Back to Intelligence

SAFEPAY Ransomware: 10 New Leak-Site Listings — Sector Targeting Analysis & Detection Engineering Brief

SA
Security Arsenal Team
October 5, 2026
12 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-06 | Source: ransomware.live leak-site monitoring | Nature of data: Unverified threat-actor claims

Executive Summary

Leak-site monitoring on 2026-10-05 identified a single-day posting wave on the SAFEPAY ransomware group's dark web leak site, in which the gang claims to have compromised 10 organizations spanning Technology, Retail & E-Commerce, and Professional Services across eight countries (CZ, CH, DE, IT, US, CL, SK, KE, plus one listing in NL). All 10 listings were independently observed by two separate leak-site crawlers, confirming the postings are genuine gang claims — not confirmed breaches.

Notably, SAFEPAY names t-systems.com (Technology, DE) among the listings — a claim of particular significance given the organization's scale, and one that remains unverified at time of publication. The geographic weighting toward Central Europe (CZ, CH, DE, SK, IT, NL) is consistent with SAFEPAY's historical European focus, while the US, CL, and KE listings indicate continued opportunistic global reach.

This briefing provides SAFEPAY's known tradecraft, detection engineering content (Sigma, KQL, PowerShell), and IR priorities tuned to this gang's pre-encryption behavior.

Sourcing & Verification

  • 10 of 10 listings in this dataset were independently observed by a second leak-site crawler (MULTI-SOURCE tier). 0 listings are single-source.
  • MULTI-SOURCE corroboration confirms only that the gang published the claim. Inclusion in this briefing reflects the threat actor's accusation and is NOT confirmation of a breach. No corroboration tier in this dataset confirms a breach — only the named organization or its regulator can do that.
  • A named organization may dispute a listing. A denial is likewise not proof the claim is false: disclosure obligations vary by jurisdiction, not every incident is reportable, and neither silence nor denial settles the question either way.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — SAFEPAY

Aliases: SafePay (sometimes written Safe-Pay). No widely confirmed rebrand lineage as of this writing, though TTP overlap with legacy LockBit-adjacent tooling has been reported by multiple researchers.

Operating model: SAFEPAY operates as a closed group rather than an open Ransomware-as-a-Service program. The gang does not publicly recruit affiliates on underground forums, which correlates with more consistent tradecraft across victims and fewer low-skill operational mistakes — but also a lower overall victim volume than open RaaS brands.

Ransom demands: Observed demands typically range from $100K to $3M USD, calibrated to victim revenue. SAFEPAY negotiates via a Tor-based chat portal and is known for relatively short negotiation windows (often 7–14 days) before data publication.

Initial access methods (historical):

  • Exploitation of internet-facing VPN and firewall appliances (unpatched edge devices are the most consistent entry theme)
  • RDP exposure — brute force and purchased credentials from initial access brokers
  • Phishing with macro-enabled documents and malicious loaders
  • Occasional abuse of managed/build infrastructure in victim environments

Extortion model: Double extortion — data theft prior to encryption, with a public leak site countdown used to pressure victims. SAFEPAY has historically published partial data samples quickly (within 48–72 hours of the deadline) to establish credibility.

Dwell time: Reported dwell time is typically short — 24 hours to 5 days from initial access to detonation, significantly faster than the industry median. This compresses the defender's window and elevates the value of pre-ransomware behavioral detection over perimeter alerts alone.

Current Campaign Analysis

Listings observed (all published 2026-10-05, all MULTI-SOURCE)

Organization (as listed)SectorCountry
dd-automation.chTechnologyCZ
stuecheli.chRetail & E-CommerceCH
bwi-bau.deProfessional ServicesDE
halservice.itProfessional ServicesIT
grundens.comRetail & E-CommerceUS
t-systems.comTechnologyDE
anwo.clNot FoundCL
duhaas.skOtherSK
ikhasas.comNot FoundKE
sterrer.netTechnologyNL

Sector targeting

Technology (3), Professional Services (2), and Retail & E-Commerce (2) dominate the wave, with three listings lacking sector classification. This is consistent with SAFEPAY's opportunistic-but-weighted model: mid-market technology and services firms with high data value and, frequently, weaker segmentation than large enterprises.

