The Munich-based secure file-transfer provider FTAPI has confirmed an IT security incident after the criminal gang The Gentlemen posted a claim of a break-in on its darknet leak site. The entry, first spotted by heise online on Tuesday, contains no technical detail — only general company facts — and runs a countdown that had roughly five days left at the time of reporting. What happens when it expires is unclear.

FTAPI's version, given to heise online on request, is specific. The company says it detected a security incident on 14 September in which unauthorised parties gained access to a single, locally operated internal server and deployed ransomware there. The affected systems were isolated immediately, an external forensic team was brought in, and customers and partners were informed once the first reliable findings about exposure were available. FTAPI says it met its supervisory and data-protection reporting obligations and has filed a criminal complaint.

The company draws a sharp line between the compromised internal server and its product. According to FTAPI, the FTAPI platform itself, customer systems, and the data customers exchange through it were not affected; the review of customer systems is complete with no indications of compromise; and service was never disrupted. Further forensic work is ongoing.

FTAPI has not said how the attackers got in. It is therefore unknown whether an unpatched software vulnerability, stolen credentials, or a spear-phishing campaign opened the door — the three routes that account for the overwhelming majority of intrusions at SaaS and managed-service providers.

The context makes the claim consequential. Founded in 2010, FTAPI counts more than 2,000 companies as customers, among them public authorities, healthcare organisations and industrial firms, with more than a million users working through the service. Data-exchange platforms sit deliberately close to sensitive material: the whole point of buying one is to move documents that ordinary email or consumer file-sharing is not considered safe enough for.

That is exactly why attackers target them, and why an intrusion into an internal server — even one the vendor says never touched production data — has to be taken seriously. Third-party providers concentrate risk: one successful compromise can reach many organisations at once, and the victims learn about it from their supplier rather than from their own logs. The Gentlemen have built a reputation for aggressive extortion and public leak-site pressure rather than quiet negotiation, which raises the stakes of the countdown.

Investigations at this stage are typically slow. Forensics will try to establish whether the intruders moved laterally from the internal server, whether any credentials or customer metadata were staged for exfiltration, and whether the ransomware was deployed to destroy evidence as much as to extort. FTAPI's statement that customer systems are clean is a claim about what has been checked so far, not a final finding — the company says reviews continue.

What to watch: whether the leak site publishes data when the countdown ends, whether other European data-exchange and managed-file-transfer providers report similar intrusions, and whether the German supervisory authorities open a formal proceeding. Customers of any such platform should, in the meantime, audit which documents they have routed through it and rotate any credentials shared via the service.