Unsafe
Unsafe is a ransomware group and ransomware-as-a-service operation active since at least late 2022.
Profile source: Mallory opens in a new tabUnsafe
Family profile
Unsafe is a ransomware group and ransomware-as-a-service operation active since at least late 2022. The group is associated with double-extortion activity, combining data theft with threats to publish stolen information and, in some cases, ransomware deployment. Reporting indicates the group was relatively quiet during 2024 and 2025 before reappearing in 2026.
Unsafe has been linked to intrusions affecting organizations in multiple countries, with observed victimology including Germany and Brazil and broader targeting reported in the United States, Germany, Switzerland, and France. Known victims publicly associated with the group include Deutsche Bank, CCR Solutions, and Straight Performance. Its targeting spans sectors such as financial services and business services.
The group has been described as using tactics intended to evade detection and increase pressure on victims, including disabling security controls, removing traces of activity, and leveraging stolen data for extortion. Reported tradecraft also includes exploitation of vulnerabilities, including claims of zero-day exploitation, and publication of purported proof-of-breach material on a leak site. In at least one publicly reported case involving Deutsche Bank, Unsafe claimed access to internal systems and exposed samples allegedly containing employee-related and internal database information, consistent with its extortion model.
Unsafe has also been associated in some reporting with malware families such as GandCrab and Emotet, although the precise nature of that relationship is not fully established from the available information and should be treated cautiously. Overall, Unsafe is best characterized as a financially motivated ransomware actor that uses data theft, public shaming, and extortion to pressure victims.
Operational record
Recent claims
MITRE ATT&CK