SafePay — Ransomware Profile

SafePay became one of the most active ransomware groups of 2025 with 340+ victims in one year. First observed September 2024. Non-RaaS model with same core operators managing intrusion, encryption, and extortion. Uses stolen credentials, exposed VPN/RDP, and fake IT support call social engineering.

IntelFusions coverage (6)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions