Ransomware Group intelligence
Safepay
ActiveTrack Safepay with 616 published victims and 5 known leak locations in a single intelligence view.
Overview
Safepay is tracked by Breach House as a ransomware group with 616 published victims.
United States is currently the most targeted country in this dataset.
5 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 139 99.3%
- Deleted 1 0.7%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (5)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 5 | Onion service | Up checked 2h ago | safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion |
| Leak location 4 | Onion service | Down checked 2h ago | j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion |
| Leak location 3 | Onion service | Down checked 2h ago | nj5qix45sxnl4h4og6hcgwengg2oqloj3c2rhc6dpwiofx3jbivcs6qd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | cqkrkmmivhakl3fwgxscurduu3znmroablt7jskxszkctixyseij5gad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion |
Top Activity Sectors (16)
- Not identified 144
- Communication / Marketing 93
- Manufacturing / Engineering 54
- Services 38
- Construction / Real Estate 31
- IT 30
- Healthcare / Pharma 28
- Finance / Legal / Insurance 27
- Education 25
- Retail / E-commerce 22
- Agriculture / Food 15
- Transportation / Travel / Logistics 14
- Public Sector 13
- Hospitality / Food & Beverage / Tourism 12
- NGOs / Associations 9
- Energy 4
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Safepay, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: safepay executes PowerShell scripts to run payload logic, disable defenses, and stage ransomware components.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: safepay uses registry run keys and startup folders to maintain persistence after reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: safepay disables or modifies security tools such as antivirus and monitoring agents to prevent detection and cleanup.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: safepay attempts safe mode boot manipulation to disrupt recovery workflows and evade host-based defenses.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.016 Junk Code Insertion Stealth
What they do: safepay inserts junk code into binaries to evade static analysis and signature-based detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: safepay deletes Volume Shadow Copies and temporary files to eliminate recovery options and reduce forensic traces.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: safepay uses network share discovery to locate victim file shares and staging directories for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: safepay moves laterally through SMB/Windows Admin Shares to encrypt additional systems across the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: safepay encrypts victim files and backups using its ransomware payload to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: safepay performs internal defacement by replacing or corrupting victim files to demonstrate impact and pressure victims.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (8)
▼Software Safepay has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery
Exfiltration
LOLBAS (living-off-the-land binaries)
RMM Tools
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_safepay.txt
Greetings! Your corporate network was attacked by SafePay team. Your IT specialists made a number of mistakes in setting up the security of your corporate network, so we were able to spend quite a long period of time in it and compromise you. It was the misconfiguration of your network that allowed our experts to attack you, so treat this situation as simply as a paid training session for your system administrators. We ve spent the time analyzing your data, including all the sensitive and confidential information. As a result, all files of importance have been encrypted and the ones of most interest to us have been stolen and are now stored on a secure server for further exploitation and publication on the Web with an open access. Now we are in possession of your files such as: financial statements, intellectual property, accounting records, lawsuits and complaints, personnel and customer files, as well as files containing information on bank details, transactions and other internal documentation. Furthermore we successfully blocked most of the servers that are of vital importance to you, however upon reaching an agreement, we will unlock them as soon as possible and your employees will be able to resume their daily duties. We are suggesting a mutually beneficial solution to that issue. You submit a payment to us and we keep the fact that your network has been compromised a secret, delete all your data and provide you with the key to decrypt all your data. WE ARE THE ONES WHO CAN CORRECTLY DECRYPT YOUR DATA AND RESTORE YOUR INFRASTRUCTURE IN A SHORT TIME. DO NOT TRY TO DECRYPT YOUR FILES YOURSELF, YOU WILL NOT BE ABLE TO DO THIS, YOU WILL ONLY DAMAGE THEM AND WE WILL NOT BE ABLE TO RESTORE THEM. In the event of an agreement, our reputation is a guarantee that all conditions will be fulfilled. No one will ever negotiate with us later on if we don't fulfill our part and we recognise that clearly! We are not a politically motivated group and want nothing more than money. Provided you pay, we will honour all the terms we agreed to during the negotiation process. In order to contact us, please use chat below, you have 10 days to contact us, after this time a blog post will be made with a timer for 3 days before the data is published and you will no longer be able to contact us. To contact us follow the instructions: Install and run Tor Browser from https://www.torproject.org/download/ Go to http://dgcg5ncjab6scb7fnk7gx5php4lbpxjy2jjnu3apnkxyippqf6yhw3ad.onion Reserve Link: http://oxly5vxvvhi5fv5vsvj3kvlqeprbijitycqisylaxzf324bn7e4qr2ad.onion Log in with ID: [snip] Contact and wait for a reply, we guarantee that we will reply as soon as possible, and we will explain everything to you once again in more detail. Our blog: http://j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion http://nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion Our TON blog: tonsite://safepay.ton You can connect through your Telegramm account.
