ibague.losolivos.co Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ibague.losolivos.co was listed by the safepay ransomware group on 7 May 2025 after internal files were exfiltrated in a ransomware attack, though the actual date of the intrusion is not established. Individuals who may have had data held by the organisation should review the available information and take appropriate protective steps.
People who have arranged funerals, prepaid plans, or sought support through Los Olivos in Ibagué may now face uncertainty about whether personal details shared during those difficult moments have left the company’s systems. Public reporting indicates that the domain ibague.losolivos.co has been listed by the safepay ransomware group, which claims to have taken internal files. The number of individuals involved remains unknown, and the precise contents of any taken material have not been confirmed beyond the group’s assertion of exfiltration. For families already navigating loss, even the possibility of exposed records adds a layer of practical concern about privacy and potential misuse of sensitive information.
The listing was reported on May 07, 2025. Because details such as the scale of any compromise or the exact method of intrusion have not been independently verified in available records, those who interacted with the firm are left to weigh the claim carefully and take basic protective steps while fuller information is awaited.
Inside the incident
According to the available record, ibague.losolivos.co was listed by the safepay ransomware group. The group asserts that internal files were exfiltrated as part of a ransomware attack. No confirmed figure for the number of people affected has been published, and public detail does not describe the timing of the intrusion, the technical vector used, or whether systems were encrypted in addition to any data removal. The listing itself constitutes the group’s claim rather than an independently verified confirmation of the full scope or success of the operation. No further operational specifics, such as ransom demands or proof samples, appear in the reported facts.
Inside safepay
Safepay is a ransomware operation that has been observed conducting double-extortion campaigns: operators encrypt systems where possible and simultaneously remove copies of data, then threaten to publish the material on a dedicated leak site if payment is not received. The group has listed victims across multiple sectors and geographies since becoming active in public reporting. Typical tactics include initial access through compromised credentials or unpatched services, followed by lateral movement, data staging, and exfiltration before encryption. Like other contemporary ransomware actors, safepay relies on the reputational and regulatory pressure created by public leak-site postings to encourage negotiation. In this instance the group claims to have obtained internal files from ibague.losolivos.co; that assertion has not been corroborated by independent sources in the available record, and no additional statements attributed specifically to this victim beyond the listing itself are documented.
Who is ibague.losolivos.co?
Los Olivos operates as a funeral-services provider based in Ibagué, Colombia. The company offers funeral plans, crematorium and cemetery services, wake rooms, transportation, posthumous tributes, and psychological support for bereaved families. Organisations of this type routinely collect and store personal identifiers, contact details, next-of-kin information, financial data related to prepaid plans or payments, and sometimes medical or ceremonial preferences. Because the services are rendered at moments of acute vulnerability, the records often contain intimate details that families expect to remain private. A compromise affecting such an organisation therefore carries heightened sensitivity: the data can link living relatives to deceased individuals and may include payment histories or support-service notes that are not intended for wider circulation.
The information in question
The reported facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of data types—such as customer databases, financial ledgers, or employee records—has been disclosed. Funeral-service providers typically maintain files containing names and contact information of clients and families, addresses, identification numbers, payment or insurance details for funeral plans, and notes related to arrangements or counselling. Whether any of those categories were among the material claimed by safepay remains unconfirmed. Public detail is limited to the group’s assertion of internal-file exfiltration; exact contents and volume are therefore unknown.
What's at stake
For individuals whose information may have been involved, the practical risks include unwanted contact, identity-related fraud, or the emotional distress of knowing that private arrangements surrounding a death could become public. Financial data tied to prepaid plans could be misused for unauthorised transactions if it was present and accessible. For the organisation, the incident raises questions of operational continuity, regulatory notification obligations under Colombian data-protection rules, and the need to restore trust with families who rely on discretion. Because the number of affected people is unknown and the precise data set is unconfirmed, the full extent of these risks cannot yet be quantified. The listing alone, however, creates a period of uncertainty during which both the company and potentially impacted individuals must assume that sensitive material may be in unauthorised hands.
Were you affected?
If you have used Los Olivos services, monitor bank and credit statements for unexpected activity and consider placing fraud alerts with relevant financial institutions. Change passwords on any accounts that may have shared credentials or email addresses with the company, and enable multi-factor authentication where available. Be cautious of unsolicited communications that reference funeral arrangements or claim to offer support, as such messages can be used for phishing. Readers can also run a free exposure scan of their email address to check whether that address has appeared in previously known breach data sets; a positive result does not prove involvement in this specific incident, but it can indicate whether broader monitoring is warranted. Official notifications, if any are issued by the company or regulators, should be treated as the primary source of confirmation.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
47club.jp Listed by safepay Ransomware Groupvitatrac.com.gt Listed by safepay Ransomware Grouppeus-muenzen.de Listed by safepay Ransomware Groupspringersjewelers.com Listed by safepay Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ibague.losolivos.co Listed by safepay Ransomware Group →
Publicly posted by safepay — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.