cali.losolivos.co Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
cali.losolivos.co was listed by the safepay ransomware group on March 11, 2025, after internal files were exfiltrated in a ransomware attack that affected an undisclosed number of people. Individuals are advised to check whether their information was exposed and to take appropriate protective steps.
On March 11, 2025, the domain cali.losolivos.co was listed by the safepay ransomware group, which claims to have carried out a ransomware attack involving the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited to this listing and the stated nature of the data taken. For anyone connected to the organisation or its services, the disclosure raises questions about what information may now be in unauthorised hands and what practical steps follow.
Ransomware listings of this kind are claims by the threat actor until independently verified. What is confirmed in available records is the date of the report, the attribution to safepay, and the description of internal files as having been removed during the attack.
Inside the incident
According to the reported information, cali.losolivos.co appeared on a safepay leak site on March 11, 2025. The group asserts that internal files were exfiltrated as part of a ransomware attack. No further specifics have been made public regarding the precise timing of the intrusion, the method of initial access, the volume of data taken, or any ransom demand. The number of individuals whose information may be involved is listed as unknown. Public detail beyond the listing itself and the characterisation of the data as internal files remains limited.
Because the available record consists primarily of the threat actor’s claim, independent confirmation of the full scope or success of the attack has not been established in the sources reviewed. Organisations facing such listings typically investigate internally while assessing whether systems were encrypted, whether backups were affected, and whether any data has begun circulating outside the group’s control.
Who is safepay?
Safepay is a ransomware operation that has been observed conducting double-extortion attacks: encrypting systems while also stealing data and threatening to publish it if payment is not made. Like many contemporary groups, it maintains a leak site where it posts victim names and, in some cases, samples of stolen material to pressure organisations. Public reporting on safepay has documented its use of common initial-access techniques and its focus on mid-sized entities across various sectors, though tactics can vary by campaign.
In this instance, the group’s listing of cali.losolivos.co constitutes its claim that the organisation was compromised and that internal files were taken. No additional statements attributed specifically to this victim beyond the listing itself appear in the available facts. Readers should treat such claims as unverified until corroborated by the organisation or independent investigators.
About cali.losolivos.co
The domain cali.losolivos.co points to an entity operating under the Los Olivos name in Cali, Colombia. Public knowledge associates Los Olivos with funeral and related memorial services in the country. Organisations of this type typically manage sensitive personal information belonging to clients and their families, including contact details, identification records, service arrangements, and financial or insurance-related data connected to arrangements for the deceased.
A breach involving such an organisation is consequential because the data it holds is often highly personal and linked to moments of vulnerability. Even when the precise contents of any stolen material remain unconfirmed, the sector’s routine handling of private records means that unauthorised access can affect both living relatives and the reputation and operational continuity of the service provider.
The information in question
The facts state that internal files were exfiltrated in the ransomware attack. No more granular inventory of file types, databases, or specific data categories has been disclosed. People affected are recorded as unknown.
Organisations providing funeral and related services commonly store names, addresses, telephone numbers, national identification numbers, next-of-kin details, payment information, and documentation related to death certificates or insurance claims. Whether any of these categories were among the internal files claimed by safepay is unconfirmed. The exact contents therefore remain unknown, and no assertion can be made that particular personal data elements were or were not exposed.
What's at stake
For individuals whose information may have been among the internal files, the primary risks include potential misuse of personal identifiers for fraud, unwanted contact, or social-engineering attempts that reference private family circumstances. Because funeral-service records can contain sensitive biographical and contact data, exposure can create lasting privacy concerns even if financial accounts are not directly involved.
For the organisation, the stakes include operational disruption if systems were encrypted, the cost of investigation and remediation, possible regulatory obligations under applicable data-protection rules, and erosion of trust among clients who rely on discretion. The absence of confirmed numbers of affected people or a detailed data inventory means the full scale of impact cannot yet be quantified from public sources.
If your data was in this claimed breach
If you have had dealings with cali.losolivos.co or related Los Olivos services and are concerned your information may have been involved, begin by monitoring financial accounts and credit reports for unexpected activity. Be cautious of unsolicited communications that reference personal or family details, as these can be used in phishing or social-engineering attempts. Change passwords on any accounts that may have shared credentials or recovery information with the organisation, and enable multi-factor authentication where available.
Document any suspicious contacts and consider placing fraud alerts with relevant credit or identity-protection services if you believe sensitive identifiers were held by the organisation. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Stay alert for any official statements from the organisation itself, as these remain the most reliable source of confirmation and guidance specific to this incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
retycol.com Listed by safepay Ransomware Groupnotar-gerresheim.de Listed by safepay Ransomware Groupseguriamericas.com Listed by safepay Ransomware Groupadesursas.com Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the cali.losolivos.co Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.