Critical Unverified

Bio-Strath Ransomware Claim by safepay (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming bio-strath.com data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming bio-strath.com data breach - full size

Claim Summary

On or around September 28, 2026, a ransomware group calling itself “safepay” allegedly listed bio-strath.com, a Swiss healthcare and nutrition company, on its dark web leak site. According to the threat actor’s claim, the company was established in 1961 and operates the Bio-Strath brand, which is particularly associated with liquid and tablet nutritional supplements.

The group claims to have exfiltrated data from the organization, though the specific volume of allegedly stolen data remains undisclosed. The victim is listed as being based in Switzerland (CH) and operating in the healthcare sector.

This claim has NOT been independently verified by Yazoul Security or any third party. It represents only the unverified assertion of the threat actor.

Threat Actor Profile

The group operates under the name safepay. At the time of this writing, safepay has no established public track record that Yazoul Security can confirm. Key intelligence gaps include:

  • Total known victims: Unknown
  • Known tools and tactics: No confirmed tooling, malware families, or TTPs have been publicly attributed to this group.
  • Research references: No public research or threat intelligence reporting is currently available.

Because safepay lacks a documented history, its credibility cannot be assessed with confidence. Groups with little or no verifiable track record sometimes rebrand from prior operations, but equally often they are new entrants, low-effort actors, or even “name-squatters” seeking attention. Some actors also post claims without possessing meaningful data, hoping victims will pay to avoid exposure.

Without corroborating evidence, we treat safepay’s claims as unproven and its operational maturity as unknown.

Alleged Data Exposure

The leak site entry purportedly references the victim’s corporate history and brand identity, but provides no data samples, file listings, or volume figures that Yazoul Security can review. The claimed data volume is explicitly undisclosed.

We cannot confirm what data, if any, was actually taken. Ransomware operators frequently exaggerate the scope and sensitivity of stolen information to increase pressure on victims. In the absence of samples or proof-of-life artifacts, the alleged exposure remains entirely unverified.

Potential Impact

If the claim were accurate, a healthcare-adjacent organization could face risks including:

  • Exposure of internal business, employee, or partner information
  • Regulatory scrutiny under Swiss data protection law (revDSG/FADP) and, where applicable, GDPR
  • Operational disruption if systems were encrypted
  • Reputational harm to a long-established consumer nutrition brand

These are hypothetical considerations only. No impact has been confirmed, and the organization has not been verified as a victim.

What to Watch For

  • Official statements from Bio-Strath or its representatives
  • Swiss data protection authority (FDPIC) or sector regulator notifications
  • Publication of verifiable data samples by the threat actor
  • Rebranding indicators linking safepay to previously known groups
  • Any YARA rules or detection signatures that may later be published for tooling associated with this actor

Organizations in the healthcare and nutrition sectors should maintain robust backup, segmentation, and monitoring controls regardless of this specific claim.

Disclaimer

This report is based solely on an unverified claim posted to a ransomware group’s leak site. Yazoul Security has NOT independently confirmed the attack, the data theft, or the authenticity of any information attributed to safepay. Ransomware groups routinely exaggerate or fabricate claims. Nothing here should be treated as fact or as an admission by the named organization. No personal data, credentials, samples, or access links are included. Readers should await official confirmation before drawing conclusions.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.