🌐 SafePay¶
Threat-actor battle card · maintained from public sources · last updated 2026-08-30
Overview¶
SafePay emerged in September 2024 as a centrally operated, non-RaaS ransomware group. Unlike most extortion operations, it develops its own encryptor, manages its own infrastructure, and conducts negotiations directly — no affiliates. It claimed 300+ victims by mid-2025 and has now surpassed 537+ total victims by August 2026 across 45+ countries, placing in the global monthly top-7 multiple times in H1 2026. The US is the primary target (206 victims), followed by Germany (125), UK (33), Canada, and Australia. Over 90% of victims are small and mid-sized businesses (Flare IO analysis of 500+ attacks). The DLS went temporarily inactive mid-March to early April 2026 (reason undisclosed) then resumed; Q1 2026 showed a notable dip (22 victims vs 97 in Q4 2025) but pace recovered in Q2-Q3. 27 new victims in the 30 days to August 3, 2026. A CIS-country exclusion kill-switch (Cyrillic language check halts execution) suggests Eastern European origin. The group also operates a TON (Telegram Open Network) channel for affiliate communications and leak notifications.
Tradecraft¶
- Initial access: primarily through vulnerable edge devices — VPN gateways, firewalls, Remote Desktop Gateway servers; also targets MSPs with downstream multi-tenant access.
- Reconnaissance: ShareFinder.ps1 (PowerTools) enumerates network, SMB shares, and accessible assets immediately post-access.
- Lateral movement: living-off-the-land binaries (PSExec, WinRM, RDP) and legitimate RMM software.
- Evasion: disables security services, eliminates backup software, halts Volume Shadow Copy; token impersonation for privilege escalation where needed.
- Exfiltration: WinRAR, 7-Zip, Rclone, FileZilla, RDP clipboard.
- Encryption: ChaCha20 or AES depending on target hardware; per-file keys wrapped in asymmetric cryptography.
- Extortion: double-extortion (decryption key + DLS publication); employs Conti-lineage TTPs including spam phishing with custom loaders and ESXi/Citrix appliance targeting.
Notable victims¶
- Ingram Micro (technology distribution/US) — attack July 2–3, 2025; 3.5TB claimed exfiltrated; ~42,000 individuals notified January 2026; Social Security Numbers, financial data, and business records exposed; largest publicly attributed SafePay victim to date by organisational scale
- Energy Action (energy management/Australia) — ~470GB claimed, under investigation — seen June 2026
- hellmold-plank.de (manufacturing/Germany — est. 1904) — DLS June 27, 2026; data scope unconfirmed; 🟥 unverified
- Hokuyo 2006 Co., Ltd. (manufacturing/packaging-logistics/Japan) — DLS May 4, 2026; 🟥 unverified
- Tokyo Civil Co., Ltd. (civil engineering/Japan) — DLS June 26, 2026; 🟥 unverified
- Kawai Musical Instruments (manufacturing/Japan) — DLS June 15, 2026; 🟥 unverified
- Hugh Stirling Ltd (construction/UK) — DLS June 15, 2026; 🟥 unverified
Assessment¶
SafePay's in-house model eliminates the affiliate interdiction playbook; there is no affiliate network to penetrate or flip. Its 90%+ SMB targeting concentration means organisations too small to run a mature IR programme are being hit hardest. Conti-lineage TTPs, a rapid climb from zero to global top-6 in under 18 months, and edge-device initial-access focus make it a high-severity risk for any organisation running internet-exposed VPN or firewall infrastructure. Healthcare, finance, and manufacturing sub-sectors running unpatched edge devices or MSP-managed environments should treat themselves as in-scope. The mid-March to early April 2026 DLS outage resolved without public explanation — likely infrastructure migration rather than disruption; the group remains fully operational. Q3 2026 pace (27 victims per month as of August 3) is running below the Q4 2025 peak of 97 per month but above the Q1 2026 dip — consistent with a mature operation maintaining steady cadence rather than a growth phase.
Sources¶
- ThreatLocker — SafePay ransomware explained: IOCs, TTPs, and defense strategies
- Bitdefender — SafePay Ransomware: How a Non-RaaS Group Executes Rapid Fire Attacks
- Blackpoint Cyber — SafePay Ransomware Threat Profile
- Infosecurity Magazine — Unmasking the SafePay Ransomware Group
- SOCPrime — SafePay Ransomware: Centralized Double-Extortion Group
- SureFire Cyber — Threat Actor Profile: SafePay Ransomware Group
- Flare IO — SafePay Ransomware: Mapping the Real Victims Behind the Leak Sites
- Flare IO — 90% of SafePay Ransomware Victims are SMBs
- Halcyon — SafePay threat group profile
- Acronis — SafePay ransomware: The fast-rising threat targeting MSPs
🗂️ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
July 2026
June 2026
May 2026