Safepay
SafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code. Soon after launching, the group made a big impact in the ransomware world, hacking at least 33 organizations by December 9. The first version of SafePay was created by modifying the LockBit source code. It adds the ".safepay" extension to files that it encrypts and includes a ransom note called "readme_safepay.txt." This version uses a three-step XOR method with a random single-byte key, making it hard for security researchers to analyse. The group's technical infrastructure includes both a dark web blog and a presence on the TON network for victim communications. Their attack methodology follows a double extortion model, combining traditional file encryption with data theft to maximise pressure on victims. SafePay operators typically move from initial access to ransomware deployment in under 24 hours, significantly faster than the industry average. . Among the Tactics, Techniques, and Procedures (TTPs) of the SafePay group, notable characteristics include the use of compromised VPN credentials as an initial access vector, extensive use of living-off-the-land binaries (LOLBins), and sophisticated privilege escalation techniques. The group frequently employs ShareFinder.ps1 for network reconnaissance and uses WinRAR for data archival before exfiltration. Post encryption, SafePay directs victims to their negotiation portal accessible through both Tor and TON n
Most affected countries
- Germany25
- United States12
- Spain5
- Switzerland3
- Italy3
- Japan2
- Philippines2
- United Kingdom2
Most affected sectors
- Manufacturing22
- Technology7
- Government5
- Professional services5
- Healthcare5
- Non-profit4
- Construction4
- Education3
Recent victims
| Organisation | Country | Sector | Claimed | Status |
|---|---|---|---|---|
| wolfusofsky.de | Germany | Construction | 9/30/2026 | ◌ Claimed (unverified) |
| econ-tec | — | Manufacturing | 9/30/2026 | ◌ Claimed (unverified) |
| assist2enjoy | Belgium | Retail | 9/30/2026 | ◌ Claimed (unverified) |
| LFG Holding | — | Finance & insurance | 9/28/2026 | ◌ Claimed (unverified) |
| Children's Memorial Hospital | Philippines | Healthcare | 9/28/2026 | ◌ Claimed (unverified) |
| Bio-Strath | — | Pharma & chemicals | 9/28/2026 | ◌ Claimed (unverified) |
| Šumperk | Czechia | Government | 9/28/2026 | ◌ Claimed (unverified) |
| EA Groep | Netherlands | Professional services | 9/28/2026 | ◌ Claimed (unverified) |
| Holiday Inn Vilnius | Lithuania | Hospitality & tourism | 9/28/2026 | ◌ Claimed (unverified) |
| Manno | Switzerland | Government | 9/28/2026 | ◌ Claimed (unverified) |
| Auromex | Thailand | Manufacturing | 9/28/2026 | ◌ Claimed (unverified) |
| Cromados | Spain | Manufacturing | 9/28/2026 | ◌ Claimed (unverified) |
| Marlin HVAC | United States | Construction | 9/15/2026 | ◌ Claimed (unverified) |
| Neumerkel GmbH | Germany | Manufacturing | 9/15/2026 | ◌ Claimed (unverified) |
| Triniti Caring | United States | Healthcare | 9/15/2026 | ◌ Claimed (unverified) |
| La Concepción | Mexico | Healthcare | 9/15/2026 | ◌ Claimed (unverified) |
| 🔒 Pequeña empresa manufacturera (DE) | Germany | Manufacturing | 9/15/2026 | ◌ Claimed (unverified) |
| Stöcklin Küchen | Switzerland | Manufacturing | 9/15/2026 | ◌ Claimed (unverified) |
| Ryomo | Japan | Technology | 9/15/2026 | ◌ Claimed (unverified) |
| ARA Lyss | Switzerland | Energy & utilities | 9/15/2026 | ◌ Claimed (unverified) |
| Gob.pe | Peru | Government | 9/15/2026 | ◌ Claimed (unverified) |
| Compunnel | — | Technology | 9/12/2026 | ◌ Claimed (unverified) |
| Gayafores | Spain | Manufacturing | 9/9/2026 | ◌ Claimed (unverified) |
| Cenmar | Philippines | Other | 9/9/2026 | ◌ Claimed (unverified) |
| GSN Gestión | Spain | Professional services | 9/9/2026 | ◌ Claimed (unverified) |
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.