Mid-sized companies have become the primary target for ransomware and data extortion attacks, accounting for nearly three-quarters of publicly disclosed incidents in North America and Europe between January 2023 and June 2026. An analysis of 13,336 incidents with known revenue, conducted by Black Kite, defined mid-market companies as those with annual revenues ranging from $10 million to $1 billion. This segment consistently represented between 72% and 75% of all reported incidents throughout the period, indicating a sustained targeting trend.
The majority of these mid-market victims, over half, fell within the lower end of the revenue spectrum, specifically between $10 million and $50 million annually. The manufacturing sector was the most heavily impacted industry, comprising more than a quarter of all mid-market victims. It was followed by professional, scientific, and technical services, and then construction.
Attackers frequently exploit common weaknesses to gain initial access to company systems. A review of over 120,000 mid-market organizations revealed that 54.7% had at least one significant patch-management deficiency on a public-facing system. Furthermore, more than a quarter of these organizations had vulnerabilities that were already known to be actively exploited by threat actors.
Stolen credentials represent another significant entry point. Nearly one-third of the monitored organizations showed evidence of "stealer-log" findings, indicating that their credentials had been compromised by information-stealing malware. These stolen login details can be used by attackers for direct account access, lateral movement within networks, or as a preparatory step for more extensive attacks.
The challenge for security teams, particularly in mid-sized companies with limited staff and resources, lies in prioritizing which vulnerabilities to address first. The continuous emergence of new vulnerabilities, coupled with the increasing speed of their discovery and analysis facilitated by artificial intelligence, exacerbates this problem. While AI tools can assist security teams in identifying vulnerabilities and processing large volumes of security data, attackers also leverage similar capabilities to pinpoint weaknesses more rapidly.
This dynamic creates a greater workload for mid-sized companies already struggling to manage numerous vulnerabilities with constrained staff. Simply identifying a vulnerability does not automatically convey its urgency; teams must still determine if the affected system is internet-exposed, if the weakness is being actively exploited, and what level of access it could provide. Without this context, treating every vulnerability as equally critical becomes unmanageable when facing thousands of potential issues.
Mid-sized companies are also deeply embedded in complex supply chains, acting as both providers to larger organizations and consumers of services from their own suppliers, cloud platforms, and technology vendors. A security incident at one company can therefore ripple across the entire supply chain. A compromised supplier, for instance, could expose customer data, disrupt services, or offer attackers an alternative route into connected organizations.
Managing these intricate relationships presents another hurdle. The analysis noted that a typical vendor-risk team might consist of only two individuals responsible for overseeing more than 300 suppliers. Additionally, some software and services may operate outside formal vendor inventories, leaving security teams with an incomplete view of their third-party risk exposure.
However, regulatory requirements are increasingly bringing supply chain risks into focus. Directives such as the EU's NIS2 and U.S. regulations like NYCRR 500 and HIPAA mandate that organizations address risks associated with their suppliers. Consequently, mid-sized vendors may face growing demands from customers to provide detailed information about their security controls. For smaller security teams, understanding which vulnerabilities and third-party connections pose the greatest risk is crucial for effectively allocating their limited resources.






