brunetti.com Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
brunetti.com has been listed by the safepay ransomware group, with internal files reported exfiltrated in an attack that came to light on 14 January 2025. The number of people affected is not yet known; anyone who may have had an account or dealings with the site should check for unusual activity and change passwords immediately.
On January 14, 2025, the website brunetti.com was listed by the safepay ransomware group, which claims to have carried out a ransomware attack involving the exfiltration of internal files. Public reporting so far provides no confirmed figure for the number of people affected, and further operational details remain limited. The listing itself is an unverified claim by the group rather than an independently confirmed disclosure.
For customers, staff and partners of a well-known Melbourne café business that also offers catering and online ordering, the appearance of the organisation on a ransomware leak site raises practical questions about what information may have left its systems and what steps those potentially affected should take.
Inside the incident
According to the available record, brunetti.com was listed by the safepay ransomware group on January 14, 2025. The group asserts that internal files were exfiltrated as part of a ransomware attack. No public confirmation of the precise date of intrusion, the method of initial access, the volume of data taken, or any ransom demand has been released. The number of individuals whose information may have been involved is listed as unknown. Beyond the claim of internal-file exfiltration, the exact contents of any stolen material have not been detailed in the public summary.
Because the primary source of the allegation is the group’s own leak-site listing, the incident remains an asserted claim pending any statement from the organisation or independent verification. No additional technical indicators, file samples or timelines have been disclosed in the material available for this report.
Inside safepay
Safepay is a ransomware operation that has been observed publicly since mid-2024. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also copying data and threatening to publish or sell it if payment is not made. Victims are commonly named on a dedicated leak site, sometimes accompanied by sample files or countdown timers. The group has listed organisations across multiple sectors and geographies, though individual claims vary in the amount of supporting evidence provided.
Public reporting on safepay emphasises that its listings should be treated as claims until corroborated. The group has not, in the material available here, released further specifics about the brunetti.com incident beyond the assertion that internal files were taken. No unique statements or additional proof packages tied exclusively to this victim have been described in the given facts.
Who is brunetti.com?
Brunetti is a long-established Italian café and restaurant business founded in Melbourne, Australia, in 1985. It is known for European-style dining, authentic Italian cuisine, gelato, pastries, cakes and desserts, and it also operates catering services and online takeaway ordering. Organisations of this type typically maintain customer contact details, loyalty or order histories, payment-related records, staff information and internal operational documents.
A ransomware incident affecting such a business is consequential because it sits at the intersection of hospitality, retail and online commerce. Customers who place orders or join mailing lists, employees whose personal data is held for payroll or rostering, and suppliers whose contracts or invoices may be stored all form part of the broader data environment that could be drawn into an attack. The public listing therefore carries implications beyond a single technical event.
What was likely exposed
The facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of data categories—such as customer names, email addresses, payment card details, employee records or financial documents—has been disclosed. Exact contents therefore remain unconfirmed.
Businesses of this kind commonly hold customer contact information collected through online ordering and catering enquiries, reservation or loyalty data, staff personal and employment records, supplier contracts, and internal operational files. Any of these could theoretically fall within the broad description of “internal files,” yet it is not possible to state with certainty which, if any, were among the material claimed by the group. Readers should treat all specific data types as unconfirmed until official notification or further evidence appears.
What's at stake
For individuals, the primary risks centre on the possible misuse of personal or contact information that may have been present in internal systems. Even limited data can enable targeted phishing, social-engineering attempts or identity-related fraud if combined with other publicly available details. Employees face similar concerns if personnel files were involved. Because the scale and precise contents are unknown, the actual exposure level for any given person cannot yet be quantified.
For the organisation, the stakes include operational disruption from any encryption, potential regulatory notification obligations under Australian privacy law, reputational impact among customers who rely on its online and catering services, and the cost of investigation and remediation. The absence of confirmed numbers of affected people does not eliminate these pressures; it simply means the full picture is still developing.
Were you affected?
If you have ordered from Brunetti online, used its catering service, worked for the business, or otherwise supplied personal information, treat the listing as a prompt to stay alert rather than as proof of personal compromise. Monitor bank and card statements for unexpected activity, be cautious of unsolicited emails or messages that reference the café or claim to offer refunds or account updates, and consider changing passwords on any accounts that reused credentials associated with Brunetti services.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Official updates from the organisation, if issued, will provide the most reliable guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ryc.org Listed by safepay Ransomware Groupmaxdream.tur.ar Listed by safepay Ransomware Groupbecksgroup.au Listed by safepay Ransomware Groupbarnet.com.au Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the brunetti.com Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.