Geographic concentration

Seven of ten listings are European (CZ, CH, DE ×2, IT, SK, NL), with outlier listings in the US, Chile, and Kenya. The Central European clustering in a single-day wave suggests either a coordinated access broker supply of regional credentials or a deliberate regional campaign cycle.

Victim profile

With the notable exception of the t-systems.com claim, the listed organizations skew toward small-to-mid-market (estimated $5M–$250M revenue based on sector norms) — the classic SAFEPAY sweet spot: large enough to pay, small enough to lack 24/7 detection coverage.

Posting cadence

All 10 listings carry the same publication date (2026-10-05). A synchronized single-day dump of 10 victims is an escalation pattern — it maximizes media pressure, signals pipeline depth to future victims, and is often used after a quiet period to reassert brand relevance in the extortion market.

CVE exposure hypothesis (sector-level, not victim-attributed)

We have no evidence linking any specific CVE to any specific listing above. However, SAFEPAY's documented preference for edge-device exploitation makes the following actively exploited vulnerabilities (CISA KEV, confirmed ransomware use) priority patch candidates for organizations matching this campaign's victim profile:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (KEV 2026-06-08): direct match to VPN/gateway initial access patterns.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password (KEV 2026-07-29): firewall management plane takeover.
  • CVE-2026-59310 — VMware vCenter path traversal (KEV 2026-08-18): hypervisor-layer access enabling mass encryption — highly relevant given SAFEPAY's virtualization targeting.
  • CVE-2026-63077 — JetBrains TeamCity deserialization (KEV 2026-08-05): build-server compromise; relevant to the Technology-sector weighting of this wave.
  • CVE-2026-48027 — Nx Console embedded malicious code (KEV 2026-05-27): developer-tooling supply-chain exposure.

Treat these as hypothesized exposure paths for the sector, not confirmed vectors for any named organization.

Detection Engineering

Sigma Rules

YAML
---
title: SAFEPAY - Suspicious VPN/Firewall Authentication Anomaly (Edge Device Initial Access)
id: 7f3a1c2e-9b41-4d2a-8e5f-safepay0001
status: experimental
description: Detects anomalous authentication patterns against VPN/firewall edge devices consistent with SAFEPAY initial access via compromised or brute-forced edge credentials, including logins from new geographies followed by immediate internal admin activity.
author: Security Arsenal Threat Intelligence
references:
  - https://securityarsenal.com/darkside
logsource:
  category: authentication
  product: firewall
detection:
  selection_success:
    action: success
    logon_type|contains:
      - vpn
      - sslvpn
      - ike
  filter_business_hours:
    src_ip|cidr:
      - '10.0.0.0/8'
      - '192.168.0.0/16'
      - '172.16.0.0/12'
  condition: selection_success and not filter_business_hours
falsepositives:
  - Legitimate remote workforce VPN usage
level: medium
tags:
  - attack.initial_access
  - attack.t1133
  - attack.t1078
date: 2026/10/06
---
title: SAFEPAY - Pre-Encryption Staging (PsExec/WMI Lateral Movement + VSS Deletion Chain)
id: 7f3a1c2e-9b41-4d2a-8e5f-safepay0002
status: experimental
description: Detects the compressed dwell-time execution chain associated with SAFEPAY pre-detonation activity - remote service creation via PsExec-style named pipes or WMI process creation followed within the same host window by Volume Shadow Copy deletion or backup tampering.
author: Security Arsenal Threat Intelligence
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\wbadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'recoveryenabled no'
      - 'delete catalog'
  selection_lateral_parent:
    ParentImage|endswith:
      - '\wmiprvse.exe'
      - '\services.exe'
      - '\PSEXESVC.exe'
      - '\rundll32.exe'
  condition: selection_vss and selection_lateral_parent
falsepositives:
  - Legitimate backup maintenance executed remotely by admin tooling
level: high
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1047
  - attack.impact
  - attack.t1490
date: 2026/10/06
---
title: SAFEPAY - Bulk Data Staging to Archive Before Exfiltration
id: 7f3a1c2e-9b41-4d2a-8e5f-safepay0003
status: experimental
description: Detects mass archive creation with 7z/rar/WinRAR targeting file shares and document stores, consistent with SAFEPAY double-extortion staging prior to exfiltration and encryption.
author: Security Arsenal Threat Intelligence
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_archiver:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\rar.exe'
      - '\winrar.exe'
  selection_args:
    CommandLine|contains:
      - ' a '
      - ' -v'
      - '\\'
  filter_known_backup:
    CommandLine|contains:
      - 'veeam'
      - 'backup_exec'
  condition: selection_archiver and selection_args and not filter_known_backup
falsepositives:
  - Administrative archive jobs; tune with approved archive tool paths
level: high
tags:
  - attack.collection
  - attack.t1560.001
  - attack.exfiltration
date: 2026/10/06

