SafePay Ransomware Breach Exposes Business Training Data

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
BusinessTraining.be
INDUSTRY
Business Services
LOCATION
Belgium
ATTACKER
SafePay
FIRST REPORTED
November 19, 2024

Ransomware Attack on Business Training by SafePay

Business Training, a prominent provider of IT and management training services in Belgium, has recently fallen victim to a ransomware attack orchestrated by the SafePay group. This incident, which occurred on November 21, resulted in the unauthorized access and subsequent leak of 80GB of sensitive data from the company's systems.

About Business Training

Business Training is a well-established entity in the business services sector, specializing in professional training and consulting services. With over 30 years of experience, the company is renowned for its comprehensive IT and management training programs. These programs are designed to be both accessible and flexible, ensuring participants gain practical skills applicable in their work environments. The organization is classified as a small to medium-sized enterprise (SME), which allows it to maintain a personalized approach to its services.

Vulnerabilities and Targeting

As a provider of IT training and consulting services, Business Training holds a significant amount of sensitive data, making it an attractive target for cybercriminals. The company's focus on technology rollout and system migrations may have inadvertently exposed vulnerabilities that SafePay exploited. The attack underscores the risks faced by organizations in the education and consulting sectors, where data security is paramount.

Attack Overview

The SafePay ransomware group, known for its double-extortion tactics, claimed responsibility for the attack. This method involves encrypting files and threatening to release stolen data unless a ransom is paid. In this case, SafePay managed to exfiltrate 80GB of data, which they subsequently leaked. The group typically gains access to networks through valid credentials, often acquired via VPN gateways, suggesting a sophisticated approach to infiltration.

About SafePay

SafePay is a relatively new player in the ransomware landscape, utilizing ransomware-as-a-service (RaaS) tactics and leveraging LockBit source code. The group distinguishes itself through its stealthy infiltration methods, avoiding common access points like Remote Desktop Protocol (RDP). SafePay's operations are characterized by a significant presence on the dark web, where they list victims and details of stolen data. Despite their lower profile compared to more notorious groups, SafePay's activities pose a significant threat to organizations across various sectors.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.