SafePay Ransomware Disrupts Platinum Collision Operations
Ransomware Attack on Platinum Collision by SafePay
On January 16, 2025, Platinum Collision, a prominent auto body repair company, became the latest victim of a ransomware attack by the cybercriminal group SafePay. This incident disrupted the company's operations, affecting its ability to deliver essential services to its clientele.
About Platinum Collision
Platinum Collision is a reputable auto body repair center known for its comprehensive services, including collision repair, paintless dent repair, and windshield repair. The company operates multiple locations across the United States, with a workforce estimated between 11-50 employees. Platinum Collision distinguishes itself in the industry through its commitment to high-quality repairs, certified technicians, and exceptional customer service. Their use of advanced repair technologies and computerized systems underscores their dedication to restoring vehicles to their pre-accident condition.
Vulnerabilities and Attack Overview
The ransomware attack exposed vulnerabilities within Platinum Collision's cybersecurity infrastructure. SafePay, known for its sophisticated ransomware-as-a-service operations, utilized advanced encryption techniques to lock the company's systems, demanding a ransom for the decryption key. The attack highlighted the need for enhanced cybersecurity measures, as the company's reliance on computerized systems for damage assessment and repair tracking made it an attractive target for cybercriminals.
SafePay Ransomware Group
SafePay is a relatively new player in the ransomware landscape, employing a double-extortion strategy to pressure victims into paying ransoms. The group is known for using LockBit source code and has claimed responsibility for multiple attacks across various sectors. SafePay's modus operandi involves gaining access to victim networks through valid credentials, often acquired via VPN gateways. Their stealthy approach and use of a Tor-based leak site for listing victims and stolen data distinguish them from other ransomware groups.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!