SafePay — Ransomware Profile

SafePay became one of the most active ransomware groups of 2025 with 340+ victims in one year. First observed September 2024. Non-RaaS model with same core operators managing intrusion, encryption, and extortion. Uses stolen credentials, exposed VPN/RDP, and fake IT support call social engineering.

Read the full analysis on IntelFusions