LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › FTAPI Software Listed by The Gentlemen Ransomware Group

HIGH severityUnverified claimHow we verify

FTAPI Software Listed by The Gentlemen Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 25, 2026
FTAPI Software Listed by The Gentlemen Ransomware Group

Reported September 25, 2026.

HIGH
Severity
September 25, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

FTAPI Software was listed by the ransomware group The Gentlemen on September 25, 2026; the group claims to hold data belonging to an undisclosed number of individuals, but the organisation has not confirmed or commented on the listing. Anyone who may have shared information with FTAPI should review their accounts and monitor for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On September 25, 2026, the ransomware group known as The Gentlemen listed FTAPI Software on its leak site. That listing is an unverified claim by the group. As of writing, FTAPI Software has not publicly confirmed that an incident occurred, and independent confirmation from regulators or established breach indexes is not reflected in the available record. Public detail on timing, method, scale, and any data involved remains limited.

FTAPI provides tools for exchanging sensitive business information. A leak-site claim against a firm in that role matters because customers and partners may want to understand what is actually known, what is only alleged, and what practical steps make sense if their information were ever involved. Nothing in the public listing alone establishes that files left the company or that any particular person was affected.

What is being claimed

The Gentlemen have listed FTAPI Software on their leak site, according to reporting dated September 25, 2026. The available facts do not describe how the group says it obtained access, whether a ransom demand was made, what volume of material is allegedly held, or when any intrusion is said to have taken place. The number of people potentially affected is unknown. Data types named as exposed are not disclosed in the record provided.

A leak-site listing is a form of pressure commonly used by extortion crews. It signals that the group wants attention and leverage; it does not, by itself, prove that a breach succeeded, that sample files are authentic, or that a full dataset will be published. Readers should treat the listing as an accusation until the company, a regulator, or other authoritative sources confirm or deny it.

Who is The Gentlemen?

The Gentlemen are known publicly as a ransomware and extortion actor. Groups in this category typically encrypt systems or claim to have copied data, then threaten publication on a dedicated leak site if payment is not made. Public reporting on such actors often describes double-extortion patterns: disruption inside the victim environment paired with the threat of leaking stolen files. Tactics, tooling, and victim selection can vary over time and are not fixed for every listing.

For this specific case, the only incident-related assertion in the facts is that the group listed FTAPI Software. No further claims by The Gentlemen about this victim—such as file counts, screenshots, or technical narratives—are included in the material supplied for this article. Any broader reputation the group has from other reported activity should not be read as proof of what happened at FTAPI.

Who is FTAPI Software?

FTAPI Software is a Munich-based software company founded in 2010. It offers a platform aimed at secure, GDPR-oriented exchange of sensitive business data and related workflow automation, including encrypted email and file transfer, virtual data rooms, digital forms, and no-code process automation. Public descriptions state that it serves more than 2,000 organizations and over a million users, with a concentration in public administration, healthcare, insurance, and industry, and that data is hosted in Germany under certifications such as ISO 27001, BSI C5, and SOC 2, with optional zero-knowledge encryption among its offerings.

Organizations that build products for moving regulated or confidential business content sit in a consequential spot in the supply chain. Customers often rely on them precisely because the workloads involve contracts, personal data, health-related information, or other material that must stay controlled. A public extortion listing against such a vendor can raise questions for clients even when the underlying claim is unconfirmed, because the hypothetical blast radius includes not only the vendor’s own staff records but also data customers may have entrusted to the service. That consequence flows from the sector’s role, not from any verified finding about this listing.

What data was at risk

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say what, if anything, was taken. Asserting a specific inventory would go beyond the record and would treat attacker marketing as an audit.

If files were taken from a company in this sector, firms of this kind typically hold combinations of business contact data, account and tenancy metadata, support correspondence, configuration details, and—depending on how customers use the product—documents and form submissions that may include personal or commercially sensitive content. Whether any of that was involved here is unconfirmed. People affected are listed as unknown.

The real-world impact

Until there is confirmation, the concrete impact on individuals and on FTAPI remains speculative. Leak-site listings can still create operational and reputational strain: customers may open tickets, security teams may review logs and vendor risk questionnaires, and staff may face phishing that pretends to reference the alleged incident. Extortion groups sometimes release samples or full archives later; sometimes listings appear and little further material follows. Neither outcome should be assumed from the listing date alone.

If data were eventually shown to have been copied, real-world risks for affected people would depend on the content. Typical concerns in this industry context include targeted phishing, social engineering that cites internal project names, fraud against businesses using stolen invoices or contracts, and long-term misuse of personal details where regulated data were present. For the organisation, an confirmed event would usually mean investigation costs, customer notification duties where the law requires them, and possible contractual follow-up. None of those outcomes are established by the current claim.

If your data was involved

Because the listing is unverified and the company has not publicly confirmed an incident as of writing, treat the following as precautions for the possibility that your information was involved—not as a statement that it was.

In short: The Gentlemen have listed FTAPI Software; the claim is unconfirmed; scale and data types are undisclosed; and sensible hygiene is conditional on risk, not on an established inventory of stolen files.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyFTAPI Software security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See FTAPI Software’s full breach history →

More recent breaches

Enkei******* Listed by The Gentlemen Ransomware GroupSeptember 24, 2026Charles Keith Listed by The Gentlemen Ransomware GroupSeptember 24, 2026Ligue se Grupo Listed by The Gentlemen Ransomware GroupSeptember 24, 2026ANP Health Listed by The Gentlemen Ransomware GroupSeptember 21, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the FTAPI Software Listed by The Gentlemen Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by thegentlemen — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram