SafePay is a ransomware and extortion group also referred to as the SafePay ransomware gang, SafePay ransomware group, SafePay ransomware actors, and SafePay team. It operates a dedicated leak site and has posted healthcare organizations as victims. Its reported targeting spans Europe, the Americas, and other regions, with Germany and the United States featuring prominently. Reported victims include technology providers, construction and infrastructure businesses, architectural and professional-services firms, manufacturers, retailers, hospitality businesses, agricultural enterprises, healthcare institutions, and municipal government organizations. Its victim disclosures demonstrate broad cross-sector targeting rather than a narrowly defined industry focus. No established country of origin, state affiliation, or named subgroup is identified.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against dwi-bau.de, a German company specializing in building systems for metal roofs and facades. The incident was discovered on October 9, 2026, at 22:09 UTC. The report provides no technical details about the intrusion or ransomware deployed.
Reportedly conducted a ransomware attack against hoteldelfinolugano.ch, a Swiss hospitality organization. The incident was discovered on October 9, 2026, at 22:10 UTC. The content does not describe the intrusion method, malware family, or extent of the breach.
SafePay lists Hotel Delfino Lugano (hoteldelfinolugano.ch), a Swiss hotel, as a victim, with a discovery date of 2026-10-09. The supplied post provides no stolen-data details, proof of compromise, ransom amount, or deadline.
SafePay lists dwi-bau.de, a German company specializing in building systems for metal roofs and facades, as a victim discovered on 2026-10-09. The supplied post provides no stolen-data volume, proof of compromise, ransom demand, or deadline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.