Ransomware Group The Gentlemen Claims Attack on German Secure-File Firm FTAPI Software

A criminal gang that has posted dozens of claimed victims in recent months has listed FTAPI Software on its dark-web extortion site. The Munich company serves hospitals, insurers and public agencies across Europe. Nothing has been confirmed.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • The Gentlemen listed FTAPI Software, a German provider of encrypted file-transfer and workflow tools, on its extortion site on 2026-09-25, first observed by the monitoring service Ransomware.live.
  • FTAPI has not publicly confirmed any incident, and the claim could not be independently verified at the time of publication.
  • The group's post describes FTAPI as serving more than 2,000 organisations and over one million users, figures attributed to the attackers and not independently confirmed.
  • The listing was observed live by Threat Vectr on 28 September 2026 at 04:54 UTC.

Ransomware gangs run so-called leak sites, pages on the dark web where criminals name companies they claim to have attacked. The tactic is pressure: pay up, or we release your data. Listings can precede any public confirmation by days or weeks. They're sometimes exaggerated. Occasionally, they're false.

The Gentlemen's listing on 2026-09-25 named FTAPI Software, a Munich-based company founded in 2010 that sells encrypted email and secure file-transfer tools, pitched as a European alternative to US cloud services under GDPR and related rules. According to the group's post, the company holds certifications including ISO 27001, BSI C5 and SOC 2, and serves clients in public administration and healthcare. Those details are written by the attackers to make the listing look credible and to maximise pressure on the target. Read them accordingly.

The group's post also claims FTAPI raised €65 million from private-equity investors Armira and Tikehau Capital in 2025. That kind of funding round is publicly visible, which is probably why the attackers highlighted it: it signals the company can pay.

How active is this group?

Active enough to have featured in our coverage repeatedly. We reported on The Gentlemen in September, when the group claimed to have stolen millions of patient records from Chicago health-tech firm Veradigm after using a vendor's credentials to access a customer-service API. That's the pattern worth watching: credential-based entry, high-value data, public pressure via the leak site.

Manufacturing is the most commonly listed sector in the group's posts, though claims have spread across multiple industries. These are aggregate counts of unverified criminal claims, not confirmed breaches.

Groups that post this frequently tend to reuse working methods across targets rather than crafting bespoke attacks each time. Volume is the tell.

Should FTAPI's customers do anything right now?

Waiting for confirmation before acting is reasonable. Nothing's proven. A few sensible steps cost nothing while the picture is unclear, though.

If you use FTAPI's platform for file transfers or secure messaging, watch your inbox. Criminals sometimes use the publicity around a leak-site listing to send fake emails pretending to be the company, a tactic called phishing, where fraudulent messages try to trick you into handing over a password or clicking a harmful link. Be especially wary of any email offering "breach compensation" or asking you to verify your account urgently.

If you've reused your FTAPI password anywhere else, change it on those other accounts now. Enabling two-factor authentication, where a second check beyond your password is required to log in, is worth doing on any account that holds sensitive data.

FTAPI hasn't issued a public statement, and no regulatory filing confirming an incident has appeared as of publication.

© 2026 Threat Vectr