New extortion crew claims Turkey's banks and flag carrier

A ransomware leak site that published its first victims four days ago is now claiming to hold data from Turkish Airlines, the defense manufacturer ASELSAN and three of Turkey's banks. The leap is abrupt enough that it deserves scrutiny before it deserves alarm.

The crew calls itself CRPxO. IntelFusions tracks extortion leak site postings continuously through ransomware.live, and CRPxO's entire recorded history amounts to two posting days. On July 27 it listed 20 victims, nearly all of them small American businesses: dental and orthodontic practices, a hospice care provider, two small law firms, local insurance agencies and a handful of tiny hosting and software shops.

On July 31 it posted 10 more, and the character of the list changed completely. Seven are Turkish household names: the flag carrier Turkish Airlines (listed as THY), the state linked defense electronics manufacturer ASELSAN, the banks Kuveyt Turk, Finansbank and Anadolubank, the insurer Anadolu Sigorta, the discount retail chain A101 and the media and industrial conglomerate Dogan Holding. The remaining entries name Johnson and Johnson and Hyundai.

These are claims, not confirmed breaches

Everything above is an unverified extortion claim posted by the group on its own leak site. None of the named organizations has confirmed an intrusion. A leak site listing is not evidence that a network was breached, that any published data is authentic, or that it is recent rather than recycled from an older incident elsewhere.

Three things argue for treating this particular batch skeptically. The first is the profile break itself: a crew whose opening slate was single location dental offices does not usually reach a national flag carrier and a defense manufacturer four days later. The second is motive. In its own affiliate advertising CRPxO is openly recruiting, pitching a 70 percent revenue share, Monero and Bitcoin payouts, settlement within 24 hours and a 333 dollar one time buy in. A brand new site that needs to look credible to attract affiliates has an obvious incentive to post trophy names it cannot back up. The third is precedent: recycled and outright invented victim lists have become common enough that we recently covered crews generating fake victims with AI.

None of that makes the claims false. New affiliates arrive at new programs carrying access they obtained months earlier, and a genuine compromise at a shared supplier can produce a cluster of large names at once. It does mean the burden of proof sits with the group, and so far it has published names rather than proof.

What defenders should do

For organizations named in the post, and for peers in Turkish finance, aviation and defense generally, the useful response is verification rather than reaction. Check for unexplained data egress and for authentication from unfamiliar locations across the window since May, review what third party suppliers and integrators hold on your behalf, since supplier compromise is the most plausible route to a list this varied, and hold public statements until the group actually publishes samples. Anyone tracking the broader picture can follow the running Turkey country profile for incident activity, and our recent look at how a low profile crew built its victim list shows how quickly a leak site's real pattern becomes visible once it has posted a few times.

CRPxO has posted twice. A third batch, and whether it comes with published data, will say more about this group than either of the first two.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions