CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

FTAPI ransomware incident and The Gentlemen leak-site claim (September 2026)

incident · incident:ftapi-ransomware-gentlemen-claim-2026-09 single-source-victim

FTAPI Software of Munich, a secure file-transfer vendor whose customers include authorities, said it detected ransomware on a single internal server on 2026-09-14 and that its platform, customer systems and exchanged data were not affected; The Gentlemen listed it on their leak site with a countdown heise read as about five days on 2026-09-29 (heise online, 2026-09-29).

Aliases: FTAPI ransomware

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
A file-transfer supplier to authorities had ransomware on one internal server; the vendor says its platform…
Peak priority
routine
1 routine
Targets
public-sector
sectors: public-sector, technology · regions: europe, dach
Sources cited
3
3 hosts

Defender insights

What each entry about FTAPI ransomware incident and The Gentlemen leak-site claim (September 2026) tells a defender to do, newest first.

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-10-02FTAPI, a file-transfer vendor whose customers include authorities, confirms ransomware on an internal server; The Gentlemen list it on their leak site
    active-threatsA file-transfer supplier to authorities had ransomware on one internal server; the vendor says its platform is untouched
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ImpactData Encrypted for Impact

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-10-02/ftapi-ransomware-the-gentlemen-supplier-to-authorities · ATT&CK page ↗

Entries about FTAPI ransomware incident and The Gentlemen leak-site claim (September 2026) (1)

2026-10-02 · view entry permalink →

ROUTINENATOB2

FTAPI, a file-transfer vendor whose customers include authorities, confirms ransomware on an internal server; The Gentlemen list it on their leak site

FTAPI told heise it detected ransomware on a single internal server on 2026-09-14 and says its platform, customer systems and exchanged data were not affected, while The Gentlemen listed it on their leak site with a countdown heise read as about five days and FTAPI has not said how the server was reached (heise online, 2026-09-29; Cybernews, 2026-09-30). The Canton of Lucerne's portal names FTAPI SecuTransfer as its secure file-transfer service and lists the notification data it collects: names, phone number, email address, company and position (Kanton Luzern).

Exposure: customers of FTAPI SecuTransfer; the vendor's statement covers the platform and the exchanged data, not what the compromised internal server held.

Unauthorized individuals gained access to a single, locally operated internal server

The company emphasizes that the FTAPI platform, customer systems, and data exchanged by customers via it were not affected.

heise online (relaying FTAPI's statement)

Builds on: Cisco Talos maps The Gentlemen's AD attack chain, including credential theft from a mounted…

incident02 Oct 04:52Zsingle-source · victim disclosureOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • cybernews.com1 (33%)
  • heise.de1 (33%)
  • kantonale-verwaltung.lu.ch1 (33%)