CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
ROUTINENATOB2incident

FTAPI, a file-transfer vendor whose customers include authorities, confirms ransomware on an internal server; The Gentlemen list it on their leak site

A file-transfer supplier to authorities had ransomware on one internal server; the vendor says its platform is untouched

Analysis

FTAPI told heise it detected ransomware on a single internal server on 2026-09-14 and says its platform, customer systems and exchanged data were not affected, while The Gentlemen listed it on their leak site with a countdown heise read as about five days and FTAPI has not said how the server was reached (heise online, 2026-09-29; Cybernews, 2026-09-30). The Canton of Lucerne's portal names FTAPI SecuTransfer as its secure file-transfer service and lists the notification data it collects: names, phone number, email address, company and position (Kanton Luzern).

Exposure: customers of FTAPI SecuTransfer; the vendor's statement covers the platform and the exchanged data, not what the compromised internal server held.

Cited evidence

Unauthorized individuals gained access to a single, locally operated internal server

The company emphasizes that the FTAPI platform, customer systems, and data exchanged by customers via it were not affected.

heise online (relaying FTAPI's statement)

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.