Low Unverified

gob.pe Ransomware Claim by safepay (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming gob.pe data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming gob.pe data breach - full size

Claim Summary

On or around September 15, 2026, a ransomware group calling itself “safepay” allegedly listed gob.pe, a Peruvian government web domain, on its dark web leak site. According to the threat actor’s post, the victim is described as the country’s primary online point of contact between public institutions and citizens, providing government information and administrative procedures.

The group claims to have exfiltrated data but has not disclosed a specific data volume. No sample files, screenshots, or proof-of-compromise artifacts have been publicly referenced in the information available to Yazoul Security at the time of writing. This claim remains entirely unverified.

It is important to note that gob.pe is a national government domain rather than a single agency. A claim against “gob.pe” may refer to one portal, one subdomain, or a broader set of services. The ambiguity itself is a reason for caution when assessing the claim’s scope.

Threat Actor Profile

The group operating as safepay is not well documented in public threat intelligence. At the time of this report:

  • Total known victims: unknown
  • Known tools and tactics: no reliable public information
  • Research references: none identified in open sources

Because there is no established track record, no known tooling, and no prior confirmed campaigns tied to this name, the group’s credibility cannot be meaningfully assessed. This is a significant caveat. Ransomware branding is frequently recycled, impersonated, or invented outright. A name with no history may indicate a new operation, a rebrand of an existing group, or a low-capability actor attempting to gain attention with a high-profile target.

Yazoul Security has no YARA rules or detection signatures specific to this group at this time. Analysts should rely on generic ransomware detection guidance, including monitoring for unusual data staging, mass file access, and anomalous outbound transfers.

Alleged Data Exposure

The leak site post purportedly references citizen-facing government information and administrative procedures. However, the group has not provided:

  • A data volume or file count
  • Any sample records
  • Any proof of access to internal systems

Without these, the claim that sensitive data was taken is speculative. Even if access occurred, it is unclear whether the affected systems held personal data, internal documents, or only publicly available content. Public-facing government portals often contain a mix of both.

Potential Impact

If the claim were accurate, potential consequences could include exposure of citizen data submitted through administrative procedures, disruption of public services, and reputational harm to the affected institution. Government portals in this category can process identity documents, applications, and personal records.

That said, these are hypothetical impacts based on the group’s own description. No confirmed data type, record count, or affected service has been established.

What to Watch For

  • Official statements from Peruvian government authorities or CERT-PE
  • Any verified sample data published by the group
  • Independent confirmation from incident response firms
  • Whether the leak site post is updated, removed, or escalates with a deadline
  • Reuse of the “safepay” name in other claims, which may reveal a pattern

Disclaimer

This report is based solely on an unverified claim published on a ransomware group’s leak site. Yazoul Security has not independently confirmed the attack, the data exposure, or the group’s identity. Ransomware operators routinely exaggerate or fabricate claims to pressure victims and attract attention. Nothing in this report should be treated as established fact. Organizations should verify through official channels before acting.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.