Cybernews FTAPI Data Breach Linked to The Gentlemen Ransomware Gang
Article Content
- •FTAPI confirmed a breach involving The Gentlemen ransomware gang.
- •The attack affected one internal server, not customer systems or data.
- •A countdown on the gang's leak site suggests an imminent data release.
FTAPI, a Munich-based file transfer platform, confirmed a data breach after the ransomware group The Gentlemen claimed responsibility. The attackers accessed one internal server but did not compromise customer systems or data. FTAPI isolated the affected systems and engaged forensic investigators to assess the incident. The breach was detected on September 14, and FTAPI has since notified customers and filed a criminal complaint. The Gentlemen has not provided specific details about the data allegedly stolen, and a countdown on their leak site indicates an activation in approximately five days. The method of access to the server remains unclear, with possibilities including unpatched vulnerabilities or spearphishing. FTAPI serves over 2,000 businesses and more than one million users across various sectors, including government and healthcare.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Qilin and Ftapi in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…