Skip to content
Cyber attack on data exchange service FTAPI

Cyber attack on data exchange service FTAPI

Heise.De • September 29, 2026

Munich-based provider FTAPI offers services for easy data transfer. Its customers include authorities and companies. The criminal online gang The Gentlemen has now claimed a breach into FTAPI’s IT systems on their darknet leaksite.

However, the extortion gang provides no details, only some general information the company FTAPI. This can be found on the company’s website: It was founded in 2010 and now has more than 2000 companies as customers, with more than one million users from administration, health, and industry working with it. A countdown indicates around five more days until the report time. Then the entry apparently “activates” – it is unclear what this specifically means.

FTAPI has confirmed the IT incident when asked by heise online. According to the company, an IT security incident was detected on September 14. Unauthorized individuals gained access to a single, locally operated internal server and injected ransomware . FTAPI consequently isolated the affected systems immediately and involved an external forensics team for investigation. FTAPI also informed customers and partners after initial reliable findings the affected systems were available. FTAPI has complied with supervisory reporting obligations, for example regarding data protection, and has also filed a criminal complaint.

The company emphasizes that the FTAPI platform, customer systems, and data exchanged by customers via it were not affected. The investigation of customer systems has already been completed, and there are no indications that they were compromised. FTAPI’s operations were therefore not restricted at any time. However, further forensic investigations are currently ongoing.

FTAPI has not provided information on how the extortion gang managed to penetrate the server; it is therefore unclear whether a software vulnerability enabled the unauthorized entry or whether the attackers used access data obtained from employees via spearphishing, for example.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Domains (1)

Industries (1)

MITRE ATT&CK (1)