Ransomware gangs are increasingly skipping the household names and going after the companies in between. New data from risk intelligence firm Black Kite shows that ransomware attacks on distributors are concentrated among midmarket companies, not the largest enterprises in the sector. According to the research, 42% of the 2,289 distribution companies Black Kite monitors sit above its critical threshold for ransomware susceptibility, a warning sign that the industry's middle tier is dangerously exposed.

Why Midmarket Distributors Are Ransomware's New Sweet Spot

The pattern isn't unique to distribution. Black Kite's broader mid-market ransomware research has found that companies with revenues between $10 million and $1 billion accounted for roughly 73% of publicly disclosed ransomware incidents since 2023. Manufacturing led the pack as the most targeted industry, representing more than a quarter of mid-market victims, but distribution is following close behind.

The reason is straightforward. Large enterprises typically have dedicated security teams, mature incident response plans, and budgets for advanced monitoring tools. Midmarket distributors often operate with lean IT staff, legacy systems, and security programs that haven't kept pace with the scale of their operations. Yet these companies frequently sit at the center of complex supply chains, moving goods, invoices, and sensitive customer data between manufacturers and end buyers. That combination, valuable data plus weaker defenses, makes them an efficient target for attackers looking for maximum payout with minimum resistance.

Recent Breaches That Show the Pattern

This isn't a theoretical risk. Several recent incidents illustrate exactly how midmarket distributors are being hit. The Wesco data breach saw the extortion group ExfilSquad claim to have stolen millions of CRM records from the global supply chain and distribution company. Around the same period, ShinyHunters claimed a breach at Baker Distributing, one of the largest HVAC, refrigeration, and foodservice equipment distributors in the country, exposing hundreds of thousands of records.

Healthcare distribution hasn't been spared either. McKesson, a major pharmaceutical distributor, was hit with an extortion attempt that exposed 6.4 million unique email addresses, and separate reporting on the incident described how extortion tactics are increasingly replacing traditional ransomware encryption as the preferred method of attack. Instead of locking up systems, attackers steal data and threaten to release it, a tactic that requires less time inside a victim's network and is harder to detect until the damage is already done.

How One Distributor Breach Ripples Through Supply Chains

Distributors don't operate in isolation. They sit between manufacturers, retailers, healthcare providers, and countless other downstream partners who depend on timely, accurate data flow. When a distributor gets breached, the fallout rarely stays contained. Customer records, purchase orders, pricing agreements, and shipment data can all be exposed or held hostage, disrupting operations for every business connected to that distributor.

This is precisely why large enterprises now scrutinize their midmarket suppliers so closely, often requiring detailed security questionnaires before signing contracts. A single weak link in a distribution network can become the entry point for an attack that eventually touches hospitals, retailers, or manufacturers who never directly interacted with the attacker. The McKesson and Wesco incidents both show how a breach at one distributor can expose data belonging to countless downstream partners and customers who had no direct relationship with the attacker.

Practical Steps for Midmarket Firms

Midmarket distributors don't need enterprise-sized budgets to meaningfully reduce their risk. A few foundational practices go a long way:

  • Network segmentation: Isolating critical systems (inventory management, financial platforms, customer databases) from general office networks limits how far an attacker can move once they gain initial access.
  • VPNs and secure remote access: With many distributors relying on remote or hybrid staff, business-grade VPNs with strong authentication help prevent credential theft from becoming a full network compromise.
  • Limiting lateral movement: Enforcing least-privilege access, multifactor authentication, and regular audits of who can reach sensitive systems makes it harder for attackers to escalate a single compromised account into a company-wide breach.
  • Third-party risk monitoring: Since so many distribution breaches stem from vendor or partner weaknesses, regularly assessing the security posture of suppliers and partners is no longer optional.

What This Means For You

If you work for or with a midmarket distributor, this data is a call to action rather than a cause for alarm. Ransomware groups are opportunistic, and they gravitate toward targets where the effort-to-reward ratio favors them. Closing basic security gaps, such as segmenting networks and securing remote access, meaningfully changes that calculation. For businesses that rely on distributors as part of their supply chain, it's worth asking vendors directly about their security practices before an incident forces the conversation.

Key Takeaways

The data is clear: midmarket ransomware distributors are bearing a disproportionate share of attacks, and incidents at companies like Wesco and Baker Distributing show what that looks like in practice. Distributors of every size should treat network segmentation, secure remote access, and vendor risk assessments as baseline requirements, not optional upgrades. The businesses that act now, before an attacker forces the issue, will be far better positioned to keep their operations and their partners' data intact.