Ransomware victim disclosure
← All victimsFTAPI Software
Claimed by Thegentlemen · listed 4 hours ago
Status timeline
- ListedSep 26, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Sep 26, 2026
About the victim
AI dossier — public-source company profileFTAPI Software GmbH is a Munich-based enterprise software company founded in 2010 that provides GDPR-compliant secure data exchange, encrypted communications, and workflow automation platforms. It serves 2,000+ organizations and over one million users primarily in public administration, healthcare, insurance, and industrial sectors across Europe, with all infrastructure hosted in Germany and certified under ISO 27001, BSI C5, and SOC 2.
- Industry
- Enterprise Software & Data Security
- Address
- Munich, Germany
- Employees
- 150
- Founded
- 2010
Attack summary
Severity: low — The leak post contains no claimed proof files, screenshots, or technical evidence of data exfiltration or encryption. No specific data categories are named as compromised. The post reads as a company listing without substantiation of an actual attack or data breach.The leak post does not explicitly state what data was exfiltrated or encrypted, nor does it claim operational disruption. The post appears to be a listing/announcement without detailed attack claims or proof of data compromise.
What the group claims
ftapi.com zoominfo.com/c/ftapi-software/346927067 FTAPI (founded 2010, Munich, Germany) is a software company offering a secure, GDPR-compliant platform for exchanging sensitive business data and automating workflows — encrypted email and file transfer, virtual data rooms, digital forms and no-code process automation. It serves 2,000+ organizations and over a million users, mainly in public administration, healthcare, insurance and industry, with all data hosted exclusively in Germany under strict certifications (ISO 27001, BSI C5, SOC 2) and optional zero-knowledge encryption. Its core selling point is European digital sovereignty — a compliant alternative to US cloud tools like Dropbox under GDPR, NIS-2 and DORA regulations. In 2025 it raised €65 million from PE investors Armira and Tikehau Capital, which took control to fund EU expansion and acquisitions. The company employs around 150 people and targets becoming a leading European player in secure data exchange by 2028–29.
Sources
- Victim siteftapi.com
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

