Cenesco Data Breach

Alleged

Ransomware claim involving Cenesco.

Published: Jul 20, 2026 SafePay
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Cenesco
Industry
Business Services
Threat Actor
SafePay
Date of Incident
Jul 20, 2026

Executive Summary

Cenesco, a company based in Germany, has been listed as a victim on the SafePay ransomware group’s dark web portal, published on July 20, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company’s specific sector is not classified in our source dataset, so no industry label is asserted here. Cenesco is one of a large batch of German organisations SafePay surfaced on its portal in this period. In the 60 days prior to this listing, SafePay has claimed 36 other victims across its leak portal. The group has shown a strong targeting pattern in the business services, manufacturing, and technology sectors. Geographically, its victims are heavily concentrated in Germany, with smaller clusters in Japan, Canada, and the United States. Other recent SafePay listings that overlap with Cenesco’s German footprint include Mende Grundbesitz, Ströbel Gruppe, TimeTEX, and LBB Treuhand. Cenesco fits SafePay’s pronounced German concentration during this window, part of a visible cluster of DE-based listings that dominated the group’s recent activity.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the cenesco.de domain. The sample contained roughly seven employee credentials on organisation-owned systems and about three corporate identities appearing on third-party services. Notably, the high-value endpoints included what appear to be internal infrastructure hosts (an internal datacenter/admin endpoint and an enterprise-resource host) carrying corporate administrative credentials, alongside Microsoft identity endpoints (live.com sign-in and a Microsoft B2C portal). The dominant profile was corporate intrusion risk, and the freshness window was long — records ran from early 2024 through July 2026, with an administrative account recurring across both internal hosts and Microsoft identity services. That combination of admin-level credentials on internal infrastructure plus long unrotated persistence is the more concerning end of what we see in these correlations. For ransomware groups such as SafePay, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to authenticate against Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by SafePay to gain entry, the presence of administrative credentials on internal infrastructure endpoints is consistent with the kill chain typically observed for this class of incident. CTI teams should treat the exposed accounts — particularly the recurring admin identity — as candidate access paths and prioritise immediate password rotation, session revocation, MFA enforcement, and forensic review of the affected internal hosts.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.