All threat actors

Safepay

Alert me

A ransomware and double-extortion group that emerged in late 2024. It targets organizations through stolen or brute-forced VPN credentials and vulnerable edge devices, exfiltrates data, encrypts systems, and publishes victims on a leak site; public reporting suggests experienced operators but no definitive lineage.

Create a free account to see the reports

Sign in or create a free account to see every report that names Safepay.

Create free account