LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › simonrack.com Listed by safepay Ransomware Group

HIGH severityUnverified claimHow we verify

simonrack.com Listed by safepay Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 3, 2026
simonrack.com Listed by safepay Ransomware Group

Reported August 3, 2026.

HIGH
Severity
1
Data types exposed
August 3, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Simonrack.com was listed by the safepay ransomware group on August 03, 2026, after internal files were exfiltrated in a ransomware attack; the exact date of the intrusion is not established. Anyone who may have interacted with the site should check whether their data was exposed and take protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the simonrack.com Listed by safepay Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

People who have worked with, supplied, or bought from simonrack.com may now face uncertainty about whether internal company material that includes their details has left the organisation’s control. Public reporting places the firm on a ransomware group’s leak site, which raises ordinary but serious questions about exposure of business contacts, contracts, and related records.

What is known so far is limited. The listing attributes the incident to the group known as safepay and describes internal files as having been taken in a ransomware attack. How many people are affected, exactly which records left the network, and whether any data has been published beyond the claim itself remain undisclosed. For anyone whose name, email, or commercial relationship appears in those systems, the practical stake is straightforward: stolen internal files can be misused for fraud, targeted phishing, or further intrusion long after the initial event.

Breaking down the breach

According to available public detail, simonrack.com was listed by the safepay ransomware group, with the report dated 3 August 2026. The organisation is identified as headquartered in Alfamén, Zaragoza, Spain. The summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been released, and public detail does not describe the intrusion method, the duration of access, or whether encryption was deployed alongside theft.

Because the primary public signal is a leak-site listing, the claim that data was taken should be treated as an assertion by the group rather than as independently verified disclosure from the company. No file counts, sample sets, ransom demands, or confirmation of public release beyond the listing itself appear in the reported facts. Timing of the underlying intrusion, as distinct from the listing date, is also undisclosed.

The group behind it: safepay

Safepay is a ransomware operation that has appeared in public reporting as a double-extortion actor: operators typically seek to encrypt systems while also copying data, then pressure victims by threatening to publish or sell the stolen material on a dedicated leak site. Like other groups in this category, safepay has been associated with opportunistic targeting across multiple sectors rather than a single industry focus, and with the use of affiliate-style or service-based models common among contemporary ransomware crews.

In this case, the group’s listing of simonrack.com constitutes its claim that internal files were exfiltrated. No further statements attributed to safepay about this specific victim—such as volume of data, deadlines, or proof packs—are included in the facts at hand. Readers should therefore separate the well-documented general pattern of safepay activity from the still-unverified particulars of this incident.

simonrack.com and its sector

Simonrack.com is described as a manufacturer of metal shelving, based in Alfamén, Zaragoza, Spain, with operations dating to 1964 and a position among European producers in that field. Companies of this type sit in the industrial manufacturing and storage-equipment supply chain. They commonly maintain records covering employees, distributors, wholesale and retail customers, logistics partners, product specifications, pricing, and procurement.

A breach affecting such an organisation is consequential because manufacturing firms hold both operational data and relationship data that connect many third parties. Even when the core business is physical goods rather than consumer digital services, the supporting IT estate often contains enough personal and commercial detail to enable follow-on fraud or competitive harm if it is copied and circulated.

The information in question

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of specific data types—such as names, identity documents, financial accounts, or health information—has been publicly itemised, and the number of people affected is unknown.

Organisations in industrial manufacturing typically hold employee personnel files, customer and supplier contact lists, order histories, invoices, shipping records, engineering or product documents, and internal correspondence. Whether any of those categories were among the files the group claims to have taken is unconfirmed. Until a fuller disclosure appears, the exact contents should be treated as unknown rather than assumed.

The real-world impact

For individuals, the main risks are secondary misuse: phishing that references real orders or colleagues, invoice fraud directed at suppliers or customers, and credential stuffing if work emails and passwords were stored in the taken files. Business contacts may also see their commercial terms or personal work details used to build convincing social-engineering attempts.

For the organisation, consequences can include operational disruption from the ransomware event itself, regulatory notification duties under applicable European data-protection rules, contractual friction with partners, and longer-term reputational cost if the claim is substantiated by later publication. Because scale and content remain undisclosed, the severity for any single person cannot yet be measured precisely; the prudent stance is to assume that internal business records may be in unauthorised hands until clearer information emerges.

If your data was in this breach

If you have a past or current relationship with simonrack.com—as staff, customer, or supplier—treat unsolicited messages that cite the company or recent orders with extra caution. Prefer official channels you already trust when checking invoices or account changes. Consider changing passwords on any work-related accounts that may have been reused elsewhere, and enable multi-factor authentication where it is available. Monitor financial and email accounts for unusual activity over the coming months rather than only in the immediate aftermath.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or rule out inclusion in this specific incident, but it helps you see whether your address appears in other circulated collections and prioritise further protections accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companysimonrack.com security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See simonrack.com’s full breach history →

More recent breaches

southshorerecycling.com Listed by safepay Ransomware GroupAugust 3, 2026cpu-ag.com Listed by safepay Ransomware GroupAugust 3, 2026naskdoorinc.com Listed by safepay Ransomware GroupAugust 3, 2026industriesjaro.com Listed by safepay Ransomware GroupJuly 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the simonrack.com Listed by safepay Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by safepay — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram