Unsafe — Ransomware Profile

Unsafe is a data-extortion leak-site operation first observed in October 2022. Independent trackers assess that it is not a conventional ransomware group: it operates no known encryptor and functions primarily as a data broker and re-leaker, reposting and reselling data originally stolen by other operations including REvil and ALPHV/BlackCat, at times accompanied by blackmail tactics such as publishing personal material on victim employees. Its Tor leak site has listed roughly 14 to 16 organizations across the energy, education, manufacturing, transportation, and government sectors, with sporadic activity between late 2022 and mid-2026 and extended dormant periods. At least one listing, Invenergy, duplicates a victim originally claimed by REvil in June 2021, and recent claims, including a July 2026 post naming Deutsche Bank, lack any corroborating disclosure; no original intrusion by the group has ever been confirmed.

Also tracked as

nSafe

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions