Ransomware Disproportionately Targets Mid-Market Firms, Straining Supply Chain Security
A new report from risk management firm Black Kite reveals that mid-market companies those with annual revenues between $10 million and $1 billion face a disproportionate share of ransomware attacks, yet receive far less attention than smaller businesses or large enterprises. Analyzing 13,336 ransomware incidents between January 2023 and June 2026, the study highlights critical vulnerabilities in this overlooked segment.
The smallest mid-market firms ($10M–$50M in revenue) bore the brunt of attacks, accounting for nearly half of all incidents, while the "core mid-market" ($50M–$500M) saw 40–45%. In contrast, "upper mid-market" firms ($500M–$1B) experienced a 64% decline in attacks from 2023 (126 incidents) to 2025 (45 incidents).
North America was the hardest-hit region, with 72% of mid-market attacks occurring there victim counts rose from 2023 to 2026, while European incidents remained flat. The data, drawn from 120,128 mid-market businesses, underscores the region’s heightened exposure.
Supply Chain Risks and Regulatory Pressures
Mid-market firms often serve as both suppliers and customers, creating a dual security challenge that many lack the resources to manage. Large enterprises frequently demand cybersecurity compliance from their mid-sized vendors, but oversight is fragmented vendor-risk teams of just two people may be responsible for 300+ suppliers, making continuous monitoring nearly impossible.
Manufacturing was the most targeted industry (25%+ of victims), followed by professional services, construction, and wholesale. Nearly 30% of mid-market organizations had at least one known exploited vulnerability, amplifying risks across interconnected supply chains.
The report warns that when a mid-market firm is breached, the impact extends beyond the victim disrupting larger partners and customers. With 73% of ransomware incidents striking mid-market businesses, the findings highlight a growing threat to global supply chain resilience.
Source: https://www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257/
Black Kite Games cybersecurity rating report: https://www.rankiteo.com/company/black-kite-studios
National Center for the Middle Market cybersecurity rating report: https://www.rankiteo.com/company/midmarketcenter
"id": "BLAMID1787156865",
"linkid": "black-kite-studios, midmarketcenter",
"type": "Ransomware",
"date": "1/2023",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['Manufacturing',
'Professional Services',
'Construction',
'Wholesale'],
'location': 'North America',
'size': 'Annual revenues between $10M and $1B',
'type': 'Mid-market firms'}],
'description': 'A new report from risk management firm Black Kite reveals '
'that mid-market companies (those with annual revenues between '
'$10 million and $1 billion) face a disproportionate share of '
'ransomware attacks, yet receive far less attention than '
'smaller businesses or large enterprises. The study highlights '
'critical vulnerabilities in this overlooked segment, '
'analyzing 13,336 ransomware incidents between January 2023 '
'and June 2026. The report warns that breaches in mid-market '
'firms disrupt larger partners and customers, amplifying risks '
'across interconnected supply chains.',
'impact': {'operational_impact': 'Disruption to larger partners and '
'customers'},
'lessons_learned': 'Mid-market firms are disproportionately targeted by '
'ransomware attacks, yet lack sufficient resources to '
"manage supply chain security risks. Large enterprises' "
'cybersecurity compliance demands on mid-sized vendors are '
'often inadequately monitored due to limited oversight '
'teams.',
'post_incident_analysis': {'root_causes': 'Known exploited vulnerabilities in '
'mid-market firms, fragmented '
'vendor-risk oversight, and supply '
'chain interconnectedness'},
'references': [{'source': 'Black Kite Report'}],
'title': 'Ransomware Disproportionately Targets Mid-Market Firms, Straining '
'Supply Chain Security',
'type': 'Ransomware',
'vulnerability_exploited': 'Known exploited vulnerabilities'}