KQL — Microsoft Sentinel Hunt Query (pre-ransomware staging & lateral movement)

KQL — Microsoft Sentinel / Defender
// SAFEPAY hunt: compressed dwell-time staging chain
// Looks for: new scheduled tasks/services -> archive tooling -> VSS tampering on same host within 24h
let Window = 24h;
let SuspiciousTaskOrService =
    union isfuzzy=true
    (DeviceProcessEvents
     | where TimeGenerated > ago(Window)
     | where FileName =~ "schtasks.exe" and ProcessCommandLine has_any ("/create", "/change")
     | project HostTime1=TimeGenerated, DeviceName, AccountName, Evidence1=ProcessCommandLine),
    (DeviceEvents
     | where TimeGenerated > ago(Window)
     | where ActionType == "ServiceInstalled"
     | extend Evidence1 = tostring(parse_json(AdditionalFields).ServiceName)
     | project HostTime1=TimeGenerated, DeviceName, AccountName=InitiatingProcessAccountName, Evidence1);
let ArchiveStaging =
    DeviceProcessEvents
    | where TimeGenerated > ago(Window)
    | where FileName in~ ("7z.exe","7za.exe","rar.exe","winrar.exe")
    | project HostTime2=TimeGenerated, DeviceName, Evidence2=ProcessCommandLine;
let VSSTamper =
    DeviceProcessEvents
    | where TimeGenerated > ago(Window)
    | where (FileName =~ "vssadmin.exe" and ProcessCommandLine has "delete shadows")
       or (FileName =~ "bcdedit.exe" and ProcessCommandLine has "recoveryenabled")
       or (FileName =~ "wbadmin.exe" and ProcessCommandLine has "delete catalog")
    | project HostTime3=TimeGenerated, DeviceName, Evidence3=ProcessCommandLine;
SuspiciousTaskOrService
| join kind=inner ArchiveStaging on DeviceName
| join kind=inner VSSTamper on DeviceName
| where HostTime2 between (HostTime1 .. HostTime1+24h) and HostTime3 between (HostTime2 .. HostTime2+24h)
| project DeviceName, AccountName, HostTime1, Evidence1, HostTime2, Evidence2, HostTime3, Evidence3
| order by HostTime1 asc;

PowerShell — Rapid Triage Script (edge exposure + 7-day persistence sweep + VSS health)

PowerShell
# SAFEPAY rapid-response triage - run elevated on suspect hosts / via fleet tooling
# 1) Exposed RDP check  2) Scheduled tasks added in last 7 days  3) VSS health & recent deletions

Write-Host "=== [1] RDP Exposure Check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) {
    $fw = Get-NetFirewallRule -DisplayGroup "Remote Desktop" | Where-Object Enabled -eq 'True'
    Write-Warning "RDP LISTENING. Enabled firewall rules: $($fw.Count). Verify NLA + gateway-only exposure."
    Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' |
        Select-Object UserAuthentication, SecurityLayer
} else { Write-Host "RDP not listening locally." -ForegroundColor Green }

