Mid-sized enterprises across North America and Europe face an overwhelming majority of publicly disclosed ransomware and data-extortion incidents, according to a new report from Black Kite.
Data compiled between January 2023 and June 2026 shows that mid-market companies—defined as businesses with annual revenues ranging from $10 million to $1 billion—accounted for 73% of all publicly disclosed ransomware and data-extortion incidents with known revenue. Throughout the measured timeframe, this share remained consistently between 72% and 75%, demonstrating that threat actors continuously target this specific market segment.
Organizations generating between $10 million and $50 million annually made up more than half of all mid-market victims recorded in the study. By sector, manufacturing experienced the highest volume of attacks, absorbing over a quarter of total mid-market incidents, followed closely by professional, scientific, technical services, and construction industries.
The research, which evaluated more than 120,000 mid-market organizations, revealed widespread security gaps that invite exploitation. Over 54% of analyzed companies displayed at least one significant patch-management vulnerability on public-facing systems, while more than 25% harbored specific vulnerabilities already actively targeted by cybercriminals.
Stolen credentials further exacerbate the risk profile for mid-sized enterprises. Nearly one-third of the monitored entities presented at least one stealer-log finding, reflecting login information harvested by information-stealing malware that attackers leverage to infiltrate corporate networks and initiate lateral movement.
Supply chain connectivity and emerging artificial intelligence tools continue to complicate defense strategies. With typical vendor-risk teams managing hundreds of third-party suppliers using constrained resources, security analysts must prioritize remediation efforts against a backdrop of sophisticated, AI-driven vulnerability discovery.