TimeTEX Data Breach

Alleged

Ransomware claim involving TimeTEX

Published: Jul 20, 2026 SafePay
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
TimeTEX
Industry
Business Services
Threat Actor
SafePay
Date of Incident
Jul 20, 2026

Executive Summary

TimeTEX, a business services company based in Germany, has been listed as a victim on the SafePay ransomware group’s dark web portal, with the listing published on July 20, 2026. This information was identified through SOCRadar’s Dark Web Monitoring service. The organization operates in the business services sector, which is one of the most frequently targeted industries by SafePay in recent weeks. TimeTEX is part of a notable cohort of German businesses listed by the group during this period. In the 60 days preceding this listing, SafePay claimed 36 other victims on its leak portal. The group consistently targets the business services, manufacturing, and technology sectors. Geographically, its victims are predominantly located in Germany, with smaller numbers in Japan, Canada, and the United States. Recent SafePay victims with similar profiles to TimeTEX, including those in the business services sector and in Germany, include Mende Grundbesitz, A.C. Small & Maxwell, LBB Treuhand, and Cenesco. Consequently, TimeTEX aligns closely with SafePay’s dominant targeting pattern within the German business services segment during the observed timeframe.

Technical Analysis

Initial access correlation against SOCRadar’s stealer-log telemetry revealed a significant exposure for the timetex.de domain. However, the nature of this exposure requires careful consideration. Out of approximately 25 records observed in the sample, the majority, around 21, consisted of consumer-facing accounts using personal email addresses (Gmail, Yahoo, Outlook, etc.) to authenticate to timetex.de. This pattern is more indicative of customer or external user credentials rather than employee access. A single record exhibited a potential corporate signal, but this could not be definitively confirmed as an internal account. No credentials were found associated with identity providers, VPNs, or mail infrastructure. The observed data primarily points towards customer account takeover and supplier risk, rather than a direct corporate intrusion. The observed credentials had a broad freshness window, spanning from late 2024 to mid-July 2026. For ransomware groups like SafePay, credentials harvested by infostealers represent a well-documented vector for initial access. Threat actors and initial access brokers often source fresh logs from underground marketplaces, validate corporate credentials, and use them to gain access to platforms such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. In this instance, the stealer-log evidence leans towards customer credentials rather than successfully validated employee access, suggesting it does not clearly indicate an infostealer-driven corporate foothold and does not confirm SafePay’s entry method. Cybersecurity intelligence teams should interpret this as a signal of customer exposure and potential account takeover, necessitating customer notification and monitoring for account takeovers. Continued monitoring for any records of corporate credentials would be advisable to alter the assessment of the initial access picture.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.