blog banner

Why Ransomware Gangs Like M&A Deals

They know sellers managing a deal are highly motivated to pay.

What’s the Problem?

The scale and growth of cyberattacks are staggering. Ransomware, the most destructive and common threat type, cost its victims $58 billion last year, with the number of attacks doubling. See our Ransomware Threat Landscape infographic for a live feed of ongoing ransomware attacks and related statistics.

Ransomware victims by industry — manufacturing, technology and healthcare lead

As expected, companies most frequently targeted are based in the US.

Midmarket Sellers in the Crosshairs

Ransomware black hats are particularly attracted to mid-market M&A sellers ($10M – $100M) for three reasons:

  1. Compared to larger firms, they’re easy prey. Only about 65% have implemented multi-factor authentication (MFA), and less than 40% use automated cloud security monitoring. These firms are even more vulnerable because their often understaffed IT teams can become distracted by M&A due diligence.
  2. Additionally, mid-market firms are three times more likely to pay quickly because: a) they lack the expertise to fight back and recover rapidly, and b) their owners are more likely to suffer personally if a breach discounts M&A value or chases all buyers away. The likelihood of an attack cratering an M&A deal is twice that of larger firms.
  3. Mid-market victims possess enough cash to make the extortion worthwhile.

 

All these factors combine to double the risk of a mid-market seller becoming a ransomware victim — from 3% to 6%. So, what to do about cyber threats when preparing to sell? Fortunately, the steps are few and straightforward.

Cyber To-Do List

Strengthen Core Identity & Access Controls

  • Use MFA (Multi-Factor Authentication or 2FA) everywhere — on all computers, VPNs, and email accounts. It’s a simple way to stop hackers from breaking in with stolen passwords, especially during M&A due diligence when they target company executives. While it may be a bit more time-consuming for users, that’s far less costly than paying extortion money and returning to normal operations.
  • Limit Data Access. Keep virtual data room (VDR) and important company documents reserved to those who clearly can’t do their job without it. Also, block outside parties from downloading, printing, or sharing files unless absolutely necessary.
  • Kill Old Accounts. Remove Internet access for former employees and vendors. Simple and can greatly reduce the number of your “attack surfaces.”

Protect Networks & Digital Assets

  • Lock Down the Network. Close or block unused ports and services, such as SMB, RDP, or SSH. Hackers slink through their open doors.
  • Patch Fast. Ensure your IT department promptly installs updates for servers, computers, and web browsers. Monitor warnings about common attack vulnerabilities, such as those published on the CISA KEV list. Automated subscription services can handle these repetitive tasks.
  • Back Up Data. Frequently save copies of all important business and deal files in a safe place, such as an offline (“air-gapped”) drive or a secure cloud. Periodically confirm that you can restore these backups.

Ransomware victims by industry, live feed — manufacturing and technology most targeted

Enhance Email Security & Employee Vigilance

  • Protect Email. Turn on SPF, DKIM, and DMARC, tools that help stop criminals from faking your company’s email address to trick your team or partners.
  • Warn Your People About Phishing. Hold an employee meeting to talk about the threat of credential theft, the most common way for ransomware extortionists to gain access. After that, test employee responses to simulated phishing attacks where attackers impersonate a trusted request for passwords, bank access, etc.
  • Use Antivirus and EDR Tools. Double-check that your endpoint security or antivirus software monitors for unusual activity, such as files being rapidly encrypted. This helps you catch and stop attacks like ransomware before they spread.

Don’t make a hacker rich while you’re at your most vulnerable — during M&A preparations and negotiations.


Contact us at (650) 353-3353 or by email for more suggestions on how to prepare your company for a safe, successful sale. And check out our M&A Resource Hub for dozens of articles on growing and preparing a mid-market tech company for sale.

Some Source Material
RSM 2025 Cybersecurity Special Report · West Monroe Partners: Cybersecurity Due Diligence in M&A · Forescout: Managing Cybersecurity Risks in M&A · IBM: Cost of a Data Breach Report · NetDiligence: Cyber Claims Study · WEIS 2023 Research Paper on M&A Data Breaches

Share post on:

Posted by:

Ryan Kuhn

Ryan Kuhn linkedin facebook

08/31/2026

Ryan Kuhn is the founder of Kuhn Capital (bio). This article is not the product of AI. AI is a product of this article.

Kuhn Capital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.