Ransomware Attackers Are Zeroing In on Mid-Market Companies – Veri Sızıntısı
Veri Sızıntısı
Veri Sızıntısı
Free on Google Play
Open

Ransomware Attackers Are Zeroing In on Mid-Market Companies

According to a new report by Black Kite, 73% of ransomware and data-extortion incidents target mid-market companies with annual revenues between $10 million and $1 billion. The report reveals the challenges these companies face in cybersecurity and the methods attackers use.

A businessman looks at a laptop with a red lock icon in the background, symbolizing a cyber threat.

What Happened

A new report published by cybersecurity firm Black Kite shows that cybercriminals have largely turned their attention to mid-market companies. According to the analysis, which covers the period from January 2023 to June 2026, 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe targeted mid-sized businesses with annual revenues between $10 million and $1 billion. The fact that this share remained consistent, between 72% and 75%, throughout the analysis period proves that this is an ongoing problem, not a fleeting trend.

The report indicates that attackers are particularly focused on the smaller segments of the market. More than half of the victimized mid-market companies had annual revenues between $10 million and $50 million. This suggests that attackers view companies with fewer security resources and personnel, yet still capable of paying a ransom, as ideal targets. For cybercriminals, these companies have become a low-risk, high-reward hunting ground, fitting the description of "not too big, not too small."

Exfiltrated Data

The Black Kite report focuses on the frequency of attacks and the profiles of targeted companies, and does not provide specific details about the types of data stolen. However, in such data extortion and ransomware attacks, it is known that attackers typically target critical data to halt a company's operations or threaten to leak sensitive information. This data can include valuable information such as customer details, financial records, employee personal data, trade secrets, and private correspondence. Attackers use this data as leverage to pressure the company into paying the ransom.

How the Attack Happened

According to the report, attackers often exploit known and predictable weaknesses to infiltrate company systems. These methods once again demonstrate how costly a lack of basic cybersecurity hygiene can be. Black Kite's assessment of over 120,000 mid-market organizations reveals just how widespread these weaknesses are.

The key attack vectors highlighted in the report are:

  • Unpatched Software: It was found that 54.7% of the companies analyzed had at least one significant patch-management issue affecting a public-facing system. This means attackers can easily infiltrate systems by exploiting known vulnerabilities.
  • Known Vulnerabilities: More than a quarter of the organizations were found to have a vulnerability already known to be actively exploited by attackers. This shows that companies are lagging one step behind cybercriminals.
  • Stolen Credentials: Nearly one-third of the monitored organizations had at least one stealer-log finding, indicating credentials collected by information-stealing malware. Attackers can use these stolen usernames and passwords to gain direct access to networks, move laterally within the network, or prepare the ground for larger attacks.

The report also notes how artificial intelligence (AI) is changing this equation. AI is accelerating the speed at which software vulnerabilities are discovered and analyzed. While security teams can use AI to detect vulnerabilities faster and process large amounts of data, attackers are using similar tools to find weaknesses. This further increases the workload for mid-sized companies that are already trying to manage thousands of potential security issues with limited resources.

Who is Affected

The report also lists the sectors most affected by ransomware attacks. The manufacturing sector leads the list, accounting for more than a quarter of mid-market victims. This sector is followed by professional, scientific, and technical services, and construction. The reason these sectors are targeted may be their reliance on operational technology (OT) systems and the very high costs associated with production downtime, making them more vulnerable to ransom demands.

The primary target audience is mid-market companies with annual revenues between $10 million and $1 billion. Smaller businesses in the $10 million to $50 million revenue bracket are the target of more than half of the attacks. These companies often do not have the extensive cybersecurity budgets or dedicated security teams of large corporations, making them easier targets for attackers.

What You Can Do

There are steps mid-sized companies can take to protect themselves against these growing threats. In light of the report's findings, prioritization is crucial.

  • Risk-Based Vulnerability Management: Treating every vulnerability as equally urgent is not feasible with limited resources. Instead, prioritization should be based on factors such as whether the affected system is exposed to the internet, whether the vulnerability is being actively exploited by attackers, and what kind of access a breach could provide.
  • Take Patch Management Seriously: Ensure that patches on internet-facing systems are up-to-date. The fact that more than half of the companies in the report are weak in this area shows that this is one of the most critical lines of defense.
  • Protect Credentials: Mitigate the impact of stolen credentials by using additional security layers like multi-factor authentication (MFA). It is also important to check if employee credentials have been exposed in previous data breaches. A Data Breach Search tool can provide a proactive defense in this regard.
  • Cybersecurity Awareness: Train employees on the dangers of phishing attacks and information-stealing malware. The human factor is often the weakest link, so training is a critical investment.

What the Company Says

Black Kite, the publisher of this report, emphasizes that the findings point to a consistent and serious problem facing the mid-market. According to the report, the fact that attack rates have remained steadily high over a three-and-a-half-year period indicates that cybercriminals have found a persistent weakness in this market. Black Kite states that the biggest challenge for security teams is deciding which weaknesses to address first. Finding a vulnerability does not automatically indicate its urgency. Teams need to know which systems are at risk and which weaknesses are being actively exploited while reviewing thousands of potential issues.

Source

https://www.helpnetsecurity.com/2026/08/24/black-kite-mid-market-ransomware-risk-report/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.

Argus

Scheduled Maintenance Notice

August 29, 2026, 00:00 – 05:00 (UTC+3)

A scheduled maintenance will be performed for infrastructure security updates and performance improvements. The following services will be temporarily unavailable during this period.

  • Breach Search
  • Argus LiveStream
  • API Services
  • HUBOne Account Management

Your data is safe — this maintenance is solely for security updates and system optimization.