Summary
- FTAPI has confirmed unauthorised access to one internally operated server and deployment of ransomware.
- The company says its customer platform and customer file transfers were not affected.
- The Gentlemen ransomware group has claimed data theft, but that claim remains unverified publicly.
German secure file-transfer provider FTAPI has confirmed that attackers gained access to one internally operated server and deployed ransomware, while saying the incident did not reach its customer platform or data exchanged through the service.
The Munich-based company disclosed details after the ransomware group known as The Gentlemen listed FTAPI among its claimed victims. FTAPI has confirmed the underlying intrusion but has not confirmed the group’s separate claim that information was stolen.
The company says unauthorised individuals accessed a single server operated at one of its own locations. It isolated affected systems, brought in external forensic specialists, informed customers and partners after establishing initial findings, and began the required legal and regulatory response.
FTAPI says systems used to provide its customer platform were not affected and that information transferred by customers through the service was not compromised by the incident.
That distinction materially changes the potential exposure. FTAPI provides secure data-exchange services used by organisations handling sensitive business information, including regulated and confidential material. A compromise of the transfer platform itself could create a downstream incident involving many customers; an intrusion confined to an internal corporate server would have a much narrower operational boundary.
The Gentlemen has nevertheless claimed possession of stolen information. Public evidence establishing what, if anything, left FTAPI’s environment has not been produced, and the company has not disclosed whether the affected server contained data that could substantiate the claim.
The initial access route also remains unclear. There is no confirmed public account showing whether attackers exploited vulnerable software, used compromised credentials, or entered the server through another route.
The investigation therefore has two separate questions to resolve: whether the technical compromise was contained to the infrastructure FTAPI has identified, and whether data left that infrastructure before ransomware was deployed.
Those questions carry additional weight for a company selling secure information exchange. Customers place unusual trust in file-transfer providers because the services are often chosen specifically for data that organisations do not want moving through ordinary email or consumer sharing platforms.
The wider sector has also faced repeated targeting. Previous mass exploitation of managed file-transfer products has demonstrated how one vulnerable supplier can create access to many organisations through a shared service. There is no evidence that the FTAPI incident follows that model, and the company’s current account is that its customer service was untouched.
If forensic work confirms that boundary, the event remains a corporate ransomware incident rather than a compromise of FTAPI’s secure-transfer platform. If investigators establish exfiltration from the internal server, the company will still need to define what information was involved and who was affected.
For now, the ransomware deployment and unauthorised access to one internal server are confirmed. The company says customer transfers were unaffected, while the ransomware group’s claim of stolen data remains an allegation rather than an established consequence.





