Ransomware Group:  
Safepay



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | TTPs | Activity | Worldmap | Victims (55)


Sites

Favicon Title Available Last Visit FQDN Screenshot
SAFEPAY 🟢 2025-01-18 00:02:05.664572 nz4z6ruzcekriti5cjjiiylzvrmysyqwibxztk6voem4trtx7gstpjid.onion 📸
SAFEPAY 🔴 2025-01-11 19:17:27.113817 cqkrkmmivhakl3fwgxscurduu3znmroablt7jskxszkctixyseij5gad.onion N/A
None 🔴 2025-01-11 19:17:57.687167 nj5qix45sxnl4h4og6hcgwengg2oqloj3c2rhc6dpwiofx3jbivcs6qd.onion N/A

TTPs

Activity over time

Worldmap

55 Victims

US flag

gonzalesusd.net 

Company logo
Ransomware Group:

Discovery Date: 2025-01-18 00:38

Sector: Education
[AI generated] I'm sorry for the confusion but gonzalesusd.net is not a company. It's actually the domain for the Gonzales Unified School District in Gonzales, California, primarily responsible for all public education in the city. It incorporates various levels of education including elementary, middle, and high school. It works to create enriching, engaging environments for students, teachers and staff.

Victim:   |  Group: 
US flag

platinumcollision.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-16 22:14
Estimated Attack Date: 2024-01-09

Sector: Not Found
[AI generated] Platinum Collision is a reputed automotive repair company specializing in car body repair and paint services. They provide high-quality restorative solutions to vehicle owners, promising excellent craftsmanship, advanced equipment, and certified technicians. They ensure full collision repairs in line with vehicle manufacturer standards. Customer satisfaction, consistency in deliverance and commitment to quality makes Platinum Collision a preferred choice for many.

Victim:   |  Group: 
US flag

safecoastseafoods.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:47
Estimated Attack Date: 2025-01-04

[AI generated] Safecoast Seafoods is a premium seafood sourcing and distribution company. They are focused on delivering the highest quality fresh and frozen seafood to various markets. They partner with sustainable fisheries worldwide, ensuring they offer a wide variety of species. Their services include wholesale distribution, home delivery and even private labeling, meeting the needs of restaurants, markets, and individual consumers alike.

Victim:   |  Group: 
SG flag

greyform.sg 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:45

[AI generated] Greyform Pte Ltd is a Singapore-based construction company specialising in prefab construction methods. With a focus on sustainability and high-efficiency construction, Greyform uses innovative techniques to meet the demands of today's construction industry. Their services include the design, production, logistics and installation of prefabricated components for residential, commercial and civil engineering projects.

Victim:   |  Group: 
CO flag

proexequialesresurgir.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:43
Estimated Attack Date: 2024-12-26

Sector: Not Found
Inicio | Proexequiales Resurgi

Victim:   |  Group: 
NZ flag

bellandgraham.co.nz 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:40
Estimated Attack Date: 2024-12-22

Back in 1954, a man named Ray Kroc discovered a small burger restaurant in California, and wrote the first page of our history. From humble beginnings as a small restaurant, we're proud to have become one of the world's leading food service brands with more

Victim:   |  Group: 
SV flag

termopuerto.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:39

[AI generated] Termopuerto.com is a logistics company specializing in the integral control of perishable goods. With its operations based in Guatemala, the company ensures efficient and safe handling of products during transportation and storage. It provides advanced temperature-controlled solutions ideal for preserving the quality of goods like fruits, vegetables, and seafood among others. Its services include pre-cooling, packing, labeling, inventory management and customs services.

Victim:   |  Group: 
MX flag

equipo-postal.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:36
Estimated Attack Date: 2025-01-07

[AI generated] Equipo Postal is a Mexican company that specializes in logistics and delivery services. They offer comprehensive solutions for mail and parcel deliveries, e-commerce distribution, and personalized logistics strategies. With a focus on innovation, they utilise advanced technology to provide efficient and reliable services. Dedicated to customer satisfaction, Equipo Postal Implements custom solutions to meet individual business needs. All while remaining eco-friendly and sustainably focused.

