Cybersecurity

Ransomware’s Real Target Isn’t the Giants. It’s the Squeezed Middle.

0

When a ransomware attack makes the news, it is usually a household name: a hospital chain, an airline, a retailer with millions of customers. That coverage has quietly misled everyone about who really gets hit. According to new research from Black Kite, which studied 13,336 disclosed incidents across North America and Europe from 2023 through mid-2026, nearly three-quarters of victims were mid-market companies, firms with revenue between $10 million and $1 billion. Not the giants, and not the corner shop. The middle.

The most striking thing is how steady that figure is. The mid-market’s share of attacks stayed between 72% and 75% every year, even as the raw number of incidents climbed 44% over the period. This is not a blip or a passing fashion among criminals. It is the settled shape of the business.

Big enough to pay, too small to defend

The logic behind it is coldly rational. A mid-sized firm is large enough to afford a ransom that makes the effort worthwhile, yet rarely has the security budget, staff, or tooling of a Fortune 500. As one industry analyst put it, these companies are simply easier to break into than large organisations, which makes them the better bet. More than half of the victims sat at the smaller end, between $10 million and $50 million in revenue, and manufacturing was the single most-hit sector, ahead of professional services and construction.

Black Kite’s scans of more than 120,000 mid-market organisations show why. Over half had a significant patching gap on an internet-facing system, more than a quarter carried a vulnerability already known to be exploited in the wild, and roughly a third had stolen credentials floating around from information-stealing malware. Each of those is an unlocked door, and small teams cannot check them all.

A problem that spreads

What makes the mid-market especially valuable to attackers is where it sits. These firms supply parts and services to much larger customers while depending on their own web of vendors and cloud providers. Breach one, and the damage can ripple outward, exposing a bigger partner’s data or opening a path into a more prestigious target. Black Kite’s own framing is sharp: a mid-market company is both a supplier and a customer, and those two kinds of risk, usually handled by separate teams at a large firm, often get handled by no one at all in the middle.

The staffing gap is stark. The report describes a typical vendor-risk team as two people responsible for more than 300 suppliers. Regulators are piling on pressure too, with rules like the EU’s NIS2 and US requirements such as HIPAA pushing companies to vouch for their suppliers’ security, which lands hardest on the smaller vendors being asked to prove it.

AI does not rewrite this story so much as speed it up. Black Kite calls it “attack-chain glue,” making reconnaissance, phishing, and target research faster and cheaper without inventing anything new. The trouble is that the same acceleration helps stretched defenders far less than it helps attackers with time to burn.

So what does a two-person security team do with all this? Not everything at once, which is the trap. The workable move is triage: fix the internet-facing systems first, patch the vulnerabilities attackers are already exploiting, and kill exposed credentials before chasing theoretical risks. Mid-market firms cannot outspend the giants on defence. What they can do is stop being the easy door, because easy is the whole reason they were chosen.

CONF3RENCE 2026: Germany’s Biggest Emerging Tech Event Throws Open Its Doors

Previous article

Companies Leaked Their AWS Keys Years Ago. Most Still Work.

Next article

You may also like

Comments

Comments are closed.