Skip to content
Deep Dive high msp-it-servicesprofessional-servicesmanufacturingHealthcareretail

SafePay: How a LockBit Code Derivative Became 2026's Most Active Ransomware Group

Executive Summary

SafePay is, by leak-site tracking, the most active ransomware operation in the world as of mid-2026. It didn’t get there through a viral affiliate program or a headline-grabbing attack on critical infrastructure. It got there by taking leaked LockBit source code, stripping out the affiliate layer, and running a lean, centrally controlled operation that hits managed service providers, VPN gateways, and mid-market businesses at a pace few other groups have sustained. The group’s July 2025 attack on IT distributor Ingram Micro put it on the radar of enterprise security teams; the twelve months since have shown that incident was not an outlier but a preview of its operating tempo. By early August 2026, SafePay had publicly claimed 537 victims on its leak site, with dozens more added monthly — a volume that puts it ahead of established names like Qilin and RansomHub on several tracking platforms.

Background and Profile

SafePay first surfaced in late 2024 with a small handful of claimed victims — fewer than two dozen by the end of that year, according to Infosecurity Magazine’s reporting on the group’s early activity. That low profile didn’t last. Through the first half of 2025 the group’s claimed-victim count climbed sharply, and researchers at Picus Security and Halcyon began flagging it as a group worth tracking closely well before it became a mainstream name.

What distinguishes SafePay structurally from most of the ransomware groups Adversary Wire has profiled is its operating model. The dominant pattern across the ecosystem since LockBit’s decline and ALPHV/BlackCat’s exit scam has been ransomware-as-a-service: a core developer team licenses an encryptor to a roster of affiliates, who handle their own initial access and intrusion in exchange for a cut of the ransom. SafePay does not appear to run this way. Reporting from Acronis’s Threat Research Unit and multiple incident responders describes a centralized operation in which the same team develops the encryptor, gains initial access, conducts the intrusion, deploys the payload, and negotiates with victims — with no public affiliate recruitment, no advertised RaaS program, and no leak-site “partner” branding of the kind LockBit and RansomHub used to attract talent.

That centralization has a technical fingerprint. Analysts examining SafePay’s encryptor binaries have identified substantial code overlap with the LockBit 3.0 (LockBit Black) builder that leaked publicly in 2022, along with elements that echo ALPHV/BlackCat and INC Ransom tooling. The most plausible read, shared across several of the vendor writeups cited here, is that SafePay’s operators built their toolkit on top of the leaked LockBit source rather than writing an encryptor from scratch — a now-familiar pattern in a ransomware landscape where leaked builders have outlived the groups that lost control of them.

Publicly Reported Tactics and Incidents

Initial access. CyberPress and Acronis both document SafePay’s primary entry vectors as internet-facing RDP and VPN infrastructure, frequently reached via valid but compromised credentials rather than novel exploitation. This is a low-cost, high-yield approach: it doesn’t require the group to burn a zero-day, and it scales easily against the long tail of small and mid-sized organizations that make up most of SafePay’s victim list. Channel Insider’s reporting on the Ingram Micro intrusion points to the company’s GlobalProtect VPN platform as the likely foothold, consistent with the group’s broader pattern of targeting remote-access appliances.

Speed. Multiple sources, including Halcyon and ransomware-tracking outlet ransomware.live, describe SafePay completing the full attack chain — from initial access to encryption — in under 24 hours in some documented intrusions. That is fast relative to the two-to-four-week dwell times reported for more patient operators like INC Ransom, and it suggests SafePay prioritizes throughput over the kind of extended reconnaissance that maximizes leverage on a single high-value target.

Execution. Acronis’s technical writeup describes a fairly conventional but well-executed playbook once inside a network: disabling endpoint protection, deleting volume shadow copies, and clearing event logs to blunt detection and slow incident response, followed by double-extortion encryption using a hybrid AES/RSA scheme. Acronis estimates an average of roughly 111GB of data exfiltrated per victim before encryption — enough to sustain credible leak-site pressure without the multi-terabyte hauls some larger operators pursue.

The Ingram Micro attack (July 2025). SafePay’s defining public incident to date remains its intrusion into Ingram Micro, one of the world’s largest IT distributors. The attack disrupted the company’s AI-powered Xvantage ordering platform and halted online ordering and product shipments for nearly a week, a disruption that rippled downstream to thousands of value-added resellers and MSPs who depend on Ingram Micro for procurement. The incident functioned as a case study in supply-chain blast radius: a single successful intrusion against an IT distributor produced operational impact across an entire partner ecosystem, without SafePay needing to individually compromise any of those downstream organizations.

