Known Exploited Vulnerabilities and the brutal mid-market ransomware truth
Everyone pictured a Fortune 500 breach. Black Kite's 13,336-incident study says the real target has $10 million to $1 billion in revenue, and it usually falls to a known exploited vulnerability nobody got round to patching.
By Katie Delaney · 2026-08-26 · 15 min read
Why ransomware crews are targeting the mid-market, not the enterprise#
A fox does not stalk the biggest beast in the field. It reads the wind, watches the weaker gait, and picks the quarry that will not fight back too hard. That is the plain, unglamorous logic behind the single most important finding in cybersecurity this month: ransomware crews are not chasing giants, they are chasing the mid-sized firm next door, and most mid-market security budgets have been planning for the wrong attacker, and the wrong known exploited vulnerabilities, entirely.
Black Kite's mid-market ransomware research analysed 13,336 ransomware and data-extortion incidents with verifiable revenue data, spanning January 2023 through June 2026, and the pattern held steady the whole way through: firms earning between $10 million and $1 billion a year absorbed 73% of the hits, consistently between 72% and 75% every single year in the window. That is not a blip. It is a business model, and it means defences built for the household-name enterprise are protecting the wrong shape of company.

The reason is not mystery, it is arithmetic. A company worth $50 million holds real data, real payroll, real supplier relationships, and a genuine incentive to pay quietly and quickly. It rarely holds a security operations centre, a dedicated patch-management team, or the budget of a Fortune 500 defender that closes known exploited vulnerabilities within days. Enterprises get the headlines because their breaches are loud. Mid-market firms get the money because their breaches are easy, and the gap between those two facts is where every serious conversation about ransomware readiness should now begin.
Manufacturing carries the heaviest weight#
CISA's own Gunra ransomware advisory names government and critical infrastructure, the government-defined category manufacturing sits inside, among Gunra ransomware's stated targets, which lines up with what Black Kite found across the wider mid-market: manufacturing accounted for more than 25% of mid-market ransomware victims, the single hardest-hit sector in the study. That tracks with what the FBI's Internet Crime Complaint Center separately documented for 2025, naming critical manufacturing among the sectors its top ransomware variants hit hardest, alongside healthcare and government facilities.
Manufacturing floors run on uptime, not on patch cycles. A production line stopped for six hours costs more, in board-level panic, than most ransom demands, which is precisely the leverage a mid-sized manufacturer's attacker is counting on. Buying security tooling is one line item; understanding that the line already has known exploited vulnerabilities painted on it is another, and too few mid-market operations directors have made that connection yet. A manufacturer building real ransomware readiness should ask, specifically, how a vendor handles operational-technology networks, since the office estate and the factory floor rarely share the same weak points.
Read that climb the way a tracker reads a fresh trail: the direction matters more than any single footprint. Incident counts rose 44% across two years while the mid-market's share of total attacks barely moved, which means the growth is not attackers discovering the segment, it is attackers scaling what already worked. A hunting ground that returns 73% of the reward for a fraction of the resistance does not stay quiet once word gets around, and word has clearly got around. Ransomware readiness should be rising at the same pace as that line, and for most mid-market firms it plainly is not.
The known exploited vulnerabilities problem behind every mid-market breach#
Being targeted is only half of Black Kite's finding. The other half explains why the targeting works, and it comes down to a gap that a working patch programme exists specifically to close.
None of this is exotic tradecraft. It is a mid-sized firm's own front door, left ajar because the team responsible for closing it is stretched across a dozen other duties. That is the honest case for treating known exploited vulnerabilities as a standing discipline rather than an annual scan: the weaknesses attackers used were already public, already catalogued, and already patchable before the breach happened.
Black Kite analysed 13,336 incidents spanning January 2023 through June 2026. Mid-market companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents in North America and Europe.
That thread went further than the press release did, and it is worth sitting with the follow-on point rather than skimming past it: the same poster flagged that mid-market firms adopting AI agents are handing attackers a faster route once they are inside, because an agent holds credentials and acts at machine speed with nobody watching every step. A compromised login used to need a human at the keyboard to do damage. It increasingly does not, and a security programme that stops at the network perimeter misses that shift entirely.
Carried a known exploited vulnerability
Present at the moment of breach, not discovered after it.
Had significant patch-management gaps
On systems already facing the public internet.
Left a CVSS 8.0+ flaw unaddressed
A severity band CISA treats as priority-one.
Put those three figures side by side and the pattern is not subtle. A mid-sized firm does not usually fall to a novel attack technique, it falls to a known problem that sat unpatched long enough for someone to come looking, and CISA's own StopRansomware Guide consistently urges organisations to prioritise exactly this class of fix over anything more exotic. That is also the exact test to apply before signing any vendor claiming to improve ransomware readiness: ask which known exploited vulnerabilities they patched on your estate this month, not which dashboard they can screenshot in a sales call.
What the research means for real ransomware incident response#
Ferhat Dikbiyik, Black Kite's Chief Research and Intelligence Officer, framed the shift plainly: “This is the first time we examined the mid-market as a segment in its own right, rather than a set of companies scattered through larger studies”. Treating the mid-market as its own segment, rather than folding it into broader enterprise research, is what makes the 73% figure legible in the first place.