readme_safepay_ascii.txt
Greetings! Your corporate network was attacked by SafePay team. Your IT specialists made a number of mistakes in setting up the security of your corporate network, so we were able to spend quite a long period of time in it and compromise you. It was the misconfiguration of your network that allowed our experts to attack you, so treat this situation as simply as a paid training session for your system administrators. We ve spent the time analyzing your data, including all the sensitive and confidential information. As a result, all files of importance have been encrypted and the ones of most interest to us have been stolen and are now stored on a secure server for further exploitation and publication on the Web with an open access. Now we are in possession of your files such as: financial statements, intellectual property, accounting records, lawsuits and complaints, personnel and customer files, as well as files containing information on bank details, transactions and other internal documentation. Furthermore we successfully blocked most of the servers that are of vital importance to you, however upon reaching an agreement, we will unlock them as soon as possible and your employees will be able to resume their daily duties. We are suggesting a mutually beneficial solution to that issue. You submit a payment to us and we keep the fact that your network has been compromised a secret, delete all your data and provide you with the key to decrypt all your data. WE ARE THE ONES WHO CAN CORRECTLY DECRYPT YOUR DATA AND RESTORE YOUR INFRASTRUCTURE IN A SHORT TIME. DO NOT TRY TO DECRYPT YOUR FILES YOURSELF, YOU WILL NOT BE ABLE TO DO THIS, YOU WILL ONLY DAMAGE THEM AND WE WILL NOT BE ABLE TO RESTORE THEM. In the event of an agreement, our reputation is a guarantee that all conditions will be fulfilled. No one will ever negotiate with us later on if we don't fulfill our part and we recognise that clearly! We are not a politically motivated group and want nothing more than money. Provided you pay, we will honour all the terms we agreed to during the negotiation process. In order to contact us, please use chat below, you have 10 days to contact us, after this time a blog post will be made with a timer for 3 days before the data is published and you will no longer be able to contact us. To contact us follow the instructions: Install and run Tor Browser from https://www.torproject.org/download/ Go to http://dgcg5ncjab6scb7fnk7gx5php4lbpxjy2jjnu3apnkxyippqf6yhw3ad.onion Reserve Link: http://oxly5vxvvhi5fv5vsvj3kvlqeprbijitycqisylaxzf324bn7e4qr2ad.onion Log in with ID: [snip] Contact and wait for a reply, we guarantee that we will reply as soon as possible, and we will explain everything to you once again in more detail. Our blog: http://j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion http://nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion Our TON blog: tonsite://safepay.ton You can connect through your Telegramm account.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (616)
Search, filter and paginate the victim timeline for Safepay. Showing 1–100 of 616.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | compunnel.com id32763 View details | United States | IT | pending | ||
|
Compunnel.com operates within the IT sector and is located in the United States. The entity functions as a technology services provider, offering infrastructure and digital solutions relevant to enterprise operations and network environments. Within the threat-intelligence index, compunnel.com is cataloged as a ransomware victim linked to the safepay threat actor. This listing reflects its association with malicious activity in cybersecurity records, without disclosing confirmed breach details, data loss specifics, or operational impact. The designation serves as a neutral reference point for threat analysts tracking ransomware incidents across sectors and geographies. |
||||||
| Ransomware | compunnel.com id32763 View details | United States | IT | pending | ||
|
The company provides a combination of talent acquisition, IT consulting, digital engineering, artificial intelligence, cybersecurity, and workforce management services to … |
||||||
| Ransomware | palmettoeyeinstitute.com id32693 View details | United States | Healthcare / Pharma | pending | ||
|
palmettoeyeinstitute.com operates within the United States healthcare and medicine sector, providing clinical services and institutional functions aligned with patient care infrastructure. The entity is formally listed within the threat-intelligence index under the designation ransomware victim, associated with the threat actor or source identified as safepay. This classification reflects the security event documented in the index without elaborating on unverified technical or operational details. The catalog entry serves to contextualize the organization's sector, geographic location, and its recognized relationship to the safepay threat actor for analytical and defensive purposes. It neutrally states that palmettoeyeinstitute.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | palmettoeyeinstitute.com id32693 View details | United States | Healthcare / Pharma | pending | ||
|
The practice was founded by Dr. Prat Itharat, a board-certified ophthalmologist who specializes in cataract surgery and comprehensive eye care. … |
||||||
| Ransomware | reichenau.at id32694 View details | Austria | IT | pending | ||
|
