Discovery Enum
- Invoke-ShareFinder
SafePay is a financially motivated ransomware operation and associated custom ransomware strain that emerged in late 2024 and became one of the more active extortion actors through 2025 and early 2026.
Profile source: Mallory opens in a new tabSafePay
SafePay is a financially motivated ransomware operation and associated custom ransomware strain that emerged in late 2024 and became one of the more active extortion actors through 2025 and early 2026. The group presents itself as a private, centralized operation rather than a ransomware-as-a-service program. It uses a double-extortion model, stealing victim data and then encrypting systems to pressure payment, with non-paying victims publicly exposed on its leak site. Reported victimology indicates broad cross-sector targeting, with repeated visibility in healthcare and notable activity against managed service providers and small-to-midsize businesses, as well as organizations in North America and Europe, especially the United States and Germany.
Observed intrusions show SafePay relying on conventional but effective human-operated tradecraft rather than highly novel techniques. Documented initial access includes password spraying against VPN infrastructure, followed by a dwell period before privilege escalation, internal discovery, data collection, exfiltration, and rapid encryption. Operators have used publicly available administrative and post-compromise tooling for share enumeration and data staging, searched for and encrypted backup resources, and deleted shadow copies to hinder recovery. In at least one investigated case, the actor obtained domain administrator privileges after a prolonged intrusion and completed collection, exfiltration, and encryption in a compressed final phase. The group has also been reported to directly contact victims by telephone to intensify extortion pressure.
The SafePay ransomware itself is a custom Windows encryptor written in C. Analysis has described asynchronous file encryption using Overlapped I/O, support for partial encryption, and conditional use of AES-CBC or ChaCha20 depending on processor support, with Curve25519 protecting per-file key material. Researchers assessing the malware found design similarities to several established ransomware families but concluded it was likely independently developed rather than a direct derivative. Operational reporting has also suggested that, at least during part of 2025, SafePay lacked a native VMware ESXi encryptor and instead carried out observed encryption activity from within guest virtual machines.
SafePay has been linked to multiple significant extortion incidents, including attacks affecting healthcare entities, government service providers, and large enterprises. Public reporting associates the group with major data theft and disruption events involving organizations such as Conduent and Ingram Micro. Across 2025, SafePay was repeatedly ranked among the more active ransomware brands by victim volume and was consistently identified as a notable threat to the healthcare sector.
Reported operators
The SafePay ransomware group is a relatively new group, first appearing on our radar in November 2024. The group follows a double-extortion scheme, both exfiltrating data and encrypting it on victim machines using their own SafePay ransomware.
MITRE ATT&CK
Reporting
Marlboro-Chesterfield Pathology has agreed to settle a class action lawsuit tied to a January 2025 ransomware attack attributed to the SafePay group, after attackers gained unauthorized access to its network and obtained files containing sensitive patient information. The pathology provider reported to the U.S. Department of Health and Human Services Office for Civil Rights that 235,911 individuals were affected, with compromised data including names, dates of birth, Social Security numbers, and protected health information. The proposed settlement, which received preliminary court approval, provides reimbursement of documented fraud- or identity-theft-related losses of up to $1,000 per class member, a $10 alternative cash payment for certain people whose Social Security numbers were exposed, and one year of credit monitoring and identity theft protection. Marlboro-Chesterfield Pathology denied wrongdoing and liability, and no ransom payment details were disclosed, while a final fairness hearing is scheduled for October 12, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.