Unsafeleak is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 14 public victims claimed by this operator between December 21, 2022 and January 14, 2024. Unsafeleak is a relatively new ransomware group that emerged in December 2022, operating with primarily financial motivations and targeting organizations across developed nations. The group has claimed 14 victims to date, with their operations concentrated in the United States, France, and Switzerland, showing a preference for attacking manufacturing companies, government entities, educational institutions, and transportation/logistics organizations. Due to the limited public documentation available from major threat intelligence sources, specific details about Unsafeleak's country of origin, operational structure, attack methodologies, and technical capabilities remain largely unknown to security researchers. Given the group's recent emergence and relatively small victim count, there have been no widely reported major campaigns or high-profile attacks that have garnered significant attention from law enforcement agencies or cybersecurity firms. The current operational status of Unsafeleak is unclear, as the group's low profile and limited public reporting make it difficult to determine whether they remain active, have ceased operations, or have potentially rebranded under a different name.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.