Title: Ransomware Strikes: Mid-Sized Organizations Bear the Brunt
A recent study conducted by the third-party risk specialist Black Kite has revealed a striking trend in ransomware attacks, indicating that nearly 75% of victims since the start of 2023 were mid-sized organizations, defined by revenue figures ranging from $10 million to $1 billion. This alarming statistic is drawn from a comprehensive analysis of 13,336 disclosed ransomware incidents, dating back to January 2023, alongside a separate security evaluation of 120,128 mid-market companies, culminating in the report titled Mid-Market Is the Routing Target, published on August 18, 2023.
Black Kite’s report adheres to the revenue-based market size definitions established by Dun & Bradstreet, categorizing companies into three segments: lower mid-market ($10 million to $50 million), core mid-market ($50 million to $500 million), and upper mid-market ($500 million to $1 billion). The findings indicate that 73% of ransomware incidents targeted companies within the $10 million to $1 billion revenue bracket, astonishingly remaining consistent even as the overall volume of ransomware attacks surged by 44% between 2023 and 2025.
Delving into specifics, the report illustrates a concerning trend where the largest proportion of mid-market ransomware victims fell into the lower mid-market category, comprising 54% of the total. The absolute count of victims within this segment rose sharply from 1,391 in 2024 to 1,821 in 2025. The core mid-market, meanwhile, accounted for the second-largest number of ransomware victims during this timeframe, with figures fluctuating between 40% and 45% over the three-and-a-half-year period analyzed. Here, the victim count increased from 970 in 2024 to 1,474 in 2025. In contrast, the upper mid-market category saw a significant decline, with victim numbers plummeting from 126 in 2023 to just 45 in 2025, marking a staggering 65% decrease.
When analyzing geography, North America was identified as the predominant region for ransomware incidents, contributing 72% of the total cases, while Europe accounted for the remaining 28%. Notably, within Europe, firms in the UK suffered the highest number of attacks.
Sector Vulnerabilities: Who is Targeted?
Among various sectors, manufacturing emerged as the most attractive target for cybercriminals, comprising 26% of mid-market ransomware victims. The allure lies in the manufacturing sector’s low tolerance for operational outages and the possession of sensitive information, making them susceptible to ransomware attacks. Data collected from industry body Make UK in August highlighted that approximately 30% of UK manufacturers encountered a cyber incident in the prior year, either directly or through their supply chains.
Further emphasizing the crisis, a separate report from ESET indicated that almost all UK manufacturers suffering from cyber incidents acknowledged the direct impact on their operations, with 53% reporting financial losses. Common consequences also included supply chain disruptions (44%) and the failure to fulfill commitments to customers or suppliers (39%).
In examining the security posture of over 120,000 mid-market firms, Black Kite revealed significant deficiencies that may contribute to the vulnerability of these organizations to ransomware attacks. Key findings include:
- 28% of firms had at least one known exploited vulnerability (KEV).
- 55% displayed significant patch management issues on public-facing software.
- 48% had disclosed vulnerabilities with a CVSS score of 8.0 or higher.
- 32% were identified with at least one stealer log finding.
- 47% lacked adequate DMARC protection, or had missing measures in place.
As organizations strive to fortify their defenses against the rising tide of ransomware, the complexity of these challenges is anticipated to escalate, especially with the growing adoption of artificial intelligence (AI). Black Kite forewarned that AI not only accelerates the discovery of new vulnerabilities but also contributes to an overwhelming volume of potential exploits. The report expressed concern that such rapid vulnerability growth presents an insurmountable challenge for mid-sized organizations, which often lack the resources to effectively address and triage these vulnerabilities.
In conclusion, as ransomware attacks continue to proliferate, mid-sized organizations must prioritize their cybersecurity measures and develop robust strategies to safeguard against potential breaches. With the threat landscape constantly evolving, being proactive in addressing vulnerabilities and enhancing security posture has never been more critical for these vulnerable sectors.