reichenau.at is an entity operating within the IT sector, situated in Austria (country AT). The domain and associated organization represent a technology-focused entity whose infrastructure or operations are cataloged within a threat-intelligence index. This listing identifies reichenau.at specifically as a ransomware victim, with the associated threat actor or source designated as safepay. The catalog entry reflects observed threat-intelligence data concerning this entity's exposure to ransomware activity within its sector and geographic context. The final assessment neutrally states that reichenau.at was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | reichenau.at id32694 View details | Austria | IT | pending | ||
|
The official website, reichenau.at, serves as the municipality's central digital information and service platform for residents, businesses, and visitors. The … |
||||||
| Ransomware | cannonpuntana.com id32695 View details | Argentina | Retail / E-commerce | pending | ||
|
cannonpuntana.com operates within the Retail and E-commerce sector and is associated with the country of Ar. The entity represents a business in a digitally connected retail environment where cyber threats pose significant operational and financial risk. It has been formally cataloged as a ransomware victim linked to the threat actor Safepay within this threat-intelligence index. This listing reflects the entity's inclusion based on verified threat-intelligence data without disclosing unconfirmed incident details. The classification supports security professionals monitoring retail and e-commerce environments for potential attack patterns and actor activity. |
||||||
| Ransomware | cannonpuntana.com id32695 View details | Argentina | Retail / E-commerce | pending | ||
|
The company operated in Argentina and was historically connected with the manufacture and distribution of fragrances, toiletries, and personal-care products. … |
||||||
| Ransomware | assiprime.it id32696 View details | Italy | Healthcare / Pharma | pending | ||
|
assiprime.it operates within the Healthcare and Pharma sector, based in Italy. The entity provides digital services relevant to clinical operations, pharmaceutical administration, or patient data management within its regional healthcare infrastructure. It has been formally cataloged as a ransomware victim associated with the threat actor safepay. This listing reflects the entity's inclusion in the threat-intelligence index based on verified incident correlation data. The description remains neutral, focusing solely on the entity's sector, geographic context, and its designation within the ransomware victim index tied to safepay. |
||||||
| Ransomware | assiprime.it id32696 View details | Italy | Healthcare / Pharma | pending | ||
|
The company provides insurance brokerage, risk-management, financial consulting, and related assistance services to private individuals, businesses, professionals, artisans, and commercial … |
||||||
| Ransomware | gayafores.es id32697 View details | Spain | Retail / E-commerce | pending | ||
|
gayafores.es operates within the retail and e-commerce sector, with its primary business location identified as Spain (country code ES). The entity provides online commerce and retail services, making it a relevant case within cyber threat intelligence analysis for digital commerce environments. This listing type identifies gayafores.es as a ransomware victim associated with the threat actor or source designated as safepay. The description remains factual and neutral, focusing on the entity's known sector, geographic context, and its classification within the threat-intelligence index without speculating on unconfirmed incident details. This entry supports researchers and defenders in understanding ransomware patterns affecting retail and e-commerce organizations in the region. |
||||||
| Ransomware | gayafores.es id32697 View details | Spain | Retail / E-commerce | pending | ||
|
The company is headquartered in Onda, Castellón, one of Europe's most important ceramic manufacturing regions. Established in 1949, Gayafores has … |
||||||
| Ransomware | cenmar-manila.com id32698 View details | Philippines | Services | pending | ||
|
cenmar-manila.com operates within the Philippine services sector, providing commercial and professional service offerings under its domain identity. As documented in the threat-intelligence index, this entity is classified as a ransomware victim linked to the threat actor safepay. The classification reflects the cybersecurity context surrounding the entity's exposure within the indexed threat landscape, emphasizing sector relevance and geographic location for analytical purposes. This entry serves to catalog the relationship between the entity, its operational context, and the associated threat actor without disclosing unverified incident details. |
||||||
| Ransomware | cenmar-manila.com id32698 View details | Philippines | Services | pending | ||
|
The company was registered with the Philippine Securities and Exchange Commission in 1997 and received authorization to operate as a … |
||||||
| Ransomware | gsngestion.es id32699 View details | Spain | IT | pending | ||
|
gsngestion.es operates within the IT sector and is associated with the country of Spain. The entity represents a ransomware victim entry within the threat-intelligence index, explicitly linked to the threat actor or source identified as safepay. Its inclusion reflects documented intelligence concerning cybersecurity incidents affecting this organization. The listing provides neutral context for defenders assessing risks tied to this actor and sector profile. This description avoids speculative claims regarding breach details, data exposure, or operational impact. |
||||||
