Skip to content

🌐 SafePay

Threat-actor battle card · maintained from public sources · last updated 2026-08-30

CategoryRansomware
AttributionUnknown; suspected Eastern European (CIS-exclusion kill-switch; Conti-lineage TTPs)
First seen2024-09
StatusActive
Rank#6
Victims L3M27
Victims YTD537+
Primary targetsBusiness Services, Manufacturing, Technology, Consumer Services, Education, Finance, Healthcare, Government; US-heavy (206 victims), Germany (125), UK (33), Canada, Australia

Overview

SafePay emerged in September 2024 as a centrally operated, non-RaaS ransomware group. Unlike most extortion operations, it develops its own encryptor, manages its own infrastructure, and conducts negotiations directly — no affiliates. It claimed 300+ victims by mid-2025 and has now surpassed 537+ total victims by August 2026 across 45+ countries, placing in the global monthly top-7 multiple times in H1 2026. The US is the primary target (206 victims), followed by Germany (125), UK (33), Canada, and Australia. Over 90% of victims are small and mid-sized businesses (Flare IO analysis of 500+ attacks). The DLS went temporarily inactive mid-March to early April 2026 (reason undisclosed) then resumed; Q1 2026 showed a notable dip (22 victims vs 97 in Q4 2025) but pace recovered in Q2-Q3. 27 new victims in the 30 days to August 3, 2026. A CIS-country exclusion kill-switch (Cyrillic language check halts execution) suggests Eastern European origin. The group also operates a TON (Telegram Open Network) channel for affiliate communications and leak notifications.

Tradecraft

  • Initial access: primarily through vulnerable edge devices — VPN gateways, firewalls, Remote Desktop Gateway servers; also targets MSPs with downstream multi-tenant access.
  • Reconnaissance: ShareFinder.ps1 (PowerTools) enumerates network, SMB shares, and accessible assets immediately post-access.
  • Lateral movement: living-off-the-land binaries (PSExec, WinRM, RDP) and legitimate RMM software.
  • Evasion: disables security services, eliminates backup software, halts Volume Shadow Copy; token impersonation for privilege escalation where needed.
  • Exfiltration: WinRAR, 7-Zip, Rclone, FileZilla, RDP clipboard.
  • Encryption: ChaCha20 or AES depending on target hardware; per-file keys wrapped in asymmetric cryptography.
  • Extortion: double-extortion (decryption key + DLS publication); employs Conti-lineage TTPs including spam phishing with custom loaders and ESXi/Citrix appliance targeting.

Notable victims

  • Ingram Micro (technology distribution/US) — attack July 2–3, 2025; 3.5TB claimed exfiltrated; ~42,000 individuals notified January 2026; Social Security Numbers, financial data, and business records exposed; largest publicly attributed SafePay victim to date by organisational scale
  • Energy Action (energy management/Australia) — ~470GB claimed, under investigation — seen June 2026
  • hellmold-plank.de (manufacturing/Germany — est. 1904) — DLS June 27, 2026; data scope unconfirmed; 🟥 unverified
  • Hokuyo 2006 Co., Ltd. (manufacturing/packaging-logistics/Japan) — DLS May 4, 2026; 🟥 unverified
  • Tokyo Civil Co., Ltd. (civil engineering/Japan) — DLS June 26, 2026; 🟥 unverified
  • Kawai Musical Instruments (manufacturing/Japan) — DLS June 15, 2026; 🟥 unverified
  • Hugh Stirling Ltd (construction/UK) — DLS June 15, 2026; 🟥 unverified

Assessment

SafePay's in-house model eliminates the affiliate interdiction playbook; there is no affiliate network to penetrate or flip. Its 90%+ SMB targeting concentration means organisations too small to run a mature IR programme are being hit hardest. Conti-lineage TTPs, a rapid climb from zero to global top-6 in under 18 months, and edge-device initial-access focus make it a high-severity risk for any organisation running internet-exposed VPN or firewall infrastructure. Healthcare, finance, and manufacturing sub-sectors running unpatched edge devices or MSP-managed environments should treat themselves as in-scope. The mid-March to early April 2026 DLS outage resolved without public explanation — likely infrastructure migration rather than disruption; the group remains fully operational. Q3 2026 pace (27 victims per month as of August 3) is running below the Q4 2025 peak of 97 per month but above the Q1 2026 dip — consistent with a mature operation maintaining steady cadence rather than a growth phase.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

July 2026

Jul 20 Stroebel Gruppe SafePay Ransomware · manufacturing · Germany SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 20 TimeTEX GmbH SafePay Ransomware · education · Germany German educational supplies company; SafePay DLS claim July 20, 2026; part of coordinated 7-victim Germany spree on same date; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 02 AWO Kreisverband Südost e.V. SafePay Ransomware · social welfare non-profit · Germany German social welfare organization; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02 DIA179 SafePay Ransomware · architecture · Germany German architecture firm; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]

June 2026

Jun 27 hellmold-plank.de SafePay Ransomware · manufacturing · Germany long-established German manufacturer (roots to 1904); SafePay DLS claim June 27, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jun 26 Tokyo Civil Co., Ltd. SafePay Ransomware · civil engineering · construction/Japan public infrastructure specialist (river works, bridges, foundation engineering, water supply systems, government-related construction; established 2020; Edogawa City, Tokyo); SafePay DLS claim June 26, 2026; internal org data, employee info, and operational files claimed; 🟥 unverified — no Tokyo Civil statement · https://www.cyfirma.com/news/weekly-intelligence-report-26-jun-2026/ · https://www.ransomware.live/group/safepay · Sources: [CYFIRMA] · [ransomware.live]
Jun 15 Kawai Musical Instruments Mfg. Co., Ltd. SafePay Ransomware · musical instruments manufacturing · Japan renowned Japanese manufacturer of pianos, digital keyboards, and band/orchestral instruments; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-kawai-musical-instruments/ · https://www.ransomware.live/id/a2F3YWl1cy5jb21Ac2FmZXBheQ== · https://www.hendryadrian.com/ransom-kawaius-com-jun-2026/ · Sources: [DeXpose] · [ransomware.live] · [hendryadrian.com]
Jun 15 Hugh Stirling Ltd SafePay Ransomware · construction · UK established UK construction company; SafePay DLS claim June 15, 2026; data scope and impact unconfirmed · https://www.dexpose.io/safepay-ransomware-attack-on-hugh-stirling-ltd/ · https://www.ransomware.live/group/safepay · Sources: [DeXpose] · [ransomware.live]
Jun 01 Energy Action SafePay Ransomware · energy management · Australia ~470GB claimed; under investigation · Sources: SafePay DLS

May 2026

May 04 Hokuyo 2006 Co., Ltd. SafePay Ransomware · manufacturing · packaging-logistics/Japan SafePay DLS claim; data exfiltration from multiple directories claimed incl. employee records and business documents; no victim statement · https://www.redpacketsecurity.com/safepay-ransomware-victim-hokuyo2006-co-jp/ · https://www.ransomware.live/id/aG9rdXlvMjAwNi5jby5qcEBzYWZlcGF5 · Sources: [RedPacket Security] · [ransomware.live]

← All threat actors · Full victim database →