SafePay is a ransomware operation that emerged in late 2024 and climbed to become one of the most active crews worldwide by mid-2025, striking more than 200 organisations with a run that continued into 2026. It stands out for two reasons: it rejects the affiliate model most rivals rely on, running a tightly centralised operation instead, and it moves fast, often going from first login to full encryption inside 24 hours. The Ransomnews tracker logged 17 confirmed SafePay victims in 2026, weighted toward business services, healthcare and government.
Who is SafePay?
SafePay was first identified in September and October 2024 and rose quickly through 2025’s rankings, recording the most monthly victim claims of any group in May 2025 by one industry count. Unlike most modern ransomware brands, it does not appear to recruit external affiliates. Researchers describe a centralised structure in which the same operators handle intrusion, infrastructure, negotiation and leak-site publishing. That closed model trades scale for consistency, and it makes SafePay’s tradecraft unusually uniform from case to case. You can track its listings alongside the rest of the field in the Ransomnews threat-group catalogue.
How does SafePay break in?
SafePay lives on remote access. Its primary entry points are stolen or brute-forced credentials on RDP servers and VPN gateways, plus misconfigured firewalls that lack MFA. The group has been especially active against Fortinet SSL VPN deployments, mirroring the wider 2026 pattern where exposed edge devices function as ransomware’s front door. Many of the credentials it uses are harvested from infostealer logs, which is why SafePay so rarely needs an exploit at all. When a valid VPN password is sitting in a stealer dump, there is nothing to patch.
Why speed is the whole strategy
SafePay intrusions are quick, sometimes moving from initial access to encryption within a single day. That compression is deliberate. A defender who spots the intrusion at hour two can still act; one who finds it after the encryptor has run is doing incident response, not defence. SafePay also leans on living-off-the-land tooling and has been observed exfiltrating data through legitimate cloud services such as OneDrive, so the theft blends into normal traffic. The window to detect and contain is short, which is exactly the point.
Who does SafePay target?
SafePay concentrates on managed service providers and small-to-midsize businesses, a choice that pays off twice. SMBs tend to run thinner security teams and flatter networks, and an MSP compromise can cascade into every downstream client. That MSP focus places SafePay squarely in one of 2026’s defining risk stories, where a single provider breach becomes many. In the Ransomnews victim tracker, its 2026 victims skew toward business services, with healthcare and government close behind.
What should defenders do?
Close the remote-access gaps first, because that is SafePay’s entire opening move. Put phishing-resistant MFA on every RDP, VPN and firewall admin surface, and never expose RDP directly to the internet. Patch VPN appliances, especially Fortinet SSL VPN, the moment fixes ship. Assume any credential in a stealer log is live and rotate it. Because SafePay moves in hours, detection speed is decisive: alert on anomalous VPN logins, unusual OneDrive upload volumes, and mass file changes. Offline, tested backups turn a same-day encryption event into a bad afternoon rather than an existential one, and business EDR that flags fast, anomalous behaviour buys back the time SafePay tries to take; our business ransomware protection guide goes deeper.
Frequently asked questions
Is SafePay a ransomware-as-a-service group?
No. Unlike most modern crews, SafePay appears to operate a centralised model with no external affiliates, handling intrusion, infrastructure and negotiation in-house. That makes its tradecraft unusually consistent across victims.
How does SafePay get initial access?
SafePay primarily uses stolen or brute-forced credentials on RDP servers and VPN gateways, and targets firewalls without MFA. It is especially active against Fortinet SSL VPN and often relies on credentials sourced from infostealer logs.
How fast is a SafePay attack?
Very fast. SafePay intrusions frequently move from initial access to full encryption within 24 hours, and sometimes within a few hours, which leaves defenders a narrow window to detect and contain.
Why does SafePay target MSPs?
Managed service providers offer leverage. One MSP breach can reach many downstream clients at once, and smaller businesses served by MSPs often lack the security depth to stop a fast intrusion.
Does SafePay use double extortion?
Yes. SafePay exfiltrates sensitive data such as financial records and intellectual property before encrypting systems, then threatens to publish it on its leak site if the victim refuses to pay.
