Black Kite Says Middle Market Firms Took 73 Percent of Ransomware Attacks
Black Kite released a report on ransomware attacks against middle market companies, announced in a press release. The study analyzed 13,336 ransomware incidents with verifiable revenue across North America and Europe from January 2023 to June 2026, and found that 73 percent hit organizations with $10 million to $1 billion in annual revenue.
The share stayed consistent across the period: 74.6 percent in 2023, 72.1 percent in 2024, 74 percent in 2025, and 72.3 percent in the first half of 2026. The total number of ransomware incidents rose 44 percent, from 2,320 in 2023 to 3,340 in 2025.
Manufacturing accounted for more than 25 percent of middle market ransomware victims. Professional, scientific, and technical services followed, along with construction.
Black Kite also assessed 120,128 middle market organizations from an external attack surface view. It found that 28.3 percent had at least one known exploited vulnerability, 54.7 percent had at least one significant patch management finding on public facing software, 48.1 percent had at least one disclosed vulnerability with a CVSS score of 8.0 or higher, 32.3 percent had at least one stealer log finding, and 46.8 percent had missing or insufficient DMARC protection.
The report said AI is widening the gap by speeding vulnerability discovery for defenders and attackers. It cited ISC2's 2025 Cybersecurity Workforce Study, which found that 20 percent of mid sized organizations had adopted AI tools in security operations.
We hope you enjoyed this article.
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from: Cybersecurity
Subscribe to Cybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Whitepaper
AI and the Law: Discussion Paper
This discussion paper explores the intersection of artificial intelligence and legal frameworks, addressing potential legal challenges posed by AI's autonomy, adaptiveness, and opacity. It examines issues such as liability gaps, causation, and the potential for granting AI systems legal personality, aiming to foster further discussion on AI's impact on law reform.
Read more