Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group Active in the last 30 days

Unsafe ransomware

19 victims listed on the Unsafe leak site across 7 countries. Most recent disclosure .

Victims
19
0.1% of all tracked
Countries
7
Most: United States
Sectors
7
Most: Technology
First seen
Jan 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Unsafe and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Who Unsafe is

A group which seems to recycle leak from other ransomware groups

Recorded activity

Disclosures attributed to Unsafe in this database run from January 2024 to September 2026, totalling 19 victims — 0.1% of everything tracked here. Unsafe has listed victims in 7 countries in this database, most often United States, followed by Canada and India. The sectors appearing most in its listings are Technology, Business Services, Manufacturing.

YARA detection rules

unsafe.yar
/*
unsafe ransomware
*/

rule unsafe_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.unsafe"
        description = "Detects unsafe ransomware ransom note or artifact"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $name1 = "unsafe" ascii nocase
        $name2 = "UNSAFE" ascii
        $onion  = "unsafe.onion" ascii nocase

    condition:
        any of them
}

Community-contributed rules for Unsafe, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Unsafe has disclosed 19 victims on its leak site, 0.1% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.

The group has listed organisations in 7 countries, most often in United States (7 victims), followed by Canada, India, Germany.

By industry, its listings concentrate in Technology, Business Services, Manufacturing — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Unsafe is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Unsafe victims 19

Organization Disclosed
kyyba.com
FIFinland
kyyba.com
FIFinland
voltgames.io
voltgames.io
geekybunch.com
USUnited States
watchops.com
USUnited States
watchops.com
USUnited States
amzur.com
BRBrazil
DECK APP TECHNOLOGIES PTE. LTD
INIndia
Presentations.AI
USUnited States
Constellation HomeBuilder Systems
USUnited States
Jiva Health
INIndia
CCR Solutions
CACanada
CCR Solutions
CACanada
Deutsche Bank
DEGermany
straightperformance.de
DEGermany
American International College
USUnited States
Hartl European Transport Company
CHSwitzerland
SPARTAN Light Metal Products
USUnited States

Frequently asked questions

What is Unsafe ransomware?

Unsafe is a ransomware threat group that has claimed 19 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Unsafe attacked?

Unsafe has claimed 19 victims in our database, representing 0.1% of all tracked ransomware attacks. The most targeted countries are United States, Canada, India, Germany.

Which countries does Unsafe target?

Unsafe has attacked organizations in 7 countries. The top targeted countries are: United States, Canada, India, Germany.

Which industries does Unsafe target?

Unsafe most frequently targets the Technology, Business Services, Manufacturing sectors based on victim disclosures in our database.

Is Unsafe still active?

Unsafe's most recent victim disclosure in our database was on September 21, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.