decrypted · 21 august 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security

The ransomware report that puts UK firms top of Europe's target list

A new piece of research published this week gives UK boards a number worth sitting with: when European ransomware gangs pick a country to hit, they pick Britain more often than anywhere else on the continent. That is the headline from Black Kite's latest ransomware report, released on 18 August, which analysed over 13,000 incidents with verifiable revenue data going back to 2023. It is not really a story about being unlucky. It is a story about which companies get skipped, and why the ones that do get hit tend to be missing the same basic things.

The mid-market is the target, not the exception

Black Kite's analysis found that 73% of ransomware victims across North America and Europe sit in the mid-market band: companies turning over between $10 million and $1 billion a year. That share has barely moved in four years, running between 72% and 75% every year since 2023, even as the raw number of attacks climbed by 44%. Within that band, the smallest companies, those turning over $10 to 50 million, took the biggest share of hits at 54%. Manufacturing was the most targeted sector, at just over a quarter of mid-market victims.

Within Europe, UK firms were the single most frequently hit. That is worth pausing on given how much UK cyber commentary still centres on FTSE 100 breaches and NHS trusts. The organisations actually absorbing the volume of ransomware are smaller: manufacturers, professional services firms, mid-sized logistics operators, the kind of company that runs a lean IT function and has never had a penetration test scoped beyond the website.

Why this segment, and what Secure by Design would change

Black Kite's researchers point to a mismatch: mid-market companies carry enterprise-grade consequences from an outage, customers who will not wait, data worth stealing, without enterprise-grade security teams to keep pace. The vulnerability data bears that out. Across the mid-market organisations Black Kite assessed, 28% had at least one known exploited vulnerability present on internet-facing assets, 55% showed significant gaps in patch management, 48% carried unaddressed vulnerabilities with a CVSS score of 8.0 or higher, and 47% had no working DMARC record, meaning anyone can spoof their domain in a phishing email.

None of that is exotic. It is the same list of basics that has appeared in every incident post-mortem for a decade. The Secure by Design lesson here is not really aimed at the mid-market company, which by definition does not have the headcount to chase every CVE by hand. It is aimed at the vendors and platforms those companies buy from: software that ships with DMARC enforcement, automatic patching and least-privilege defaults switched on removes the decision from a stretched IT manager entirely. A ransomware gang scanning for a way in does not care whether the target skipped a control on purpose or never knew it existed. The fix that scales is the one nobody has to remember to apply.

Also this week

AI is now writing exploit code for industrial control systems. A joint advisory from CISA, the NSA, the FBI, the Department of Energy and the EPA, published on 19 August, warns that attackers are using AI tools to generate working Python exploitation scripts against Siemens S7 series PLCs, the controllers that run manufacturing lines, water treatment plants and energy infrastructure. The attackers scan the internet with tools such as Censys and ZoomEye for S7 devices exposed on port 102, then feed the results into AI models that produce scripts using the open-source snap7 library to read and write directly to PLC memory and ladder logic. The agencies call it an evolution in capability: AI collapses the specialist knowledge an attacker used to need into a prompt. Siemens S7 controllers are common across UK manufacturing and utilities; the advice is unglamorous but familiar, inventory every PLC, patch, and take them off the public internet.

A widely used AI platform shipped without authentication on by default, and attackers noticed within hours. CISA added CVE-2026-64849, a critical flaw in the open-source MLflow platform, to its Known Exploited Vulnerabilities catalogue on 19 August. MLflow's tracking server exposes a webhook API with no authentication unless an administrator switches it on, and a flaw in how it handled redirects let attackers use that endpoint to reach cloud metadata services and steal cloud credentials directly. Scanning for exposed instances began within hours of the CVE being assigned. It is patched in version 3.15.0. MLflow has around 60 million monthly downloads, and any UK team that stood up a self-hosted instance while experimenting with AI tooling this year is worth checking today.

Sources

If you want a second opinion on where your own basics might be missing, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.