Black Kite
Reports
All Statistics
More than half of mid-market ransomware victims generate less than $50M in annual revenue.
Mid-market organizations accounted for approximately 72–75% of ransomware victims each year.
32.3% of mid-market organizations have at least one stealer log finding.
30.8% of ransomware victims carried KEV exposure.
18.5% of ransomware victims carried FocusTag signals.
The five largest ransomware actors controlled 43.6% of all victims.
In the last 16 months, nearly 70% of Europe's ransomware activity was concentrated in Germany, the United Kingdom, France, Italy, and Spain.
Manufacturing was the most-affected sector at 27.9% of ransomware victims.
Germany reported 370 ransomware incidents (17.9%), the United Kingdom reported 347 (16.8%), France repored 255 (12.3%), Italy reported 240 (11.6%), and Spain reported 203 (9.8%) among ransomware incidents across Europe.
Direct ransomware attacks on financial institutions spiked 76% year-over-year in Q1 2026.
Across all financial services vendors, 50.2% carry high-severity CVEs.
Over 48,000 CVEs were published globally in 2025, an 18% year-on-year increase.
Attackers exploited vulnerabilities an average of seven days before public disclosure in 2025.
More than 48,000 CVEs were published in 2025, an 18% increase year-over-year.
2,130 AI-related vulnerabilities were reported in 2025, a more than 200% increase since 2023.
Average downstream breach victims per vendor increased from 2.46 in 2021 to 5.28 in 2025.
An estimated 26,000 shadow victims remain impacted by vendor breach cascades but are never officially named.
433 million people are publicly disclosed as impacted by third-party breaches.
Among companies with less than $20 million, manufacturing is the second targeted industry at 17%.
Manufacturing remains ransomware's number one target. It has held the number one position for the fourth year in a row.
75% of manufacturing companies have critical vulnerabilities with a CVSS score of 8 or higher.
There were 156 disclosed ransomware victims in the financial sector in 2024.
65% of third-party vendors are not maintaining current patch levels, which exposes financial institutions to inherited risk from known vulnerabilities (CVEs) and potentially unpatched zero-day vulnerabilities in legacy technologies.
Cl0p claimed responsibility for targeting companies using unpatched versions of Cleo's MFT products in December 2024.
There has been a 123% increase in ransomware attacks over two years.
The number of publicly disclosed victims saw a 25% increase from the previous year (between April 2024 and March 2025)2. This follows an 81% surge in the period before that.
Ransom payment values declined by 35%.
Over 4,400 of the disclosed CVEs in 2024 were classified as critical (CVSS 9.0+).
Over 20,000 of the disclosed CVEs in 2024 had a CVSS score of 7.0 or higher.
There was a 38% year-over-year increase in published CVEs.
The healthcare sector is the third-most targeted sector for ransomware attacks, following manufacturing and professional services.
There was a significant rise in healthcare ransomware attacks in 2024. From Q1 2023 to Q3 2023, healthcare was the 6th or 7th most targeted sector, but it jumped to third position in Q4 2023 and has remained there.
There were 66 ransomware healthcare victims in Q1 2024, 87 healthcare victims in Q2 2024, 99 healthcare victims in Q3 2024, and 121 healthcare victims in Q4 2024.
73% of ransomware attacks in North America and Europe hit companies with $10M to $1B in annual revenue from 2023 through the first half of 2026.
Mid-market organizations accounted for 74.6% of ransomware incidents in 2023, 72.1% in 2024, 74% in 2025, and 72.3% in the first half of 2026.
Manufacturing represented more than 25% of mid-market ransomware victims.
48.1% of mid-market organizations carry at least one disclosed vulnerability with a CVSS score of 8.0 or higher.
54.7% of mid-market organizations have at least one significant patch management finding on public-facing software.
46.8% of mid-market organizations have missing or insufficient DMARC protection.
28.3% of mid-market organizations carry at least one known exploited vulnerability (KEV).
7,551 publicly disclosed ransomware victims were identified between April 1, 2025 and March 31, 2026, a 24.9% increase from the previous reporting period.
There were 146 active ransomware groups by June 2026, including 61 new groups entering during the reporting period.
Stealer log exposure increased 175% in a before-and-after security posture comparison.
Ransomware activity accelerated 60% in the second half of the reporting period and closed with 861 victims in March 2026, the highest monthly total in four years.
Qilin claimed more than 1,300 victims, nearly twice as many as its nearest rival.
43.5% of victims still carried critical patch vulnerabilities in the latest assessment.
Within professional, scientific, and technical services, IT service providers were the single most-targeted subindustry by ransomware.
Ransomware attacks rose 55.1% year-over-year in the first four months of 2026 and reached an average of 171 incidents per month.
More than half of SafePay's ransomware activity in Europe targeted German organisations.
The Qilin ransomware group was linked to ransomware incidents in 26 of the 31 countries analysed.