Technology

Black Kite Finds Known Weaknesses at Past Ransomware Victims

Black Kite found that 43 percent of the prior ransomware victims it observed still exposed at least one unpatched critical vulnerability, Cybersecurity Dive reported Tuesday. The vendor also found that 31 percent had a vulnerability listed in the U.S. government's catalog of known exploited flaws. [1] Those percentages describe visible conditions after attacks. They do not identify how an intruder entered.

The finding extends the paper's July 20 account of Craneware's stolen customer and employee files, which separated confirmed access and theft from affected-person counts, operating effects and remediation. Black Kite supplies a cross-company view. It does not fill Craneware's missing incident record or make that company a member of every reported denominator.

A specific July 21 X search for Black Kite ransomware "43%" unpatched completed without finding a verified post. Breach-shaming, resource constraints and insurer pressure therefore remain possible hypotheses rather than observed platform reactions. Cybersecurity Dive's frame is narrower: recovery can end publicly while externally visible weaknesses remain. [1]

The report also found that 59 percent of observed prior victims lacked proper DMARC configuration and 32 percent had misconfigured DKIM, two controls used to authenticate email. [1] Those findings are not identical to an unpatched server flaw. They describe different layers of exposure and should not be added into a single count of compromised systems or people.

Black Kite's reported method covered activity associated with nearly 300 ransomware groups from April 2025 through March 2026. It drew on open-source victim infrastructure, dark-web posts and endpoint intelligence. [1] The company counted 61 new groups, while the five largest accounted for 43.6 percent of victims in its analysis. [1] Breadth makes the report useful; it does not make the sample random or complete.

Victim selection is the first unresolved denominator. Public extortion posts favor incidents attackers chose to advertise. Open infrastructure may be easier to scan for some organizations than others. The fetched account does not provide the matching rules, organization mix, exact scan dates, remediation grace period or false-positive rate needed to treat the percentages as a census of every ransomware victim.

Timing can alter every percentage. A scan taken days after disclosure may catch emergency work in progress; one taken months later may reveal a durable gap. Without dates tied to each victim and control, the study cannot distinguish delayed remediation from a decision to leave a weakness unresolved.

Causation is the second boundary. A critical vulnerability visible after an attack could have existed before it, appeared later or sat on a system the attacker never used. Weak email authentication can increase impersonation risk without proving that phishing caused the first intrusion. Even a repeat attack would require incident-level evidence before one of these conditions became its entry vector.

None of that makes unfinished remediation trivial. An organization that has already paid the cost of disruption has a practical reason to close known openings, rotate exposed credentials, harden email and verify the work independently. The report makes that follow-through inspectable across a selected population. It cannot explain why each gap remained or whether the relevant fix was technically, financially or operationally available.

The useful next record joins Black Kite's outside view to inside evidence: named sampling rules, dated scans, verified victim matches, repeat-attack counts and forensic entry paths. Until then, the vendor has shown unresolved weaknesses around past victims, not the cause of either their first attack or another one.

-- DAVID CHEN, Beijing

Get the New Grok Times in your inbox

A weekly digest of the stories shaping the timeline — delivered every edition.

No spam. Unsubscribe anytime.