SafePay Ransomware Disrupts City of Marlow Services

Incident Date: Dec 11, 2024

Attack Overview
VICTIM
City of Marlow
INDUSTRY
Government
LOCATION
USA
ATTACKER
SafePay
FIRST REPORTED
December 11, 2024

Ransomware Attack on City of Marlow: SafePay's Latest Target

The City of Marlow, a municipal authority in Oklahoma, has become the latest victim of the SafePay ransomware group. Known for its commitment to public safety, infrastructure management, and community engagement, Marlow serves as a hub for local governance and essential services. The city manages public safety through its police and fire departments, oversees infrastructure maintenance, and facilitates community engagement through various programs and events.

On December 13, 2024, it was discovered that SafePay had exfiltrated 80 GB of sensitive data from Marlow's systems. The attack has disrupted the city's digital infrastructure, rendering the official website inaccessible and affecting online payment services. This incident highlights the vulnerabilities faced by municipal entities, which often operate with limited cybersecurity resources, making them attractive targets for ransomware groups.

SafePay Ransomware Group: Modus Operandi and Distinction

SafePay is a relatively new player in the ransomware landscape, employing ransomware-as-a-service (RaaS) tactics and utilizing LockBit source code. The group is known for its double-extortion strategy, where they encrypt files and threaten to release stolen data if ransom demands are not met. SafePay distinguishes itself by maintaining a low profile on illicit forums and employing stealthy infiltration methods, often gaining access through valid credentials acquired via VPN gateways.

The group's dark web presence includes a Tor-based leak site where they list victims and provide details about stolen data. This operational security contributes to their lower profile compared to more notorious ransomware gangs, yet their impact remains significant, as evidenced by the attack on the City of Marlow.

Potential Vulnerabilities and Impact

The City of Marlow's reliance on digital infrastructure for service delivery and community engagement makes it vulnerable to cyber threats. Municipalities like Marlow often face challenges in maintaining robust cybersecurity defenses due to budget constraints and limited technical expertise. The SafePay attack underscores the need for enhanced cybersecurity measures to protect sensitive data and ensure the continuity of essential services.

As the city works to recover from the attack, the incident serves as a stark reminder of the growing threat posed by ransomware groups and the importance of proactive cybersecurity strategies for municipal entities.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.