A group tracked under the name unsafe surfaced on our radar in late June 2026 and has posted 15 claimed victims to date, 13 of them in the last 30 days, with an unusually compressed, high-tempo cadence concentrated across technology, business services, and professional services targets in the US, India, and Germany. Recent postings, including duplicate entries for the same victims (Presentations.AI, DECK APP TECHNOLOGIES, Constellation HomeBuilder Systems) and a claim against Deutsche Bank, suggest a leak site padded with repeated or recycled listings rather than a steady stream of fresh intrusions. No MITRE ATT&CK technique set has been catalogued for this actor yet, so no verified tooling or intrusion chain can be described. Open-source characterization of the group describes it as reposting leaks originally obtained by other ransomware operations, a claim that should be treated as unverified pending independent confirmation. Its geographic and sector spread remains broad but shallow, consistent with a low-effort, high-volume claims strategy rather than a