Turkish Ajan
Attribution profile
- Type
- Activist
- Location
- Turkey
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2014-02-20
- Last seen
- 2014-02-20
- Updated
- 2026-07-31 06:05
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Turkish Ajan is a hacker group that operates under the alias Turkish Ajan and is known to be based in Turkey. The group first came to public attention in February 2014 when it claimed responsibility for a breach of Mercantile Communications Pvt. Ltd., a major Nepali internet service provider. In that incident the attackers leaked the internal database structure and over 100 employee records containing names and email addresses, while stating they had also accessed phone numbers and physical addresses but chose not to disclose those details to protect individual privacy. The group described the attack as a means to announce their comeback after a period of inactivity.
According to the hackers’ own statements, their strategic objective is to shift focus toward government organizations in the United States, Israel, and China, citing political and religious grievances against those nations. They characterized the United States as a “terrorist country” that is against Islam, and described China and Israel as entities that are “killing Muslims,” which motivates their intended targeting of government sites in those countries. This declared focus indicates a motivation rooted in ideological rather than financial gain, as the group explicitly frames its actions as a response to perceived injustices.
The only publicly documented operation attributed to Turkish Ajan remains the 2014 breach of the Nepali ISP, during which they demonstrated the ability to exfiltrate structural and personal data from a corporate network. No further campaigns, malware families, initial access vectors, or tooling details have been reported in open sources, and no affiliations with state actors or criminal consortia have been established. Consequently, the profile is limited to the confirmed facts of the group’s alias, location, the single attributed incident, and the self‑described future targeting intentions.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.