Victim:   |  Group: 
MX flag

ddelta.com.mx 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 22:33

[AI generated] Ddelta.com.mx is a Mexico-based company that specializes in offering software solutions and automation services. Their products and services span across various industries including energy, mining, chemical, food and beverage, and more. They offer solutions that optimize processes, improve production efficiency, reduce operating costs and increase profitability. These include programming, instrumentation, electrical design, etc. The company prides itself on its customer-centric approach.

Victim:   |  Group: 
SG flag

royalinsignia.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:56
Estimated Attack Date: 2024-12-22

Revenue $6.5 Million

Victim:   |  Group: 
US flag

starkvillesd.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:56
Estimated Attack Date: 2024-12-20

Sector: Education
Revenue $9.1 Million

Victim:   |  Group: 
US flag

spiro.k12.ok.us 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:55

Sector: Education
Revenue $5 Million

Group: 
US flag

byronunionschooldistrict.us 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:55

Sector: Education
Revenue $19.3 Million

Victim:   |  Group: 
SG flag

multicoasia.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:53
Estimated Attack Date: 2024-12-13

Revenue $11.6 Million

Victim:   |  Group: 
AI flag

dprinvestments.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:52

Sector: Financial
Revenue $13 Million

Victim:   |  Group: 
SG flag

UPR.SG 

Company logo
Ransomware Group:

Discovery Date: 2024-12-29 23:51

Revenue $8.9 Million

Victim:   |  Group: 
SV flag

itca.edu.sv 

Company logo
Ransomware Group:

Discovery Date: 2024-12-25 13:28

Sector: Education
Revenue $56.5 Million

Victim:   |  Group: 
AE flag

etplaw.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-25 13:27

Revenue $5 Million

Victim:   |  Group: 
AU flag

muswellbrook.nsw.gov.au 

Company logo
Ransomware Group:

Discovery Date: 2024-12-14 02:27
Estimated Attack Date: 2024-12-03

Sector: Government
Soon

Victim:   |  Group: 
GB flag

cityofmarlow.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-11 23:13
Estimated Attack Date: 2024-11-27

Sector: Government
Revenue $5 Million

Victim:   |  Group: 
US flag

nbkenney.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-11 23:11
Estimated Attack Date: 2024-11-28

Revenue $5 Million

Victim:   |  Group: 
US flag

casaimports.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-06 03:29
Estimated Attack Date: 2024-11-16

Revenue $5 Million

Victim:   |  Group: 
CA flag

ktpartners.ca 

Company logo
Ransomware Group:

Discovery Date: 2024-12-06 03:27
Estimated Attack Date: 2024-11-18

Sector: Financial
Revenue $5 Million

Victim:   |  Group: 
US flag

elwood.k12.in.us 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 08:13

Sector: Education
Revenue $5 Million

Victim:   |  Group: 
US flag

scottelec.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 08:13

Revenue $19.6 Million

Victim:   |  Group: 
BM flag

helixbermuda.bm 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 08:11

Sector: Financial
Revenue $5 Million

Victim:   |  Group: 
AU flag

australianhearthealth.org.au 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 08:09

Sector: Healthcare
Revenue $7 Million

Victim:   |  Group: 
US flag

midlandtool.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-28 08:07

Revenue $126 Million

Victim:   |  Group: 
US flag

mdmcusa.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 00:57
Estimated Attack Date: 2024-11-08

Revenue $5 Million

Victim:   |  Group: 
US flag

titlenine.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-24 19:11
Estimated Attack Date: 2024-11-02

Revenue $60.8 Million

Victim:   |  Group: 
GB flag

www.microlise.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-20 23:31

Revenue $91.4 Million

Victim:   |  Group: 
AU flag

snowbrand.com.au 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:48
Estimated Attack Date: 2024-09-26

