1. Executive summary
On 2026-09-08, the ransomware group "safepay" listed the Spanish ceramics manufacturer Gayafores (gayafores.es, headquartered in Onda, Castellón) as a victim on its leak site. The listing is a claim of compromise and data theft; the source material contains no technical detail on initial access, malware, or exfiltration, and no CVE is implicated. Attribution to "safepay" is unconfirmed — the group has no MITRE ATT&CK profile in our verified reference data, and the claim rests solely on the group's own leak-site post as indexed by Ransomware.live. For EMEA financial services clients, the direct risk is limited: Gayafores is an industrial manufacturer, not a financial entity, but any client with a supply-chain or third-party relationship to Spanish ceramics/logistics should verify exposure and treat the claim as unverified until corroborated.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The item is a single-sourced leak-site claim against a non-financial Spanish manufacturer with no confirmed incident detail; no fact in the source triggers a distinctive obligation under the articles in scope. Clients with a contractual relationship to the victim should handle it through their existing third-party incident processes rather than a regulatory trigger.
3. Technical analysis & attack chain
No confirmed attack chain can be reconstructed from the source material. Ransomware.live records only the leak-site listing itself: group "safepay", victim "gayafores.es", country ES, published 2026-09-08. No initial access vector, exploited CVE, malware family, persistence mechanism, C2 infrastructure, or exfiltration evidence is present.
What the source does provide:
- Leak-site listing. safepay claims Gayafores as a victim. The listing implies the group claims data theft (consistent with the extortion model of posting victims), but no stolen-data sample, file listing, or screenshot content is described in the material provided.
- Hudson Rock exposure data (single-sourced, vendor-sponsored). Ransomware.live's Hudson Rock panel reports for gayafores.es: 0 compromised employees, 1 compromised user, 0 third-party employee credentials, 1 external attack-surface entry, and DNS records for the domain. The "1 compromised user" entry is an infostealer-credential signal, not confirmation of how the ransomware operator accessed the environment — it is a weak, unverified correlation and should not be treated as the initial access vector. Note also that this panel is sponsored content on the indexing site; treat as low-confidence context only.
- Victim profile. Gayafores is a ceramics manufacturer established in 1949, headquartered in Onda, Castellón — one of Europe's principal ceramic manufacturing regions. This is an OT/industrial-sector victim, which is relevant to any client with Spanish industrial supply-chain dependencies.
Confidence caveat: the entire item is single-sourced (Ransomware.live's index of the safepay leak site). There is no independent corroboration of the compromise, no second vendor report, and no statement from the victim. Verify before enforcement: confirm with any direct relationship to Gayafores before treating the compromise as established fact.
4. Mitigation & containment
There are no technical indicators to act on, so containment is limited to relationship and exposure checks.
P1 — within 24h
- Identify whether your organisation has any live commercial, data, or network interconnection with Gayafores or gayafores.es (supplier records, EDI/ERP integrations, shared portals, payment counterparties). If an integration exists, review traffic and credential usage to/from that domain for the past 30 days.
- Check your own credential-monitoring feeds for the "1 compromised user" signal on the gayafores.es domain; if any of your staff or partners appear in related infostealer data, force credential rotation.
P2 — within 72h
- If Gayafores is a material supplier, invoke your standard third-party security enquiry: ask them to confirm or deny the incident and whether any of your shared data or credentials are affected.
- Review any file exchanges received from the victim domain since 2026-08-08 for unexpected archive or macro-bearing attachments.
P3 — within 7 days
- No patching or configuration change is indicated — no CVE or product is implicated. Fold this victim into routine third-party risk review; re-check the leak-site listing for a data dump or deadline, which would escalate the assessment.
5. Indicators of compromise
No indicators of compromise available in the source material. The only domain referenced (gayafores.es) is the victim's legitimate domain and is not an IOC.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- Ransomware.live — "Victim: gayafores.es – safepay" — https://www.ransomware.live/id/Z2F5YWZvcmVzLmVzQHNhZmVwYXk= — 2026-09-08
8. Adverse Trace position
This is a low-information, single-sourced leak-site claim: safepay names Gayafores, a Spanish ceramics manufacturer, with no technical detail, no corroborating source, and no MITRE ATT&CK profile for the actor — attribution and the compromise itself are both unconfirmed. Severity for EMEA financial services clients is low absent a direct relationship with the victim; the actionable element is the Hudson Rock "1 compromised user" signal on the victim domain, which is worth a credential-hygiene check but is not evidence of the ransomware intrusion. We will monitor the listing for a data dump, deadline, or victim statement, and will reissue if corroboration or technical detail emerges.
Published via PulseTrace — Adverse Trace threat intelligence.