AUTO-UPDATED

Ransomware attackers are zeroing in on mid-market companies

Mid-sized companies accounted for 73% of all publicly disclosed ransomware incidents in North America and Europe between January 2023 and June 2026, according to a Black Kite report.

Key Points

  • Mid-market firms with annual revenues between $10 million and $50 million were the most frequent targets for ransomware attackers.
  • Manufacturing was the most impacted industry, followed by professional, scientific, technical services, and construction sectors.
  • Over 54% of mid-market organizations surveyed had significant unpatched vulnerabilities in public-facing systems.
  • Nearly one-third of monitored companies showed evidence of stolen credentials, which attackers use to gain unauthorized network access.
  • Supply chain risks are increasing as mid-sized firms struggle to manage security oversight for hundreds of third-party vendors with limited staff.

Why it Matters

Mid-sized businesses face a disproportionate cybersecurity threat because they often lack the resources to manage complex vulnerability patching and extensive supply chain risks. As regulatory requirements tighten, these companies must prioritize security investments to protect their operations and maintain their standing within larger corporate ecosystems.
Help Net Security Published by Anamarija Pogorelec
Read original