| Ransomware | gsngestion.es id32699 View details | Spain | IT | pending | ||
|
The company is based in Villaviciosa de Odón, Madrid, and operates through the GSN Gestión brand. Its website states that … |
||||||
| Ransomware | hbpro.pt id32700 View details | Portugal | Services | pending | ||
|
hbpro.pt is a Portuguese services-sector entity identified within the threat-intelligence index as a ransomware victim. Its name and sector context indicate operational presence in the services industry within Portugal, where the entity was cataloged alongside its associated threat actor safepay. This listing type documents the relationship between hbpro.pt and safepay without disclosing unverified incident details such as stolen data, affected records, ransom terms, or confirmed breach specifics. The entry serves as a neutral reference point for catalogued ransomware-victim intelligence, linking the entity to its geographic context, sector classification, and threat actor attribution for analyst review and index maintenance. |
||||||
| Ransomware | hbpro.pt id32700 View details | Portugal | Services | pending | ||
|
Established in 1994, the company has more than three decades of experience providing technology products, infrastructure, consulting, maintenance, and technical … |
||||||
| Ransomware | recoverycafe.org id32691 View details | United States | NGOs / Associations | pending | ||
|
recoverycafe.org operates within the NGO and associations sector based in the United States, providing support resources and recovery services for affected organizations. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor safepay. This listing reflects the association between the organization and the identified malicious actor without disclosing unverified incident details such as data stolen, ransom demands, or specific breach metrics. The entry serves to document the victim profile, sector context, geographic location, and threat actor attribution for cybersecurity researchers and defenders monitoring ransomware activity in non-profit and association environments. |
||||||
| Ransomware | recoverycafe.org id32691 View details | United States | NGOs / Associations | pending | ||
|
The organization was founded in 2003 and opened its first physical café in Seattle in 2004. Its approach is based … |
||||||
| Ransomware | mcnishsteel.com id32692 View details | Canada | Manufacturing / Engineering | pending | ||
|
mcnishsteel.com operates within the manufacturing and engineering sector, with operations and presence associated with Canada. The entity represents a business organization whose cybersecurity posture and incident history are cataloged within threat-intelligence indexing frameworks. This listing identifies mcnishsteel.com specifically as a ransomware victim associated with the threat actor safepay. The description remains factual and neutral, reflecting the indexed classification without attributing unverified claims, breach details, or operational specifics. Such entries support threat-intelligence analysis by documenting real-world victim profiles tied to identifiable actors and sectors. |
||||||
| Ransomware | mcnishsteel.com id32692 View details | Canada | Manufacturing / Engineering | pending | ||
|
The company is headquartered in Edmonton, Alberta, and was founded in 1978 by William and Wallace McNish. It has developed … |
||||||
| Ransomware | industry.airliquide.kr id32128 View details | Korea, Republic of | Manufacturing / Engineering | pending | ||
|
industry.airliquide.kr operates within the Manufacturing and Engineering sector based in South Korea (KR). The entity provides industrial gas and related engineering solutions essential to manufacturing operations and industrial processes across its regional market. This listing identifies industry.airliquide.kr as a ransomware victim associated with the threat actor safepay. The entry documents the cybersecurity event within a threat-intelligence index for monitoring and analysis purposes. No specific incident details such as data stolen, ransom demands, or breach confirmation are included per strict factual reporting guidelines. |
||||||
| Ransomware | industry.airliquide.kr id32128 View details | Korea, Republic of | Manufacturing / Engineering | pending | ||
|
Air Liquide has operated in South Korea for several decades and supplies essential gases and related technologies to major industries, … |
||||||
| Ransomware | lagegepesca.it id32085 View details | Italy | Agriculture / Food | pending | ||
|
lagegepesca.it operates within the Agriculture and Food sector and is situated in Italy. The entity serves as a catalog entry identifying a ransomware victim linked to the threat actor safepay within the threat-intelligence index. This listing type documents the association between the organization, its geographic and sectoral context, and the identified threat actor without disclosing unconfirmed incident details. The description remains neutral and factual, reflecting the index's role in mapping cybersecurity incidents to affected entities and responsible actors. No specifics regarding stolen data, ransom demands, or confirmed breach elements are included per strict analytical constraints. |
||||||
| Ransomware | lagegepesca.it id32085 View details | Italy | Agriculture / Food | pending | ||
|
Based in Lallio, near Bergamo in Lombardy, the company traces its origins to 1957, when Santo Gavazzi established a small … |
||||||
| Ransomware | granjarinya.com id31721 View details | Spain | Agriculture / Food | pending | ||
|
Granjarinya.com is a Spanish company operating in the agriculture and food sector. The company is likely involved in activities such as farming, food processing, or distribution. Granjarinya.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | granjarinya.com id31721 View details | Spain | Agriculture / Food | pending | ||
|
Headquartered in Albal, Valencia, the family-owned company traces its origins to three generations of livestock farming. What began as a … |
||||||
| Ransomware | pradotuylaw.com id31191 View details | United States | Finance / Legal / Insurance | pending | ||
|
Pradotuylaw.com is a US-based law firm operating in the finance and legal sector, providing services to clients in the United States. The firm is involved in various legal practices, including insurance law. Pradotuylaw.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | pradotuylaw.com id31191 View details | United States | Finance / Legal / Insurance | pending | ||
|
The firm focuses on practice areas including personal injury, wrongful death, workplace harassment, business litigation, civil settlements, and environmental litigation. … |
||||||
| Ransomware | naskdoorinc.com id31192 View details | United States | IT | pending | ||
|
Naskdoorinc.com is an IT company based in the United States, offering various services within the IT sector. The company operates in a competitive market, providing solutions to its clients. Naskdoorinc.com was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | naskdoorinc.com id31192 View details | United States | IT | pending | ||
|
Headquartered in West Chester, Pennsylvania, the company has served customers throughout southeastern Pennsylvania and northern Delaware for several decades. Although … |
||||||
| Ransomware | new-point.it id31193 View details | Italy | IT | pending | ||
|
New-point.it is an Italian company operating in the IT sector, providing various services and solutions. The company is based in Italy and offers a range of IT-related services. New-point.it was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | new-point.it id31193 View details | Italy | IT | pending | ||
|
Headquartered in Signa, Florence, Italy, the company was founded in 2006 and has grown into one of Italy's established suppliers … |
||||||
| Ransomware | simonrack.com id31194 View details | Spain | IT | pending | ||
|
Simonrack.com is a company operating in the IT sector, based in Spain. The company likely provides various IT services, given its sector classification. Simonrack.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | simonrack.com id31194 View details | Spain | IT | pending | ||
|
Headquartered in Alfamén, Zaragoza, Spain, the company has been manufacturing metal shelving since 1964 and has become one of Europe's … |
||||||
| Ransomware | hanan-hov.co.il id31195 View details | Israel | Construction / Real Estate | deleted | ||
|
Hanan Hov is an Israeli company operating in the construction and real estate sector, providing various services to clients in Israel. The company is involved in development and construction projects, offering a range of services. Hanan Hov was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | hanan-hov.co.il id31195 View details | Israel | Construction / Real Estate | deleted | ||
|
Headquartered in Neve Yamin, Israel, the company provides comprehensive logistics support for construction, infrastructure, industrial, and commercial projects throughout the … |
||||||
| Ransomware | azn.co.jp id31185 View details | Japan | Manufacturing / Engineering | pending | ||
|
Azn.co.jp is a Japanese company operating in the manufacturing and engineering sector. The company is based in Japan and provides various offerings related to its sector. Azn.co.jp was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | azn.co.jp id31185 View details | Japan | Manufacturing / Engineering | pending | ||
|
Founded in 1991, the company specializes in comprehensive asset management, inheritance planning, business succession consulting, real estate advisory services, and … |
||||||
| Ransomware | southshorerecycling.com id31186 View details | United States | Manufacturing / Engineering | pending | ||
|
South Shore Recycling is a company based in the United States, operating within the manufacturing and engineering sector. The company likely provides recycling services, given its name. South Shore Recycling was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | southshorerecycling.com id31186 View details | United States | Manufacturing / Engineering | pending | ||
|
The company specializes in metal recycling, concrete and asphalt recycling, aggregate production, and construction waste processing for commercial, industrial, and … |
||||||
| Ransomware | cpu-ag.com id31187 View details | Germany | IT | pending | ||
|
cpu-ag.com operates in the IT sector, based in Germany, providing various services. The company's offerings cater to the IT industry, with a focus on serving clients in Germany. cpu-ag.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | cpu-ag.com id31187 View details | Germany | IT | pending | ||
|
Founded in 1981 and headquartered in Friedberg, Bavaria, the company has more than four decades of experience developing specialized software … |
||||||
| Ransomware | multiaqua.com id31188 View details | United States | Agriculture / Food | pending | ||
|
Multiaqua.com operates in the agriculture and food sector in the United States, providing various offerings to its customers. As a company in this sector, it plays a crucial role in the food supply chain. Multiaqua.com was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | multiaqua.com id31188 View details | United States | Agriculture / Food | pending | ||
|