Write-Host "=== [2] Scheduled Tasks Created/Modified in Last 7 Days ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
    $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
    $reg = (Get-Item "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree$($_.TaskPath)$($_.TaskName)" -ErrorAction SilentlyContinue)
    if ($reg) {
        $lw = $reg.LastWriteTime
        if ($lw -gt (Get-Date).AddDays(-7)) {
            [PSCustomObject]@{ Task="$($_.TaskPath)$($_.TaskName)"; Modified=$lw; Author=$_.Author; State=$_.State }
        }
    }
} | Format-Table -AutoSize

Write-Host "=== [3] Volume Shadow Copy Health ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) { Write-Warning "NO shadow copies present - possible anti-recovery tampering (T1490)." }
else { $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table -AutoSize }

Write-Host "=== [4] Recent Service Installs (7045 events, 7 days) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, @{n='Service';e={$_.Properties[0].Value}}, @{n='Binary';e={$_.Properties[1].Value}} |
    Format-Table -AutoSize

Incident Response Priorities (SAFEPAY playbook)

T-minus detection checklist (before encryption fires)

Given SAFEPAY's short dwell time (24h–5 days), treat any two of the following as a likely pre-detonation state and escalate immediately:

  1. New VPN/firewall admin session from an unfamiliar ASN or geography
  2. PsExec-style service creation or WMI-spawned processes on servers the account has never touched
  3. Archive tooling (7z/rar) executing against file shares, especially with volume-splitting flags
  4. vssadmin delete shadows, bcdedit recoveryenabled no, or backup catalog deletion
  5. New scheduled tasks or services created within the last 7 days outside change windows
  6. EDR tampering attempts, event log clearing, or security service stop events

Critical assets this gang prioritizes for exfiltration

  • Finance/HR data stores (payroll, banking, PII) — highest extortion leverage
  • File shares and document management systems (bulk archive staging)
  • Email archives of executives and legal counsel
  • Backup infrastructure credentials/catalogs (to disable recovery before detonation)
  • For technology-sector victims: source code repositories and build servers (consistent with TeamCity-class exposure)

Containment actions, ordered by urgency

  1. Isolate, don't power off — network-quarantine affected hosts to preserve memory artifacts; SAFEPAY tooling often lives in memory
  2. Disable the suspected access path — force-reset all VPN/firewall local and AD credentials touched since earliest suspicious auth; revoke sessions
  3. Protect backups — take backup infrastructure offline from the production network; verify immutable/offline copies exist before anything else
  4. Block egress — deny unsanctioned outbound transfer (rclone, MEGA, unknown TLS endpoints) at the proxy/firewall; double extortion dies without exfil
  5. Hunt laterally before re-enabling — run the KQL chain query fleet-wide; assume at least one additional foothold
  6. Engage IR retainers and legal/comms early — SAFEPAY's short negotiation clocks punish delayed mobilization

Hardening Recommendations

Immediate (24 hours)

  • Patch or mitigate CVE-2026-50751 (Check Point gateway), CVE-2026-20316 (Cisco FMC), and CVE-2026-59310 (vCenter) — these map directly to SAFEPAY's known entry and mass-encryption patterns
  • Enforce phishing-resistant MFA on all VPN/remote access; audit and disable dormant VPN accounts
  • Block macro execution from internet-sourced Office documents (Mark-of-the-Web policy)
  • Deploy the Sigma rules above to your SIEM and enable the KQL query as a scheduled analytics rule
  • Verify shadow copies exist and backups are immutable; alert on any vssadmin delete execution

Short-term (2 weeks)

  • Remove direct RDP exposure entirely — place all remote administration behind a hardened gateway/jump host with JIT access
  • Segment backup infrastructure and hypervisor management planes onto isolated networks with separate credentials; vCenter compromise is SAFEPAY's force multiplier
  • Implement egress filtering with TLS inspection for bulk-transfer tooling (rclone, WinSCP to unknown destinations)
  • Deploy application control (WDAC/AppLocker) blocking unauthorized archive tools and LOLBins on servers
  • Establish deception — canary files on file shares and honey credentials to catch staging activity within SAFEPAY's compressed dwell window
  • Contract-test your IR retainer activation path; with 24-hour dwell times, procurement delays are fatal

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.