Ransomware attacks on mid-market firms are on the rise, with recent research revealing that three-quarters of incidents now target this segment. The latest findings from Black Kite highlight that manufacturers, in particular, face heightened risk from ransomware campaigns. This trend underscores the urgent need for robust ransomware controls and incident readiness among mid-size organisations, especially those in the manufacturing sector.
Ransomware Attacks Targeting Mid-Market Firms: The Key Findings
Black Kite, a cybersecurity risk intelligence provider, recently published a report examining the landscape of ransomware attacks globally. According to their data, around 75 percent of ransomware incidents in the past year have involved mid-market organisations. These findings were announced in early June 2024 and have quickly drawn attention within the cybersecurity community.
Mid-market firms, typically defined as businesses with annual revenue between £10 million and £1 billion, are increasingly caught in the crosshairs of cybercriminals. The report found that manufacturers were the most frequently targeted group within this segment. This is significant because manufacturers often hold sensitive intellectual property and operate critical supply chains, making them attractive to threat actors seeking leverage for ransom payments.
- 75 percent of all ransomware attacks now impact mid-market firms
- Manufacturing sector is most frequently targeted
- Ransomware operators favour organisations with moderate resources and valuable data
- Attacks have continued to increase in frequency throughout 2023 and early 2024
This new trend marks a shift from earlier years, when large enterprises and public sector organisations were the primary targets of ransomware gangs. The growing focus on mid-market firms reflects the changing tactics of attackers, who have learned that these organisations often lack the sophisticated defences of larger corporations but still have the financial incentive to pay ransoms.
How Ransomware Attacks on Mid-Market Firms Unfold
Ransomware attacks typically begin with an initial compromise, often through phishing emails, exposed remote desktop services, or vulnerabilities in software applications. Once inside, threat actors deploy ransomware to encrypt critical data, bringing operations to a halt until a ransom is paid.
For mid-market firms, attackers often exploit the following weaknesses:
- Limited internal cybersecurity resources
- Gaps in patch management and endpoint protection
- Lack of formal incident response plans
- Insufficient employee awareness training
Manufacturing organisations, in particular, face unique challenges. Many rely on legacy systems and operational technology (OT) environments that are difficult to patch or segment from business networks. This makes them susceptible to lateral movement by attackers once a foothold is gained.
The report notes that ransomware groups such as LockBit, BlackCat, and Cl0p have been especially active in targeting organisations fitting the mid-market profile. These groups use double extortion tactics, stealing sensitive data before encrypting files and threatening to publish it if demands are not met.
Timeline and Recent Activity
The trend of targeting mid-market firms has accelerated since mid-2023, according to Black Kite. Attackers have refined their targeting, using tools and reconnaissance to identify companies with enough resources to pay a ransom but without the extensive protections of larger enterprises. The manufacturing sector has seen a series of high-profile incidents in recent months, with ransomware groups increasingly focusing on disrupting supply chains and production lines.
As of June 2024, there is no evidence that this trend is slowing. In fact, the number of ransomware incidents reported by mid-market firms continues to rise quarter-on-quarter. Black Kite’s data also indicates that threat actors are becoming more selective in their targeting, seeking out firms that combine valuable data with potential operational disruption.
Why Ransomware Attacks on Mid-Market Firms Matter
The shift in ransomware targeting strategies has significant implications for the mid-market segment, particularly in manufacturing. A successful ransomware attack can halt production, disrupt supply chains, and result in substantial financial losses. The reputational damage from data breaches and operational downtime can also be severe, impacting customer trust and future business opportunities.
For the wider economy, the vulnerability of mid-market manufacturers presents a systemic risk. As these firms often supply larger enterprises or critical infrastructure, successful attacks can have knock-on effects far beyond the initial victim.
What Organisations Should Do in Response
Given the heightened risk to mid-market firms, particularly manufacturers, organisations should consider the following targeted measures:
- Prioritise ransomware-specific controls such as regular offline backups and rapid restoration testing
- Update and test incident response plans with ransomware scenarios relevant to your sector
- Review and harden remote access and third-party connections, especially in operational technology environments
- Invest in staff awareness training focused on current ransomware tactics
By focusing on these sector-specific controls, mid-market organisations can reduce their risk and improve their ability to respond effectively to ransomware threats.
Originally reported by infosecurity-magazine.com.







