~/f4n6 $ grep -r "Ransomware: safepay named gsngestion.es (ES)" ./investigations/ --include="*.md"

Ransomware: safepay named gsngestion.es (ES)

Jeff Davies 09 Sep 2026 5 min read

1. Executive summary

On 2026-09-08, the ransomware operator "safepay" listed the Spanish firm GSN Gestión (gsngestion.es, Villaviciosa de Odón, Madrid) as a victim on its leak site. This is a leak-site listing only: no CVSS-scored vulnerability, no confirmed intrusion detail, and no technical indicators accompany the claim, and "safepay" has no MITRE ATT&CK profile in our verified reference data — the attribution is unconfirmed. The listing is consistent with safepay's contemporaneous activity against other European SMEs (e.g. cenesco.de, DE, listed by the same actor), which suggests opportunistic targeting of small and mid-sized organisations rather than a sector-specific campaign against financial services. Bottom line for EMEA financial services clients: direct exposure is limited to any relationship with GSN Gestión; the broader relevance is as a reminder that leak-site claims are claims, not confirmed breaches, and should trigger third-party exposure checks, not incident escalation on their own.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 28: ICT third-party risk — general principles GSN Gestión is a named Spanish company whose compromise is claimed by a ransomware operator; any client using GSN Gestión as an ICT or outsourced-service provider holds unassessed third-party exposure arising from this listing. Clients with a contractual relationship to the victim should assess the provider's status and any data or connectivity exposure under their ICT third-party risk principles.
DORA Art. 18: classification of ICT-related incidents and cyber threats A credible-source cyber threat (ransomware leak-site listing naming a Spanish entity) exists that clients must classify — including as a potential third-party incident if a relationship exists. Run the listing through the incident/threat classification process to determine whether it constitutes an ICT-related incident in the client's own environment; classification precedes any Art. 19 reporting decision.

No NIS2 or UK NIS article is engaged by this item on the facts available. We note explicitly that DORA Art. 19 (reporting of major ICT-related incidents) is not cited: a leak-site listing naming a third party does not, on these facts, establish a major incident in a client's own environment.

3. Technical analysis & attack chain

No confirmed attack chain exists in the source material. The ransomware.live entry contains only: actor name (safepay), victim name and domain (gsngestion.es), country (ES), publication timestamp (2026-09-08T19:46:37Z), and a partial company description placing GSN Gestión in Villaviciosa de Odón, Madrid, operating under the GSN Gestión brand. The listing references DNS records and a leak screenshot on the ransomware.live page, but no record values, screenshot content, data samples, or stolen-file details are present in the material provided.

What can and cannot be said:

  1. Claimed actor: "safepay". This actor has no MITRE ATT&CK profile in our verified reference data; the attribution rests entirely on the leak-site listing itself and is unconfirmed. Single-sourced; verify before enforcement.
  2. Claimed victim: GSN Gestión (gsngestion.es), a Spanish company based in Villaviciosa de Odón, Madrid. The victim's own confirmation of an incident is not present in the source material.
  3. Claimed impact: Ransomware with implied data theft (the listing sits on a leak site, whose purpose is typically to pressure victims by publishing or threatening to publish stolen data). No sample data, file counts, or exfiltration evidence is available, so the theft claim is unverified. We do not describe this as a confirmed double-extortion event.
  4. No technical detail: No initial access vector, exploited CVE, malware family, payload, persistence mechanism, C2 infrastructure, or IOCs are present. Any attack chain we constructed here would be fabrication.

Context from related sources (corroborating activity level, not this incident): the same actor listed cenesco.de (DE, an IT solutions SME) — indicating safepay was actively naming European SMEs in the same window. Other, unrelated actors (BrainCipher, Global Secret Group, thegentlemen) were listing separate Spanish and European victims in the same period; these are not connected to this item.

Confidence caveat: every substantive claim in this section is single-sourced (the ransomware.live leak-site index). Treat the listing as an unconfirmed claim until the victim, a law-enforcement statement, or a second independent source corroborates it.

4. Mitigation & containment

There are no technical indicators to hunt, so containment is relationship- and exposure-driven. Prioritise:

P1 — within 24h

  • Determine whether your organisation has any commercial, data-sharing, or network relationship with GSN Gestión (gsngestion.es). Check vendor master files, procurement records, and email/VPN allowlists for the domain.
  • If a relationship exists: identify what data or connectivity the relationship involves, contact the counterpart through established channels, and open an incident record under your ICT incident process (DORA Art. 17/18) pending their response.
  • If no relationship exists: log the check and close; no further action is warranted by this item alone.

P2 — within 72h

  • For confirmed relationships: review data flows from/to the victim for the past 90 days; assess whether any client, employee, or counterparty data was shared with the victim and whether that data is in scope of the leak claim.
  • Rotate credentials and revoke any standing access (API keys, VPN accounts, SFTP accounts) associated with the counterpart if shared credentials or interconnects exist.

P3 — within 7 days

  • Re-check the ransomware.live listing for posted data samples or a deadline extension; the presence of actual leaked data changes the assessment materially.
  • If leaked data containing your organisation's information is confirmed, re-run classification under DORA Art. 18 and reassess whether Art. 19 reporting thresholds are met — that determination cannot be made from the current listing alone.
  • No patching action arises from this item; no CVE is involved.

5. Indicators of compromise

No indicators of compromise available in the source material.

The source references DNS records and a leak screenshot for the victim's domain but provides no record values, hashes, domains, IPs, or other atomic indicators. The victim domain gsngestion.es is not an IOC — it is the victim's legitimate domain and must not be blocked.

6. Detection

Insufficient indicators to author detection rules.

The source material contains no malware artefacts, strings, command lines, registry keys, or behavioural indicators attributable to the threat. Authoring a YARA or Sigma rule here would require fabricating artefacts.

7. Sources

  • Ransomware.live — Ransomware: safepay named gsngestion.es (ES) — https://www.ransomware.live/id/Z3NuZ2VzdGlvbi5lc0BzYWZlcGF5 — 2026-09-08
  • Ransomware.live — Victim: gsngestion.es – safepay (page detail incl. DNS records reference and legal disclaimer) — https://www.ransomware.live/id/Z3NuZ2VzdGlvbi5lc0BzYWZlcGF5 — accessed 2026-09-09
  • Ransomware.live — Ransomware: safepay named cenesco.de (DE) (context on actor activity) — https://www.ransomware.live/id/Y2VuZXNjby5kZUBzYWZlcGF5 — accessed 2026-09-09

8. Adverse Trace position

This is a low-confidence, single-sourced leak-site listing with no technical corroboration, no victim confirmation, and no MITRE-verified attribution for the actor "safepay" — we treat both the breach and the attribution as unconfirmed. Severity for EMEA financial services clients is low absent a commercial relationship with GSN Gestión; the actionable element is the third-party exposure check, not threat hunting. We are monitoring the ransomware.live listing for posted data samples, victim statements, or corroborating reporting, and will reissue this advisory at version 2.0 if leaked data, IOCs, or confirmed intrusion detail emerges — at which point DORA Art. 19 reporting analysis becomes live for affected clients.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies