hacks. Black Kite’s report, based on an analysis of 13,336 ransomware incidents between January 2023 and June 2026, examines the unique position that mid-market firms find themselves in, a dynamic that affects their ability to protect their systems.
Companies’ twin roles as suppliers and customers “are usually treated as separate problems, handled by separate teams under separate budgets,” the report said. “In a mid-market company they are rarely handled by anyone at all, and they are the same problem seen from two directions.”
The most victimized sectors — manufacturing, professional services, construction and wholesale — are full of companies that supply other companies, meaning that the damage from a cyberattack can quickly cascade downward and outward. “When one of these companies is attacked,” Black Kite said, “the incident is recorded against its own name, but the damage does not stop there.”
These supply-chain risks explain why large companies with medium-sized suppliers ask those mid-market firms to answer so many security questions, according to the report, which listed examples of regulations in the U.S. and Europe that codify suppliers’ cybersecurity responsibilities.
But mid-market firms often struggle to meet these oversight demands.
“Industry surveys of vendor-risk programs find teams of two or fewer people responsible for portfolios that run well past three hundred suppliers,” Black Kite researchers wrote, “a ratio that makes continuous oversight impossible by hand.”
Ransomware attacks during Black Kite’s research period were not evenly distributed across the mid-market. The smallest slice of those companies — those with annual revenue between $10 million and $50 million — accounted for roughly half of all incidents, followed closely by the “core mid-market” ($50 million to $500 million), with 40% to 45% of incidents. Very few “upper mid-market” firms ($500 million to $1 billion) experienced ransomware incidents; Black Kite noted that the number fell from 126 in 2023 to 45 in 2025, a 64% decline.
Black Kite’s report is based on data collected from the networks of 120,128 mid-market businesses in North America and Europe, but the company found that North America heavily dominated the data set. Seventy-two percent of mid-market attacks during the research period targeted North American companies, and the number of North American victims grew from 2023 to 2026, even as the number of European victims effectively remained flat.