Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

ChatGPT launches Google Translate competitor

January 16, 2026

Bharat Forge wins Rs 300 Cr defence drone contracts from IAF

January 16, 2026

The Lagos-based startup making it simpler to simply accept crypto

January 16, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • ChatGPT launches Google Translate competitor
  • Bharat Forge wins Rs 300 Cr defence drone contracts from IAF
  • The Lagos-based startup making it simpler to simply accept crypto
  • ‘There is a expertise hole, however the true downside is mindset’, says tech professional
  • MAX raises $24 million after hitting profitability in Nigeria
  • Tallinn grasp plan focuses on human-centred setting
  • MassRobotics Declares fifth Cohort of Healthcare Robotics Startup Catalyst Program
  • After a month of no reply, NASA will attempt hailing its silent MAVEN Mars orbiter immediately
Friday, January 16
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - SafePay Ransomware: What You Want To Know
Cybersecurity & Digital Rights

SafePay Ransomware: What You Want To Know

NextTechBy NextTechJune 28, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
SafePay Ransomware: What You Want To Know
Share
Facebook Twitter LinkedIn Pinterest Email


What’s the SafePay ransomware?

SafePay is a comparatively new ransomware risk that was first noticed round September 2024. Like different ransomware, SafePay encrypts victims’ information in order that they can’t be accessed, after which calls for the fee of a cryptocurrency ransom for his or her restoration. As a part of a “double extortion” tactic, the hackers behind SafePay additionally steal knowledge from affected organisations and threaten to publish it on their darkish net leak web site if a ransom will not be paid.

What makes SafePay uncommon?

Most fashionable ransomware gangs function a Ransomware-as-a-Service (RaaS) mannequin, the place associates are allowed to deploy the ransomware in return for a share of the proceeds they handle to extort. Nevertheless, SafePay doesn’t function like this. As a substitute, it seems to not supply itself to associates, however as a substitute the identical group develops and deploys the ransomware themselves slightly than relying upon others. 

Certainly, a banner on SafePay’s darkish net leak web site says:

SAFEPAY RANSOMWARE HAS NEVER PROVIDED AND DOES NOT PROVIDE THE RAAS

Why would they not function as a ransomware-as-a-service mannequin? Aren’t they turning their again on plenty of money?

Whereas it’s true that SafePay could also be closing the door on affiliate revenue, it does supply the good thing about higher operational safety and tighter management of how its ransomware is used.

Fascinating. So, why is SafePay within the information?

A just lately revealed risk report launched by safety consultants at NCC Group revealed that SafePay was at present probably the most lively ransomware group. Within the month of Might 2025 alone, 70 ransomware assaults have been linked to Safepay, accounting for 18% of the whole.

 

In a sign of the ransomware group’s elevated exercise, this was the primary time that SafePay had appeared in NCC Group’s high 10 checklist of risk actors.

What has made SafePay so profitable so rapidly?

The reply to that query will not be clear, however it’s suspected that SafePay could also be carefully associated to different infamous ransomware teams, together with LockBit, BlackCat, and INC Ransomware.

In different phrases, the parents behind SafePay is probably not new to the scene?

Appropriate. If the hyperlinks to different infamous ransomware gangs are discovered to be true, it could imply that these are cybercriminals who’re skilled in extorting cash out of their victims, and have the assets to make a major affect.

Which corporations have been hit by SafePay?

UK telematics enterprise Microlise, which presents automobile monitoring companies to the likes of DHL and Serco, revealed that it had been hit by ransomware in October 2024, and was certainly one of SafePay’s first publicised victims after the theft of 1.2TB of knowledge. Different victims have included a North Carolina anatomic pathology lab, which was breached in January 2025 in an assault that noticed the theft of data associated to over 200,000 sufferers, together with names, birthdates, addresses, medical health insurance particulars, and medical therapy knowledge.

Isn’t any-one protected from being hit by SafePay ransomware?

Nicely, really, sure, some persons are. The SafePay ransomware is programmed to verify the language settings of the pc it’s working on, and if it spots the system is working any of the next languages, it’ll instantly cease working with out inflicting any harm: If the system language matches any specified languages, the malware will instantly terminate. A whole checklist of languages checked might be seen under:

  • Armenian
  • Azerbaijani (Cyrillic)
  • Belarusian
  • Georgian
  • Kazakh
  • Russian
  • Ukrainian

Why would the ransomware need to try this?

Two instantly causes bounce to thoughts. One is, for example, that the ransomware doesn’t need to depend – say – Russian companies amongst its unintended victims, in concern that native regulation enforcement businesses would possibly come after it.

Is sensible. What different cause might there be?

Nicely, perhaps the ransomware authors’ themselves run computer systems that are configured to make use of these languages. They might hardly need to grow to be unintended victims of SafePay themselves, would they?

I assume not. So, how can my enterprise shield itself from the SafePay ransomware? I do not suppose it could be sensible to vary the language settings of all our PCs to Russian.

SafePay is thought for breaking into organisations through the use of stolen VPN or RDP credentials. It has not been reported to have used phishing methods ceaselessly seen in lots of different ransomware assaults. Subsequently, organisations that fear they may be focused can be sensible to implement multi-factor authentication on all distant entry factors, disable unused RDP or VPN entry totally, and use IP allowlists or geofencing the place attainable. As well as, we advocate all corporations observe our normal recommendation for defending in opposition to ransomware assaults, which incorporates ideas akin to:

  • Making safe off-site backups.
  • Working up-to-date safety options and making certain that your computer systems are protected with the newest safety patches in opposition to vulnerabilities.
  • Utilizing hard-to-crack distinctive passwords to guard delicate knowledge and accounts, in addition to enabling multi-factor authentication.
  • Encrypting delicate knowledge wherever attainable.
  • Lowering the assault floor by disabling performance that your organization doesn’t want.
  • Educating and informing employees concerning the dangers and strategies utilized by cybercriminals to launch assaults and steal knowledge.

Editor’s Be aware: The opinions expressed on this and different visitor creator articles are solely these of the contributor and don’t essentially replicate these of Fortra.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Your Digital Footprint Can Lead Proper to Your Entrance Door

January 16, 2026

CrowdStrike to Purchase Seraphic Safety to Higher Safe Browsers

January 16, 2026

Is it time for web providers to undertake identification verification?

January 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

ChatGPT launches Google Translate competitor

By NextTechJanuary 16, 2026

OpenAI has lastly launched a brand new translation service for its chatbot, ChatGPT. The online…

Bharat Forge wins Rs 300 Cr defence drone contracts from IAF

January 16, 2026

The Lagos-based startup making it simpler to simply accept crypto

January 16, 2026
Top Trending

ChatGPT launches Google Translate competitor

By NextTechJanuary 16, 2026

OpenAI has lastly launched a brand new translation service for its chatbot,…

Bharat Forge wins Rs 300 Cr defence drone contracts from IAF

By NextTechJanuary 16, 2026

Bharat Forge’s aerospace division has gained contracts value roughly Rs 300 crore…

The Lagos-based startup making it simpler to simply accept crypto

By NextTechJanuary 16, 2026

Chidubem Ogbuefi, the Chief Govt Officer (CEO) and founding father of CoinCircuit,…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!