ZeroHour

safepay

ransomware group · aka SafePay · unknown (no widely accepted country attribution in public reporting) · active since 2021-07

Victims · 7d
10flat
Victims · 30d
22active targets
Victims · 90d
67
All-time (tracked)
573since 2024-11-20
Last post
09-15 21:35UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

SafePay is a ransomware and data-extortion group first observed in mid-2021, known for a double-extortion model in which it encrypts victim systems and threatens to publish stolen data on its Tor-based leak site. Early vendor research described initial access through exposed remote-access services such as VPN and RDP, as well as SQL injection, though no specific CVEs are consistently attributed in public reporting. The group has primarily targeted small and mid-sized organizations across Europe and North America, reportedly avoiding CIS-region victims and high-profile targets. Attribution, country of origin, and the group's affiliate structure are not documented in detail in public sources. This dashboard recorded 10 leak-site posts in the 7 days ending 2026-09-09, indicating continued activity.

Tactics & tooling
  • Double extortion: encrypts systems and threatens publication of exfiltrated data on a Tor leak site
  • Initial access via exposed VPN/remote-access infrastructure and RDP (early vendor reporting)
  • SQL-injection-based access described in 2021 vendor research
  • Data exfiltration prior to encryption, reportedly using legitimate file-transfer/exfiltration utilities
  • Per-victim negotiation rather than standardized public ransom demands
  • Targets predominantly small and mid-sized businesses with no single sector focus
  • Maintains a low public profile with limited dedicated malware analysis
Targeted sectors
manufacturinghealthcareprofessional and IT servicesnonprofitagri-food
Notable public victims

Recovery Cafe (US nonprofit; SafePay leak site, Sep 2026, per dashboard tracking), McNish Steel (US steel manufacturer; SafePay leak site, Sep 2026, per dashboard tracking), Palmetto Eye Institute (US healthcare provider; SafePay leak site, Sep 2026, per dashboard tracking), Gaya Fores (Spanish agri-food company; SafePay leak site, Sep 2026, per dashboard tracking), Reichenau (Austria; reichenau.at; SafePay leak site, Sep 2026, per dashboard tracking)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
pronatec.com · Nov 20, 2024
Snow Brand Australia · Nov 20, 2024
nkce.jp · Nov 20, 2024
omint.com.ar · Nov 20, 2024
gilazo.com · Nov 20, 2024
richmond.doncaster.sch.uk · Nov 20, 2024
activecosmetic.com.ar · Nov 20, 2024
omara-ag.com · Nov 20, 2024
tritonsourcing.co.nz · Nov 20, 2024
kingswoodpark.ca · Nov 20, 2024
onnicar.it · Nov 20, 2024
euromedix.com · Nov 20, 2024
incocommercial.com · Nov 20, 2024
businesstraining.be · Nov 20, 2024
ib-spieth.de · Nov 20, 2024
safex.us · Nov 20, 2024
millerservicecompany.com · Nov 20, 2024
mcauslan.com · Nov 20, 2024
stats.gov.bb · Nov 20, 2024
smartdimensions.com · Nov 20, 2024
piburners.com · Nov 20, 2024
westwood-cc.com · Nov 20, 2024
threadfxinc.com/bluedogmerch.com · Nov 20, 2024

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .