Mid-sized companies accounted for 73% of all publicly disclosed ransomware incidents in North America and Europe between January 2023 and June 2026, according to a Black Kite report.
Key Points
- Mid-market firms with annual revenues between $10 million and $50 million were the most frequent targets for ransomware attackers.
- Manufacturing was the most impacted industry, followed by professional, scientific, technical services, and construction sectors.
- Over 54% of mid-market organizations surveyed had significant unpatched vulnerabilities in public-facing systems.
- Nearly one-third of monitored companies showed evidence of stolen credentials, which attackers use to gain unauthorized network access.
- Supply chain risks are increasing as mid-sized firms struggle to manage security oversight for hundreds of third-party vendors with limited staff.