German secure data transfer provider FTAPI has confirmed a ransomware attack on its internal infrastructure after the cybercrime group The Gentlemen listed the company on its data leak site.

 

 

The Munich-based company provides encrypted file transfers, email services, protected data rooms and other tools designed for organizations handling sensitive information. More than 2,000 organizations and over one million users across government, healthcare and industry rely on its platform.

FTAPI said unauthorized attackers gained access to a single internally operated server at one of its local sites. Ransomware was deployed on that system, prompting the company to isolate affected infrastructure and bring in external cybersecurity and forensic specialists to investigate the incident.

Crucially, FTAPI says its main customer platform was not compromised. The systems used by customers and the information exchanged through FTAPI services were not affected, according to the company’s current investigation.

The separation is significant because FTAPI is specifically designed to handle potentially sensitive documents and communications. Its products include encrypted email, secure online forms, protected collaboration spaces and automated data exchange systems, meaning a compromise of the production environment could potentially have affected information belonging to many organizations.

However, the incident did involve internal FTAPI information. The compromised environment reportedly included internal services, test and laboratory systems without production data, as well as archived email communications belonging to former employees.

FTAPI’s investigation indicates that some information from those archived emails was taken during the attack. Because former employees may have communicated with customers and business partners, the stolen material could contain information connected to outside organizations, although the company has not yet provided a detailed breakdown of the affected records.

The Gentlemen has claimed responsibility for the attack and added FTAPI to its dark web leak site. The ransomware operation placed a countdown on the listing, threatening to make stolen information available after the deadline expires.

At the time the attack became public, the group had not released evidence demonstrating what information it possessed. Its listing largely contained publicly available details about FTAPI, so the hackers’ broader claims about stolen data could not be independently confirmed.

FTAPI said it informed customers and partners after obtaining reliable initial findings from its investigation. The company also fulfilled relevant regulatory reporting requirements, including data protection notifications, and filed a criminal complaint with authorities.

How the attackers initially entered the internal server remains unclear. FTAPI has not publicly identified a vulnerability, stolen account, or other specific access method responsible for the compromise.

The attack is particularly notable because FTAPI promotes itself as a European alternative for organizations seeking greater control over sensitive information. Its services are hosted exclusively on servers in Germany, and the company holds security and compliance certifications including ISO 27001 and BSI C5.

Despite the ransomware infection, FTAPI says its service remained operational, and its customer environment has been examined without finding evidence of compromise. The forensic investigation into information taken from the internal server continues, leaving the exact contents of the stolen archived communications as the main unresolved part of the incident.

Leave a Reply