This is the first time we examined the mid-market as a segment in its own right, rather than a set of companies scattered through larger studies.
A useful way to picture how a single overlooked patch becomes a full breach, and why good ransomware incident response has to cover the whole chain rather than one link of it, is to follow the trail an attacker actually walks, one paw print at a time, rather than treating ransomware as a single dramatic event.
Automated tooling sweeps internet-facing firewalls, VPN gateways and remote-access portals for devices still running known exploited vulnerabilities.
One of those known exploited vulnerabilities grants initial access without needing a stolen password, the same route CISA documented for Gunra ransomware affiliates.
Once inside, the actor lifts stored logins and, increasingly, the access tokens any AI agents on the network are already carrying.
With a working credential, the intruder crosses from the entry point to file servers and backups, usually well before anyone notices.
Data is encrypted, a copy is exfiltrated as leverage, and a ransom note lands on a screen someone was not expecting to see that morning.
Every step in that chain has a countermeasure a competent ransomware incident response plan already accounts for: perimeter scanning that flags known exploited vulnerabilities before an attacker finds them, credential hygiene that assumes an agent's token is worth stealing, and network segmentation that turns lateral movement into a dead end instead of a highway. None of it is glamorous. All of it is the actual job.
It is also, notably, cheaper than the alternative. Sophos's State of Ransomware 2026 report put the average recovery cost from a ransomware incident at $1.7 million in 2026, up 11% year on year, even as median ransom demands fell to $698,000 in the same survey of 2,158 IT and security leaders across 17 countries. Prevention is not a nicer number than recovery, it is a smaller one.
Cost is not the only pressure mid-market leaders are carrying, either. Where a company outsources detection and response, provider quality now varies more than the marketing suggests, and the wave of private-equity consolidation reshaping that market is its own reason to check exactly what a managed provider is promising versus what it is actually staffed to deliver.
Choosing a security vendor on the strength of a logo slide rather than a patch cadence is how a firm ends up back in Black Kite's next dataset. The research gives buyers a short, specific checklist instead: ask for the KEV response time, ask for the patch-gap number, ask for the CVSS backlog, and treat a vague answer to any of the three as the real red flag when scoping ransomware incident response.
The ransomware attack statistics that corroborate the pattern#
Black Kite's 13,336 incidents are the headline, but the wider ransomware attack statistics landscape corroborates the same story from several independent angles, which is exactly what should make a mid-market operations leader stop scrolling and start reading.
Verizon's 2026 Data Breach Investigations Report found ransomware involved in 48% of all breaches it analysed in 2026, up from 44% the year before, a rise consistent with attackers finding the technique reliably profitable rather than running out of road. Meanwhile the FBI's Internet Crime Complaint Center logged 3,611 ransomware complaints in 2025 with more than $32 million in reported financial loss, a figure the Bureau itself flags as an undercount, since it only reflects what victims chose to report.
| Finding | Figure | Source |
|---|---|---|
| Mid-market share of ransomware incidents | 73% | Black Kite, Aug 2026 |
| Breaches involving ransomware | 48%, up from 44% | Verizon DBIR 2026 |
| Ransomware complaints reported to the FBI | 3,611 in 2025 | FBI IC3 2025 |
| Average ransom payment, Q2 2026 | $1.88M (median $150K) | Coveware by Veeam |
| Average ransomware insurance claim, under $25M revenue | $422K, up 40% YoY | At-Bay, via Help Net Security |
That last row deserves a second look. At-Bay's 2026 InsurSec Report found ransomware severity for companies under $25 million in annual revenue climbed 40% year over year to $422,000, with frequency up 21%, because attackers pulled smaller firms into the same infrastructure-driven campaigns previously aimed at mid-market and larger targets. The floor is not holding, it is being crossed.
Coveware's Q2 2026 ransomware payment data recorded a similar squeeze from the payment side: mid-market organisations, those with 11 to 10,000 employees, accounted for 75.8% of extortion cases it tracked in Q2 2026, with the 101-to-1,000-employee band alone making up 35.4% on its own. Average payments jumped sharply that quarter, but the median fell, meaning most victims are paying less while a small number of severe cases skew the headline number upward, a pattern that only holds if incident teams are actually catching the smaller, quieter breaches alongside the dramatic ones.
One figure worth repeating to a board#
Ransomware attack statistics like these are not decoration for a slide deck, they are the business case every security budget request actually needs, because a board that hears "73% of firms our size" reacts differently than a board that hears "some companies get hit sometimes."
If a mid-market board only remembers one line from this article, make it this: 73% of ransomware incidents in a 13,336-case study hit firms their size, not the enterprise names in the trade press. Every budget conversation about known exploited vulnerabilities should open with that sentence, because it is the one that reframes the whole spend as necessary rather than aspirational.
Building real ransomware readiness on a mid-market budget#
None of the research above is much use without a plan a mid-market team can actually run, on the budget a mid-market team actually has. Ransomware readiness does not need to be perfect on day one, it needs to close the gaps Black Kite measured, in the order that removes the most risk fastest.
