A ransomware crew that spent the past three weeks listing dental offices and small American firms is now claiming to hold data from Turkish Airlines, the defense manufacturer ASELSAN and three of Turkey's banks. The leap is abrupt enough that it deserves scrutiny before it deserves alarm.
The crew calls itself CRPxO. IntelFusions tracks extortion leak site postings continuously through ransomware.live, and CRPxO has now posted on three days. It first appeared on July 9 with six healthcare victims, five of them single location US dental practices and the sixth a Chinese biopharmaceutical firm. On July 27 it listed 20 more, again almost entirely small American businesses: dental and orthodontic practices, a hospice care provider, small law firms, local insurance agencies and a handful of tiny hosting and software shops.
On July 31 it posted 10 more, and the character of the list changed completely. Eight are Turkish household names: the flag carrier Turkish Airlines (listed as THY, with 4.2 GB of data claimed), the state linked defense electronics manufacturer ASELSAN (4.5 GB, the largest claim in the batch), the banks Kuveyt Turk, Finansbank and Anadolubank, the insurer Anadolu Sigorta, the discount retail chain A101 and the media and industrial conglomerate Dogan Holding (3.1 GB). The other two entries name Johnson and Johnson and Hyundai, which the leak site lists under the United States and South Korea respectively.
These are claims, not confirmed breaches
Everything above is an unverified extortion claim posted by the group on its own leak site. None of the named organizations has confirmed an intrusion. A leak site listing is not evidence that a network was breached, that any published data is authentic, or that it is recent rather than recycled from an older incident elsewhere.
Several things argue for treating this particular batch skeptically. The first is the profile break itself: a crew whose first two batches were single location dental offices, small law firms and local insurers does not usually reach a national flag carrier and a state linked defense manufacturer in its third. The second is motive. In its own affiliate advertising CRPxO is openly recruiting, pitching a 70 percent revenue share, Monero and Bitcoin payouts, settlement within 24 hours and a 333 dollar one time buy in. A young program that needs to look credible to attract affiliates has an obvious incentive to post trophy names it cannot back up. The third is precedent: recycled and outright invented victim lists have become common enough that we recently covered crews generating fake victims with AI.
The fourth is specific to this batch. Johnson and Johnson has been listed before: a different crew, Space Bears, named Johnson and Johnson Innovative Medicine on its own leak site on May 4, roughly three months before CRPxO claimed the company. Two unrelated groups claiming the same corporate victim is a recognized signature of a listing recycled from somebody else's breach rather than a fresh intrusion. It is not proof, but it is the kind of concrete signal that is worth more than the general argument.
None of that makes the claims false. Affiliates arrive at young programs carrying access they obtained months earlier, and a genuine compromise at a shared supplier can produce a cluster of large names at once. It does mean the burden of proof sits with the group, and so far it has published names and file sizes rather than proof.
What defenders should do
For organizations named in the post, and for peers in Turkish finance, aviation and defense generally, the useful response is verification rather than reaction. Access typically predates a leak site listing by weeks or months, so check for unexplained data egress and for authentication from unfamiliar locations across the past several months rather than only the last few days. Review what third party suppliers and integrators hold on your behalf, since supplier compromise is the most plausible route to a list this varied, and hold public statements until the group actually publishes samples. Anyone tracking the broader picture can follow the running Turkey country profile for incident activity in the region.
CRPxO has posted three times in three weeks. A fourth batch, and whether it finally arrives with published data rather than just names and file sizes, will say more about this group than any of the first three.
Correction, August 1: an earlier version of this article said CRPxO published its first victims four days ago and had posted on two days. The group first posted on July 9, and this is its third batch. The timeline has been corrected throughout, and the article has since been updated with the claimed data volumes and with the earlier Space Bears listing of Johnson and Johnson.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.