Skip to content
RansomwareContained

FTAPI confirms ransomware breach of internal server claimed by The Gentlemen

German data-exchange provider FTAPI confirmed ransomware hit one internal server after The Gentlemen's leak-site claim; it says its platform and customer data were unaffected.

Victim
FTAPI

On 29 September 2026, FTAPI β€” a Munich-based provider of secure data-exchange software used by more than 2,000 companies and over a million users across public administration, healthcare and industry β€” confirmed that it had suffered a ransomware intrusion. The disclosure followed the ransomware group The Gentlemen listing FTAPI on its dark-web leak site and threatening to publish stolen data.

According to the company, the IT security incident was detected on 14 September 2026, when unauthorized individuals gained access to a single, locally operated internal server and deployed ransomware on it. FTAPI said it isolated the affected systems immediately and brought in an external forensics team to investigate.

Scope and impact

FTAPI emphasised that the breach was confined to one internal server and that its core platform, customer systems, and the data exchanged by customers through the service were not affected. The company said investigations of customer systems found no indication they had been compromised and that operations were not disrupted at any point. It has not disclosed how the attackers gained their initial foothold β€” whether through a software vulnerability or stolen employee credentials obtained via spearphishing.

Response

The company informed affected customers and partners once it had reliable initial findings, complied with its regulatory reporting obligations β€” including under data-protection law β€” and filed a criminal complaint. The Gentlemen's leak-site entry carried a countdown threatening release of the allegedly stolen data, but FTAPI maintained that the material exposed to the attackers did not include customer data processed through its platform.

Why it matters

As a secure file- and data-exchange provider serving sensitive sectors, FTAPI is precisely the kind of supplier whose compromise can cascade to its customers, which makes the company's assertion that the platform itself was untouched the central question of the incident. With the affected server isolated, forensics underway, regulators notified and no reported disruption to the service, the incident is recorded as contained, pending the outcome of the investigation and any data The Gentlemen may ultimately publish.

Timeline

  1. FTAPI detects unauthorized access to a single, locally operated internal server on which ransomware is deployed; affected systems are isolated.

  2. FTAPI publicly confirms the incident after The Gentlemen lists the company on its dark-web leak site.

Sources

  1. heise.dehttps://www.heise.de/en/news/Cyber-attack-on-data-exchange-service-FTAPI-11469688.html
  2. heise.dehttps://www.heise.de/news/Cyberangriff-auf-Datenaustauschdienst-FTAPI-11469629.html
  3. cybernews.comhttps://cybernews.com/security/ftapi-eu-data-transfer-platform-data-breach/

Related incidents