# Safepay

> As of 2026-07-27, Safepay is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning ransomware. Also known as SafePay Ransomware Group. ATT&CK coverage spans 48 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1021.001 (Remote Desktop Protocol), T1021.002 (SMB/Windows Admin Shares), T1486 (Data Encrypted for Impact).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** RANSOMWARE
- **Also known as:** SafePay Ransomware Group
- **As of:** 2026-07-27

## ATT&CK techniques observed

48 techniques observed across 3 of 3 tracked threats. Tactics: Initial Access (7), Discovery (6), Execution (6), Credential Access (4), Impact (4), Lateral Movement (4).

- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 3 of 3 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 3 of 3 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 3 of 3 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 3 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 3 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1039](https://intel.threadlinqs.com/technique/T1039) Data from Network Shared Drive — Collection — observed in 2 of 3 tracked threats
- [T1048.003](https://intel.threadlinqs.com/technique/T1048.003) Exfiltration Over Unencrypted Non-C2 Protocol — Exfiltration — observed in 2 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 3 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 2 of 3 tracked threats
- [T1072](https://intel.threadlinqs.com/technique/T1072) Software Deployment Tools — Execution — observed in 2 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1078.002](https://intel.threadlinqs.com/technique/T1078.002) Domain Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 2 of 3 tracked threats
- [T1135](https://intel.threadlinqs.com/technique/T1135) Network Share Discovery — Discovery — observed in 2 of 3 tracked threats

## Tracked threats

- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — HIGH
- [Black Kite 2026 European Cyber Risk Report: Ransomware Surges 55.1% as Third-Party Supply Chains Become Europe's Primary Attack Path (Qilin-Led)](https://intel.threadlinqs.com/threat/TL-2026-0958) — HIGH
- [Conduent Safepay Ransomware Breach — 25M+ PII/PHI Records Exfiltrated from Gov/Healthcare BPO Provider, Double-Extortion Data Theft via VPN Credential Abuse](https://intel.threadlinqs.com/threat/TL-2026-0161) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Safepay
