Summary
- Black Kite found that 73% of tracked ransomware victims across North America and Europe from 2023 to H1 2026 were mid-market companies.
- The proportion stayed near 72–75% each year even as the absolute number of incidents increased sharply.
- Manufacturing led victim counts, while externally visible patching, vulnerability, and email-security weaknesses remained common across the segment.
Mid-market companies are carrying a disproportionate share of ransomware exposure across North America and Europe, with new research finding that businesses generating between $10 million and $1 billion in annual revenue accounted for 73% of tracked victims from 2023 through the first half of 2026.
Black Kite analysed 13,336 ransomware incidents with verifiable revenue data across the two regions. The proportion hitting mid-market organisations remained unusually stable despite a sharp increase in the total number of incidents: 74.6% in 2023, 72.1% in 2024, 74% in 2025, and 72.3% in the first half of 2026.
The absolute number of ransomware incidents in the dataset rose by 44%, from 2,320 in 2023 to 3,340 in 2025. More than half of the mid-market victims generated less than $50 million a year.
Manufacturing was the most heavily targeted sector, accounting for more than a quarter of mid-market ransomware victims, followed by professional, scientific and technical services, and construction.
The researchers also assessed externally observable security conditions across 120,128 mid-market organisations. They found that 28.3% had at least one vulnerability listed in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue, while 54.7% had a significant patch-management finding affecting public-facing software.
Almost half, 48.1%, carried at least one disclosed vulnerability rated 8.0 or higher under the Common Vulnerability Scoring System. Around a third had a stealer-log finding, and 46.8% lacked adequate DMARC protection for email domains.
Supplier exposure increases the consequences
The figures reinforce a ransomware pattern that is easy to miss when attention centres on very large victims. Mid-sized companies can hold commercially valuable data and occupy critical positions in customer supply chains without having the staffing, budget, or redundancy of a multinational enterprise.
That position can magnify disruption. A manufacturer, engineering company, specialist service provider, or construction supplier may serve much larger organisations that depend on it for physical production, technical services, data exchange, or access to operational systems. An attack on the smaller company can therefore propagate into customers even where the customer’s own environment is not directly compromised.
The regulatory consequences are also becoming more direct in Europe. NIS2 expands expectations around supply chain security and risk management for organisations within scope, while DORA places detailed requirements on financial entities’ management of information and communications technology third-party risk. Those rules increase scrutiny not only on regulated organisations but also on the suppliers expected to demonstrate that their controls are adequate.
Black Kite’s research does not establish that every externally observable weakness caused a ransomware incident, and internet-facing risk indicators should not be treated as proof of compromise. They do, however, show how common unresolved exposures remain across a business segment that attackers repeatedly reach.
The mid-market concentration has also persisted while ransomware ecosystems have fragmented and changed. Criminal groups can move between brands, infrastructure, and affiliate models, but they continue to favour organisations where disruption creates leverage and recovery options may be constrained.
The data therefore points to a structural issue rather than a short-lived spike. As the overall number of ransomware victims rises, the mid-market remains the largest pool of affected organisations, and its role inside larger commercial networks means the operational cost rarely stops at the victim’s own perimeter.



