Quick Summary
AllegedExecutive Summary
Lagege Pesca, an Italian company specializing in seafood production and distribution, operating under the domain lagegepesca[.]it, was identified on SafePay’s leak site on August 24, 2026. Italy, where Lagege Pesca is based, is a significant target region for SafePay. The agriculture and food production sector, to which Lagege Pesca belongs, has been experiencing increased ransomware activity, particularly in Southern Europe. This makes the company a potentially attractive target for such cybercriminal groups. In the 60 days preceding this listing, SafePay claimed responsibility for 39 victims. Their primary focus has been on the Manufacturing and Business Services sectors, with Germany, the United States, and Italy being their most frequently targeted countries. SafePay consistently targets companies within the food production and agriculture industries, aligning with their broader manufacturing victim base, especially in European markets. Past victims in the food production sector attributed to SafePay include Granja Rinya, Multiaqua, New-Point, and CPU AG.
Technical Analysis
SOCRadar’s investigation using stealer-log telemetry did not return any records associated with lagegepesca[.]it within the queried dataset. It is important to note that this dataset represents a paginated sample and does not encompass all active log feeds, alternate corporate domains, or credentials that might have been harvested using personal email aliases. Small and medium-sized businesses in Italy’s food sector often utilize multiple email domains for various operational units; therefore, a query focused on a single domain may not capture the complete credential exposure surface. The operational methodology of SafePay involves acquiring infostealer logs from underground marketplaces. These logs are then used to validate credentials and gain access to systems, often through Microsoft 365, VPNs, or remote-access portals, before deploying ransomware. For Lagege Pesca, an Italian seafood company with production and distribution activities, the potential attack surface likely includes both its internal IT infrastructure and logistics portals utilized by supply chain partners. Any externally facing portal that allows credential authentication represents a potential initial access vector. Given SafePay’s documented pattern of targeting the Italian food sector, prompt attention to credential hygiene for Lagege Pesca is critical.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.