Mid-sized enterprises face a disproportionate volume of data-extortion campaigns as ransomware groups leverage unpatched systems and stolen credentials.
Mid-sized enterprises accounted for 73 percent of publicly disclosed ransomware and data-extortion incidents with known revenue across North America and Europe between January 2023 and June 2026, according to a report published by Black Kite. The research evaluated 13,336 total incidents, classifying mid-market companies as organizations generating annual revenues between $10 million and $1 billion. Throughout the tracking period, this sector’s share of attacks remained stable, hovering between 72 percent and 75 percent.
Organizations with annual revenues between $10 million and $50 million bore the brunt of the activity, representing over half of all mid-market victims. By vertical sector, manufacturing emerged as the most targeted industry, capturing over a quarter of all mid-market incidents. Professional, scientific, and technical services alongside construction rounded out the most heavily impacted segments.
An assessment of more than 120,000 mid-market organizations revealed pervasive foundational security gaps. Approximately 54.7 percent of evaluated entities exhibited at least one significant patch-management vulnerability on a public-facing system, while more than 25 percent harbored flaws already known to be actively exploited in the wild. Furthermore, nearly one-third of the monitored organizations showed stealer-log indicators, signaling that information-stealing malware had successfully harvested employee credentials.
The convergence of artificial intelligence is further compounding risk profiles. Security teams and threat actors alike are leveraging automated capabilities to unearth and analyze software vulnerabilities at unprecedented speeds. However, mid-market organizations frequently manage massive backlogs of security alerts with lean operational staffs, complicating triage processes that require determining whether exposed systems face active exploitation.
Complex supply chain dependencies amplify these operational exposures. Mid-market vendors often connect directly into larger corporate infrastructures while simultaneously relying on third-party cloud platforms and software suppliers, creating broad vectors for secondary compromise. Emerging regulatory mandates, including the European Union’s NIS2 Directive and U.S. frameworks such as NYCRR 500 and HIPAA, are increasing compliance pressures on smaller vendors to systematically validate and disclose third-party risk controls.