Founded in 1999, the company specializes in the design, engineering, and production of air-cooled water chillers, heat pump chillers, hydronic … |
||||||
| Ransomware | zinorm.de id30991 View details | Germany | IT | pending | ||
|
Zinorm.de is a German company operating in the IT sector, providing various services to its clients. Located in Germany, the company is involved in the IT industry, offering a range of solutions. Zinorm.de was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | zinorm.de id30991 View details | Germany | IT | pending | ||
|
Founded in 1952 and headquartered in Ahrensburg, Schleswig-Holstein, the family-owned company has more than seventy years of experience serving customers … |
||||||
| Ransomware | moebelmayer.de id30992 View details | Germany | Retail / E-commerce | pending | ||
|
Moebelmayer.de is a German-based company operating in the retail and e-commerce sector, offering various products to customers in Germany. As an e-commerce platform, it provides online shopping experiences. Moebelmayer.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | moebelmayer.de id30992 View details | Germany | Retail / E-commerce | pending | ||
|
Founded in 1952 and headquartered in Ahrensburg, Schleswig-Holstein, the family-owned company has more than seventy years of experience serving customers … |
||||||
| Ransomware | paritaet-nrw.org id30993 View details | Germany | NGOs / Associations | pending | ||
|
Paritaet-nrw.org is a non-governmental organization based in Germany, operating in the sector of NGOs and associations. The organization likely provides various services and support to its members and the community. Paritaet-nrw.org was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | paritaet-nrw.org id30993 View details | Germany | NGOs / Associations | pending | ||
|
Headquartered in Wuppertal, the organization represents approximately 3,100 legally independent member organizations operating more than 7,000 social institutions and services … |
||||||
| Ransomware | haugbuersten.de id30994 View details | Germany | Manufacturing / Engineering | pending | ||
|
Haugbuersten.de operates in the manufacturing and engineering sector in Germany, providing various products and services. The company's specific offerings cater to the needs of its clients within the industry. Haugbuersten.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | haugbuersten.de id30994 View details | Germany | Manufacturing / Engineering | pending | ||
|
Although the company in its current industrial form was founded in 1962, its family-owned brush-making tradition dates back to 1836, … |
||||||
| Ransomware | landesmuseum.de id30995 View details | Germany | Public Sector | pending | ||
|
The Landesmuseum is a cultural institution located in Germany, operating within the public sector. It provides various offerings, including exhibitions and educational programs, to promote cultural awareness and preservation. Landesmuseum.de is its online presence, serving as a platform for information and engagement. It was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | landesmuseum.de id30995 View details | Germany | Public Sector | pending | ||
|
Established in 1919, the museum preserves and presents more than 50,000 years of human cultural history, ranging from prehistoric artifacts … |
||||||
| Ransomware | hst.eu id30996 View details | Germany | — | pending | ||
|
Headquartered in Kressbronn am Bodensee, Germany, the company traces its mechanical engineering heritage back to 1950, while the original tea … |
||||||
| Ransomware | braywoodschool.co.uk id30997 View details | United Kingdom | — | pending | ||
|
Founded in 1858, the school has more than 165 years of educational history and serves children from early years through … |
||||||
| Ransomware | weier.org id30985 View details | Germany | Other | pending | ||
|
Weier.org is an organization based in Germany, operating in the Other sector. The entity provides various offerings, although specific details about its services are not readily available. Weier.org was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | weier.org id30985 View details | Germany | Other | pending | ||
|
The company specializes in representing manufacturers of plumbing, heating, water treatment, pumping, drainage, and building services equipment throughout western Germany. … |
||||||
| Ransomware | bnpdist.com id30986 View details | United States | Finance / Legal / Insurance | pending | ||
|
Bnpdist.com is a US-based company operating in the finance, legal, and insurance sector, providing various financial services. The company is headquartered in the United States and offers a range of financial solutions. Bnpdist.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | bnpdist.com id30986 View details | United States | Finance / Legal / Insurance | pending | ||
|
Headquartered in New York City, the company has been operating since 1979 and supplies restaurants, hotels, retailers, and wine merchants … |
||||||
| Ransomware | upland.k12.ca.us id30831 View details | United States | Education | pending | ||
|
Upland Unified School District is a public school district located in California, US, providing education services to students. The district operates several schools, offering various academic programs and extracurricular activities. It was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | upland.k12.ca.us id30831 View details | United States | Education | pending | ||
|
The district provides comprehensive education from kindergarten through twelfth grade and operates 14 schools, including elementary, junior high, and high … |
||||||
| Ransomware | gvsurgicalarts.com id30832 View details | United States | Healthcare / Pharma | pending | ||
|
Gvsurgicalarts.com is a healthcare service provider based in the US, offering medical services. The company operates in the healthcare sector, providing essential medical care to patients. Gvsurgicalarts.com was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | gvsurgicalarts.com id30832 View details | United States | Healthcare / Pharma | pending | ||
|
Founded in 2004 by Dr. Brian R. Chisdak, the practice has grown into one of Montana's leading surgical centers and … |
||||||
| Ransomware | wdk.de id30710 View details | Germany | Finance / Legal / Insurance | pending | ||
|
Wdk.de is a German company operating in the finance, legal, and insurance sector, providing various services to its clients. Located in Germany, the company is part of a critical sector that requires high security standards. Wdk.de is listed as a ransomware victim associated with safepay |
||||||
| Ransomware | wdk.de id30710 View details | Germany | Finance / Legal / Insurance | pending | ||
|
Founded in 1950 and headquartered in Frankfurt am Main, the organization serves as the central voice of German manufacturers of … |
||||||
| Ransomware | jaecklin-industrial.de id30711 View details | Germany | Manufacturing / Engineering | pending | ||
|
Jaecklin Industrial is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides industrial products and services, given its name and sector. Jaecklin Industrial was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | jaecklin-industrial.de id30711 View details | Germany | Manufacturing / Engineering | pending | ||
|
Founded in 1935 by Julius Jäcklin, the company has developed from a regional machine repair workshop into a globally recognized … |
||||||
| Ransomware | lbb-treuhand.de id30712 View details | Germany | Finance / Legal / Insurance | pending | ||
|
lbb-treuhand.de is a German company operating in the finance, legal, and insurance sector, offering various services to its clients. The company is based in Germany and provides financial and legal expertise to its customers. lbb-treuhand.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | lbb-treuhand.de id30712 View details | Germany | Finance / Legal / Insurance | pending | ||
|
The company specializes in tax consulting, auditing, accounting, payroll administration, financial reporting, and business advisory services for private individuals, self-employed … |
||||||
| Ransomware | timetex.de id30713 View details | Germany | Manufacturing / Engineering | pending | ||
|
Timetex.de is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Timetex.de was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | timetex.de id30713 View details | Germany | Manufacturing / Engineering | pending | ||
|
The company traces its origins to 1991, when the TimeTEX brand was acquired and expanded into a comprehensive supplier of … |
||||||
| Ransomware | stroebel-gruppe.de id30714 View details | Germany | Manufacturing / Engineering | pending | ||
|
Stroebel-gruppe.de is a company based in Germany, operating in the manufacturing and engineering sector. The company likely provides various services and products related to these fields. Stroebel-gruppe.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | stroebel-gruppe.de id30714 View details | Germany | Manufacturing / Engineering | pending | ||
|
Headquartered in Langenzenn, Bavaria, the company was founded in 1978 by Gerlinde and Gerhard Ströbel and has grown from a … |
||||||
| Ransomware | industriesjaro.com id30715 View details | Canada | Manufacturing / Engineering | pending | ||
|
Industriesjaro.com is a company based in Canada, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Industriesjaro.com was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | industriesjaro.com id30715 View details | Canada | Manufacturing / Engineering | pending | ||
|
Over several decades, Jaro has evolved from manufacturing telephone booths into a supplier of advanced outdoor enclosures, interactive kiosks, bus … |
||||||
| Ransomware | cenesco.de id30716 View details | Germany | IT | pending | ||
|
Cenesco.de is an IT company based in Germany, providing various IT services. The company operates in the IT sector, offering solutions to its clients. Cenesco.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | cenesco.de id30716 View details | Germany | IT | pending | ||
|
Founded in 1998, the company provides comprehensive information technology solutions for small and medium-sized enterprises (SMEs), helping organizations modernize their … |
||||||
| Ransomware | acsmallmaxwell.com.au id30717 View details | Australia | Finance / Legal / Insurance | pending | ||
|
acsmallmaxwell.com.au is an Australian company operating in the finance, legal and insurance sector, providing various services to its clients. The company is based in Australia and offers a range of financial and legal services. acsmallmaxwell.com.au was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | acsmallmaxwell.com.au id30717 View details | Australia | Finance / Legal / Insurance | pending | ||
|
Founded in 1916 by Ambrose Cecil Small, the firm has provided professional accounting and financial services to businesses and individuals … |
||||||
| Ransomware | mende-grundbesitz.de id30718 View details | Germany | Construction / Real Estate | pending | ||
|
Mende Grundbesitz is a real estate company based in Germany, operating in the construction sector. The company likely provides various services related to property management and development. Mende Grundbesitz was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | mende-grundbesitz.de id30718 View details | Germany | Construction / Real Estate | pending | ||
