When you picture a ransomware victim, you probably imagine a Fortune 500 company — a big-name target with deep pockets and a press release. The reality is more specific, and less flattering.
A new study from cybersecurity firm Black Kite analyzed 13,336 disclosed ransomware incidents dating back to January 2023. The finding: 73% of ransomware victims in North America and Europe were mid-sized organizations with $10 million to $1 billion in annual revenue. Not Fortune 500. Not one-person shops. The middle.
And the volume is climbing. Incident counts in that revenue band grew 44% between 2023 and 2025.
The Sweet Spot
The largest segment of victims — 54% — sat in what researchers call the “lower mid-market”: companies doing $10 million to $50 million in revenue. These are manufacturing firms, construction companies, professional services practices, regional healthcare providers. Businesses with enough revenue to be worth a ransom demand, but without the dedicated security teams that larger enterprises can field.
Think about it from the attacker's perspective. A company doing $30 million a year has real money — enough to justify a six- or seven-figure ransom. But they probably don't have a Chief Information Security Officer. They may not even have a full-time IT security person. Their defenses are a mix of whatever their managed IT provider set up, whatever insurance required, and whatever seemed like a good idea at the time.
That gap — between having something worth stealing and having the people to protect it — is exactly where ransomware crews operate.
Why Manufacturing Leads
Manufacturing accounted for 26% of all mid-market ransomware victims, more than any other sector. The reason is operational, not technical. Manufacturing businesses run on continuous production. When a line goes down, the cost isn't measured in IT repair hours — it's measured in lost output, missed shipments, and idle workers who still need to be paid.
Ransomware crews know this. A manufacturer that can't ship product is under pressure to restore operations immediately, and paying the ransom starts to look like the fastest path back to production — even though it often isn't.
This played out in July when Coca-Cola suspended U.S. dairy production after a ransomware attack. It wasn't a data breach headline — it was a factory floor standing still. Cameron Regional Medical Center in Missouri confirmed a ransomware attack this month. SickKids in Toronto was hit again. The pattern repeats across industries where downtime is measured in minutes, not days.
The Gaps That Let Them In
Black Kite also scanned the security posture of over 120,000 mid-market companies. The results explain a lot:
- 28% had at least one known exploited vulnerability — a flaw that attackers are actively using, with a fix available
- 55% had patch management gaps on public-facing software — the stuff exposed directly to the internet
- 48% carried at least one known vulnerability rated severe (a severity score of 8.0 or higher)
- 47% had missing or weak email authentication, leaving the door open for phishing
These aren't exotic zero-day exploits requiring state-level resources. They're basics. Unpatched software. Open email gates. Known problems with known fixes that nobody got around to addressing.
That's the real story. Ransomware isn't breaking down fortress walls. It's walking through doors that were never locked.
What This Means for Your Business
If your organization sits in that $10 million to $50 million range — and many Southern Colorado businesses do — you're in the target zone whether you know it or not. The question isn't whether ransomware crews would find you interesting. The data says they already do.
The good news is that the gap between “vulnerable” and “defensible” is narrower than it looks. Most of the failures in the Black Kite study come down to fundamentals: patch the known vulnerabilities, authenticate your email, train your people to spot phishing, and know what you'd do if an attack got through. You don't need a massive security team. You need someone who knows what to look for and can prioritize the fixes that actually matter.
If you're not sure where your gaps are, that's the conversation worth having — before someone else finds them for you.