Ransomware crews are not chasing headline-grabbing enterprises as much as the industry’s threat narrative suggests. New research from risk-monitoring firm Black Kite finds mid-market companies, those with $10 million to $1 billion in annual revenue, accounted for 73 percent of disclosed ransomware and data-extortion incidents across North America and Europe from 2023 through the first half of 2026.
What happened
Black Kite analyzed 13,336 ransomware and extortion incidents with verifiable revenue data, plus attack-surface scans of over 120,000 mid-market organizations. The mid-market share of victims held steady across the study period: 74.6 percent in 2023, 72.1 percent in 2024, 74 percent in 2025 and 72.3 percent in H1 2026. More than half of victims generated under $50 million annually. Manufacturing led all industries at over a quarter of victims, followed by professional services and construction. “This is the first time we examined the mid-market as a segment in its own right, rather than a set of companies scattered through larger studies,” said Ferhat Dikbiyik, Black Kite’s chief research and intelligence officer.
Why it matters
The report ties the targeting pattern to exposure, not luck: 54.7 percent of scanned mid-market organizations had significant patch-management gaps on public-facing systems, 28.3 percent carried a known exploited vulnerability, and 46.8 percent lacked adequate DMARC email authentication. Mid-market firms typically run leaner security teams than large enterprises while holding comparable access to supply chains, customer data and cyber insurance payouts attackers can price into a ransom demand.
The original angle
The steadiness of that 72 to 75 percent share across four years is the real finding: this is not a temporary shift in attacker behavior, it is a stable business model. Ransomware groups have priced mid-market companies as the segment with the best ratio of payout capacity to defensive investment, and that will not change until patch-management and email-authentication gaps close faster than they have. CyberTech has tracked the operational side of that gap in coverage of Medusa’s expanding victim count and fraudulent ransomware “rescue” services that prey on victims after the fact; this data explains why the victim pool those schemes draw from keeps growing.
Source: PR Newswire