CiberLATAMbywhalemate

Peru’s gob.pe listed as SafePay victim

Threat intel aggregators and accounts listed gob.pe as a SafePay victim. Peru has not confirmed any breach.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Peru’s government portal gob.pe was listed as a SafePay ransomware victim on specialized intelligence platforms, with records dated Sept. 16, 2026. The mention appeared in Pulse, from Kalir.io, and in two HookPhish posts, while alerts on X were already circulating about a possible link between SafePay and the Peruvian government.

Update September 21, 2026: A new detail has been added about SafePay, which, according to a Provendata analysis, had claimed 560 public victims on its leak site as of Sept. 14, 2026. The rest of the picture around gob.pe remains without official confirmation from Peru.

Peru’s government portal gob.pe was listed as a SafePay ransomware victim on specialized intelligence platforms, with records dated Sept. 16, 2026. The mention appeared in Pulse, from Kalir.io, and in two HookPhish posts, while threat-focused accounts on X were already warning about a possible link between SafePay and the Peruvian government. For now, there is no official confirmation from Peru of a compromise of the portal or any data leak.

How did the alert about gob.pe appear?

The alert first surfaced in threat intel tools and accounts that track ransomware group postings. Pulse, from Kalir.io, included gob.pe among the victims listed by SafePay, and HookPhish logged two notices reading "Ransomware Group safepay Hits: gob.pe", both tagged with country PE and the date 2026-09-16.

That circulation did not stay limited to specialist aggregators. An X account focused on threats, under the username Alph4, shared an alert titled "Threat Alert | Ransomware | Gobierno del Perú" linking SafePay to the Peruvian government. Another X account also spread the claim that the group had posted gob[.]pe as a victim, although it provided no additional technical evidence or official confirmation.

What context does this add about SafePay?

The available material shows SafePay’s attributed operating method and helps explain why the gob.pe mention matters, although it does not by itself prove a concrete intrusion into the portal. A security research index references a Sygnia technical analysis describing the use of OneDrive as a data exfiltration channel over HTTPS to a trusted SaaS endpoint.

That analysis also says the group leaves forensic traces in the sync client, which can be used to show information leaving the environment. In this case, however, the evidence gathered so far is limited to ransomware intelligence alerts and their spread across networks of researchers and cybersecurity enthusiasts.

According to a Provendata analysis, SafePay had claimed 560 public victims on its leak site as of Sept. 14, 2026.

What other recent incident affected the Peruvian government?

The Peruvian government had already faced recent cyber pressure from another separate episode. The Ministry of Economy and Finance publicly acknowledged that its official X account had been compromised to promote a cryptocurrency, activated security protocols, and clarified that those posts were not official communications.

Peruvian local media also reported that the ministry warned the public about the lack of official status of messages posted by third parties and about the account’s recovery. That incident does not mention gob.pe or SafePay, but it does show recent exposure on a government digital channel.

Sources

View all