SafePay Ransomware Group

Threat Actor

SafePay is a relatively new but highly active ransomware operation known for using a "double extortion" tactic—encrypting victims' files while also stealing their data and threatening to leak it. The group gains initial access to corporate networks using compromised credentials for VPN gateways.

Malware Used by this Threat Actor

No malware identified for this threat actor.