SafePay and Qilin Ransomware Claims Raise Fresh Alarms Over Italian and Romanian Institutions + Video

Listen to this Post

Featured Image

A New Wave of Ransomware Claims

The ransomware landscape rarely stays quiet for long. As organizations continue strengthening their defenses, extortion groups are constantly looking for new opportunities to pressure businesses, public institutions, universities, and other organizations into paying for stolen or encrypted data. Two new victim claims attributed to the SafePay and Qilin ransomware operations are now drawing attention after being published through threat-intelligence monitoring.

According to information attributed to the ThreatMon Threat Intelligence Team, SafePay has listed New Point (new-point.it) as a victim, while Qilin has reportedly added Universitatea de Vest Vasile Goldi din Arad, a Romanian university, to its claimed victim list.

The reports appeared on August 3–4, 2026, and were presented as ransomware activity detected through dark-web monitoring. However, it is important to understand the distinction between a ransomware group’s victim claim and a confirmed cyberattack. A listing on a leak site or intelligence feed can indicate that an organization has been targeted, but it does not automatically prove that attackers successfully compromised systems, stole data, encrypted infrastructure, or obtained sensitive information.

SafePay Claims New Point as a Victim

The first incident concerns New Point, identified through the domain new-point.it.

ThreatMon attributed the claim to the SafePay ransomware group and reported that the organization had been added to the group’s victim list. The activity was timestamped at approximately 00:11 UTC+3 on August 4, 2026.

The available information does not provide enough evidence to determine the exact attack method, the systems allegedly compromised, the amount of data involved, or whether encryption occurred.

That uncertainty matters because modern ransomware groups increasingly use data theft and extortion independently of encryption. An organization can therefore become a victim of an extortion campaign even when its internal systems remain operational.

Qilin Claims a Romanian University

The second claim is potentially more significant because it involves an educational institution.

ThreatMon reported that the Qilin ransomware group had added Universitatea de Vest Vasile Goldi din Arad to its alleged victim list. The university is located in Arad, Romania, and its digital infrastructure supports academic, administrative, communication, and institutional operations.

Universities can be particularly attractive targets because they often operate large and complex technology environments containing numerous user accounts, research systems, administrative databases, student information, employee records, and third-party services.

A successful compromise could therefore provide attackers with multiple avenues for extortion, even if only a portion of the organization’s infrastructure is ultimately affected.

Why Universities Remain Attractive Targets

Higher-education institutions have become increasingly complicated cybersecurity environments.

A modern university is not simply a collection of computers inside classrooms. It may operate cloud platforms, learning-management systems, research infrastructure, identity-management services, remote-access systems, email platforms, financial applications, student portals, laboratory networks, and numerous third-party integrations.

Every additional system creates another potential entry point.

Attackers understand this complexity. Rather than attempting to defeat a single heavily protected server, ransomware operators may search for weaker accounts, exposed remote services, vulnerable applications, stolen credentials, or poorly secured third-party connections.

Qilin’s Continued Visibility

Qilin has become one of the most recognizable names in the modern ransomware ecosystem.

The

The important lesson is that ransomware should no longer be viewed simply as a malicious program that encrypts files.

The threat is increasingly an end-to-end intrusion operation involving initial access, privilege escalation, lateral movement, data discovery, exfiltration, disruption, and psychological pressure.

SafePay Represents Another Extortion Threat

SafePay has also appeared repeatedly in ransomware monitoring, demonstrating how fragmented the modern ransomware ecosystem has become.

Instead of a small number of dominant groups controlling every stage of an operation, the ecosystem can involve multiple actors, affiliates, access brokers, malware developers, infrastructure operators, and extortion platforms.

This makes attribution more difficult.

A victim may know that its systems were compromised without immediately knowing which actor was responsible. Threat-intelligence teams may subsequently associate the incident with a ransomware operation based on infrastructure, leak-site activity, malware characteristics, or other indicators.

A Leak-Site Listing Is Not Proof by Itself

One of the most important details in these reports is the wording: the organizations were reportedly added as victims.

That distinction should remain central when discussing ransomware intelligence.

