FTAPI, a file-transfer vendor whose customers include authorities, confirms ransomware on an internal server; The Gentlemen list it on their leak site
A file-transfer supplier to authorities had ransomware on one internal server; the vendor says its platform is untouched
Analysis
FTAPI told heise it detected ransomware on a single internal server on 2026-09-14 and says its platform, customer systems and exchanged data were not affected, while The Gentlemen listed it on their leak site with a countdown heise read as about five days and FTAPI has not said how the server was reached (heise online, 2026-09-29; Cybernews, 2026-09-30). The Canton of Lucerne's portal names FTAPI SecuTransfer as its secure file-transfer service and lists the notification data it collects: names, phone number, email address, company and position (Kanton Luzern).
Exposure: customers of FTAPI SecuTransfer; the vendor's statement covers the platform and the exchanged data, not what the compromised internal server held.
Cited evidence
Unauthorized individuals gained access to a single, locally operated internal server
The company emphasizes that the FTAPI platform, customer systems, and data exchanged by customers via it were not affected.
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.