|
Founded in 1994, the company specializes in the professional administration of residential, commercial, and mixed-use real estate throughout the Berlin … |
||||||
| Ransomware | shuttlemeadowcc.com id30525 View details | United States | Transportation / Travel / Logistics | — | ||
|
Shuttlemeadowcc.com is a transportation company based in the US, operating in the travel and logistics sector, providing services to customers. The company likely offers transportation solutions, given its name and industry classification. Shuttlemeadowcc.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | shuttlemeadowcc.com id30525 View details | United States | Transportation / Travel / Logistics | — | ||
|
Founded in 1917, the club is one of the oldest and most prestigious private golf clubs in New England. It … |
||||||
| Ransomware | matrixwebagency.com id30296 View details | United States | Communication / Marketing | pending | ||
|
Matrixwebagency.com is a US-based company operating in the communication and marketing sector, providing various services. The company's offerings likely include web development, marketing strategies, and other related services. Matrixwebagency.com was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | matrixwebagency.com id30296 View details | United States | Communication / Marketing | pending | ||
|
The company specializes in providing integrated digital solutions that help businesses improve their online visibility, customer engagement, and revenue growth. … |
||||||
| Ransomware | bmiprojects.de id30297 View details | Germany | Construction / Real Estate | pending | ||
|
bmiprojects.de is a German company operating in the construction and real estate sector, providing various services to clients in Germany. The company's offerings likely include project management, development, and other related services. bmiprojects.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | bmiprojects.de id30297 View details | Germany | Construction / Real Estate | pending | ||
|
Originally operating under the name Bez Marine Interiors GmbH, the company built on decades of experience in the maritime industry … |
||||||
| Ransomware | caritas-koblenz.de id30298 View details | Germany | NGOs / Associations | pending | ||
|
Caritas Koblenz is a non-governmental organization based in Germany, operating in the sector of NGOs and associations, providing social services and support. The organization is part of the broader Caritas network, offering various forms of assistance to those in need. Caritas Koblenz was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | caritas-koblenz.de id30298 View details | Germany | NGOs / Associations | pending | ||
|
Headquartered in Koblenz, the association was founded in 1918 and has provided charitable and community-based services for more than a … |
||||||
| Ransomware | knobel-bau.de id30299 View details | Germany | Construction / Real Estate | pending | ||
|
Knobel-Bau.de is a construction and real estate company based in Germany, providing various services to the sector. The company operates in the German market, offering construction and real estate solutions. Knobel-Bau.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | knobel-bau.de id30299 View details | Germany | Construction / Real Estate | pending | ||
|
Founded in 1947, the company has grown from a small sand and gravel business established after the Second World War … |
||||||
| Ransomware | rtngmbh.de id30300 View details | Germany | IT | pending | ||
|
rtngmbh.de is an IT company based in Germany, providing various services to its clients. The company operates in the IT sector, offering solutions to businesses in the region. rtngmbh.de was listed as a ransomware victim associated with safepay |
||||||
| Ransomware | rtngmbh.de id30300 View details | Germany | IT | pending | ||
|
Founded in 2015, the company specializes in the construction, installation, maintenance, and rehabilitation of underground utility networks and civil engineering … |
||||||
| Ransomware | stedwardscatholicfirstschool.co.uk id30301 View details | United Kingdom | Education | pending | ||
|
St Edward's Catholic First School is an educational institution based in the United Kingdom, providing primary education to students. As part of the education sector in GB, the school offers various academic programs and activities. St Edward's Catholic First School was listed as a ransomware victim associated with safepay. |
||||||
| Ransomware | stedwardscatholicfirstschool.co.uk id30301 View details | United Kingdom | Education | pending | ||
|
The school provides education for children aged 5 to 9 years and operates as a Voluntary Aided School under the … |
||||||
| Ransomware | lh-wohnverbund-wohnen-nrw.de id30302 View details | Germany | Construction / Real Estate | pending | ||
|
LH Wohnverbund Wonen NRW is a German company operating in the construction and real estate sector, providing various services related to housing in North Rhine-Westphalia. The company's offerings likely include property management, development, and other related services. LH Wohnverbund Wonen NRW is listed as a ransomware victim associated with safepay |
||||||
| Ransomware | lh-wohnverbund-wohnen-nrw.de id30302 View details | Germany | Construction / Real Estate | pending | ||
|
They specialize in providing residential care, supported living, and social assistance for children, adolescents, and adults with intellectual and developmental … |
||||||