Skip to main content
Back to Ransomware Database
Ransomware Group

safepay

SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.

Known victims569

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

DiscoveryEnum

  • Invoke-ShareFinder

Exfiltration

  • 7-Zip
  • WinRAR

LOLBAS

  • CMSTPLUA
  • Regsvr32.exe
  • dllhost.exe
0

Check If You’re Affected

Search our database to see if your organization appears in safepay’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request