Revenue $9.5 Million

Victim:   |  Group: 
US flag

piburners.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:46
Estimated Attack Date: 2024-10-04

ZIP-156GB - Revenue $5 Million

Victim:   |  Group: 
NZ flag

tritonsourcing.co.nz 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:44
Estimated Attack Date: 2024-10-08

ZIP-10GB - Revenue $5 Million

Victim:   |  Group: 
IT flag

onnicar.it 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:42

ZIP-127GB - Revenue $23.2 Million

Victim:   |  Group: 
CA flag

kingswoodpark.ca 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:40
Estimated Attack Date: 2024-10-10

ZIP-55GB

Victim:   |  Group: 
US flag

incocommercial.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:38
Estimated Attack Date: 2024-10-17

ZIP-210GB - Revenue $5 Million

Victim:   |  Group: 
BE flag

euromedix.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:34
Estimated Attack Date: 2024-10-14

Sector: Healthcare
ZIP-105GB - Revenue $6.2 Million

Victim:   |  Group: 
BE flag

BusinessTraining.be 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:32

Sector: Education
ZIP-80GB - Revenue $16.3 Million

Victim:   |  Group: 
US flag

ccseniorservices 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:30

Sector: Healthcare
ZIP-50GB

Group: 
DE flag

ib-spieth.de 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:30
Estimated Attack Date: 2024-10-21

ZIP-415B - Revenue $5 Million

Victim:   |  Group: 
US flag

Safex.us 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:28

ZIP-70GB - Revenue $5,4 Million

Victim:   |  Group: 
US flag

millerservicecompany.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:26
Estimated Attack Date: 2024-10-25

ZIP-70GB

Victim:   |  Group: 
CA flag

mcauslan.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:24
Estimated Attack Date: 2024-10-27

ZIP-50GB - Revenue $16.1 Million

Victim:   |  Group: 
BB flag

stats.gov.bb 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:21
Estimated Attack Date: 2024-10-29

Sector: Government
ZIP-330GB - Revenue $14.5 Million

Victim:   |  Group: 
US flag

smartdimensions 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-10-29

Sector: Not Found
ZIP-18GB - Revenue $<5 Million

Victim:   |  Group: 
US flag

westwood 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19

Sector: Not Found
ZIP-50GB - Revenue $8.1 Million

Victim:   |  Group: 
US flag

threadfxinc/bluedogmerch 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-10-18

ZIP-70GB - Revenue $10.7 Million

Victim:   |  Group: 
CH flag

Pronatec 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-10-06

Revenue $5 Million

Victim:   |  Group: 
IL flag

Gilazo 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-09-25

Sector: Not Found
Revenue $5 Million

Victim:   |  Group: 
AR flag

OMINT 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-09-27

Sector: Healthcare
Revenue $540.7 Million

Victim:   |  Group: 
JP flag

NKCE Japan 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-09-26

Sector: Not Found
[AI generated] NKCE Japan is a company known for its expertise in engineering and manufacturing, specializing in precision components and advanced technological solutions. It serves various industries, providing high-quality products and innovative services. NKCE Japan is committed to excellence and customer satisfaction, leveraging cutting-edge technology and skilled craftsmanship to meet diverse client needs.

Victim:   |  Group: 
GB flag

Richmond Hill Primary Academy 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-09-20

Sector: Education
[AI generated] Richmond Hill Primary Academy is an educational institution focused on providing a nurturing and dynamic learning environment for children. It emphasizes academic excellence, personal growth, and community engagement. The academy offers a broad curriculum designed to foster creativity, critical thinking, and a love for learning, supported by a dedicated team of educators and staff.

Victim:   |  Group: 
AR flag

Active Cosmetic 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-09-17

Revenue $26.7 Million

Victim:   |  Group: 
IE flag

O'mara 

Company logo
Ransomware Group:

Discovery Date: 2024-11-19 22:19
Estimated Attack Date: 2024-08-26

Sector: Not Found
Revenue $5.7 Million

Victim:   |  Group: