« All threats

Ransomware group

Safepay

SafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code. Soon after launching, the group made a big impact in the ransomware world, hacking at least 33 organizations by December 9. The first version of SafePay was created by modifying the LockBit source code. It adds the ".safepay" extension to files that it encrypts and includes a ransom note called "readme_safepay.txt." This version uses a three-step XOR method with a random single-byte key, making it hard for security researchers to analyse. The group's technical infrastructure includes both a dark web blog and a presence on the TON network for victim communications. Their attack methodology follows a double extortion model, combining traditional file encryption with data theft to maximise pressure on victims. SafePay operators typically move from initial access to ransomware deployment in under 24 hours, significantly faster than the industry average. . Among the Tactics, Techniques, and Procedures (TTPs) of the SafePay group, notable characteristics include the use of compromised VPN credentials as an initial access vector, extensive use of living-off-the-land binaries (LOLBins), and sophisticated privilege escalation techniques. The group frequently employs ShareFinder.ps1 for network reconnaissance and uses WinRAR for data archival before exfiltration. Post encryption, SafePay directs victims to their negotiation portal accessible through both Tor and TON n

Victims in the last 90 days74

Most affected countries

  1. Germany25
  2. United States12
  3. Spain5
  4. Switzerland3
  5. Italy3
  6. Japan2
  7. Philippines2
  8. United Kingdom2

Most affected sectors

  1. Manufacturing22
  2. Technology7
  3. Government5
  4. Professional services5
  5. Healthcare5
  6. Non-profit4
  7. Construction4
  8. Education3

Recent victims

OrganisationCountrySectorClaimedStatus
wolfusofsky.deGermanyConstruction9/30/2026◌ Claimed (unverified)
econ-tec—Manufacturing9/30/2026◌ Claimed (unverified)
assist2enjoyBelgiumRetail9/30/2026◌ Claimed (unverified)
LFG Holding—Finance & insurance9/28/2026◌ Claimed (unverified)
Children's Memorial HospitalPhilippinesHealthcare9/28/2026◌ Claimed (unverified)
Bio-Strath—Pharma & chemicals9/28/2026◌ Claimed (unverified)
ŠumperkCzechiaGovernment9/28/2026◌ Claimed (unverified)
EA GroepNetherlandsProfessional services9/28/2026◌ Claimed (unverified)
Holiday Inn VilniusLithuaniaHospitality & tourism9/28/2026◌ Claimed (unverified)
MannoSwitzerlandGovernment9/28/2026◌ Claimed (unverified)
AuromexThailandManufacturing9/28/2026◌ Claimed (unverified)
CromadosSpainManufacturing9/28/2026◌ Claimed (unverified)
Marlin HVACUnited StatesConstruction9/15/2026◌ Claimed (unverified)
Neumerkel GmbHGermanyManufacturing9/15/2026◌ Claimed (unverified)
Triniti CaringUnited StatesHealthcare9/15/2026◌ Claimed (unverified)
La ConcepciónMexicoHealthcare9/15/2026◌ Claimed (unverified)
🔒 Pequeña empresa manufacturera (DE)GermanyManufacturing9/15/2026◌ Claimed (unverified)
Stöcklin KüchenSwitzerlandManufacturing9/15/2026◌ Claimed (unverified)
RyomoJapanTechnology9/15/2026◌ Claimed (unverified)
ARA LyssSwitzerlandEnergy & utilities9/15/2026◌ Claimed (unverified)
Gob.pePeruGovernment9/15/2026◌ Claimed (unverified)
Compunnel—Technology9/12/2026◌ Claimed (unverified)
GayaforesSpainManufacturing9/9/2026◌ Claimed (unverified)
CenmarPhilippinesOther9/9/2026◌ Claimed (unverified)
GSN GestiónSpainProfessional services9/9/2026◌ Claimed (unverified)

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.