Quick Summary
AllegedExecutive Summary
Manno, a public-sector organization located in the Canton of Ticino, Switzerland, has been listed as a victim by the Safepay ransomware group. The listing was observed on September 28, 2026, according to SOCRadar’s Dark Web Monitoring. As a provider of civic and administrative services, Manno’s operations and data could be attractive targets for ransomware groups due to the critical nature of public services and the potential for disruption. Over the past 60 days, Safepay has claimed approximately 40 victims. Switzerland has emerged as a significant target for the group, ranking second in geographic targeting during this period. Notable recent victims in Switzerland include Children’s Memorial Hospital, LFG Holding, Reichenau, and Hanan-Hov. The inclusion of Manno aligns with Safepay’s ongoing pattern of targeting Swiss institutions across various sectors, indicating a sustained and active campaign against public entities in the region.
Technical Analysis
SOCRadar’s investigation queried the domain manno[.]ch against its stealer-log telemetry. The query returned no matching records. However, it is important to note that credentials for Swiss public administration organizations often route through government-shared platforms that may fall outside the scope of this specific dataset. Therefore, the absence of evidence in this particular telemetry does not rule out a potential compromise. The typical pathway for infostealer malware involves harvesting credentials, which are then validated against access points such as cantonal VPNs or Microsoft 365 tenants. Once access is confirmed, ransomware is deployed. This known modus operandi suggests that Swiss public institutions, like Manno, are facing a documented and live threat from Safepay, particularly through credential compromise. Given the potential for credential exposure and the known tactics of the Safepay group, it is recommended that Manno implement forced credential rotation and enforce Multi-Factor Authentication (MFA) across all access points. Expanded monitoring for manno[.]ch and any affiliated cantonal administrative platforms is also advised to detect any suspicious activity.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.