LFG Holding Data Breach

Alleged

Ransomware claim involving LFG Holding

Published: Sep 28, 2026 SafePay
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
LFG Holding
Industry
Financial Services
Threat Actor
SafePay
Date of Incident
Sep 28, 2026

Executive Summary

Safepay ransomware has listed LFG Holding (lfgholding[.]com) as a victim on September 28, 2026. This Swiss holding company, with its diversified business interests, has a broad credential surface due to potentially separate IT infrastructures, identity providers, and remote-access systems across its subsidiaries. A single compromised credential at the holding company level could provide access across the entire portfolio. SOCRadar’s Dark Web Monitoring identified this listing. Analyzing Safepay’s activity over the past 60 days reveals a total of 40 victims. The group’s sector distribution is dominated by Manufacturing (11 out of 41 victims), followed by Agriculture and Food Production, and other industries. Geographically, the United States remains the primary target country, with Switzerland ranking second and Spain third. LFG Holding’s listing as the second most targeted Swiss entity within this 60-day period, alongside three other Swiss entities (Manno, Reichenau, and Hanan-Hov), suggests a concentrated campaign targeting Switzerland, potentially indicating active supply from Swiss-based Initial Access Brokers or a deliberate focus on the Swiss market by the threat actor.

Technical Analysis

A query for stealer-log records associated with the domain lfgholding[.]com yielded no results within the sampled dataset. However, this absence of evidence does not confirm that the organization is unaffected. The scope of this query was limited to the primary domain and did not include personal email aliases, third-party financial platforms, or credentials associated with subsidiary domains. Given LFG Holding’s structure as a diversified holding entity, the primary domain query likely captures only a fraction of the potential attack surface. The nature of holding companies, where each subsidiary may operate independently with its own IT environment, presents a complex exposure profile. Compromised credentials, even if not found on the main corporate domain, could exist on subsidiary domains, internal network segments, or through personal email aliases used for corporate access. The Safepay ransomware group’s targeting patterns, which include a significant number of manufacturing and other industrial entities, combined with their geographical focus, indicates a need for vigilance. The pattern of four Swiss Safepay listings within a 60-day period is a significant indicator that warrants broader attention beyond individual entity monitoring. Security teams in Switzerland, particularly those managing holding companies and public institutions, should consider this a shared-threat indicator. It is recommended that these organizations conduct expanded credential audits across their entire domain portfolio, review all remote access points, and ensure robust multi-factor authentication is implemented and enforced. Continued monitoring of dark web and stealer-log feeds for any signs of credential exposure related to LFG Holding or its subsidiaries is also advised.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.