Quick Summary
AllegedExecutive Summary
Bio-Strath AG, a Swiss company operating in the healthcare and life sciences sector, has been listed as a victim by the Safepay ransomware group on September 28, 2026. SOCRadar’s Dark Web Monitoring service identified this listing on Safepay’s portal. The company, which develops and distributes health products for clinical and consumer markets, may be targeted due to its role in the sensitive healthcare industry, making it a potential target for data extortion. The Safepay ransomware group has claimed approximately 40 victims over the past 60 days. Switzerland is identified as their second most frequently targeted country. Bio-Strath AG’s listing marks the fourth Swiss victim within this recent timeframe, following LFG Holding, Manno, and Reichenau. This consistent targeting of Swiss organizations, particularly those in the healthcare sector, suggests a pattern rather than isolated incidents. This pattern also includes other organizations such as Triniti Caring, Recovery Cafe, and Palmetto Eye Institute, further indicating Safepay’s focus on Switzerland and healthcare-adjacent targets.
Technical Analysis
The domain bio-strath[.]com was queried against SOCRadar’s stealer-log telemetry data. The query returned no records. However, it is important to note that this absence of evidence does not confirm that the organization is unaffected. The scope of the query may not encompass all potential access vectors, such as credentials associated with clinical platforms or personal email aliases that might be used by employees. Therefore, the null result is inconclusive regarding the presence or absence of compromised credentials. The lack of stealer-log records does not rule out a potential compromise. Infostealer malware often harvests credentials from various sources, including web browsers and other applications. These credentials can then be used for initial access into corporate networks, leading to ransomware deployment. While this specific query did not yield direct evidence of compromised credentials for Bio-Strath AG, the possibility remains that credentials could exist under alternate corporate domains, utilize personal email aliases, or reside in data feeds not covered by this specific scan. Recommended Action Forced credential rotation for bio-strath[.]com accounts is advised. Additionally, Multi-Factor Authentication (MFA) should be enforced on all remote access and email accounts. Swiss life sciences organizations, in general, should consider this listing, along with others from Switzerland such as Manno, LFG Holding, and Reichenau, as a shared threat indicator that requires heightened sector-wide awareness and proactive security measures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.