White Paper
THREAT PROFILE: SafePay Ransomware
SafePay is a ransomware group first identified in 2024 that operates as a private cybercriminal organization rather than a traditional ransomware-as-a-service platform. The group employs a double-extortion strategy, encrypting victims’ systems while also stealing sensitive data and threatening to publish the information on a data leak site if ransom demands are not met. SafePay has primarily targeted organizations in the industrial and manufacturing sectors, with many victims headquartered in North America. This threat profile examines the group’s operations, attack methods, known tools, industry and geographic targets, associations with other ransomware groups such as BlackSuit, and observed behaviors in Windows environments. The report also uses frameworks such as the Diamond Model, kill
