Quick Summary
AllegedExecutive Summary
Caritas Koblenz, a healthcare organization in Germany, was listed as a victim by the SafePay ransomware group on July 6, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. The SafePay group has been actively targeting organizations, with a notable pattern of victimizing entities in the business services, construction, and technology sectors, primarily in Germany, Japan, and the United Kingdom. While healthcare is not their most frequent target, Caritas Koblenz’s location in Germany aligns with the group’s geographical preference.
Technical Analysis
SOCRadar’s investigation into initial access vectors for Caritas Koblenz did not return positive results in their stealer-log telemetry database for the `caritas-koblenz.de` domain. However, this absence of evidence does not confirm the organization’s security. It is possible that credentials were harvested under different domains, personal email aliases, or that the data was used and rotated before SOCRadar’s indexed sample was captured. Ransomware groups like SafePay commonly use credentials sourced from stealer logs as an initial access method into corporate networks, exploiting these to access systems like Microsoft 365 or VPNs before deploying ransomware. CTI teams are advised to continue monitoring and implement proactive credential hygiene measures rather than relying on a null query as a sign of clearance.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.