Back to Exposure Report
Cross-Sector / National CampaignAugust 3, 2026Turkey

CRPxO — Turkey Campaign

The national flag carrier. The defense contractor. Three banks, an insurer, a media group, an automaker, the largest grocery chain. All posted the same day, by the same group.

Not yet disclosedPassenger and loyalty data (inferred)Defense program documentation (inferred)Banking account records (inferred)Insurance policy and claims files (inferred)
1

What happened?

On August 3, 2026, a group operating as CRPxO published a coordinated set of victim listings targeting Turkish organizations: Turkish Airlines, Aselsan, QNB, Kuveyt Türk, Anadolubank, Anadolu Sigorta, Doğan Holding, Togg, Hyundai Motor Türkiye, A101, and Encore Enterprises.

The claims have not been independently verified as of this writing, and none of the named organizations had publicly confirmed a breach at the time of publication. Specific data types have not been disclosed for any listed entity. What is observable is the pattern: eleven organizations, one country, one day, one actor.

2

What data was actually inside?

Not yet disclosed for any of the listed organizations.

Reading the target list by sector indicates what the underlying records would be expected to contain, clearly labeled as inference: passenger manifests, frequent flyer profiles and travel histories at the airline; account and transaction records at QNB, Kuveyt Türk, and Anadolubank; policy and claims files at Anadolu Sigorta; customer and loyalty data at A101; and program, supplier, and export documentation at Aselsan.

Aselsan is the entry that changes the character of the list. A state-linked defense electronics manufacturer holds material where the sensitivity is national rather than personal.

3

Who gets hurt and how?

If the consumer-facing claims hold, the affected populations overlap heavily. A Turkish adult may hold an account at one of the listed banks, a policy with the listed insurer, a frequent flyer number with the flag carrier, and a loyalty card at the grocery chain. Aggregated across a single campaign, those datasets compose into a detailed profile: finances, travel, health-adjacent insurance claims, and daily movement.

That aggregation is the harm that individual breach notifications never capture. Each company assesses its own exposure in isolation and concludes, correctly, that its dataset alone supports limited fraud. The attacker holds the combination.

For Aselsan, the potential harm has no individual victim and no notification framework. Defense program documentation and supplier relationships, if exposed, affect national capability and third-country partners — a category of damage that breach law was never designed to address.

4

What did they think they were doing right?

While not publicly confirmed for these organizations, the listed entities operate in Turkey's most heavily regulated sectors. Turkish banks are supervised by the BDDK with prescriptive information security requirements. Aviation carries international security obligations. A defense manufacturer operates under national security controls stricter than anything in the commercial sector. Turkey's KVKK data protection law applies across all of them.

Each of these organizations almost certainly meets its sectoral requirements, and each does so independently. That independence is the assumption worth questioning. Sectoral regulation produces vertical compliance — banks are secured to banking standards, airlines to aviation standards — and nothing in that model gives any participant visibility into a campaign running horizontally across all of them simultaneously.

5

What did they not know about their own data?

Cross-sector campaigns get read as a geopolitical story, and at the national level they are one. For each named organization it is a very ordinary problem, and the ordinariness is the point: prove what was in the environment, prove whose data it was, and do it while ten domestic peers are running the same drill and the press is covering all of it as one event.

Being listed alongside ten others changes nothing about the internal work. It does change the timeline pressure — a company that can confirm or refute quickly separates itself from the group, and a company that cannot is grouped with whichever listing turns out to be worst.

Eleven organizations in one day also raises a question none of them can answer alone: was this eleven separate intrusions, or one shared exposure — a common vendor, a shared platform, a regional service provider? Determining that requires each victim to know precisely what it holds and where it came from, and then to share findings with competitors. Neither happens quickly.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

Turkey's KVKK requires notification to the Personal Data Protection Authority within 72 hours of becoming aware of a personal data breach, with notification to affected individuals as soon as reasonably possible. Each listed organization runs that determination separately. The banks additionally answer to the BDDK, and Turkish Airlines to aviation authorities and, for EU passengers, to GDPR.

Aselsan sits outside the consumer framework entirely. A defense manufacturer's response runs through national security channels rather than data protection authorities, with disclosure decisions driven by classification rules rather than notification statutes — which typically means the public learns least about the listing that may matter most.

Because CRPxO published simultaneously, all eleven timelines start on the same day. Turkey's incident response capacity, forensic firms, and specialist counsel are finite and now oversubscribed.

7

What would have changed the outcome?

For each organization individually: the ability to confirm or refute its own listing within hours, using an inventory that already existed — rather than being defined by the worst claim in the group.

When a leak site names a dozen companies in your market at once, the collective story is out of your control. What remains in your control is whether you can speak precisely about your own systems while everyone else is still investigating. That capability is not built during the campaign. Cross-sector campaigns reward the organizations that already knew what they held and expose the ones learning it in public. Compare the ExfilSquad mass listing, where fifteen organizations were named in a single day through one shared misconfiguration.

The organizations CRPxO listed found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.