Sumperk Data Breach

Alleged

Safepay ransomware targets Czech municipality Sumperk

Published: Sep 28, 2026 SafePay
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Sumperk
Industry
Government
Threat Actor
SafePay
Date of Incident
Sep 28, 2026

Executive Summary

Sumperk, a municipality in the Olomouc Region of the Czech Republic, identified as providing civic services and public administration, has been listed as a victim by the Safepay ransomware group. The listing occurred on September 28, 2026, and was observed by SOCRadar’s Dark Web Monitoring. Public sector entities often have limited IT budgets, making them attractive targets for ransomware actors who rely on the pressure to restore essential services to incentivize payment. The primary risk for Sumperk, if the access is confirmed, involves significant operational disruption to its local government services. Safepay has claimed approximately 40 victims over the past 60 days, with a core focus on geographies including the US, Switzerland, and Spain. While the Czech Republic is not among their top three targeted countries, Safepay’s recent activities indicate a broadening sweep across Europe. Other entities recently listed by Safepay that share a public-sector or related profile include Stöcklin Küchen, La Concepcion, azn, and Holiday Inn Vilnius. This pattern suggests Safepay is actively expanding its reach across European borders without hesitation.

Technical Analysis

The domain sumperk[.]cz was queried against stealer-log telemetry data. The query returned no records. It is important to note that credentials for Czech public administration entities may be managed through government platforms that are not typically included in Western stealer-log datasets. Therefore, the absence of records in this specific dataset is inconclusive and does not rule out the possibility of a compromise. The nature of infostealer-harvested credentials can significantly support ransomware operations by providing initial access or facilitating lateral movement within a victim’s network. While no direct correlation was found in the stealer logs for Sumperk, the listing on the Safepay portal suggests a potential intrusion. Public municipalities, like Sumperk, often present a risk profile attractive to ransomware actors due to limited IT resources and the critical nature of their services, which can create pressure for prompt payment to restore operations. Given the listing, recommended actions for Sumperk include mandatory password rotation across all systems, immediate notification to the Czech National Cybersecurity Authority (NUKIB), and the enforcement of Multi-Factor Authentication (MFA) for all access to sumperk[.]cz systems. Continued monitoring of dark web and stealer-log feeds, even with initial null results, is also advisable, as credentials may exist under alternate domains or within datasets not yet queried.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.