Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Threat Groups

SafePay: the centralised crew that skipped affiliates

Martynas VareikisBy Martynas VareikisJuly 20, 2026Updated:July 20, 2026No Comments5 Mins Read25 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
SafePay: the centralised crew that skipped affiliates, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

SafePay is a ransomware operation that emerged in late 2024 and climbed to become one of the most active crews worldwide by mid-2025, striking more than 200 organisations with a run that continued into 2026. It stands out for two reasons: it rejects the affiliate model most rivals rely on, running a tightly centralised operation instead, and it moves fast, often going from first login to full encryption inside 24 hours. The Ransomnews tracker logged 17 confirmed SafePay victims in 2026, weighted toward business services, healthcare and government.

Who is SafePay?

SafePay was first identified in September and October 2024 and rose quickly through 2025’s rankings, recording the most monthly victim claims of any group in May 2025 by one industry count. Unlike most modern ransomware brands, it does not appear to recruit external affiliates. Researchers describe a centralised structure in which the same operators handle intrusion, infrastructure, negotiation and leak-site publishing. That closed model trades scale for consistency, and it makes SafePay’s tradecraft unusually uniform from case to case. You can track its listings alongside the rest of the field in the Ransomnews threat-group catalogue.

RaaS model vs SafePay’s centralised model ransomnews.com Typical RaaS Core devs Affiliate Affiliate Affiliate SafePay One team handles it all:intrusion to payout Fewer hands means uniform tradecraft and no affiliate leaks, at the cost of scale.

How does SafePay break in?

SafePay lives on remote access. Its primary entry points are stolen or brute-forced credentials on RDP servers and VPN gateways, plus misconfigured firewalls that lack MFA. The group has been especially active against Fortinet SSL VPN deployments, mirroring the wider 2026 pattern where exposed edge devices function as ransomware’s front door. Many of the credentials it uses are harvested from infostealer logs, which is why SafePay so rarely needs an exploit at all. When a valid VPN password is sitting in a stealer dump, there is nothing to patch.

Why speed is the whole strategy

SafePay intrusions are quick, sometimes moving from initial access to encryption within a single day. That compression is deliberate. A defender who spots the intrusion at hour two can still act; one who finds it after the encryptor has run is doing incident response, not defence. SafePay also leans on living-off-the-land tooling and has been observed exfiltrating data through legitimate cloud services such as OneDrive, so the theft blends into normal traffic. The window to detect and contain is short, which is exactly the point.

SafePay timeline: access to encryption in under 24h ransomnews.com 0h RDP/VPN ~2h recon ~8h exfil <24h encrypt

Who does SafePay target?

SafePay concentrates on managed service providers and small-to-midsize businesses, a choice that pays off twice. SMBs tend to run thinner security teams and flatter networks, and an MSP compromise can cascade into every downstream client. That MSP focus places SafePay squarely in one of 2026’s defining risk stories, where a single provider breach becomes many. In the Ransomnews victim tracker, its 2026 victims skew toward business services, with healthcare and government close behind.

What should defenders do?

Close the remote-access gaps first, because that is SafePay’s entire opening move. Put phishing-resistant MFA on every RDP, VPN and firewall admin surface, and never expose RDP directly to the internet. Patch VPN appliances, especially Fortinet SSL VPN, the moment fixes ship. Assume any credential in a stealer log is live and rotate it. Because SafePay moves in hours, detection speed is decisive: alert on anomalous VPN logins, unusual OneDrive upload volumes, and mass file changes. Offline, tested backups turn a same-day encryption event into a bad afternoon rather than an existential one, and business EDR that flags fast, anomalous behaviour buys back the time SafePay tries to take; our business ransomware protection guide goes deeper.

Frequently asked questions

Is SafePay a ransomware-as-a-service group?

No. Unlike most modern crews, SafePay appears to operate a centralised model with no external affiliates, handling intrusion, infrastructure and negotiation in-house. That makes its tradecraft unusually consistent across victims.

How does SafePay get initial access?

SafePay primarily uses stolen or brute-forced credentials on RDP servers and VPN gateways, and targets firewalls without MFA. It is especially active against Fortinet SSL VPN and often relies on credentials sourced from infostealer logs.

How fast is a SafePay attack?

Very fast. SafePay intrusions frequently move from initial access to full encryption within 24 hours, and sometimes within a few hours, which leaves defenders a narrow window to detect and contain.

Why does SafePay target MSPs?

Managed service providers offer leverage. One MSP breach can reach many downstream clients at once, and smaller businesses served by MSPs often lack the security depth to stop a fast intrusion.

Does SafePay use double extortion?

Yes. SafePay exfiltrates sensitive data such as financial records and intellectual property before encrypting systems, then threatens to publish it on its leak site if the victim refuses to pay.

Sources and further reading

  • Infosecurity Magazine — Unmasking the SafePay Ransomware Group
  • CISA #StopRansomware — official ransomware guidance
  • Ransomnews live victim tracker
  • Ransomnews — Best business ransomware protection
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleINC Ransom: the RaaS that wins by mastering the basics
Next Article Interlock: the drive-by ransomware crew CISA flagged
Martynas Vareikis

Martynas Vareikis is the AI Editor at Ransomnews. He covers the intersection of artificial intelligence and information security — from machine-learning models in defensive tooling to the adversarial use of LLMs by ransomware operators, deepfake-driven social engineering, and the rise of agentic threats. His reporting focuses on translating fast-moving AI research into practical guidance for defenders, journalists, and the broader security community. Reach Martynas via [email protected].

Related Posts

Interlock: the drive-by ransomware crew CISA flagged

July 20, 2026

INC Ransom: the RaaS that wins by mastering the basics

July 20, 2026

LockBit, 2 years after Operation Cronos: where are they now?

May 11, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.