SafePay

SafePay — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

SafePayConfidence: High

Ransomware

Motivation: Financial

5Attributed Breaches Circulating
HighAttribution Confidence
RansomwareActor Type

Overview

Concentrated heavily on North American victims after appearing in late 2024, using LockBit 3.0-derived tooling and double extortion. Possibly a closed group rather than classic open RaaS; targets MSPs, SMBs, and enterprises.

Tactics, Targeting & TTPs

Model: possibly closed group rather than classic open RaaS. Targeting: MSPs, SMBs, and enterprises.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation