Quick Summary
AllegedExecutive Summary
Knobel Bau, an organization operating in the construction sector in Germany, was identified as a victim of the SafePay ransomware group. The incident was published on SafePay’s dark web portal on July 6, 2026, and discovered via SOCRadar’s Dark Web Monitoring. This listing aligns with SafePay’s known targeting patterns, which heavily focus on German entities and the construction industry. Over the 60 days preceding this listing, SafePay claimed 33 other victims, with a significant concentration in Germany, Japan, and the United Kingdom.
Technical Analysis
SOCRadar’s analysis did not find direct evidence of knobel-bau.de in their stealer-log telemetry for the period prior to the listing. This absence does not confirm the absence of a compromise, as data exposures can occur via alternate domains, personal email accounts, or feeds not covered by the query. Ransomware groups like SafePay frequently leverage initial access gained through the purchase of stolen credentials from infostealer logs. These credentials are used to access corporate networks via platforms like Microsoft 365 or VPNs, preceding ransomware deployment. Therefore, CTI teams are advised to continue monitoring and maintain robust credential hygiene practices, rather than interpreting a null query as a sign of no compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.