A ransomware group can make a claim without immediately providing independently verifiable evidence. In some cases, criminal groups exaggerate or fabricate claims to create pressure, attract attention, or strengthen their reputation within underground communities.

For that reason, a responsible security report should describe these incidents as claims or alleged attacks unless the affected organization, law-enforcement authorities, security researchers, or reliable forensic evidence confirms the breach.

The Human Cost Behind a Ransomware Listing

Behind every ransomware listing is a potentially disruptive event for real people.

For a university, an incident could interfere with students trying to access academic services, staff attempting to perform administrative tasks, researchers depending on digital resources, or faculty members managing teaching systems.

For a private company, the consequences could involve customer communication, financial operations, internal systems, supply chains, and business continuity.

The technical details may appear abstract on a dark-web monitoring dashboard, but the consequences can be very tangible.

Why Timing Matters

The reports surfaced within a short period, with the SafePay claim associated with August 4 and the Qilin claim appearing shortly afterward.

Two unrelated victim claims do not necessarily indicate a coordinated campaign.

Nevertheless, the timing illustrates something important: ransomware activity continues to move rapidly, and threat actors can maintain pressure against organizations across multiple countries and sectors simultaneously.

This is why security teams increasingly rely on continuous monitoring rather than occasional security assessments.

The Italian Connection

The SafePay claim involving a .it domain also highlights the continued international nature of ransomware.

Ransomware groups rarely restrict themselves to one country. Their infrastructure may be distributed across jurisdictions, their affiliates may operate from different regions, and their victims can be located almost anywhere.

An Italian organization can therefore be targeted by an international criminal ecosystem just as easily as a company in North America, Eastern Europe, or Asia.

The Romanian Connection

The Qilin claim demonstrates the same international pattern from another direction.

A Romanian educational institution appearing in ransomware intelligence reinforces the fact that public-sector and educational organizations remain part of the global ransomware threat landscape.

The geographic location of a victim does not necessarily determine the likelihood of attack. Instead, attackers often prioritize accessibility, valuable information, weak security controls, and the perceived ability of an organization to withstand prolonged operational disruption.

Data Theft Can Be More Dangerous Than Encryption

Encryption is highly visible.

Employees suddenly cannot access files. Servers stop functioning. Applications become unavailable. The organization immediately knows something is wrong.

Data theft can be considerably more difficult to detect.

Attackers may quietly search through databases, documents, email systems, backups, and file repositories before removing information from the environment. By the time the organization discovers the intrusion, sensitive material may already be outside its control.

This is why modern ransomware defense must focus on preventing unauthorized access and detecting abnormal data movement, not merely stopping encryption malware.

The Role of Threat Intelligence

Threat intelligence platforms can provide an important early warning system.

Monitoring ransomware infrastructure, underground forums, extortion websites, stolen credentials, malware indicators, and emerging victim claims can help defenders understand where threats are moving.

However, intelligence must be interpreted carefully.

A raw victim listing is a lead—not automatically a verified incident report.

Security teams should correlate these claims with endpoint telemetry, authentication logs, network activity, cloud access records, data-loss-prevention alerts, and forensic evidence.

What Organizations Should Check

Organizations mentioned in ransomware claims should immediately investigate whether there are signs of unauthorized access.

Security teams should review privileged-account activity, unusual authentication attempts, newly created accounts, suspicious remote-access sessions, abnormal administrative actions, unexpected outbound traffic, and unusual access to sensitive repositories.

They should also inspect endpoint and identity-management telemetry for signs of lateral movement.

The objective is not simply to determine whether ransomware was executed.

The larger question is whether an unauthorized actor gained persistent access to the organization’s environment.

Backups Are Still Essential

Reliable backups remain one of the strongest defenses against ransomware disruption.

But simply having backups is not enough.

Backups should be isolated from normal production credentials, protected against unauthorized deletion, monitored for suspicious changes, and regularly tested through actual restoration procedures.

An organization that discovers its backups were also compromised during an attack can lose one of its most important recovery mechanisms.

Identity Security Has Become Critical

Stolen credentials remain one of the most dangerous commodities in the cybercrime economy.

Strong passwords, phishing-resistant multifactor authentication, privileged-access management, conditional access controls, and rapid credential revocation can significantly reduce the opportunities available to attackers.

Security teams should pay particular attention to administrator accounts because compromise of a single highly privileged identity can dramatically accelerate an intrusion.

Universities Need Special Protection

Educational organizations should treat cybersecurity as part of institutional resilience rather than simply an IT concern.

Universities contain unusually diverse user populations. Students, professors, researchers, contractors, administrators, visiting academics, and external partners may all require different levels of access.

That complexity makes identity management difficult.

Segmenting networks and applications, enforcing least privilege, monitoring privileged access, and separating critical administrative systems from general-purpose networks can help reduce the blast radius of a compromise.

Ransomware Is Becoming a Business Continuity Problem

The greatest mistake organizations can make is treating ransomware purely as a malware problem.

It is also a business continuity problem.

If a critical application becomes unavailable for several days, the organization may face operational delays, financial losses, reputational damage, regulatory obligations, customer complaints, and difficult recovery decisions.

Cybersecurity planning therefore needs to include crisis management, communications, legal preparation, backup recovery, and executive decision-making.

The Psychology of Extortion

Ransomware is built around pressure.

Attackers want victims to believe that time is running out, that stolen data will soon be published, and that recovery will become increasingly expensive.

This psychological component is intentional.

Organizations that prepare incident-response procedures before an attack are better positioned to make decisions calmly rather than reacting under extreme pressure.

Why Verification Matters for the Public

The public should also be cautious when reading ransomware reports.

A dramatic headline saying an organization was “hacked” can create an impression of certainty that the underlying intelligence does not support.

In reality, there can be several stages between an attacker claiming a victim and a confirmed breach.

There may be an initial claim, followed by evidence, victim acknowledgment, forensic investigation, regulatory reporting, and eventually confirmation of what information was actually accessed.

Responsible cybersecurity reporting should preserve those distinctions.

Deep Analysis: What These Ransomware Claims Reveal

The Ransomware Economy Is Still Expanding

The SafePay and Qilin claims demonstrate how ransomware remains deeply embedded in the cybercrime economy.

Even when individual campaigns disappear, new groups, affiliates, and operational models can quickly replace them.

Victim Diversity Is a Warning Sign

Private companies are not the only targets.

Universities, healthcare providers, public institutions, manufacturers, retailers, and professional organizations can all become targets when attackers believe the potential reward justifies the effort.

Attackers Search for Weak Links

Cybercriminals do not necessarily need to defeat the strongest security control in an organization.

They may instead search for the weakest identity, outdated application, exposed service, vulnerable endpoint, or third-party connection.

One Compromised Account Can Change Everything

A single stolen credential can become the starting point for a much larger intrusion.

Once attackers obtain access, they can attempt privilege escalation and search for additional credentials.

Lateral Movement Remains Dangerous

Modern ransomware attacks often involve movement between systems before the final extortion phase.

Network segmentation can therefore be just as important as malware detection.

Data Exfiltration Changes the Equation

When sensitive information has been stolen, restoring systems does not necessarily end the incident.

The attacker may still possess confidential documents and use them as leverage.

Leak-Site Pressure Is Psychological

Extortion websites are designed to increase urgency.

Public countdowns, victim listings, alleged samples, and publication threats can all be used to pressure organizations.

Threat Intelligence Provides Early Signals

Monitoring underground activity can give defenders an opportunity to investigate before a ransomware incident becomes fully visible.

But intelligence must always be validated.

False Claims Are Possible

Criminal groups have incentives to exaggerate their success.

A victim listing should therefore never be treated as forensic proof without corroborating evidence.

Universities Have Valuable Data

Academic institutions can hold personal information, financial records, research data, intellectual property, and credentials.

That makes them attractive targets.

Research Networks Can Be Especially Complex

Universities often have decentralized technology environments.

Individual departments and laboratories may use different systems, applications, and security practices.

Third-Party Services Increase Exposure

Cloud platforms, learning systems, research tools, payment services, and external applications can create additional attack surfaces.

Remote Access Requires Continuous Monitoring

VPNs, remote desktops, administrative portals, and cloud authentication systems should be monitored for unusual behavior.

Multifactor Authentication Is Not Enough Alone

MFA dramatically improves security, but organizations still need monitoring, conditional access, endpoint protection, and identity controls.

Privileged Accounts Deserve Extra Attention

Administrative credentials can provide attackers with significantly greater control.

They should be tightly controlled and continuously monitored.

Backups Must Be Tested

A backup that has never been restored successfully is not a complete recovery strategy.

Organizations need regular recovery exercises.

Incident Response Should Be Preplanned

When an attack occurs, organizations should already know who makes decisions, who investigates, who communicates, and who coordinates recovery.

Cybersecurity Needs Executive Support

Security teams cannot solve every risk alone.

Funding, staffing, training, architecture, and recovery planning require organizational commitment.

Detection Speed Matters

The earlier suspicious activity is discovered, the more opportunities defenders have to contain the intrusion.

Ransomware Is Also an Identity Problem

Credential theft, privilege abuse, and authentication weaknesses frequently play an important role in modern intrusions.

Network Visibility Is Essential

Security teams need visibility across endpoints, servers, cloud environments, identity systems, and network traffic.

Security Logs Are Valuable Evidence

Authentication records and endpoint telemetry can help reconstruct what happened during an intrusion.

Data Minimization Can Reduce Damage

Organizations that retain less unnecessary sensitive information may reduce the amount of valuable material available to attackers.

Segmentation Limits Blast Radius

Separating critical systems can prevent an attacker from easily moving through an entire environment.

Patch Management Still Matters

Known vulnerabilities remain attractive to attackers when organizations fail to remediate them quickly.

Human Behavior Remains a Major Factor

Phishing, credential reuse, accidental exposure, and social engineering can undermine otherwise strong technical defenses.

Security Training Must Be Practical

Employees should understand how realistic attacks look and what they should do when something appears suspicious.

Ransomware Recovery Is Not Instant

Even after malicious software is removed, organizations may need substantial time to validate systems and restore operations.

Legal and Regulatory Issues Can Follow

A suspected data breach may trigger notification, privacy, contractual, or regulatory obligations depending on the affected organization and jurisdiction.

Communication Can Reduce Panic

Clear internal communication helps employees understand what is happening without spreading inaccurate information.

Attribution Is Difficult

Determining who actually conducted an attack can require extensive technical investigation.

Ransomware Groups Can Rebrand

Criminal operations can disappear and return under different names, making long-term attribution complicated.

Affiliates Complicate the Ecosystem

The group whose name appears on an extortion site may not represent every individual involved in the intrusion.

International Cooperation Matters

Because attackers, infrastructure, victims, and stolen data can span multiple countries, ransomware investigations increasingly require international coordination.

The Biggest Lesson Is Preparation

The most effective time to develop ransomware defenses is before a victim listing appears.

What Undercode Says:

A Claim Is a Warning, Not a Verdict

The SafePay and Qilin reports should be treated seriously, but they should not be presented as confirmed breaches without additional evidence. A ransomware group’s claim is an important warning signal, not the final word.

The Real Threat Is the Intrusion Behind the Claim

Whether encryption occurred is only one part of the story. The more important question is whether attackers obtained unauthorized access and what they may have done while inside the environment.

Universities Should Assume They Are Targets

Educational institutions should operate under the assumption that attackers will eventually test their defenses. Large user populations and complex infrastructure create too many opportunities to ignore.

Ransomware Defense Must Become Continuous

Security cannot be reduced to installing antivirus software and waiting for alerts. Organizations need continuous identity monitoring, endpoint visibility, vulnerability management, segmentation, backup protection, and incident-response readiness.

Threat Intelligence Should Trigger Investigation

When an organization appears in a ransomware intelligence report, defenders should not immediately panic—but they should investigate. External intelligence can become the trigger for an internal security review.

The Dark Web Is Only One Piece of Evidence

Leak-site monitoring is valuable, but it should be combined with forensic telemetry and direct investigation. Intelligence becomes much more useful when multiple independent signals point toward the same conclusion.

Data Theft Can Create Long-Term Consequences

Even if systems are restored quickly, stolen information can remain in criminal hands indefinitely. Organizations therefore need to think beyond recovery and consider exposure, notification, and long-term monitoring.

The Ransomware Industry Is Adapting

Attackers continue changing their techniques because defenders are improving. As encryption becomes easier to detect and recover from, extortion, data theft, credential compromise, and operational disruption become increasingly important.

Prevention and Recovery Must Work Together

No security architecture can guarantee that an organization will never be breached. Resilience therefore matters as much as prevention.

Organizations Need a Plan Before the Crisis

The difference between a manageable incident and a catastrophic one can sometimes come down to preparation. Teams that already know how to isolate systems, disable accounts, preserve evidence, restore backups, and communicate can respond much faster.

These Claims Deserve Continued Monitoring

The next important development will be evidence. If either organization confirms an incident, publishes details, or if independent researchers identify supporting technical indicators, the significance of these claims could become much clearer.

❌ The Two Attacks Are Not Independently Confirmed

The supplied report establishes that ThreatMon attributed victim listings to SafePay and Qilin, but it does not independently prove that either organization suffered a successful ransomware intrusion. They should therefore be described as alleged or claimed victims.

✅ The Reports Are Attributed to Threat Intelligence Monitoring

The source text explicitly identifies the ThreatMon Threat Intelligence Team as the source of the ransomware activity detection. That supports reporting the claims as threat-intelligence observations rather than presenting them as independently verified breaches.

✅ SafePay and Qilin Are Identified as the Alleged Actors

The supplied information specifically attributes the New Point claim to SafePay and the Universitatea de Vest Vasile Goldi din Arad claim to Qilin. The attribution should nevertheless remain qualified because ransomware-group claims can require independent verification.

Prediction

(-1) Ransomware Extortion Will Continue Targeting Complex Organizations

The most likely direction is continued ransomware pressure against organizations with large digital footprints, particularly institutions that operate many users, applications, cloud services, remote-access systems, and third-party integrations.

(+1) Continuous Monitoring Will Improve Early Detection

Organizations that combine threat intelligence with identity monitoring, endpoint detection, network visibility, strong authentication, segmentation, and tested backups will have a better chance of detecting and containing attacks before they become catastrophic.

(-1) Data Theft Will Remain a Major Extortion Weapon

Even when encryption becomes easier to mitigate, attackers can continue using stolen information as leverage. This means ransomware defense will increasingly overlap with data-security and identity-security programs.

(+1) Better Verification Will Improve Ransomware Reporting

As threat-intelligence platforms and security researchers become more careful about distinguishing claims from confirmed incidents, the public will have a clearer picture of what actually happened during ransomware campaigns.

(-1) Victim Claims Will Continue Appearing Before Full Evidence

Ransomware operators have a strong incentive to publicize alleged victims quickly. Organizations and journalists should therefore expect a gap between an initial claim and definitive confirmation.

(+1) Prepared Organizations Can Reduce the Impact

The strongest prediction is not that ransomware will disappear—it will not. The more realistic positive outcome is that organizations that prepare in advance can increasingly limit the damage, restore operations faster, and reduce the leverage available to extortion groups.

Final Assessment

The SafePay claim involving New Point and the Qilin claim involving Universitatea de Vest Vasile Goldi din Arad are notable additions to the current ransomware threat picture, but they should remain classified as claims until independently confirmed.

The broader warning is nevertheless clear: ransomware groups continue searching for organizations where operational disruption, sensitive information, or reputational pressure can be converted into financial leverage.

For defenders, the lesson is simple but increasingly urgent. Do not wait for a ransomware group to publish your organization’s name before taking the threat seriously. Continuous monitoring, strong identity protection, network segmentation, secure backups, rapid incident response, and careful verification of threat intelligence remain among the most important defenses against the next intrusion.

▶️ Related Video (82% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube