Ransomware victim disclosure
← All victimsDeventer Group (Overijssel)
Claimed by Safepay · listed 32 minutes ago
Status timeline
- ListedOct 2, 2026
Current state: Listed for ransom
At a glance
- Group
- Safepay
- Status
- Listed for ransom
- Country
- Netherlands
- Sector
- Business Services
- Listed on leak site
- Oct 2, 2026
What the group claims
The group is headquartered in Deventer, Overijssel, and brings together several specialized business units operating in areas such as career services.
The leak post
captured from the group's site# SafePay ransomware has never provided and does not provide the RaaS The group provides a broad range of construction and infrastructure services to public and private clients in Rhineland-Palatinate, Saarland, neighboring … The company was established in 2015 and operates primarily in the wholesale and retail market for electrical household appliances. Its … The company focuses on designing technical systems for industrial customers, combining engineering expertise with process optimization, automation and energy-efficient production … The company's registered business activities include thermal treatment of metals, organic and electrolytic coatings, and the manufacture and commercialization of … The company is headquartered in Samut Prakan Province and has more than five decades of experience in the surface-finishing industry. … The official website, manno.ch, provides residents, businesses and visitors with information about municipal administration, public services, local regulations, infrastructure, cultural … The property operates under the international Holiday Inn brand of IHG Hotels & Resorts. The hotel provides 134 guest rooms, … The group is headquartered in Deve…
Screenshot of the leak post

Sources
Source
Indexed 32 minutes agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

