SafePay
SafePay is a ransomware operation that emerged in late 2024, first observed around September-October 2024. Multiple sources in the content describe it as a private, centralized, closed operation rather than a ransomware-as-a-service program; the group itself states on its leak site that it has never provided RaaS. SafePay uses double extortion, stealing data before encrypting systems and pressuring victims through a Tor-based leak site, with reporting noting that listed victims are generally those that did not pay. It has been described as one of the most active ransomware groups in 2025 and early 2026, with hundreds of claimed victims, including reporting of more than 260 and later more than 450 victims on its leak site.
Behaviorally, SafePay attacks are described as fast-moving, often progressing from initial access to encryption within 24 hours. Reported initial access vectors include compromised credentials on VPN gateways and RDP servers, and misconfigured FortiGate firewalls lacking MFA. Persistence and remote access have involved QDoor and ScreenConnect. Discovery and lateral movement have used ShareFinder.ps1, PsExec, WinRM, administrative utilities, and LOLBins. Defense evasion and impact behaviors include terminating antivirus, database, and backup processes, deleting Volume Shadow Copies, and modifying boot configuration to inhibit recovery. The ransomware is described as a Windows PE32 DLL that requires specific command-line arguments including a mandatory 32-byte password. Encryption reportedly uses AES or ChaCha20 for file encryption with keys protected by RSA or x25519, employs intermittent/block encryption for speed, appends the .safepay extension, and appends metadata containing an encrypted key and validation hash. Data theft has been conducted with WinRAR, FileZilla, Rclone, and 7-Zip. A kill switch prevents execution on systems with Cyrillic keyboard layouts, including Russian, Ukrainian, or Belarusian layouts.
SafePay has targeted organizations across multiple countries including Australia, the United States, the United Kingdom, Italy, New Zealand, Canada, Belgium, Brazil, Germany, Barbados, and Argentina. The content specifically highlights targeting of managed service providers and small-to-midsize businesses, and repeated activity against healthcare. Healthcare-focused reporting identifies SafePay among the most prolific ransomware strains targeting healthcare providers in 2025, and Health-ISAC describes SAFEPAY as focused on financial disruption, targeting healthcare billing and revenue-cycle systems and threatening exposure of billing records and patient financial data.
Victims and incidents directly mentioned in the content include Conduent, Ingram Micro, Favelle Favco, Genealogy SA, and Smile Team Orthodontics. In the Conduent intrusion from January 2025, SafePay claimed to have stolen more than 8 TB of data; Conduent confirmed that data from over 25 million individuals was stolen, including names, Social Security numbers, and medical or health insurance information, and the incident caused government service outages. In the July 2025 Ingram Micro incident, SafePay was reported as the responsible group, later claimed the attack on its leak site, and alleged theft of 3.5 TB of documents; Ingram Micro disclosed that more than 42,000 individuals were affected and that stolen files included employment and applicant records with names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, and employment-related evaluations. SafePay also listed Favelle Favco and Genealogy SA on its leak site and published data it claimed to have stolen from them, including business, financial, insurance, correspondence, technical, maintenance, and identity-document data.
Across the reporting in the content, SafePay is consistently characterized as a significant ransomware threat with strong operational security, centralized control of infrastructure and negotiations, and sustained activity through 2025 into 2026.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
Execution
1 technique
Execution
Persistence
1 technique
Persistence
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
Privilege Escalation
2 techniques
Privilege Escalation
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
Stealth
1 technique
Stealth
T1078.002 - Valid Accounts: Domain Accounts. The Threat Actor was able to gain access to a local account through a simple misconfiguration of the firewall. Once inside, the Threat Actor was able to escalate to a domain administrator account not covered by MFA at the time of the attack.
Discovery
2 techniques
Discovery
Lateral Movement
1 technique
Lateral Movement
Impact
3 techniques
Impact
On the ransomware front, attribution remains consistent, and the most prevalent ransomware brands we saw deployed mirror those most often seen by other threat intelligence sources. Akira ... and Qilin ... led the way, followed by SafePay, Inc, and Play.
IOCs tracked for this family
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A centralized non-RaaS ransomware operation whose activity sharply declined after its data leak site became inactive.
Ransomware family/group associated with data theft and extortion, operating its own leak site and claiming numerous victims across multiple countries. The content states it is not a ransomware-as-a-service operation.
SafePay is a ransomware/extortion operation first observed in October 2024 that has claimed hundreds of victims across multiple countries and publicly leaks stolen victim data on its darknet leak site.
Named as one of the dominant ransomware operations by victim volume in Q1 2026 for comparative context.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.