SafePay is a financially motivated ransomware group first observed in late 2024. Microsoft Security Intelligence describes an operation that conducts intrusions and negotiations internally rather than openly distributing its malware through a conventional affiliate program. Public victim claims continued into 2026, including a claim involving the Harrison County Commission in West Virginia.
SafePay’s malware checks for Russian and Ukrainian language settings, but that behavior does not establish where its operators are located or who directs them. No reviewed authoritative source publicly identifies the members or connects the group to a government.
Activity and targeting
Microsoft reported a concentration of activity involving organizations in the United States, Germany, the United Kingdom, Australia and Canada, with victims across manufacturing, construction, health care, retail and professional services. It also identified managed service providers as especially consequential targets because one compromise may expose downstream customers. These patterns describe reported cases and should not be treated as an exclusive victim profile.
Check Point Research ranked SafePay as the most prevalent ransomware group in its May 2025 dataset and said the operation had listed more than 200 organizations by June 2025. Leak-site totals are actor claims rather than a count of independently verified intrusions.
Methods and operational characteristics
SafePay combines data theft, file encryption and threats to publish stolen information. Microsoft reported that the group may call victims directly and operates a leak site for publication pressure. Its analyzed encryptor appends the .safepay extension, supports partial encryption to accelerate impact and shows substantial similarities to LockBit while also containing deliberate modifications. Code resemblance does not by itself prove shared operators.
An NCC Group incident-response investigation documented initial access through a misconfigured FortiGate virtual private network policy and weak credentials, followed by domain administrator access, ScreenConnect persistence, a QDoor backdoor, credential-access activity, Remote Desktop Protocol and server-message-block movement, and batch-driven ransomware deployment. Those findings describe one investigated intrusion, not a fixed playbook for every SafePay case.
What type of group is it?
SafePay is best classified as a centralized ransomware group conducting financially motivated double extortion. Microsoft and Check Point reporting distinguish it from an openly recruited ransomware-as-a-service program, although the absence of a public affiliate program does not reveal the operation’s internal staffing or partnerships. The reviewed evidence does not support a confirmed alias, predecessor, geographic attribution or state relationship.