Decoding the business of technology.
examnity.

Mid-Market Firms Face 73% of Ransomware Attacks as AI and Third-Party Risks Surge

According to a new report from Black Kite, 73% of ransomware incidents now strike mid-market companies — firms too large to fly under the radar, too under-resourced to repel a serious intrusion. The figure reframes the threat model.

Aaron Blake, Threat Intelligence & Privacy Correspondent · updated August 24, 2026

Mid-Market Firms Face 73% of Ransomware Attacks as AI and Third-Party Risks Surge

Attackers are no longer chasing only Fortune-grade payouts. They are running volume on the soft middle.

The new kill zone

Mid-market firms occupy the connective tissue of the economy. They handle logistics, processing, payroll, and the third-party integrations that keep larger enterprises fed. When ransomware hits them, the blast radius travels fast — through suppliers, distributors, and the SaaS dependencies that hold modern operations together.

Black Kite's findings point to third-party access and AI-enabled techniques as the accelerants. The pattern is consistent across reporting on the current threat landscape. A successful breach on one mid-sized vendor lowers the cost of the next campaign. Threat actors iterate on the path of least resistance, and mid-sized suppliers offer plenty of it. The math is not complicated. The cost is.

The exposure that matters

Analysts cited by Business Standard argue that the technical severity of a breach matters less than the commercial exposure it creates. That distinction cuts to the core. A contained encryption event is a problem with a known cost envelope. A frozen billing system, a halted production line, a stalled contract — those compound through missed deliveries, contractual penalties, and customer flight.

Mid-market firms absorb that shock unevenly. Some carry insurance. Most do not hold reserves large enough to weather a multi-week operational freeze. The standard playbook — quiet payment, contained disclosure, vendor renegotiation — assumes the incident stays small and the optics stay contained. The accumulating data suggests otherwise.

What changes from here

Corporate IT will not solve this alone. The standard response — vendor questionnaires, annual pen tests, a slightly thicker SOC, another awareness training module — does not match the attack cadence. Threat actors iterate faster than procurement cycles. Regulators iterate slower. The gap widens by quarter.

The Black Kite data, read alongside moves like China's new 2030 cyber industry plan elevating quantum technology as a priority, suggests the offensive playbook is hardening on a national-industrial scale. The defensive playbook is still arguing about MFA enforcement. That gap will not close itself.

Until mid-market security budgets stop being treated as a cost center rather than a survival line, ransomware will keep eating the same slice of the economy that drives global GDP growth. The defenders know it. The attackers know it too.