thegentlemenRansomware Victim๐Ÿ‡บ๐Ÿ‡ธ US OrganizationTechnology

FTAPI Software

ftapi.com zoominfo.com/c/ftapi-software/346927067 FTAPI (founded 2010, Munich, Germany) is a software company offering a secure, GDPR-compliant platform for exchanging sensitive business data and automating workflows โ€” encrypted email and file transfer, virtual data rooms, digital forms and no-code process automation. It serves 2,000+ organizations and over a million users, mainly in public administration, healthcare, insurance and industry, with all data hosted exclusively in Germany under strict certifications (ISO 27001, BSI C5, SOC 2) and optional zero-knowledge encryption. Its core selling point is European digital sovereignty โ€” a compliant alternative to US cloud tools like Dropbox under GDPR, NIS-2 and DORA regulations. In 2025 it raised โ‚ฌ65 million from PE investors Armira and Tikehau Capital, which took control to fund EU expansion and acquisitions. The company employs around 150 people and targets becoming a leading European player in secure data exchange by 2028โ€“29.

Incident Details

Threat Group
thegentlemen
Victim / Organization
FTAPI Software
Website / Domain
ftapi.com
Industry Sector
Technology
Country / Region
๐Ÿ‡บ๐Ÿ‡ธ US
Date Discovered
Saturday, September 26, 2026

What This Listing Means

Posting on thegentlemen's ransomware leak site typically signals that the threat actor claims to have:

  • โ–ธGained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
  • โ–ธExfiltrated sensitive data โ€” potentially including financial records, PII, customer data, or trade secrets
  • โ–ธDeployed ransomware to encrypt systems and disrupt operations
  • โ–ธIssued a ransom demand with a deadline to publish all stolen data publicly if unpaid

๐Ÿ‡บ๐Ÿ‡ธ US-based organizations hit by ransomware may have mandatory breach notification obligations under state laws, HIPAA (healthcare), SEC regulations (public companies), or CISA guidelines. The notification window is typically 72 hours from discovery.

Is This Your Organization?

Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.

Get Emergency ResponseIR Services Overview

Protect Your Organization

โ† Back to Ransomware Tracker