Source: Cybernews, Deutsche Telekom statement
The SafePay ransomware operation has listed T-Systems, one of Germany’s largest IT service providers and a subsidiary of Deutsche Telekom, on its dark web leak site, threatening to publish stolen data if negotiations fail. The gang reportedly gave the company just two days to respond, a common extortion tactic designed to pressure victims before they can fully investigate what happened.
What Deutsche Telekom confirms
A Deutsche Telekom spokesperson confirmed that criminals calling themselves SafePay have been trying to extort money from T-Systems since October 5. According to the company, ransomware was found on a small test system in early September, was isolated and cleaned up before significant damage occurred, and the stolen data consists mainly of project presentation slides and system log files. The company says no sensitive information was involved. T-Systems operates in 26 countries with more than 26,000 employees, which makes even a test environment breach a serious reputational matter.
SafePay is a double extortion operation first observed in autumn 2024. Unlike ransomware-as-a-service groups it keeps an in-house team for access, deployment and extortion, and researchers link it to the Conti lineage with varying confidence. It is notably active in Germany: SafePay claimed breaches of 76 German companies in 2025, around a quarter of all German ransomware victim posts that year.
The lesson for European organizations
The detail that matters here is not the brand name, it is the test environment. Test and staging systems often hold copies of production data, run outdated software, sit outside the normal patch cycle and are excluded from monitoring. Attackers know this. If your organization runs systems that would embarrass you on a leak site but that nobody actively maintains, that is exactly where an intrusion will start. For German and other European providers, NIS2 also raises the stakes: significant incidents affecting large IT service providers can trigger reporting duties and regulatory scrutiny, and a quiet cleanup in September can become a public extortion case in October.
If you want an honest assessment of your exposure, from test environment hygiene and backup readiness to NIS2 reporting preparation and ransomware resilience, contact Excello Digital at https://excello.digital/contact/. We help European companies harden their infrastructure before criminals grade it for them.
