Mid-market companies are not a fringe ransomware target. According to Black Kite’s 2026 study, organizations earning $10 million to $1 billion a year accounted for 73% of 13,336 disclosed ransomware and extortion incidents with a verifiable revenue figure across North America and Europe from January 2023 through June 2026.
That finding matters because the share barely changed while the number of incidents increased. For security leaders, the consequence is a sustained budgeting problem: exposure is concentrated among companies that may not have the staffing, redundancy or purchasing power associated with the largest enterprises. The evidence does not quantify ransom payments, downtime or recovery costs, so it cannot show the financial loss per victim. It does show where the pressure is landing.
The pattern held as incident volume rose
Black Kite’s annual shares were 74.6% in 2023, 72.1% in 2024, 74% in 2025 and 72.3% in the first half of 2026. The company also reported that the absolute number of incidents rose 44%, from 2,320 in 2023 to 3,340 in 2025.
Infosecurity Magazine independently summarized the same study and described the mid-market as three segments based on revenue: $10 million to $50 million, $50 million to $500 million and $500 million to $1 billion. The lower mid-market represented the largest share of victims in the publication’s account, at 54%, while its victim count rose from 1,391 in 2024 to 1,821 in 2025. Those figures point to a concentration of risk below the largest end of the segment, although the supplied evidence does not establish why those companies were selected or compromised.
Manufacturers face the sharpest operational stakes
Manufacturing was the most targeted industry, representing more than 25% of mid-market ransomware victims in Black Kite’s report. Professional, scientific and technical services and construction followed. Infosecurity Magazine put manufacturing’s share at 26% and noted that production businesses generally have limited tolerance for outages and may hold sensitive operational information.
That does not mean every manufacturer faces the same threat or that industry membership caused an attack. It does clarify the practical trade-off. A company that cannot quickly isolate systems or restore operations may have to weigh security spending against the cost of interrupted production, delayed customer commitments and supplier disruption. The evidence pack does not provide a Black Kite estimate for any of those costs.
What the scan can—and cannot—say about readiness
Black Kite said it assessed 120,128 mid-market organizations across North America and Europe through an external internet-facing scan. It reported that 28.3% had at least one known exploited vulnerability and that 54.7% had at least one significant patch-management finding.
These are exposure indicators, not proof that a specific company will be attacked or that a particular weakness caused one of the incidents in the 13,336-event dataset. The report also does not, in the supplied material, explain the overlap between scanned organizations and disclosed victims. That distinction is important for boards and IT teams: a scan can identify a condition to investigate, but it cannot by itself measure exploitability, business impact or recovery readiness.
The turning point is resource allocation, not another headline statistic
The stable 72% to 75% range changes how the result should be read. This is not simply a one-year spike in attention around smaller companies. It is a multi-year pattern in the data Black Kite examined, while the overall count grew.
For mid-market teams, that makes prioritization the immediate issue. They may need to decide whether scarce capacity goes first to exposed internet-facing systems, patch-management gaps, supplier visibility or recovery exercises. Black Kite’s press release frames its work as support for smaller security teams, but that is a manufacturer claim rather than independent evidence that any product or program reduces ransomware losses.
The central limitation remains scope. The 73% figure covers disclosed incidents in North America and Europe with a verifiable revenue figure, not necessarily every attack. It also comes from Black Kite’s analysis, and the supplied evidence does not include a full methodology or an independent audit of the underlying records.
What to watch next
The next meaningful signal is not a more dramatic annual slogan. It is fuller methodological detail: how incidents were identified, how revenue was verified, how the scan findings overlap with victims and whether the proportions hold in later reporting. Until that information is available, the responsible conclusion is narrower but still consequential: mid-market companies were the majority of known-revenue victims in this dataset, and their share remained high as incident volume increased.
The durable significance of Black Kite's 2026 report is the consistency of the target profile. Mid-market organizations represented 72% to 75% of the study's known-revenue victims each year from 2023 through the first half of 2026, even as incident volume grew. That makes the finding more useful as a resource-allocation warning than as a prediction about any individual company. The evidence supports attention to exposure and patch-management gaps, but it does not independently prove causation, quantify recovery costs or show that a particular security product reduces risk. The next test is fuller methodology and later data.
Sources and methodology
- Black Kite report finds 73% of ransomware incidents hit mid-market companies amid growing third-party and AI risks - Industrial Cyber - https://blackkite.com/reports/2026-mid-market-report
- Black Kite Appoints Data Protection Veteran Jim Clancy as SA - https://blackkite.com/press-releases/black-kite-research-reveals-that-ransomwares-primary-target-is-the-mid-market-not-enterprises-as-widely-assumed
- Three-quarters of Ransomware Attacks Target Mid-Market ... - https://www.infosecurity-magazine.com/news/threequarters-ransomware-attacks
- Black Kite Research Reveals That Ransomware's Primary ... - https://www.prnewswire.com/news-releases/black-kite-research-reveals-that-ransomwares-primary-target-is-the-mid-market-not-enterprises-as-widely-assumed-302851242.html


