FTAPI Software GmbH has confirmed a security incident. The Munich company sells secure data exchange to German and European public authorities, hospitals and industrial firms. The Gentlemen ransomware group has listed FTAPI on its dark web leak site with a countdown of about five days before the entry "activates." FTAPI confirmed the incident to heise online. It says attackers got into a single internal server that ran on premises and deployed ransomware on it. The company says its customer-facing platform, customer systems and the files customers exchange were not affected. FTAPI says it serves more than 2,000 organisations and over one million users in government, healthcare and industry, so the claim adds supply-chain risk for a large, sensitive customer base. The gang has not yet posted any proof of stolen data.
What Happened
According to FTAPI's statement to heise online, the company detected the incident on 14 September 2026. It says unauthorised people got into one internal server that ran at a local site and deployed ransomware on it. FTAPI says it then:
- isolated the affected systems right away
- brought in an external forensics team
- notified customers and partners once it had reliable early findings
- met its regulatory reporting obligations, including data-protection notification
- filed a criminal complaint
The Gentlemen's leak-site entry came about 11 days after detection. The exact listing date differs slightly by source. Günter Born's blog, dasTECHNO and HackerFeeds give 25 September. The Cyber Threat Intelligence aggregator gives 26 September, and HackerFeeds records 26 September as its own "discovery date." Aggregator entries also label FTAPI as a US company. That is an error: every other source, including FTAPI's own company profile quoted in the listing, places it in Munich.
The public timeline developed over several days:
- 28 September: Born reported the listing. At that point FTAPI had not publicly confirmed anything. A reader told Born that their organisation had already been told about an incident "last week." That fits FTAPI's account that it notified customers before any public disclosure.
- 29 September: heise online received FTAPI's confirmation.
- 30 September: Cybernews picked up the story.
Heise notes it is unclear what the listing's "activation" means. With groups like this it usually means publishing data.
What Was Taken
No confirmed data theft has been made public. Heise and Cybernews both report that the leak-site entry gives no details about stolen data. It contains only general company information, apparently copied from FTAPI's website and ZoomInfo. No file samples, data volume or file trees have been posted.
Cybernews's headline calls this a "data breach." FTAPI's statement, as heise reports it, confirms a ransomware deployment on an internal server. It does not confirm that data was taken. Readers should keep those two things separate until the gang posts proof or FTAPI's forensics conclude.
On what was stored on the affected server, dasTECHNO (an AI-assisted outlet) reports that according to FTAPI it held internal services, test and lab systems, and archived email of former employees, and no production data. No other source in this set independently reports that detail. If it is accurate, the likeliest leaked material is internal correspondence, which could include business contacts, customer communications and internal technical details, rather than customer file transfers.
FTAPI says its review of customer systems is complete and found no sign of compromise. Heise reports that further forensic work is still under way.
Why It Matters
- Trust concentration. FTAPI's product exists to move sensitive data safely. HackerFeeds' copy of the listing text describes the company as ISO 27001, BSI C5 and SOC 2 certified, with data hosted only in Germany and optional zero-knowledge encryption. Its customers are mostly regulated organisations, including public administration, healthcare and insurers subject to NIS-2 and DORA. Even if the platform itself is intact, an attacker holding internal email is well placed to impersonate a trusted vendor.
- Phishing risk for customers. dasTECHNO specifically warns FTAPI customers to expect targeted phishing. That is a realistic follow-on threat: stolen correspondence can be turned into convincing lures that look like FTAPI notices, support tickets or file-share invitations.
- The digital sovereignty angle. Cybernews frames FTAPI as a flagship of the EU tech-sovereignty push. According to the listing text, the company markets itself as a GDPR-compliant alternative to US cloud tools and raised €65M from Armira and Tikehau Capital in 2025. An incident here draws attention beyond its technical scope.
- An aggressive actor. The Cyber Threat Intelligence profile describes The Gentlemen as a ransomware-as-a-service operation that appeared around July to August 2025. It reportedly offers affiliates a 90% revenue share and uses a Go-based locker against Windows, Linux, NAS and BSD systems. The same source gives inconsistent victim counts: "over 320 victims," 835 or 893 listed victims, and "more than 1,570 linked victims" found through a compromised C2 server in 2026. It also says the group has listed victims "since February 2023," which contradicts its own 2025 emergence date. Treat these figures as unreliable, other than that the group is high-volume.
The Attack Technique
FTAPI has not said how the attackers got in. Heise explicitly reports that the company gave no information on the initial access vector.
The only technique data in this source set is the Cyber Threat Intelligence aggregator's general profile of The Gentlemen. It maps the group to MITRE ATT&CK T1078 (Valid Accounts) and T1133 (External Remote Services): abusing stolen credentials against VPNs, remote desktop and other exposed remote-access services. That is a general description of the group, not evidence from this intrusion. The target, a single on-premises internal server, fits a pattern of entry through edge devices or credentials followed by ransomware on self-hosted infrastructure. That remains inference until FTAPI's forensic findings are published.
What Organizations Should Do
- Assume FTAPI-branded phishing is coming. Warn users that emails claiming to be from FTAPI, especially file-share notices, "security update" messages or requests to re-authenticate, may be malicious. Verify them through known contacts, not links in the message.
- Review your exposure in FTAPI correspondence. List what your organisation has sent to FTAPI staff by email: contracts, support tickets, configuration details, network information. Assume any of it could be exposed if the leak goes ahead.
- Rotate shared secrets. If API keys, integration credentials, SSO configuration details or admin passwords were ever shared with FTAPI support by email, rotate them now.
- Watch the leak site and ask FTAPI directly. Track the countdown on The Gentlemen's listing. Ask FTAPI in writing for forensic updates, whether exfiltration has been confirmed, and whether your organisation's data was on the affected server. Record your own GDPR and NIS-2 assessment.
- Harden your own remote access. The Gentlemen's documented methods rely on valid accounts and external remote services. Enforce phishing-resistant MFA on VPN, RDP and remote-management tools, remove stale accounts (including former employees'), and patch edge devices promptly.
- Inventory forgotten on-prem systems. FTAPI's affected server held test and lab systems and old email archives, according to dasTECHNO. Test environments and legacy archives are easy to overlook. Segment them from production, retire what is no longer needed, and make sure they are covered by EDR and backups.
Sources: FTAPI data breach confirmed after The Gentlemen ransomware claim C... | Cyber attack on data exchange service FTAPI heise online | Cyberangriff auf Datenaustauschdienst FTAPI heise online | heise Security: "Cyberangriff auf Datenaustausc…" - Heise Medien on... | FTAPI gehackt: Ransomware auf internem Server, Plattform laut Firma... | FTAPI Software Ransomware Attack by Thegentlemen (2026) Cyber Thre... | Ransomware group thegentlemen hits FTAPI Software HackerFeeds | Cybervorfall bei ftapi.com? Opfer der Gentlemen Ransomware?Borns IT...