Back Securitybrief.Au SafePay ransomware zeroes in on smaller firms
Cyber intelligence firm Flare has released an analysis of the SafePay ransomware operation that indicates most victims never disclose attacks and that many of the most damaging incidents emerge only after affected companies collapse.
The study examines 500 verified victim records linked to SafePay's leak infrastructure on the dark web. The group, which appeared in late 2024 and expanded its activity through 2025, uses double extortion by stealing data and encrypting systems, then naming victims on Tor-based leak sites when negotiations stall.
Flare's researchers describe these leak portals as an informal disclosure layer that reveals incidents which do not appear in regulatory filings, corporate announcements or public reports.
The dataset suggests that SafePay, like other contemporary ransomware groups, operates a systematic extortion model aimed at organisations under regulatory and operational pressure rather than only those with the largest balance sheets.
SMBs in the crosshairs
More than 90% of identified SafePay victims are small or medium-sized businesses, according to the analysis. These organisations often generate enough revenue to make ransom payment feasible but lack the resilience to sustain prolonged outages in core systems.
More than half of the victims have estimated annual revenue below USD $10 million. Flare says this profile indicates a focus on firms that face immediate disruption risk and limited financial buffers.
Roughly two-thirds of the victims operate in service industries. These include professional services providers, healthcare organisations, retailers and industrial small and medium-sized enterprises. The report states that this pattern reflects deliberate selection of sectors that depend on continuous IT operations and handle sensitive data.
The findings align with warnings from regulators and law enforcement that public statistics substantially understate the true volume of ransomware incidents. Agencies including ENISA and the FBI have said that official notifications and company announcements represent only a portion of attacks.
Geographic concentration
Victims in the dataset cluster in North America and Western Europe. The United States accounts for 158 cases and Germany for 76. The report links this regional focus to the combination of high economic output and far-reaching data and security regulations.
These jurisdictions enforce regimes such as GDPR, NIS2, HIPAA and mandatory breach reporting that raise the stakes when data theft becomes public. Flare's analysis states that SafePay and similar groups exploit this environment by threatening disclosure that may trigger investigations, fines, litigation and reputational damage.
The study concludes that ransomware operators now look for what it describes as regulatory pressure points. These include organisations with extensive digital operations, obligations to protect personal or sensitive information, and limited in-house security resources.
Flare's researchers say that SafePay's leak records contain evidence that often never appears in official channels. This includes information on prior undisclosed ransomware incidents in supply chains, historical compromise of acquisition targets and attack patterns that insurers do not see through standard self-reported control assessments.
The company argues that this type of leak-site data provides an additional source of intelligence for risk assessments and due diligence exercises. It can show whether a supplier, partner or prospective target has previously been listed as a victim by a ransomware group even if no public breach notice exists.
Flare positions the SafePay dataset as an example of the insights that can emerge from systematic monitoring of dark web infrastructure associated with extortion groups.
Anthony Cooper, Company Director at Clarient Global, which is sharing the analysis, said the findings shed light on a shift in attacker priorities away from the largest global enterprises and towards smaller firms under regulatory and operational strain.
He added that the sector pattern and geographic clustering point to calculated selection of targets that face high consequences if stolen data appears online.
"Roughly two-thirds of victims are service-based organizations, including professional services, healthcare, retail, and industrial SMEs, evidence of deliberate economic targeting rather than opportunistic scanning," said Cooper.
Cooper said SafePay's focus on North America and Western Europe fits the group's emphasis on regulatory leverage over victims.
"Victims cluster in North America and Western Europe, with the U.S. (158 victims) and Germany (76 victims) standing out," said Cooper.
He linked this pattern directly to the compliance obligations in those markets.
"These are high-GDP, high-regulation regions, where laws like GDPR, NIS2, HIPAA, and breach-notification requirements dramatically raise the cost of public exposure, which ransomware groups actively exploit," said Cooper.
Cooper said the revenue profile of the affected companies reflects attackers' focus on entities that are financially viable but structurally vulnerable.
"More than half of victims have estimated annual revenue under $10M, painting a picture of companies large enough to pay, but small enough to panic," said Cooper.
Clarient Global and Flare plan further work on leak-site intelligence and its application for organisations that assess third-party risk, negotiate cyber insurance and conduct mergers and acquisitions due diligence.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
