
The Safepay ransomware group has claimed responsibility for hacking Xortec GmbH, a Frankfurt-based video surveillance and security systems distributor, and has listed the company on its data leak site with a ransom deadline set for October 27, 2025.
Xortec, a value-added distributor and systems integrator specializing in video surveillance, IP networking, and security solutions, is a key supplier for enterprise and installer clients across Germany and international markets. The company provides cameras, network video recorders, access control systems, and related infrastructure components. It was acquired by the private equity firm Beyond Capital Partners in 2021 and employs several dozen people, generating annual revenues exceeding €7.5 million through large-scale installation projects.
The breach, if verified, could have serious implications across the security technology supply chain. Xortec’s customer base includes system integrators, installers, and resellers that serve clients in sectors such as retail, logistics, public infrastructure, and utilities. Cybersecurity analysts warn that an intrusion into a company like Xortec could allow attackers to embed malicious code into hardware or software products distributed to clients, potentially exposing surveillance layouts, shipment records, and sensitive client data. Any compromise of firmware or system components could undermine trust in thousands of deployed surveillance systems.
Disruptions to Xortec’s operations could also affect its logistics network, delaying shipments and impacting downstream resellers and end users. Given the company’s role in providing critical security infrastructure, experts say the incident could evolve into a multi-tier risk with broader systemic consequences.
Safepay, the group behind the alleged attack, is a rapidly expanding ransomware operation that has been active since late 2024. Known for using double extortion tactics—stealing and encrypting data before threatening to leak it—the group has targeted multiple sectors including manufacturing, healthcare, and government. Safepay is believed to operate independently and has been noted for striking within 24 hours of gaining system access. Its avoidance of Russian-based systems suggests a likely Eastern European origin.
As of publication, Xortec has not issued a public statement regarding the breach or confirmed whether any data was stolen. If the ransom is not paid by the October 27 deadline, Safepay is expected to begin leaking the stolen data on its site.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543