New Research: Ransomware’s Primary Target Is the Mid-Market
Black Kite, a Boston-based company specializing in third-party cyber risk management, has issued a new market research report suggesting that ransomware criminals are more likely to pursue mid-market targets, as opposed to enterprise targets. Assessing more than 120,000 mid-market organizations across North America and Europe from an attacker’s perspective, the report examines why these companies bear the brunt of ransomware attacks, and draws on disclosed incident data and external attack-surface scans to understand the pattern and what mid-market companies can do to protect themselves.
Black Kite’s analysis of more than 13,000 ransomware incidents with verifiable revenue across North America and Europe from January 2023 to June 2026 found that 73% of those incidents struck mid-market organizations with annual revenues between $10M and $1B. This concentration has proven highly consistent over time: 74.6% in 2023, 72.1% in 2024, 74% in 2025, and 72.3% during the first half of 2026. Even as the absolute number of incidents grew by 44%, surging from 2,320 in 2023 to 3,340 in 2025, the proportion of mid-market targets held firm.
Manufacturing was the most targeted industry, representing more than 25% of mid-market ransomware victims, followed by professional, scientific and technical services, and construction. More than one in four mid-market organizations (28.3%) carried at least one known exploited vulnerability. More than half (54.7%) had at least one significant patch management finding on public-facing software. Nearly half (48.1%) carried at least one disclosed vulnerability with a CVSS score of 8.0 or higher.
Mid-market organizations face a growing challenge, according to the report. They are increasingly targeted by ransomware while also exposed to cyber risk across hundreds of third-party vendors. Both require continuous visibility and rapid response, stretching even well-resourced security teams. Mid-market companies also sit inside the vendor profile of the larger organizations they serve. Regulation on both sides of the Atlantic, from the EU’s NIS2 Directive to U.S. rules like NYCRR 500 and HIPAA, increasingly makes a customer responsible for its suppliers’ security, which puts mid-market vendors under direct pressure to prove their posture.
Channel Impact®
Partners can leverage this data to help clients identify, prioritize, and reduce cyber risk without requiring enterprise-sized teams or budgets.
Stay in the Know
Keep tabs on what’s happening in the channel and the impact it will have on the partner community by subscribing to Channel Impact communications.
Recent News
Search Buzz
Buzz Categories



