Quick Summary
AllegedExecutive Summary
On September 28, 2026, the Safepay ransomware group listed Cromados, a Spanish industrial manufacturer operating via cromados[.]com, on their dark web portal. This listing was identified through SOCRadar’s Dark Web Monitoring. Cromados, which serves clients across the Iberian Peninsula, operates within the industrial manufacturing sector. This type of company, particularly those in mid-market European manufacturing, is a common target for ransomware and extortion groups due to its potential for operational disruption and the value of its data. Safepay has been actively pursuing a manufacturing campaign across multiple continents. In the past 60 days leading up to this listing, the group claimed 41 victims, with 11 of those being in the Manufacturing industry. Spain ranks among Safepay’s top three target countries, alongside the US and Switzerland. Cromados fits the group’s typical targeting profile based on both its sector and geographic location, aligning with Safepay’s strategy of systematically targeting mid-market European manufacturers. Other recent victims in the manufacturing sector include Auromex (Mexico), Neumerkel GmbH (Germany), Marlin HVAC, and McNish Steel.
Technical Analysis
SOCRadar’s investigation queried the domain cromados[.]com for associated stealer-log records. The query returned no results, indicating no directly identified credential compromise from this specific dataset for the queried domain. However, it is crucial to note that this absence of evidence does not confirm that the organization is unaffected. Credentials could exist under alternate corporate domains, be associated with personal email aliases, or reside in data feeds not covered by this specific query. Furthermore, any compromised credentials may have been used and subsequently rotated before their inclusion in the indexed datasets. Safepay typically gains initial access through compromised credentials obtained via infostealer logs, which are then used to access VPNs or remote-desktop portals. While the current query did not yield a direct hit for Cromados, this methodology highlights a potential intrusion path. The organization should consider continued dark web monitoring and proactive credential hygiene measures. This includes regular password rotation and a thorough review of multi-factor authentication configurations across all systems, especially for VPNs and remote access services, to mitigate risks associated with exposed credentials.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.