Cyber & AI intelligence
Wasteland.
Briefs indexed2946
Issues30
Published Mondays07:30 CT
█ Ransomware FTAPI-THE-GENTLEME 2026-09-30

FTAPI: The Gentlemen Ransomware Hits Secure File-Transfer Provider

"FTAPI Software GmbH has confirmed a security incident. The Munich company sells secure data exchange to German and European public authorities, hospitals and industrial firms. The Gentlemen ransomware group has listed…"

FTAPI Software GmbH has confirmed a security incident. The Munich company sells secure data exchange to German and European public authorities, hospitals and industrial firms. The Gentlemen ransomware group has listed FTAPI on its dark web leak site with a countdown of about five days before the entry "activates." FTAPI confirmed the incident to heise online. It says attackers got into a single internal server that ran on premises and deployed ransomware on it. The company says its customer-facing platform, customer systems and the files customers exchange were not affected. FTAPI says it serves more than 2,000 organisations and over one million users in government, healthcare and industry, so the claim adds supply-chain risk for a large, sensitive customer base. The gang has not yet posted any proof of stolen data.

What Happened

According to FTAPI's statement to heise online, the company detected the incident on 14 September 2026. It says unauthorised people got into one internal server that ran at a local site and deployed ransomware on it. FTAPI says it then:

The Gentlemen's leak-site entry came about 11 days after detection. The exact listing date differs slightly by source. Günter Born's blog, dasTECHNO and HackerFeeds give 25 September. The Cyber Threat Intelligence aggregator gives 26 September, and HackerFeeds records 26 September as its own "discovery date." Aggregator entries also label FTAPI as a US company. That is an error: every other source, including FTAPI's own company profile quoted in the listing, places it in Munich.

The public timeline developed over several days:

Heise notes it is unclear what the listing's "activation" means. With groups like this it usually means publishing data.

What Was Taken

No confirmed data theft has been made public. Heise and Cybernews both report that the leak-site entry gives no details about stolen data. It contains only general company information, apparently copied from FTAPI's website and ZoomInfo. No file samples, data volume or file trees have been posted.

Cybernews's headline calls this a "data breach." FTAPI's statement, as heise reports it, confirms a ransomware deployment on an internal server. It does not confirm that data was taken. Readers should keep those two things separate until the gang posts proof or FTAPI's forensics conclude.

On what was stored on the affected server, dasTECHNO (an AI-assisted outlet) reports that according to FTAPI it held internal services, test and lab systems, and archived email of former employees, and no production data. No other source in this set independently reports that detail. If it is accurate, the likeliest leaked material is internal correspondence, which could include business contacts, customer communications and internal technical details, rather than customer file transfers.

FTAPI says its review of customer systems is complete and found no sign of compromise. Heise reports that further forensic work is still under way.

Why It Matters

The Attack Technique

FTAPI has not said how the attackers got in. Heise explicitly reports that the company gave no information on the initial access vector.

The only technique data in this source set is the Cyber Threat Intelligence aggregator's general profile of The Gentlemen. It maps the group to MITRE ATT&CK T1078 (Valid Accounts) and T1133 (External Remote Services): abusing stolen credentials against VPNs, remote desktop and other exposed remote-access services. That is a general description of the group, not evidence from this intrusion. The target, a single on-premises internal server, fits a pattern of entry through edge devices or credentials followed by ransomware on self-hosted infrastructure. That remains inference until FTAPI's forensic findings are published.

What Organizations Should Do

  1. Assume FTAPI-branded phishing is coming. Warn users that emails claiming to be from FTAPI, especially file-share notices, "security update" messages or requests to re-authenticate, may be malicious. Verify them through known contacts, not links in the message.
  2. Review your exposure in FTAPI correspondence. List what your organisation has sent to FTAPI staff by email: contracts, support tickets, configuration details, network information. Assume any of it could be exposed if the leak goes ahead.
  3. Rotate shared secrets. If API keys, integration credentials, SSO configuration details or admin passwords were ever shared with FTAPI support by email, rotate them now.
  4. Watch the leak site and ask FTAPI directly. Track the countdown on The Gentlemen's listing. Ask FTAPI in writing for forensic updates, whether exfiltration has been confirmed, and whether your organisation's data was on the affected server. Record your own GDPR and NIS-2 assessment.
  5. Harden your own remote access. The Gentlemen's documented methods rely on valid accounts and external remote services. Enforce phishing-resistant MFA on VPN, RDP and remote-management tools, remove stale accounts (including former employees'), and patch edge devices promptly.
  6. Inventory forgotten on-prem systems. FTAPI's affected server held test and lab systems and old email archives, according to dasTECHNO. Test environments and legacy archives are easy to overlook. Segment them from production, retire what is no longer needed, and make sure they are covered by EDR and backups.

Sources: FTAPI data breach confirmed after The Gentlemen ransomware claim C... | Cyber attack on data exchange service FTAPI heise online | Cyberangriff auf Datenaustauschdienst FTAPI heise online | heise Security: "Cyberangriff auf Datenaustausc…" - Heise Medien on... | FTAPI gehackt: Ransomware auf internem Server, Plattform laut Firma... | FTAPI Software Ransomware Attack by Thegentlemen (2026) Cyber Thre... | Ransomware group thegentlemen hits FTAPI Software HackerFeeds | Cybervorfall bei ftapi.com? Opfer der Gentlemen Ransomware?Borns IT...