CSIDB logo
Threat actor

TurkHackTeam

Attribution profile

Type
Activist
Location
Turkey
Known incidents
9 incidents
First seen
2014-01-15
Last seen
2023-04-04
Updated
2026-07-22 02:02
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

TurkHackTeam, also known as TurkGuvenligi, is a Turkish hacking collective that has been active since at least 2014 and operates from Turkey. The group uses the aliases TurkHackTeam and TurkGuvenligi in its public communications and has claimed responsibility for a series of website defacements. Its activities are primarily described in open‑source reports that link the aliases to specific incidents involving political protest messages displayed on compromised web assets.

The collective’s targeting has focused on governmental and financial institutions as well as international organizations when motivated by geopolitical events. In April 2023 TurkHackTeam defaced Danish banks and government agencies, stating that the attacks were a response to a Quran‑burning incident in Denmark and were intended to convey political protest. Earlier, in July 2014 the group operating as TurkGuvenligi defaced two United Nations sub‑domains, esango.un.org and escwa.un.org, in connection with the #OpSaveGaza campaign. The same actor also compromised the hosting provider of the Syrian Electronic Army in January 2014, using that access to deface the SEA’s website and leave a taunting message, and previously defaced the OpenSSL website with a similar signature. These examples show a pattern of targeting entities perceived as opposing the group’s political stance.

The observed tactics, techniques, and procedures consist mainly of gaining unauthorized access to web hosting environments—often through weak or compromised credentials—and then replacing website content with protest‑oriented messages. No malware families, exploit kits, or persistent backdoors are mentioned in the source material; the group’s tooling style appears limited to web defacement scripts or direct file manipulation after obtaining host‑level access. Attribution to a state sponsor or criminal consortium is not publicly established; the group is presented as an independent hacktivist collective acting from Turkey. The most notable campaigns referenced are the 2023 Danish bank and agency defacements, the 2014 UN sub‑domain incursions under #OpSaveGaza, and the 2014 compromise of the Syrian Electronic Army’s hosting provider that led to the defacement of both SEA and OpenSSL sites. These incidents collectively illustrate the actor’s focus on politically motivated disruption through website alteration rather than financial gain or espionage.

Incidents

Attributed incidents are available to members.

9 incidents
CSIDB