Quick Summary
AllegedExecutive Summary
Hahn Airport, a transportation and logistics organization based in Germany, has been listed as a victim on the SafePay ransomware group’s dark web portal, published on July 6, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. SafePay has claimed 33 other victims in the 60 days prior to this listing, with a strong focus on the business services, construction, and technology sectors, particularly in Germany, Japan, and the United Kingdom.
Technical Analysis
Initial access correlation against SOCRadar’s stealer-log telemetry surfaced a notable exposure for the hahn-airport.de domain. The returned sample held 25 credential records, all tied to customer-facing subdomains (parking and training portals), with no corporate accounts present. The dominant profile observed is customer account takeover and supplier risk rather than direct workstation or employee compromise. Usernames were consumer email providers or generic booking handles, indicating credential reuse on public portals. Log dates ranged from late February to early July 2026. For ransomware groups like SafePay, infostealer-harvested credentials are a common initial access vector. However, the observed customer account records do not fit this corporate-access pattern, and the stealer-log evidence does not confirm that these credentials were used by SafePay. CTI teams are advised to expand queries to corporate identifiers and treat continued monitoring and credential-hygiene checks as the appropriate response.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.