Skip to main content

Operator dossier

unsafe is a ransomware operator currently active on public leak sites. Darkfield has indexed 23 public victims claimed by this operator between December 21, 2022 and September 12, 2026. The "unsafe" ransomware group is a relatively new threat actor that emerged in December 2022, operating with primarily financial motivations through ransomware deployment and extortion schemes. Based on limited public documentation, the group's origin and specific affiliations remain unclear, though their operational patterns suggest they function as an independent ransomware operation rather than a established Ransomware-as-a-Service model. With 14 documented victims since their emergence, the group has demonstrated a focused targeting approach, primarily concentrating their attacks on manufacturing organizations, transportation and logistics companies, and government entities across the United States, Switzerland, and France. Their attack methodology and specific technical capabilities have not been extensively documented by major security research organizations such as CISA, FBI, or Mandiant, limiting detailed analysis of their initial access vectors, encryption methods, or data exfiltration practices. No major high-profile campaigns or significant law enforcement actions have been publicly reported against this group, likely due to their relatively recent emergence and smaller scale of operations compared to more established ransomware families. Current intelligence suggests the group remains active as of available reporting, though their limited public footprint makes definitive status assessment challenging without additional threat intelligence sources.

Most-targeted sectors

Most-affected countries

Recent disclosures by unsafe

Most recent 22 of 23 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for unsafe

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status changes from active to dormant when no new disclosure appears for 60 days. Without a disclosure date, activity is unknown. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

unsafe

23 victims indexed · first seen 4 years ago · last activity 1 day ago

23
Victims indexed
#175 of 399 tracked operators
3y 9m
Active period
Dec 2022 → Sep 2026
3
Countries hit
top US · 2

At a glance

Status
inactive
First seen
4 years ago
Last activity
1 day ago
Onion sites
1 known endpoint
Primary sector
Manufacturing · 1 hits

About

The "unsafe" ransomware group is a relatively new threat actor that emerged in December 2022, operating with primarily financial motivations through ransomware deployment and extortion schemes. Based on limited public documentation, the group's origin and specific affiliations remain unclear, though their operational patterns suggest they function as an independent ransomware operation rather than a established Ransomware-as-a-Service model. With 14 documented victims since their emergence, the group has demonstrated a focused targeting approach, primarily concentrating their attacks on manufacturing organizations, transportation and logistics companies, and government entities across the United States, Switzerland, and France. Their attack methodology and specific technical capabilities have not been extensively documented by major security research organizations such as CISA, FBI, or Mandiant, limiting detailed analysis of their initial access vectors, encryption methods, or data exfiltration practices. No major high-profile campaigns or significant law enforcement actions have been publicly reported against this group, likely due to their relatively recent emergence and smaller scale of operations compared to more established ransomware families. Current intelligence suggests the group remains active as of available reporting, though their limited public footprint makes definitive status assessment challenging without additional threat intelligence sources.

References

1 link

External sources curated by the MISP threat-intel community.

Timeline

4 months
2022-12-01T00:00:00+00:00 · 82023-04-01T00:00:00+00:00 · 22023-06-01T00:00:00+00:00 · 12024-01-01T00:00:00+00:00 · 3
2022-12-01T00:00:00+00:002024-01-01T00:00:00+00:00

Top countries

🇺🇸 United States
2
🇨🇭 Switzerland
1
🇫🇷 France
1

Top sectors

Manufacturing
1
Transportation/Logistics
1
Government
1

MITRE ATT&CK

4 techniques · 3 tactics

Tactics

Initial AccessExecutionImpact

Techniques

  • T1566Phishing
  • T1190Exploit Public-Facing Application
  • T1059Command and Scripting Interpreter
  • T1486Data Encrypted for Impact

Recent victims

  • Loading recent victims

Onion infrastructure

1 known
  • http://unsafeipw6wbkzzmj7yqp7bz6j7ivzynggmwxsm6u2wwfmfqrxqrrhyd.onion

Source

Updated 1 day ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time unsafe posts a victim.

Add unsafe to your watchlist — Pro pings you within 5 minutes of any new unsafe leak-site post, Telegram callout, or affiliate-rebrand inference.