ZeroHour

safepay

ransomware group · aka SafePay · unknown (no widely accepted country attribution in public reporting) · active since 2021-07

Victims · 7d
10flat
Victims · 30d
22active targets
Victims · 90d
67
All-time (tracked)
573since 2024-11-20
Last post
09-15 21:35UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

SafePay is a ransomware and data-extortion group first observed in mid-2021, known for a double-extortion model in which it encrypts victim systems and threatens to publish stolen data on its Tor-based leak site. Early vendor research described initial access through exposed remote-access services such as VPN and RDP, as well as SQL injection, though no specific CVEs are consistently attributed in public reporting. The group has primarily targeted small and mid-sized organizations across Europe and North America, reportedly avoiding CIS-region victims and high-profile targets. Attribution, country of origin, and the group's affiliate structure are not documented in detail in public sources. This dashboard recorded 10 leak-site posts in the 7 days ending 2026-09-09, indicating continued activity.

Tactics & tooling
  • Double extortion: encrypts systems and threatens publication of exfiltrated data on a Tor leak site
  • Initial access via exposed VPN/remote-access infrastructure and RDP (early vendor reporting)
  • SQL-injection-based access described in 2021 vendor research
  • Data exfiltration prior to encryption, reportedly using legitimate file-transfer/exfiltration utilities
  • Per-victim negotiation rather than standardized public ransom demands
  • Targets predominantly small and mid-sized businesses with no single sector focus
  • Maintains a low public profile with limited dedicated malware analysis
Targeted sectors
manufacturinghealthcareprofessional and IT servicesnonprofitagri-food
Notable public victims

Recovery Cafe (US nonprofit; SafePay leak site, Sep 2026, per dashboard tracking), McNish Steel (US steel manufacturer; SafePay leak site, Sep 2026, per dashboard tracking), Palmetto Eye Institute (US healthcare provider; SafePay leak site, Sep 2026, per dashboard tracking), Gaya Fores (Spanish agri-food company; SafePay leak site, Sep 2026, per dashboard tracking), Reichenau (Austria; reichenau.at; SafePay leak site, Sep 2026, per dashboard tracking)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
mcsl.de · Jun 14, 2025
rusindustries.com · Jun 14, 2025
theoverheaddoorco.com · Jun 14, 2025
awo-giessen.org · Jun 14, 2025
realschule-karlstadt.org · Jun 14, 2025
bristolhose.com · Jun 14, 2025
ramlaw.com · Jun 13, 2025
electro-seal.com · Jun 9, 2025
mytaac.com · Jun 7, 2025
mercercapital.com · Jun 7, 2025
triangleheatingcooling.com · Jun 7, 2025
Myer Auto · Jun 4, 2025
ochsinc.org.com · Jun 4, 2025
digitalwarroom.com · Jun 4, 2025
universityacademy.org · May 31, 2025
meeksgroup.com · May 30, 2025
sfhumanesociety.org · May 30, 2025
donowentire.com · May 30, 2025
iicil.com · May 30, 2025
visco.de · May 30, 2025
buechel-online.com · May 30, 2025
Avance Agricola sl · May 29, 2025
murraybuildingcompany.com · May 29, 2025
sander-doll.com · May 29, 2025
ibague.losolivos.co · May 29, 2025
usmortgage.com · May 29, 2025
spring-green.com/petbutler.com · May 28, 2025
paynecountyok.gov · May 28, 2025
gruposancristobal.com.mx · May 28, 2025
radsports.com · May 28, 2025
schoenundendres.de · May 28, 2025
hennertanklines.com · May 28, 2025
bridgecast.ca · May 28, 2025
codylawfirm.com · May 28, 2025
labbeemint.com · May 26, 2025
servicecentermetals.com · May 26, 2025
ozarkah2o.com · May 26, 2025
gjszlin.cz · May 26, 2025
lrcpa.com · May 26, 2025
estudiolm.com.ar · May 26, 2025
dcbflegal.com · May 26, 2025
rtblegal.com.au · May 26, 2025
notar-roemer-troisdorf.de · May 21, 2025
rgvengineering.co.uk · May 21, 2025
servicedecorating.com · May 21, 2025
ctd-dortmund.de · May 21, 2025
planet-itservices.com · May 21, 2025
dawg-dok.de · May 21, 2025
proctorlane.com · May 21, 2025
sb-p.de · May 21, 2025

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .