Skip to main content

Computerease

Why Ransomware Gangs Are Now Targeting Mid-Market Companies, Not Just Enterprises

why do hackers target small and mid-sized businesses

For years, the assumption was simple. Big companies get the headline breaches. Small businesses fly under the radar. Everyone else sits somewhere safely in between.

New research says that middle assumption is exactly backwards.

A report released this week by third-party risk firm Black Kite found that nearly three-quarters of all publicly disclosed ransomware and data-extortion incidents across North America and Europe since 2023 hit companies with $10 million to $1 billion in annual revenue, the mid-market. Not small businesses. Not billion-dollar enterprises. The middle.

If your company falls anywhere in that range, this isn’t a distant industry trend. It’s a direct description of the group attackers are already choosing.

What the Research Actually Found

The report analyzed more than 13,000 disclosed ransomware incidents dating back to January 2023, alongside a separate security scan of over 120,000 mid-market companies. The mid-market’s share of attacks held remarkably steady, between 72% and 75%, across every period studied, even as total incident volume grew 44% between 2023 and 2025. This isn’t a temporary spike. It’s a consistent, sustained pattern.

More than half of the affected companies had annual revenue between $10 million and $50 million, the lower end of the mid-market band. Manufacturing was hit hardest, accounting for more than a quarter of all mid-market victims, followed by professional and technical services and construction, three industries with deep roots across Missouri and Illinois’ business community.

Why Attackers Prefer This Exact Size of Company

The logic is closer to a business decision than a technical one. Enterprise-level targets often have dedicated security operations centers, large budgets, and legal teams built for exactly this kind of extortion pressure. Small businesses, meanwhile, sometimes have too little revenue to make a worthwhile ransom target.

Mid-market companies sit in the middle of both curves. They typically hold enough sensitive data, financial records, client information, proprietary designs, to make a real ransom payment worthwhile. At the same time, many run lean security teams stretched across far more responsibility than headcount allows, with inconsistent patching, flat network access, and gaps in multi-factor authentication that a larger enterprise would have closed years ago.

Layer in one more factor: many mid-market companies also sit inside the supply chain of much larger organizations. A successful attack doesn’t just damage the victim. It can cascade into every enterprise customer or partner connected to that business, which makes mid-market targets attractive for reasons that go beyond their own bank account.

Why Manufacturing Gets Hit Hardest

Manufacturing’s outsized share of incidents isn’t a coincidence. Manufacturers depend on uninterrupted operations in a way many other industries don’t. A ransomware attack that halts production doesn’t just cost data. It stops shipments, breaks delivery commitments, and creates cascading financial pressure that builds by the hour, exactly the kind of leverage that pushes a victim toward paying quickly.

Manufacturing environments also frequently combine modern business systems with older operational technology that wasn’t designed with today’s threat landscape in mind, creating exactly the kind of security gaps this research points to.

How These Attacks Actually Get In

The initial access itself is rarely sophisticated. Documented mid-market incidents consistently trace back to the same small set of entry points: a VPN account without multi-factor authentication, a known vulnerability that was never patched, or credentials purchased from an initial access broker on a dark web marketplace. Ransomware-as-a-service has industrialized this process. Developers build and lease the malware; affiliates just need a working set of stolen credentials or an unpatched system to get in the door.

Once inside, modern ransomware groups increasingly steal data before encrypting anything, a tactic known as double extortion. Even a business with strong backups can still face pressure to pay, because the threat has shifted from “you can’t access your files” to “we will publish them publicly” if payment isn’t made.

What This Means for Your Business

Being mid-sized is not a middle ground of safety. This research directly contradicts the idea that mid-market companies are too small to be worth an attacker’s time. They are, statistically, the most targeted segment of the market right now.

Multi-factor authentication remains the single most common gap. Multiple documented incidents in this exact revenue band trace back to a forgotten VPN account with no MFA enforced. This is one of the least expensive controls to fix and one of the most common ways attackers get in.

Patch management is a direct line to risk reduction. A meaningful share of the mid-market companies scanned in this research had critical patch-management gaps on systems exposed directly to the internet. This is the same pattern this year’s Patch Tuesday coverage points to.

Backups need to be tested, not just present. Ransomware groups increasingly target backup systems directly before deploying their payload. A backup that hasn’t been tested for actual recovery isn’t a real safety net.

Vendor and supply chain exposure matters even if your own defenses are solid. If your business is a vendor to a larger company, or relies on smaller vendors of your own, a breach anywhere in that chain can become your problem.

Ransomware Exposure Self-Check for Mid-Market Companies

  • Multi-factor authentication is enforced on every remote access point, including VPN accounts that are rarely used.
  • Known vulnerabilities on internet-facing systems are patched on a defined, tracked schedule.
    Backups are tested for actual recovery, not just confirmed to exist.
  • Backup systems are isolated from the primary network so they can’t be encrypted alongside everything else.
  • Former employee accounts are disabled the same day they leave, not during the next scheduled review.
  • Vendor and third-party access to your systems is reviewed and limited to what’s actually needed.
  • You have a documented, tested incident response plan, not an improvised one.
  • Someone can tell you, right now, whether your company falls in this $10M-$1B revenue band, and has planned accordingly.

Not Sure Where Your Business Actually Stands?

Computerease can review your current defenses against the exact gaps this research identifies, MFA coverage, patch status, backup resilience, and vendor access, and show you where your real exposure is. Schedule a 15-minute discovery call to find out.

Download Your Free AI Policy Template

Frequently Asked Questions

Based on this research, mid-market companies, generally $10 million to $1 billion in annual revenue, have absorbed the clear majority of disclosed ransomware attacks since 2023. Size alone doesn’t guarantee safety in either direction, but this segment currently carries the heaviest documented burden.

Manufacturers depend on continuous operations, which gives attackers unusually strong leverage. A halted production line creates immediate financial pressure in a way that many other industries don’t experience at the same speed.

Insurance can help offset financial impact, but it doesn’t prevent an attack or guarantee coverage for every scenario. Most policies also require baseline security controls, like MFA, to remain valid.

Not reliably. Attackers increasingly steal data before encrypting it, so payment doesn’t guarantee stolen data won’t be published anyway, and paying can carry its own legal exposure.

Accordion Content

Enforcing multi-factor authentication across every remote access point. Multiple documented incidents in this exact company size trace directly back to an account that didn’t have it.

Key Takeaways

  • New research shows mid-market companies, not small businesses or large enterprises, absorb roughly three-quarters of disclosed ransomware attacks.
  • Manufacturing, professional services, and construction are the most targeted mid-market industries.
  • Attackers favor this segment because it combines meaningful ransom potential with common security gaps: missing MFA, unpatched systems, and flat network access.
  • Modern ransomware increasingly steals data before encrypting it, which means paying doesn’t guarantee your information stays private.
  • The fixes that matter most, MFA, patching, tested backups, and vendor review, are achievable without an enterprise-sized budget.