Sustained volume through 2026. SafePay’s pace has not slowed since. Cybersecurity News reported the group claiming more than 73 victim organizations in a single month during mid-2026, and by early August the group’s leak site listed 537 total claimed victims, including 27 in the preceding 30 days. Recent claimed victims documented in trade press span a wide geographic and sector range, from Stroebel Gruppe in Germany to AC Small Maxwell & Co, a century-old Australian accounting and advisory firm — illustrative of the group’s preference for opportunistic, broad-spectrum targeting over sector-specific campaigns.

Targeted Sectors

SafePay does not appear to select victims by industry vertical so much as by exploitable exposure. That said, reporting converges on a few consistent patterns:

  • Managed service providers and IT resellers — the Ingram Micro attack is the clearest example, and Acronis’s research frames MSP targeting as a deliberate force multiplier: compromising an MSP with broad remote access into client environments can, in principle, extend an attacker’s reach across dozens of downstream organizations from a single foothold.
  • Small and mid-sized businesses — the bulk of SafePay’s claimed victims by volume fall into this category, consistent with its emphasis on speed and scale over big-game hunting.
  • Professional and advisory services — accounting, legal, and consulting firms appear repeatedly in claimed-victim listings, likely reflecting both the sensitivity of client data these firms hold and generally thinner security staffing relative to their data exposure.
  • Manufacturing, retail, and healthcare — represented in victim listings, though without the concentrated focus seen in groups like Anubis or Interlock that have built their extortion playbooks specifically around healthcare disruption.
  • Geography — primary concentration in the United States and Western Europe, per Acronis, with the group’s Australian and German victims underscoring that its targeting is not limited to any single region.

Historical Timeline

PeriodDevelopment
Late 2024SafePay leak site appears; fewer than 20 claimed victims by year-end
Q1–Q2 2025Claimed-victim count accelerates sharply; researchers begin sustained tracking
July 2025Attack on Ingram Micro disrupts the Xvantage platform and downstream reseller/MSP ordering for nearly a week
Mid-to-late 2025Group surpasses 200 claimed victims; security vendors (Fortinet, Halcyon, Picus) publish dedicated threat profiles
Early 2026Claimed-victim total passes 400; group identified among the most active operators tracked across leak-site monitoring platforms
Mid-2026SafePay overtakes Qilin in monthly claimed-victim volume, becoming the most active tracked ransomware group; single-month totals exceed 73 new victims
July 2026Claimed attack on AC Small Maxwell & Co (Australia); continued claims against European targets including Stroebel Gruppe (Germany)
August 2026Leak site lists 537 total claimed victims, including 27 in the preceding 30 days

What Defenders Should Take Away

SafePay’s rise underscores a few points that should reshape how security teams think about ransomware risk in 2026, independent of whether SafePay itself ever targets a given organization directly.

RDP and VPN exposure remains the path of least resistance. SafePay’s success is built almost entirely on compromised credentials against internet-facing remote access infrastructure, not novel exploitation. Multi-factor authentication on every VPN and RDP entry point, combined with monitoring for anomalous authentication patterns (impossible travel, off-hours logins, credential reuse across services), remains the single highest-leverage control against this class of attacker.

MSP relationships are a material third-party risk. Organizations that grant broad remote access to a managed service provider inherit that provider’s security posture as part of their own attack surface. Security teams should treat MSP access the same way they treat any other privileged third-party integration: least-privilege scoping, session monitoring, and contractual visibility into the MSP’s own security controls and incident history.

Fast attack chains compress the response window. With documented cases of sub-24-hour time-to-encryption, organizations cannot rely on manual triage processes calibrated for multi-week dwell times. Automated isolation of compromised hosts, tested backup restoration procedures, and pre-authorized incident response engagement are what separate a contained intrusion from a full-scale outage in this threat model.

Immutable, tested backups remain the most reliable recovery path. Given SafePay’s consistent deletion of shadow copies and disabling of endpoint protection prior to encryption, recovery capability has to live outside the blast radius of the compromised environment — offline or immutable backups that are regularly tested for restoration, not just retained.

Leaked builders keep old threats alive under new names. SafePay’s apparent basis in the leaked LockBit 3.0 builder is a reminder that source code leaks in this ecosystem don’t end a threat, they redistribute it. Defenders should expect detection signatures and behavioral baselines built around LockBit’s known TTPs to have partial, not complete, relevance against LockBit-derivative operators — validate detections against the specific variant rather than assuming legacy coverage holds.