Black Kite report reveals that mid-sized organizations accounted for 73% of publicly disclosed ransomware and data-extortion incidents across North America and Europe between January 2023 and June 2026.
According to an analysis of 13,336 incidents by risk management firm Black Kite, mid-market companies defined as businesses with annual revenues between $10 million and $1 billion bore the brunt of extortion campaigns. Throughout the tracked 42-month window, the proportion of targeted mid-market entities remained remarkably consistent, fluctuating between 72% and 75% of total recorded attacks.
The data shows that smaller mid-market participants face the highest volume of incursions. More than half of all impacted mid-market victims operated within the $10 million to $50 million annual revenue bracket. Sector-wise, manufacturing emerged as the most frequently targeted industry, absorbing over a quarter of mid-market incidents, followed by professional, scientific, and technical services, as well as the construction sector.
Black Kite’s broader assessment of over 120,000 mid-market organizations highlights severe underlying hygiene deficiencies that threat actors actively exploit. Over 54% of evaluated entities exhibited at least one major patch-management flaw on public-facing systems, while more than 25% harbored known vulnerabilities already actively weaponized in the wild. Additionally, nearly one-third of monitored companies displayed stealer-log findings, indicating active credential harvesting by information-stealing malware.
The proliferation of artificial intelligence is further complicating remediation efforts for smaller IT and security departments. While defensive personnel leverage AI capabilities to process telemetry and accelerate vulnerability discovery, adversaries deploy similar tooling to rapidly pinpoint and weaponize enterprise blind spots. This dynamic exacerbates resource strains for mid-sized firms, which typically manage extensive vulnerability backlogs with lean staffing models.
Supply chain interdependencies compound these operational risks, as mid-market suppliers often connect downstream to larger enterprises while depending on third-party cloud and software vendors. Regulatory pressures, including the European Union’s NIS2 Directive, New York’s NYCRR 500, and HIPAA requirements, are increasingly mandating strict third-party risk oversight, forcing mid-tier vendors to transparently demonstrate robust security baselines to their corporate partners.