Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Attacks Singly Target Mid-Market Firms

Empty office interior with cubicles, private offices, and scattered papers, lit by soft daylight through windows.

"AI is accelerating how fast new vulnerabilities are discovered, and the volume is climbing toward levels no small team can triage by hand," the report claimed.

Black Kite study and how it measured the problem

The third-party risk specialist Black Kite compiled its findings in a report published on August 18 titled Mid-Market Is the Routing Target. The company analyzed 13,336 disclosed incidents dating back to January 2023 and combined that dataset with a separate security scan of 120,128 mid-market companies. Black Kite used Dun & Bradstreet’s revenue-based definitions for market size: lower mid-market ($10m–$50m), core mid-market ($50m–$500m) and upper mid-market ($500m–$1bn).

Mid-market companies account for nearly three-quarters of victims

Black Kite found that 73% of ransomware attacks in North America and Europe since 2023 hit companies with $10m–$1bn in annual revenue. That share held steady even as the total volume of incidents grew by 44% between 2023 and 2025. Within the mid-market cohort, lower mid-market firms represented the largest share of victims (54%); their absolute victim count rose from 1,391 in 2024 to 1,821 in 2025. Core mid-market firms accounted for the second-highest number of victims, with counts rising from 970 in 2024 to 1,474 in 2025. By contrast, upper mid-market victim counts fell from 126 in 2023 to 45 in 2025, a decline of 65%.

Geography and sector concentration: North America, the UK, and manufacturing

Geographically, North America accounted for 72% of the incidents recorded in the study, while Europe accounted for 28% — and within Europe, UK firms were the most popular target. Sectorally, manufacturing businesses were the single largest slice of mid-market ransomware victims, making up 26% of the total. Professional, scientific and technical services, and construction were the next-most-affected sectors. Black Kite noted why manufacturing is attractive to attackers: low tolerance for outages and holdings of highly sensitive information.

Those sector findings align with contemporaneous industry data. Make UK reported in August that almost a third (30%) of UK manufacturers experienced a cyber incident in the past year, either directly or through their supply chain. Separate research from ESET published in April found that, of UK manufacturers that suffered a cyber incident last year, almost all (95%) admitted the attack had a direct impact on their business and a majority (53%) suffered financial loss; supply chain disruption (44%) and missed customer or supplier commitments (39%) were also commonly reported consequences.

Security posture gaps the report linked to ransomware risk

Black Kite’s security scan of more than 120,000 mid-market firms turned up several widespread deficiencies that the company linked to ransomware exposure. Key findings include:

  • 28% had at least one known exploited vulnerability (KEV)
  • 55% had at least one significant patch management finding on public-facing software
  • 48% carried at least one disclosed vulnerability with a CVSS score of 8.0 or higher
  • 32% had at least one stealer log finding
  • 47% had missing or insufficient DMARC protection

What this means for technologists, procurement leaders, and policymakers

Technologists and security teams: Black Kite’s data frames a capacity problem. The report warned that AI is increasing the speed and volume of vulnerability discovery, producing a stream of potential issues “no small team can triage by hand”; mid-market teams already show high rates of KEVs, critical CVSS findings and patch-management gaps.

Procurement leaders and affected enterprises: The concentration of incidents in lower and core mid-market bands — and the climb in victim counts from 2024 to 2025 — points to risk in supplier and vendor relationships. Manufacturing, professional services and construction firms should note the reported prevalence of stealer logs and missing DMARC as concrete weaknesses affecting business continuity and financial exposure.

Policymakers and regulators: The regional split (72% North America, 28% Europe) and the UK’s prominence among European targets underline that mid-market resilience will be a cross-border issue. The report’s linkage of AI-driven vulnerability discovery to triage capacity highlights a structural pressure point for regulatory conversations about readiness and minimum controls.

Conclusion

Black Kite’s report presents a tightly defined portrait: three out of four ransomware victims since 2023 have been mid-market firms, incidents rose 44% from 2023 to 2025, and a raft of measurable security weaknesses are common across more than 120,000 companies scanned. The data also flags a tactical and operational squeeze: as AI accelerates discovery of new vulnerabilities, mid-market teams with documented gaps in patching, email authentication and exposed high-severity flaws face an escalating triage burden. The central question the report leaves for business and policy leaders is concrete and immediate — how will mid-market organizations scale detection and remediation when the volume of potentially critical findings is rising faster than the teams that must fix them?

https://www.infosecurity-magazine.com/news/threequarters-ransomware-attacks/