Peruvian Bank Bisa Targeted by Safepay Ransomware Group: What We Know So Far

Listen to this Post

Featured Image

Ransomware Hits Peru: Introduction to the Incident

In a chilling development in the world of cybercrime, the notorious “Safepay” ransomware gang has claimed responsibility for breaching the digital defenses of Bisa, a financial institution in Peru. The revelation was shared by the ThreatMon Threat Intelligence Team, a cybersecurity group that monitors ransomware activity on the dark web. This attack, disclosed on July 22, 2025, shines a light once again on the growing vulnerability of financial institutions in Latin America—and raises questions about the preparedness of banks globally against cyber threats.

What Happened to Bisa Bank? 📌

According to the monitoring post shared by ThreatMon on X (formerly Twitter), the Safepay ransomware gang added bisa.com.pe, the official domain of the Peruvian bank Bisa, to its growing list of victims. The attack was recorded at 19:20:27 UTC+3 on July 22, 2025. Although no ransom demands or leaked data have been publicly disclosed at the time of writing, the inclusion of Bisa’s domain on the dark web is an ominous indicator that the attackers either have access to sensitive data or are in the final stages of extortion.

ThreatMon, known for tracking ransomware operations and their victims, flagged this activity through its threat intelligence infrastructure. Safepay, the threat actor responsible, has been involved in several ransomware incidents globally, often using double-extortion tactics—encrypting victims’ files while also threatening to leak sensitive data online unless payment is made.

The announcement did not include additional details such as the ransom amount, method of entry, or the specific data compromised. However, the act of naming Bisa publicly suggests negotiations may have failed, or the group is escalating pressure.

This attack places Bisa Bank under intense scrutiny from regulators, cybersecurity professionals, and the public, especially as cyberattacks on financial services continue to increase in frequency and severity.

🔍 What Undercode Say:

Safepay’s Tactics Are Evolving—And Dangerous

The attack on Bisa Bank reflects a broader trend we at Undercode have been observing throughout 2025: ransomware groups targeting financial institutions in Latin America with growing boldness. These attacks aren’t just about money—they’re about reputation, leverage, and geopolitics.

Why Bisa Was a Target

Bisa, although not a global giant, holds regional financial influence. Its digital infrastructure might lack some of the advanced protections seen in multinational banks, making it a ripe target. Smaller financial institutions often have weaker defenses but hold valuable customer data and financial records—perfect leverage for ransomware actors.

Safepay’s Modus Operandi

Undercode’s deep web monitoring has tracked Safepay as a mid-tier but rising ransomware group. Their tactics typically include:

Initial access via phishing or credential stuffing

Privilege escalation

Lateral movement inside systems

Data exfiltration before encryption

Double-extortion via data leak sites

Safepay’s targeting of Bisa aligns with their usual profile—financial firms with moderate visibility, likely to pay due to potential customer backlash.

A Wake-Up Call for Latin American Financial Sector

This incident reinforces an urgent need for banks in the region to:

Upgrade legacy cybersecurity infrastructure

Train employees to detect phishing and social engineering

Implement incident response plans

Share threat intelligence through regional cybersecurity alliances

It also underscores the importance of government-backed cyber resilience frameworks. Financial institutions are critical national infrastructure, and continued attacks could erode public trust in the entire banking system.

Could This Be the Beginning of a Broader Campaign?

There’s growing concern among analysts that this attack may not be isolated. Undercode analysts are seeing chatter that Safepay may be preparing to strike additional institutions across South America, potentially coordinating a wave of disruptions to coincide with political or economic instability.

Bisa might be just the first domino in a sequence meant to cause panic or extract millions in cryptocurrency.

✅ Fact Checker Results:

✅ Ransomware group Safepay has verifiably claimed Bisa (bisa.com.pe) as a victim on dark web leak portals.
✅ ThreatMon Threat Intelligence Team publicly confirmed the attack via their social monitoring.
✅ No public data leak or ransom amount has been confirmed yet, but visibility suggests escalating extortion tactics.

🔮 Prediction: What’s Next for Bisa and Safepay?

Bisa Bank is likely entering containment and remediation mode, working with forensic cybersecurity teams to determine the extent of the breach. If the attackers exfiltrated data, a public leak could occur within days or weeks, especially if ransom negotiations stall.

As for Safepay, their successful compromise of a regional bank may embolden them. We predict:

🚨 More financial targets across Latin America in Q3 and Q4 of 2025
⚠️ Government response may increase in the form of cyber sanctions or task forces
🛡️ Banks will invest heavily in endpoint protection, dark web monitoring, and ransomware incident training

Stay vigilant—this is just the beginning of a broader cyber conflict targeting the financial heartbeat of developing nations.

References:

Reported By: x.com
Extra Source Hub:
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin