Data Breaches

Microlise Confirms Data Breach as Ransomware Group Steps Forward

The SafePay ransomware group claims to have stolen over 1 terabyte of data from vehicle tracking solutions provider Microlise.

The SafePay ransomware group claims to have stolen over 1 terabyte of data from vehicle tracking solutions provider Microlise.

UK-based vehicle tracking solutions provider Microlise confirmed last week that data was stolen from its systems during an October cyberattack.

Disclosed on October 31, the incident resulted in a large portion of Microlise’s network being disrupted, which impacted tracking systems and panic alarms in the prison vans and courier vehicles of at least two operators, namely DHL and Serco.

One week later, the company said it was already bringing some of the affected services online, but noted that some employee data was likely compromised during the attack.

Last week, Microlise notified the London Stock Exchange that the restoration process was essentially completed, confirming the theft of data from its systems.

“The company can now confirm that the vast majority of customer systems are back online, with some remaining customers conducting their own security verifications before enabling users. The company would like to reiterate that no customer systems data was compromised,” Microlise said.

The company said it has notified international authorities that corporate data was stolen from its headquarters, without providing further details on the matter.

Advertisement. Scroll to continue reading.

SecurityWeek has emailed Microlise for additional information on the cyberattack and will update this article as soon as a reply arrives.  

Two days after Microlise’s updated notice to the London Stock Exchange, the SafePay ransomware group listed the company on its Tor-based leak site, claiming the theft of 1.2 terabytes of data.

A relatively obscure gang, SafePay uses LockBit-based ransomware in attacks and engages in double-extortion tactics, threatening to release data allegedly stolen from its victims.

To date, the group has claimed responsibility for over 20 intrusions and has made the data of some of its alleged victims available publicly.

Related: Mexico’s President Says Government Is Investigating Reported Ransomware Hack of Legal Affairs Office

Related: Akira Ransomware Drops 30 Victims on Leak Site in One Day

Related: Russian Hackers Target Russian Companies With Ransomware

Related: Online Learning Company K12 Paying Ransom Following Ransomware Attack

Related: Microchip Technology Reports $21.4 Million Cost From Ransomware Attack

Related Content

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version