Patch when there is time
Vulnerability scans run quarterly, patching queues behind feature work, and nobody owns the known exploited vulnerabilities list specifically, so a known flaw can sit exposed for months.
Patch what attackers are using
A named owner checks the CISA KEV catalogue weekly, internet-facing systems get patched first, and every CVSS 8.0+ finding gets a deadline instead of a backlog entry.
That single change, moving from a general patch backlog to a KEV-prioritised one, is the difference between the 28.3% of victims Black Kite found carrying known exploited vulnerabilities at breach time and a firm that closed them in week one. It costs process discipline, not new headcount, which is precisely why it belongs at the top of any ransomware readiness plan. A mid-market team with no formal security function at all can still start here: NIST's Cybersecurity Framework 2.0 Small Business Quick-Start Guide was written specifically for organisations with modest or no cybersecurity plans in place, and it treats vulnerability documentation as a first step rather than an advanced one.
Firms that outsource detection rather than build it in-house are watching the managed-security market shift underneath them too: providers are proving their monitoring is real rather than theoretical, a change worth understanding before signing a renewal, and incident response services buyers now expect exactly that kind of evidence, not a dashboard screenshot.
Compliance pressure compounds the case. Regulators are not carving out mid-market exemptions, and the NIS2 compliance ruling working through European courts shows how quickly a compliance question can escalate into a legal and financial one even for firms that assumed their size kept them off the radar.
The honest answer to the FAQ every mid-market IT lead eventually asks, what is the best protection against ransomware, is unglamorous: patch the known exploited vulnerabilities first, segment the network so one stolen credential cannot reach everything, keep offline backups nobody but the response team can touch, and rehearse the incident before it happens rather than during it. Ransomware readiness that skips any one of those four steps is insurance against a fire nobody has checked for exits.
A related risk is moving just as fast through the same mid-market vendor base. A fresh look at AI supply chain security and the Phantom Raven package-poisoning campaign, published the same week as this piece, looks at how attackers are exploiting AI coding tools' own hallucinations to poison the software supply chain, a threat that arrives through the same unmonitored, agent-heavy systems the Reddit thread above was warning about.
Building any of this from a blank page is slow, which is exactly the gap folkfox works inside: helping cybersecurity vendors and MSSPs turn research like Black Kite's into content their mid-market buyers actually trust enough to act on, rather than another vendor claim lost in the same crowded inbox.
Frequently asked questions#
What are known exploited vulnerabilities, and why do they matter so much?
Known exploited vulnerabilities are flaws CISA has confirmed attackers are actively using, listed in the public Known Exploited Vulnerabilities Catalog. 28.3% of mid-market ransomware victims in Black Kite's study carried at least one at the time they were breached, meaning the weakness was public and patchable beforehand.
What does good ransomware incident response actually involve for a mid-sized firm?
A plan that covers the whole attack chain, not just cleanup: perimeter scanning for known exploited vulnerabilities, credential hygiene that assumes AI agents carry stealable tokens, network segmentation, offline backups, and a rehearsed response before the first real incident, not during it.
What is the best protection against ransomware?
Patch known exploited vulnerabilities first, segment networks so one stolen credential cannot reach everything, keep offline backups the response team controls exclusively, and rehearse incident response before an attack, not during one.
What does ransomware readiness actually cost a mid-market firm?
Less than recovery does. Sophos found average ransomware recovery costs reached $1.7 million in 2026. Ransomware readiness built around patching known exploited vulnerabilities and segmenting networks is process discipline, not new headcount, and it is consistently the cheaper number.
How fast is mid-market ransomware activity actually growing?
Black Kite recorded a 44% rise in mid-market ransomware and data-extortion incidents, from 2,320 in 2023 to 3,340 in 2025, a steady climb rather than a single spike, matching Verizon's finding that ransomware involvement in breaches rose to 48% in 2026.
Which sector gets hit hardest within the mid-market?
Manufacturing, by a clear margin. It accounted for more than 25% of mid-market ransomware victims in Black Kite's research, a pattern the FBI's 2025 Internet Crime Report separately corroborates by naming critical manufacturing among its hardest-hit sectors.
Read more on this topic#
MDR Services Just Grew a Second Set of Watchful Eyes
How the Fortinet-Virtue AI acquisition changes what mid-market buyers should expect from a managed detection provider.
Read the pieceIncident Response Services Now Have to Prove They Are Real
Why buyers are demanding evidence, not dashboards, before renewing an incident response contract.
Read the pieceNIS2 Compliance Meets the Court of Justice, and Ireland Picks Up the Bill
A CJEU referral shows how fast a compliance question becomes a legal and financial one, mid-market firms included.
Read the pieceAI supply chain security and the Phantom Raven package-poisoning campaign
A fresh look at how attackers are exploiting AI coding tools' own hallucinations.
Read the pieceNeed mid-market buyers to trust your ransomware readiness message?
folkfox turns research like Black Kite's into content, schema and reporting that cybersecurity vendors and MSSPs can use to reach mid-market IT and security leaders before the next headline does.