Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cyber Incident Disrupts Student Services at UT San Antonio

August 18, 2026

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

August 18, 2026

Three-quarters of Ransomware Attacks Target Mid-Market Firms

August 18, 2026
Facebook X (Twitter) Instagram
Tuesday, August 18
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Three-quarters of Ransomware Attacks Target Mid-Market Firms
News

Three-quarters of Ransomware Attacks Target Mid-Market Firms

Team-CWDBy Team-CWDAugust 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Nearly three-quarters of ransomware victims since 2023 were mid-sized organizations with $10m to $1bn in revenue, according to a new Black Kite study.

The third-party risk specialist analyzed 13,336 disclosed incidents dating back to January 2023, as well as a separate security scan of 120,128 mid-market companies, to compile its new report, Mid-Market Is the Routing Target.

Published on August 18, it follows the Dun & Bradstreet revenue-based definition for market size: lower mid-market at $10m-$50m, core mid-market at $50m-$500m and upper mid-market at $500m-$1bn.

The report found that 73% of ransomware attacks in North America and Europe hit companies with $10m-$1bn in annual revenue, with the figure barely moving even as the volume of incidents grew by 44% between 2023 and 2025.

Read more on ransomware: Verizon DBIR: Small Businesses Bearing the Brunt of Ransomware Attacks

Over the reporting period, the largest share of mid-market victims sat in the lower mid-market category (54%). In absolute terms, victim numbers rose here from 1391 in 2024 to 1821 in 2025.

The core mid-market accounted for the second-highest number of victims over the period, ranging from 40-45% across the three-and-a-half years.

Victim count here rose from 970 to 1474 between 2024 and 2025, while in the upper mid-market category, the numbers dropped from 126 in 2023 to 45 in 2025, a decline of 65%.

North America (72%) accounted for many more incidents than Europe (28%), where UK firms were the most popular target.

Gaps in Security Posture

Manufacturing firms were by far the most popular target for threat actors, accounting for 26% of mid-market ransomware victims, followed by professional, scientific and technical services, and construction sectors.

Manufacturing businesses typically have a low tolerance for outages and hold highly sensitive information, making them an attractive target.

Data released by industry body Make UK published in August revealed that almost a third of UK manufacturers (30%) experienced a cyber incident over the past year, either directly or through their supply chain. 

Separate data from ESET published in April found that, of UK manufacturers that suffered a cyber incident last year, almost all (95%) admit the attack had a direct impact on their business, and most (53%) suffered financial loss as a result.

Supply chain disruption (44%) and missed customer or supplier commitments (39%) were also commonplace.

Black Kite’s analysis of security posture across over 120,000 mid-market firms revealed some of the deficiencies which could lead to ransomware compromise. Its findings include:

  • Over a quarter (28%) had at least one known exploited vulnerability (KEV)
  • Over half (55%) had at least one significant patch management finding on public-facing software
  • Nearly half (48%) carried at least one disclosed vulnerability with a CVSS score of 8.0 or higher
  • Nearly a third (32%) had at least one stealer log finding
  • Nearly half (47%) had missing or insufficient DMARC protection

The challenge for security teams in these organizations is set to increase as AI adoption grows, Black Kite argued.

“AI is accelerating how fast new vulnerabilities are discovered, and the volume is climbing toward levels no small team can triage by hand,” the report claimed. “Only a fraction of those vulnerabilities are ever exploited, but finding that fraction across a company’s own systems and its suppliers is exactly the work a mid-market team has little capacity to do.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Next Article A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
Team-CWD
  • Website

Related Posts

News

Cyber Incident Disrupts Student Services at UT San Antonio

August 18, 2026
News

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

August 18, 2026
News

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

August 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Are AI tutoring tools safe for your kids?

August 10, 2026

How it preys on personal data – and how to stay safe

October 23, 2025

A phishing attack that doesn’t steal your password

June 15, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.