Incident response · SafePay ransomware
Hit by SafePay ransomware? The encryption is often shallower than it looks.
SafePay has been among the more active operations against Australian businesses, and it is built for speed rather than thoroughness. Its operators can set how deeply it encrypts each file, and they routinely choose shallow. On a large database or virtual disk, that leaves most of the data physically intact, and recoverable without paying.
Recognise it
How to confirm it is SafePay.
Before anything else, keep the encrypted files and every ransom note exactly where they are. They identify the strain, and they are often the raw material a recovery works from.
- File extension
- .safepay appended to encrypted files
- Ransom note
- readme_safepay.txt, dropped in affected folders, pointing to a Tor negotiation and leak site
- First seen
- Around September to November 2024; a fast riser through 2025 and 2026
- Typical entry
- Valid credentials on VPN gateways and RDP, often bought from access brokers or brute-forced, rather than a software exploit
Behaviour
What SafePay does to your systems.
Encryption depth is a setting
SafePay builds expose a flag that controls how much of each file is encrypted, and operators can set it to a small percentage of blocks. It finishes before defences react, and it leaves the rest of the file untouched on disk.
Runs as a DLL through trusted binaries
Commonly executed via regsvr32 or rundll32 rather than as an obvious executable, which is part of why it slips past controls that only watch for unfamiliar programs.
Shadow copies and recovery deleted
Volume shadow copies are removed and boot recovery options are modified, so the easy restore paths are gone before you notice.
Security and backup tools terminated
Antivirus and backup agent processes are killed and Windows Defender is disabled using trusted system binaries, frequently before encryption starts.
Double extortion
Data is taken before the files are locked, and publication on the leak site is used as the second lever. The claim about what was taken still needs verifying rather than accepting.
Centralised, not a franchise
SafePay has been assessed as a closed group rather than a broad affiliate programme, which tends to make its tradecraft more consistent from victim to victim, and more predictable to work against.
The honest answer
Can SafePay-encrypted files be recovered?
Often, and sometimes substantially. The whole point of SafePay's adjustable encryption depth is that encrypting everything is slow. When an operator dials it down, only a fraction of each large file's blocks are scrambled and the remainder sits on disk exactly as it was. Databases, virtual machine disks, backups and archives are large, structured files, so the untouched blocks can be located, carved out and rebuilt into something usable without any key.
The honest limits. Small files are usually encrypted end to end, because encrypting a small file costs the attacker nothing, and those are generally a loss without backups. There is no public decryptor for current SafePay builds, so nobody can promise a clean unlock. Check nomoreransom.org, then plan on the recoverable-data route rather than a decryption key.
The measurement is quick. A sample of encrypted files and their sizes tells us how deep the encryption actually went, and therefore how much is realistically recoverable, usually within hours. Keep every encrypted file and note, and do not let anyone re-image the affected machines before that assessment.
Common questions
SafePay, in plain terms.
Mid-incident and need a straight answer? Call 1300 004 766. A person answers, 24 hours a day.
What is the .safepay file extension?
Files renamed with a .safepay extension have been encrypted by the SafePay ransomware operation, active since around late 2024 and among the groups repeatedly hitting Australian businesses. The ransom note is usually readme_safepay.txt. Keep the encrypted files and the note: they identify the exact build and are often the raw material a recovery works from.
Can .safepay files be decrypted for free?
Not with any public tool for current builds. SafePay uses strong encryption on the parts of the file it does encrypt, so breaking it is not a realistic path. Check nomoreransom.org in case your incident involves something older, but the realistic routes are clean backups, snapshots, and recovering the data SafePay never encrypted in the first place.
Can SafePay-encrypted files be recovered without paying?
Often, at least partly. SafePay's operators can configure it to encrypt only a small share of each file's data blocks so the attack finishes quickly. On large files that leaves most of the content intact and recoverable by locating and rebuilding the untouched structures, with no key involved. It is a measured recovery effort with real limits, not a guarantee, and small files encrypted in full will not come back this way.
SafePay got in through our VPN. What does that mean for the response?
It means credentials, not a software bug, are the likely root cause, so the response has to include identity as well as the files. Assume the account used is compromised and any others that share its password are too: rotate credentials, revoke active sessions, and get multi-factor authentication onto remote access before you restore anything, or you invite the same entry a second time.
What should we do in the first hour?
Isolate the affected machines but leave them powered on, keep every encrypted file and ransom note, take surviving backups offline before anything else can reach them, and write down what happened when. Do not rebuild, do not run cleanup tools over the evidence, and do not pay in a panic. Our First-Response Guide covers this on one printable page, and 1300 004 766 is answered around the clock.
Not SafePay?
The extension on your files names the strain.
If the note or extension does not match what is on this page, one of these may fit. If none of them do, call anyway: the strain shapes the recovery, but identifying it is our job, not yours.
.akira
Akira →
Consistently among the most active strains in Australia. Partial encryption by design.
random extension
Qilin →
The most active operation of 2026. Every victim gets a unique file extension.
.inc
INC Ransom →
Subject of a 2026 ACSC joint advisory. Heavy targeting of Australian healthcare.
.fog / .flocked
Fog →
Education-focused, enters via VPN credentials, attacks backups first.
.dragonforce_encrypted
DragonForce →
Full, partial or header-only per file. Dedicated ESXi builds hit whole virtual estates.
Or start from ransomware recovery, which covers the method whatever the strain turns out to be.
Right now
The first hours decide what can be saved.
Isolate the machines, keep the encrypted files, take backups offline, and call before anything gets rebuilt. Australian incident response, answered by a real person.