Critical

Ransomware attackers are zeroing in on mid-market companies

Help Net Security
Actively Exploited

Overview

A recent analysis by Black Kite reveals that mid-sized companies are increasingly becoming targets for ransomware attacks. Between January 2023 and June 2026, these companies, defined as those with annual revenues between $10 million and $1 billion, accounted for 73% of all publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe. This consistent trend, showing that mid-market firms are targeted in 72% to 75% of cases during this period, indicates a shift in focus from larger enterprises to smaller businesses. The implications are significant, as these mid-sized companies often lack the extensive cybersecurity resources of larger firms, making them more vulnerable to such attacks. This trend underscores the need for improved security measures within these organizations to protect sensitive data and maintain operational integrity.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Mid-sized companies with annual revenues between $10 million and $1 billion
  • Action Required: Mid-sized companies should enhance their cybersecurity measures, including employee training, regular software updates, and incident response planning.
  • Timeline: Ongoing since January 2023

Original Article Summary

Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion. Their share of incidents remained between 72% and 75% throughout the period, showing that attacks on this part of the market are … More → The post Ransomware attackers are zeroing in on mid-market companies appeared first on Help Net Security.

Impact

Mid-sized companies with annual revenues between $10 million and $1 billion

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since January 2023

Remediation

Mid-sized companies should enhance their cybersecurity measures, including employee training, regular software updates, and incident response planning.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware.

Related Coverage

Iran-Linked Hackers Shut Down UK Power Plant for Four Days

SecurityWeek

Iranian hackers successfully targeted a power plant in the UK, causing a shutdown that lasted four days. This incident disrupted operations and raised alarms about the vulnerability of the UK's energy infrastructure. Experts are particularly concerned about the potential for similar attacks in the future, emphasizing the need for improved defenses against cyber threats. The breach underscores the ongoing risks posed by state-sponsored hacking groups, especially those linked to Iran. As the energy sector increasingly relies on digital systems, ensuring their security is becoming more critical than ever.

Aug 24, 2026

TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy

SecurityWeek

TikTok has agreed to a $400 million settlement with the U.S. Justice Department related to violations of children's privacy laws. The company will pay $300 million upfront and an additional $100 million contingent upon the dismissal of a previous consent decree involving its predecessor, Musical.ly. This settlement arises from allegations that TikTok collected personal data from minors without proper consent, raising concerns about the protection of children's online privacy. The outcome of this settlement is significant as it underscores the ongoing scrutiny of social media platforms and their practices regarding user data, particularly for younger audiences. The financial penalties serve as a warning to other companies about the importance of compliance with privacy regulations.

Aug 24, 2026

Can employees safely use AI agents? AI pentesting agent liabilities, and the news - Rob Allen - ESW #473

SCM feed for Latest

The article discusses concerns surrounding the use of AI agents in cybersecurity, particularly focusing on the risks associated with AI penetration testing tools. As organizations increasingly adopt these technologies, there are questions about the legal liabilities and potential misuse of AI agents. Employees using these tools might unintentionally expose their companies to security vulnerabilities or legal repercussions if the AI behaves unpredictably. The discussion emphasizes the need for clear guidelines and training for employees to safely utilize AI in their cybersecurity efforts. This is particularly important as companies strive to balance innovation with security and compliance.

Aug 24, 2026

Slovakia Warns of Cyber Risks in Road Speed Cameras

Security Affairs

Slovakia's National Security Authority (NBÚ) has issued a warning about vulnerabilities in certain road speed cameras. These weaknesses could allow attackers to access vehicle data and potentially gain remote control of the cameras, posing risks to public networks. This alert is not about tampering with speeding tickets; instead, it emphasizes a serious cybersecurity concern that could affect traffic management and public safety. The NBÚ's warning serves as a reminder for the need to secure critical infrastructure, as these vulnerabilities could be exploited for malicious purposes. Addressing these issues promptly is essential to protect both motorists and the integrity of public systems.

Aug 24, 2026

TikTok Settles U.S. Child Privacy Case for $400 Million

Security Affairs

TikTok has agreed to pay $400 million to settle a lawsuit in the United States regarding its collection of data from users under the age of 13. This settlement comes after claims that the social media platform violated child privacy laws. The lawsuit, announced by the U.S. Department of Justice, emphasizes the importance of protecting children's personal information online. By settling, TikTok aims to resolve the legal issues without admitting to any wrongdoing. This case is significant as it highlights ongoing concerns about data privacy for minors and sets a precedent for how similar cases may be handled in the future.

Aug 24, 2026

Fake bank websites play dead to evade security scanners

Help Net Security

A new phishing technique called Chameleon SEO Poisoning has been identified by Fortra's threat intelligence team. This method involves creating fake banking websites that are optimized to appear in search results for terms like 'Bank Name Customer Portal'. These deceptive sites can evade security scanners by disguising themselves, making it difficult for users to recognize them as fraudulent. Fortra reported a significant increase in these phishing attempts, with a 40% rise noted in the second quarter of 2026. This situation poses a serious risk to individuals seeking to access their banking information online, as attackers aim to steal credentials through these disguised sites.

Aug 24, 2026