Safepay

Active
SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
569 Victims
Nov 10, 2023 First Discovered
Sep 15, 2026 Last Discovered
1 Days Inactive
0% Infostealer
1/5 Sites Online
Known Locations (5)
SAFEPAY
cqkrkmmivhakl3fwgxscurduu3znmroablt7jskxszkctixyseij5gad.onion
nj5qix45sxnl4h4og6hcgwengg2oqloj3c2rhc6dpwiofx3jbivcs6qd.onion
SAFEPAY
j3dp6okmaklajrsk6zljl5sfa2vpui7j2w6cwmhmmqhab6frdfbphhid.onion
SAFEPAY
nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion
Safepay Blog
safepaypfxntwixwjrlcscft433ggemlhgkkdupi2ynhtcmvdgubmoyd.onion
Tools Used
DiscoveryEnum
Invoke-ShareFinder
Exfiltration
7-Zip, WinRAR
LOLBAS
CMSTPLUA, Regsvr32.exe, dllhost.exe
Intelligence
Victims (569)

Detailed victim list temporarily unavailable

This group has 569 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.