Cyber Incident Victim: Berat Albayrak
Date:
May 2021
Location:
Turkey
Summary
A Marxist hacker group breached the personal email accounts of a Turkish government minister, revealing coordinated efforts by pro-government actors to suppress opposition voices and media criticism through targeted social media manipulation. The leaked correspondence exposed strategies for silencing dissent, with the hackers threatening further data releases unless political prisoners were freed, highlighting systemic censorship mechanisms and their impact on public discourse.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In September 2016, the Marxist hacker collective RedHack breached the personal email accounts of Berat Albayrak, Turkey’s Energy Minister and son-in-law of President Recep Tayyip Erdoğan. The group publicly claimed responsibility for the intrusion on September 26, 2016, threatening to release sensitive data unless Turkey freed imprisoned leftist dissidents. The subsequent email leaks exposed extensive coordination between Turkish government officials and pro-government social media operatives. Correspondence revealed systematic efforts to mobilize Twitter troll armies that harassed opposition figures, amplified pro-government narratives, and reported critical journalists to authorities for account suspensions. The leaked materials documented how Albayrak and other officials directed these operations to suppress media criticism, particularly targeting outlets reporting on corruption allegations or challenging the ruling party’s policies.

The breach triggered immediate government countermeasures, including accelerated enforcement of expanded internet censorship laws passed earlier in 2016. Authorities arrested multiple journalists who reported on the leaked emails, citing anti-terrorism statutes. Media outlets faced administrative sanctions for publishing details from the hack, with several websites forcibly blocked. RedHack maintained pressure by periodically releasing additional email batches throughout late 2016, demonstrating the prolonged exfiltration of sensitive communications. These disclosures fueled domestic protests against media suppression and drew international condemnation from press freedom organizations. The incident illustrated the Turkish government’s reliance on coordinated online influence campaigns alongside legal mechanisms to control public discourse, while exposing vulnerabilities in officials’ personal cybersecurity practices.
