SafePay — Ransomware Profile
SafePay became one of the most active ransomware groups of 2025 with 340+ victims in one year. First observed September 2024. Non-RaaS model with same core operators managing intrusion, encryption, and extortion. Uses stolen credentials, exposed VPN/RDP, and fake IT support call social engineering.
Read the full analysis on IntelFusions