Ransomware group SafePay claims to have breached T-Systems, the enterprise IT subsidiary of German telecommunications giant Deutsche Telekom, and is threatening to publish allegedly stolen information.
The hackers added T-Systems to their dark web leak site and gave the company a two-day deadline to enter negotiations. Such listings are commonly used by ransomware groups to pressure alleged victims into paying before stolen information is released publicly.
However, the breach has not been confirmed by T-Systems. The company has not publicly disclosed a cyberattack, and there is currently no verified information showing what systems may have been accessed or what data the attackers claim to possess.
This distinction is important because appearing on a ransomware leak site does not prove that an organization suffered the type or scale of breach claimed by the attackers. SafePay has not publicly provided enough evidence to independently establish the extent of the alleged intrusion.
T-Systems is a major provider of IT services, cloud infrastructure, cybersecurity and digital transformation services. The Deutsche Telekom subsidiary employs more than 26,000 people and operates across 26 countries, serving large companies and public-sector organizations.
That makes any potential compromise particularly significant because attacks against large IT providers can potentially create risks beyond the company itself. There is currently no evidence, however, that T-Systems customers or their systems were affected.
SafePay emerged in 2024 and has since become a prominent ransomware and data-extortion operation. Unlike many ransomware groups that rely on outside affiliates to conduct attacks, SafePay claims to operate with its own closed team.
Security researchers have also identified similarities between SafePay and ransomware associated with the former Conti cybercrime operation, although assessments of a direct connection vary.
Deutsche Telekom has faced other unverified cybercrime claims in the past. Earlier this year, attackers attempted to sell a dataset they claimed belonged to the telecommunications company, but Deutsche Telekom said the information was not authentic.
For now, the latest incident remains a ransomware claim rather than a confirmed T-Systems breach. Unless the company acknowledges an intrusion or independently verifiable evidence emerges, the attackers’ claims about accessing the IT provider should be treated as unconfirmed.
