Chicago: 312-554-7550
St. Louis : 314-432-1661
Metro East IL : 618-346-8324
Central IL : 217-528-0500
For years, the assumption was simple. Big companies get the headline breaches. Small businesses fly under the radar. Everyone else sits somewhere safely in between.
New research says that middle assumption is exactly backwards.
A report released this week by third-party risk firm Black Kite found that nearly three-quarters of all publicly disclosed ransomware and data-extortion incidents across North America and Europe since 2023 hit companies with $10 million to $1 billion in annual revenue, the mid-market. Not small businesses. Not billion-dollar enterprises. The middle.
If your company falls anywhere in that range, this isn’t a distant industry trend. It’s a direct description of the group attackers are already choosing.
The report analyzed more than 13,000 disclosed ransomware incidents dating back to January 2023, alongside a separate security scan of over 120,000 mid-market companies. The mid-market’s share of attacks held remarkably steady, between 72% and 75%, across every period studied, even as total incident volume grew 44% between 2023 and 2025. This isn’t a temporary spike. It’s a consistent, sustained pattern.
More than half of the affected companies had annual revenue between $10 million and $50 million, the lower end of the mid-market band. Manufacturing was hit hardest, accounting for more than a quarter of all mid-market victims, followed by professional and technical services and construction, three industries with deep roots across Missouri and Illinois’ business community.
The logic is closer to a business decision than a technical one. Enterprise-level targets often have dedicated security operations centers, large budgets, and legal teams built for exactly this kind of extortion pressure. Small businesses, meanwhile, sometimes have too little revenue to make a worthwhile ransom target.
Mid-market companies sit in the middle of both curves. They typically hold enough sensitive data, financial records, client information, proprietary designs, to make a real ransom payment worthwhile. At the same time, many run lean security teams stretched across far more responsibility than headcount allows, with inconsistent patching, flat network access, and gaps in multi-factor authentication that a larger enterprise would have closed years ago.
Layer in one more factor: many mid-market companies also sit inside the supply chain of much larger organizations. A successful attack doesn’t just damage the victim. It can cascade into every enterprise customer or partner connected to that business, which makes mid-market targets attractive for reasons that go beyond their own bank account.
Manufacturing’s outsized share of incidents isn’t a coincidence. Manufacturers depend on uninterrupted operations in a way many other industries don’t. A ransomware attack that halts production doesn’t just cost data. It stops shipments, breaks delivery commitments, and creates cascading financial pressure that builds by the hour, exactly the kind of leverage that pushes a victim toward paying quickly.
Manufacturing environments also frequently combine modern business systems with older operational technology that wasn’t designed with today’s threat landscape in mind, creating exactly the kind of security gaps this research points to.
The initial access itself is rarely sophisticated. Documented mid-market incidents consistently trace back to the same small set of entry points: a VPN account without multi-factor authentication, a known vulnerability that was never patched, or credentials purchased from an initial access broker on a dark web marketplace. Ransomware-as-a-service has industrialized this process. Developers build and lease the malware; affiliates just need a working set of stolen credentials or an unpatched system to get in the door.
Once inside, modern ransomware groups increasingly steal data before encrypting anything, a tactic known as double extortion. Even a business with strong backups can still face pressure to pay, because the threat has shifted from “you can’t access your files” to “we will publish them publicly” if payment isn’t made.
Being mid-sized is not a middle ground of safety. This research directly contradicts the idea that mid-market companies are too small to be worth an attacker’s time. They are, statistically, the most targeted segment of the market right now.
Multi-factor authentication remains the single most common gap. Multiple documented incidents in this exact revenue band trace back to a forgotten VPN account with no MFA enforced. This is one of the least expensive controls to fix and one of the most common ways attackers get in.
Patch management is a direct line to risk reduction. A meaningful share of the mid-market companies scanned in this research had critical patch-management gaps on systems exposed directly to the internet. This is the same pattern this year’s Patch Tuesday coverage points to.
Backups need to be tested, not just present. Ransomware groups increasingly target backup systems directly before deploying their payload. A backup that hasn’t been tested for actual recovery isn’t a real safety net.
Vendor and supply chain exposure matters even if your own defenses are solid. If your business is a vendor to a larger company, or relies on smaller vendors of your own, a breach anywhere in that chain can become your problem.
Computerease can review your current defenses against the exact gaps this research identifies, MFA coverage, patch status, backup resilience, and vendor access, and show you where your real exposure is. Schedule a 15-minute discovery call to find out.
Based on this research, mid-market companies, generally $10 million to $1 billion in annual revenue, have absorbed the clear majority of disclosed ransomware attacks since 2023. Size alone doesn’t guarantee safety in either direction, but this segment currently carries the heaviest documented burden.
Manufacturers depend on continuous operations, which gives attackers unusually strong leverage. A halted production line creates immediate financial pressure in a way that many other industries don’t experience at the same speed.
Insurance can help offset financial impact, but it doesn’t prevent an attack or guarantee coverage for every scenario. Most policies also require baseline security controls, like MFA, to remain valid.
Not reliably. Attackers increasingly steal data before encrypting it, so payment doesn’t guarantee stolen data won’t be published anyway, and paying can carry its own legal exposure.
Accordion Content
Enforcing multi-factor authentication across every remote access point. Multiple documented incidents in this exact company size trace directly back to an account that didn’t have it.