SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data. Known victims: 462 2 ransom note(s) on file
Objectives
Executive Summary
SafePay is a medium-sophistication criminal threat actor specializing in ransomware operations. Known for its rapid growth and internal management of all operations, SafePay has targeted over 462 victims globally across various sectors. Its primary motivations include financial gain through ransomware activities.
Goals & Targeting
SafePay's strategic objectives are centered around financial gain through ransomware operations. The group targets organizations across multiple sectors, with a particular focus on entities that possess valuable data or services that can be disrupted for monetary gain. Its victims include both small and large businesses, reflecting an opportunistic approach to maximizing profit from each attack. By avoiding the RaaS model, SafePay retains control over its operations, allowing it to adapt quickly to defensive measures and maximize its attack success rate.
Enhanced Description
SafePay emerged as a significant ransomware operation in September 2024, quickly rising to prominence by managing its own infrastructure and avoiding the Ransomware-as-a-Service (RaaS) model. By mid-2025, SafePay had already claimed over 300 victims worldwide, with one of its earliest and most notable attacks being against a UK-based telematics firm, Microlise, from which it stole 1.2 TB of sensitive data. The group's operational independence has allowed it to maintain a high level of autonomy, enabling rapid proliferation and adaptability in its attack campaigns. SafePay's victims span various industries, including critical infrastructure, healthcare, and commercial sectors, reflecting its broad targeting strategy.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
SafePay has demonstrated a highly active and aggressive campaign pattern, with a rapid increase in the number of victims shortly after its emergence. The group's ability to independently manage its operations has allowed it to maintain a high operational tempo, frequently targeting new victims across different regions and industries. Notable campaigns include attacks on critical infrastructure, healthcare providers, and commercial entities. SafePay's use of internal tools and lack of affiliations with known RaaS groups make its campaigns distinct but challenging to attribute.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data regarding SafePay's operational details is high, given its active campaign history and numerous victims. However, specific technical details about its tools and infrastructure remain limited, which introduces some uncertainty in accurately identifying all associated IOCs.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
110
Campaigns
0
IOCs
0
Observed Data
0
Tactics