SafePay is a ransomware threat actor active by at least 2025 and observed conducting extortion operations against organizations across multiple countries and sectors. Reported victims span healthcare, education, manufacturing, construction, transportation and logistics, consumer services, business services, and public- or community-facing organizations, with notable activity affecting targets in Germany, the United States, Italy, Spain, the United Kingdom, Australia, and Canada. SafePay has been publicly associated with victim shaming and extortion via a data leak site, where it claims responsibility for intrusions and pressures victims through threatened or actual publication of stolen data. The group is commonly referred to as SafePay, with aliases including safepay_ransomware_actors, safepay_ransomware_gang, safepay_ransomware_group, and safepay_team. Available reporting supports classification of SafePay as a financially motivated ransomware group rather than a confirmed nation-state actor. Publicly observed behavior is consistent with double-extortion ransomware operations in which network compromise is followed by data theft and public coercion. Multiple incidents attributed to SafePay are described both as ransomware attacks and as data breaches, reinforcing the assessment that exfiltration is a routine component of its operations. SafePay’s targeting appears opportunistic and broad rather than narrowly sector-specific. Its victimology includes pathology and healthcare providers, schools, industrial manufacturers, real estate and consumer services firms, waste-management and infrastructure-related entities, and transportation companies. Reporting from mid-2026 also places SafePay among active ransomware brands generating repeated victim claims in weekly extortion-tracking datasets, though at a lower volume than the most prolific groups in the same period. High-confidence public information on SafePay’s internal structure, malware lineage, initial access methods, affiliate model, geographic base of operations, and technical tradecraft remains limited in the available material. No corroborated attribution to a specific state sponsor is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the cyber attack against Marlboro-Chesterfield Pathology and posted the victim on its data leak site, indicating ransomware/extortion activity.
Conducting a ransomware attack against shuttlemeadowcc.com.
Conducting a ransomware attack against shw-fr.de, a Germany-based industrial manufacturer.
Conducting a ransomware attack against lh-wohnverbund-wohnen-nrw.de, a Germany-based organization in the consumer services sector.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.