Skip to content
RansomwareContained

German secure data-exchange vendor FTAPI confirms ransomware breach of an internal server

FTAPI, a Munich secure file-transfer vendor used by 2,000+ organisations, confirmed attackers breached one internal server and deployed ransomware after The Gentlemen gang listed it as a victim.

Victim
FTAPI

On 30 September 2026, FTAPI β€” a Munich-based provider of secure file-transfer and sensitive-data-exchange software used by more than 2,000 companies and over a million users across public administration, healthcare and industry β€” confirmed it had suffered a cybersecurity incident after the ransomware group The Gentlemen listed the company on its darknet leak site. FTAPI disclosed the attack to German technology outlet Heise Online and said unauthorized individuals had gained access to a single, locally operated internal server and deployed ransomware on it.

The company said it first detected the IT security incident on 14 September 2026. The Gentlemen's leak-site entry, observed on 26 September, carried a countdown threatening to publish stolen data. FTAPI emphasised that, based on its investigation, its customer-facing platform, customer systems and the data exchanged by customers through the service were not affected, and that operations continued without restriction.

Response

FTAPI said it immediately isolated the affected systems, engaged external forensic investigators, notified customers and partners, met its data-protection reporting obligations and filed a criminal complaint. The company has not disclosed how the attackers gained their initial foothold β€” whether through an exploited vulnerability or stolen employee credentials β€” and that question remained part of the ongoing investigation.

Why it matters

Secure data-exchange platforms are entrusted with precisely the sensitive files their customers want to keep off ordinary email, which makes a vendor like FTAPI an attractive target and raises the stakes of any intrusion, even one the company says was limited to a single internal server. The Gentlemen is among the ransomware crews that pair encryption with data-theft extortion, so the leak-site listing applies public pressure regardless of how much data was actually taken. With the affected server isolated and no evidence the customer platform was reached, the incident's status was recorded as contained.

Timeline

  1. FTAPI detects an IT security incident on a single internally operated server.

  2. The Gentlemen ransomware group lists FTAPI on its darknet leak site with a countdown.

  3. FTAPI confirms the incident to German outlet Heise, stating its customer platform and exchanged data were not affected.

Sources

  1. heise.dehttps://www.heise.de/en/news/Cyber-attack-on-data-exchange-service-FTAPI-11469688.html
  2. cybernews.comhttps://cybernews.com/security/ftapi-eu-data-transfer-platform-data-breach/
  3. breachsense.comhttps://www.breachsense.com/breaches/ftapi-software-data-breach/

Related incidents