Ransomware attacks are increasingly shifting their focus toward medium-sized businesses, with cyber-criminals identifying these organizations as potentially lucrative and comparatively less protected targets, according to a study by risk management firm Black Kite.
The research, which analyzed ransomware-related data collected between 2023 and mid-2026, found that approximately 73% of ransomware victims during the period were medium-sized businesses. A significant proportion of these victims belonged to the manufacturing sector, highlighting the growing cybersecurity risks faced by companies operating within critical and interconnected supply chains.
The findings challenge the widely held assumption that cyber-criminals primarily target either small businesses with limited cybersecurity resources or large corporations with substantial financial assets. Instead, medium-sized companies appear to be emerging as an increasingly attractive target because they can offer a combination of valuable data, significant financial resources, and potentially weaker cybersecurity defenses.
Why Are Medium-Sized Businesses Becoming Targets?
Medium-sized businesses are generally considered organizations with annual revenues ranging from approximately $10 million to $1 billion. While these companies may have considerably larger budgets and resources than small businesses, they often do not have the same level ofcybersecurity investment, dedicated security teams, or advanced threat detection capabilities as large enterprises.
This security gap can make them particularly appealing to ransomware groups.
Cyber criminals are increasingly looking for organizations where a successful attack can result in a substantial financial payoff without requiring the level of effort and sophistication that may be necessary to penetrate a heavily protected multinational corporation.
Another challenge is the perception among some medium-sized businesses that they are not significant enough to attract the attention of ransomware operators. However, the Black Kite research suggests that this assumption could leave companies exposed to serious cyber threats, data breaches and ransomware attacks.
Manufacturing Sector Faces Significant Risk
The manufacturing industry appears to be particularly vulnerable because of its dependence on interconnected digital systems and uninterrupted operations. A ransomware attack that disrupts production, logistics, inventory management or business communications can quickly result in substantial financial losses.
Manufacturers can also become attractive targets because they are often connected to numerous suppliers, distributors and customers. As a result, compromising one organization could potentially provide cyber-criminals with opportunities to create additional disruption across the supply chain.
Ransomware Risks Extend Beyond One Company
The impact of a ransomware attack can go far beyond the organization that is directly compromised. Businesses may face operational downtime, financial losses, stolen data, reputational damage, regulatory consequences and recovery costs following an attack.
Furthermore, when a medium-sized company is part of a larger supply chain, an incident can affect business partners and customers as well. This makes supply chain cybersecurity an increasingly important concern for organizations of all sizes.
The latest findings serve as a warning for medium-sized businesses to reconsider their approach to cybersecurity. Investing in endpoint protection, employee security awareness, regular data backups, network monitoring, vulnerability management, and incident response planning can help organizations strengthen their defenses against ransomware.
As ransomware groups continue to adapt their strategies, the message for medium-sized businesses is clear: being overlooked by traditional assumptions about cybercrime does not mean being overlooked by cyber criminals.
