ZeroHour

safepay

ransomware group · aka SafePay · unknown (no widely accepted country attribution in public reporting) · active since 2021-07

Victims · 7d
10flat
Victims · 30d
22active targets
Victims · 90d
67
All-time (tracked)
573since 2024-11-20
Last post
09-15 21:35UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

SafePay is a ransomware and data-extortion group first observed in mid-2021, known for a double-extortion model in which it encrypts victim systems and threatens to publish stolen data on its Tor-based leak site. Early vendor research described initial access through exposed remote-access services such as VPN and RDP, as well as SQL injection, though no specific CVEs are consistently attributed in public reporting. The group has primarily targeted small and mid-sized organizations across Europe and North America, reportedly avoiding CIS-region victims and high-profile targets. Attribution, country of origin, and the group's affiliate structure are not documented in detail in public sources. This dashboard recorded 10 leak-site posts in the 7 days ending 2026-09-09, indicating continued activity.

Tactics & tooling
  • Double extortion: encrypts systems and threatens publication of exfiltrated data on a Tor leak site
  • Initial access via exposed VPN/remote-access infrastructure and RDP (early vendor reporting)
  • SQL-injection-based access described in 2021 vendor research
  • Data exfiltration prior to encryption, reportedly using legitimate file-transfer/exfiltration utilities
  • Per-victim negotiation rather than standardized public ransom demands
  • Targets predominantly small and mid-sized businesses with no single sector focus
  • Maintains a low public profile with limited dedicated malware analysis
Targeted sectors
manufacturinghealthcareprofessional and IT servicesnonprofitagri-food
Notable public victims

Recovery Cafe (US nonprofit; SafePay leak site, Sep 2026, per dashboard tracking), McNish Steel (US steel manufacturer; SafePay leak site, Sep 2026, per dashboard tracking), Palmetto Eye Institute (US healthcare provider; SafePay leak site, Sep 2026, per dashboard tracking), Gaya Fores (Spanish agri-food company; SafePay leak site, Sep 2026, per dashboard tracking), Reichenau (Austria; reichenau.at; SafePay leak site, Sep 2026, per dashboard tracking)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
www.foyernotredamedepaix.be · Mar 30, 2025
tieraerzte-warburg.de · Mar 30, 2025
system-toolsgmbh.de · Mar 30, 2025
vinylvisions.com · Mar 30, 2025
estilointeriors.co.uk · Mar 30, 2025
swr.school · Mar 30, 2025
albrecht-partner-steuerberatung.de · Mar 30, 2025
alpsteel.com · Mar 30, 2025
blunk-gmbh.de · Mar 30, 2025
cjs-buerodienstleistungen.de · Mar 30, 2025
beaudry.ca · Mar 30, 2025
bohrerhof.de · Mar 30, 2025
metalogicinspection.com · Mar 30, 2025
comfort.de · Mar 30, 2025
vcvitanzasons.com · Mar 30, 2025
tramann.de · Mar 30, 2025
schuhbode.de · Mar 30, 2025
norson.com · Mar 30, 2025
fd-friedrich.com · Mar 30, 2025
westwarwickwelding.com · Mar 30, 2025
prestigeer.com · Mar 30, 2025
ecconstructors.com · Mar 30, 2025
wrm.org · Mar 30, 2025
retycol.com · Mar 30, 2025
marcom-inc.ca · Mar 30, 2025
adolphelawgroup.com · Mar 30, 2025
wagner-transporte.com · Mar 30, 2025
children-ne.org.uk · Mar 30, 2025
mayaassurance.com · Mar 30, 2025
saiedu.fi · Mar 25, 2025
compassionhealthcare.org · Mar 22, 2025
argusdatainsights.de · Mar 19, 2025
terrell.k12.ga.us · Mar 17, 2025
tradingacademy.com · Mar 11, 2025
ultimateclasslimo.com · Mar 11, 2025
havenresorts.com · Mar 11, 2025
lgipr.com · Mar 11, 2025
jockeysalud.com.pe · Mar 11, 2025
motomecanica.com · Mar 11, 2025
cali.losolivos.co · Mar 11, 2025
willms-fleisch.de · Mar 6, 2025
plasseramerican.com · Feb 28, 2025
conduent.com · Feb 20, 2025
ziese.net · Feb 19, 2025
lowernazareth.com · Feb 19, 2025
rwrhine.com · Feb 19, 2025
foyernotredamedepaix.be · Feb 19, 2025
fastrans.com · Feb 19, 2025
harcoboe.net · Feb 16, 2025
stjerome.org · Feb 12, 2025

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .