The ransomware group SafePay claims to have attacked T-Systems, the IT subsidiary of Deutsche Telekom, and has set a two-day deadline. According to a company spokesperson, only a small test system was affected and no sensitive data was exfiltrated.
SafePay has listed T-Systems, the IT arm of Deutsche Telekom, on its dark web leak site. According to tracking service Ransomware.live, the listing appeared on October 5. Cybernews reports that the group gave T-Systems two days to enter negotiations and threatened to publish data otherwise.
Telekom Says No Sensitive Data Was Compromised
Deutsche Telekom has since confirmed to it-daily.net that attackers have been attempting to extort a ransom since October 5 using data stolen from T-Systems. However, the data primarily consists of presentation slides from project briefings and system log files stored in a test environment. The company said the data did not contain any sensitive information.
According to Deutsche Telekom, the company had already begun investigating indications of SafePay activity in early September. Ransomware was discovered on a small test system, isolated and removed before it could cause any significant damage.
SafePay Operates Without an Affiliate Model
SafePay was first observed in fall 2024 and has since become one of the most active ransomware groups. Unlike many other operators, it does not use a ransomware-as-a-service model with affiliates. Instead, its own team handles access, encryption and extortion. The group encrypts systems while also stealing data and threatening to release it. Security researchers have identified a possible link to the former Conti group, although the level of confidence varies.
According to Cybernews, SafePay claimed attacks on 76 German companies in 2025, accounting for one-quarter of all German victims named on leak sites that year. The group also targeted IT distributor Ingram Micro in 2025. RedPacket Security, however, points out that SafePay listings have reportedly included unconfirmed or fabricated victim claims.
Previous Claims Involving Deutsche Telekom
Deutsche Telekom has previously been the subject of similar claims. In 2024, the company appeared on the leak site of the LockBit ransomware group. In May 2026, attackers allegedly offered a Deutsche Telekom dataset for sale. At the time, the company said the data was not authentic.
(Editorial Team)