CSIDB logo
Incident

MNG Kargo

Incident posture

Attack window
Aug 2021
Location
Turkey
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
MNG Kargo
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Turkish transportation company, MNG Kargo, experienced a cyberattack compromising corporate customer accounts through stolen credentials, leading to unauthorized access to recipient information including names, addresses, and phone numbers. The breach was detected several days after its initiation, with the firm asserting no inherent system vulnerabilities while attributing the incident to hijacked corporate accounts; it notified national data protection authorities but could not confirm the total number of affected individuals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 23, 2021, MNG Kargo, a major Turkish cargo and logistics company, publicly disclosed a cybersecurity incident affecting its corporate customers. The breach originated on August 15 when attackers obtained corporate customer account credentials—specifically usernames and passwords—which enabled unauthorized access to the company's systems. This access led to the exfiltration of personal data belonging to cargo recipients, including full names, addresses, and telephone numbers. MNG Kargo emphasized its internal systems contained no technical vulnerabilities, attributing the breach solely to compromised customer account credentials rather than infrastructure weaknesses. The company detected the intrusion eight days after its initiation but did not specify the methods used for detection or whether external cybersecurity firms assisted in the investigation.

The incident impacted an undetermined number of individuals whose data was exposed through compromised corporate accounts. MNG Kargo formally notified Turkey’s Personal Data Protection Authority (KVKK) of the breach, fulfilling its regulatory obligations, but did not disclose whether affected individuals received direct notifications. No ransomware deployment, financial theft, or operational disruption was reported, with the attack’s consequences limited to data theft. The company’s public statement focused on the absence of systemic flaws while omitting details about containment measures, forensic investigations, or post-incident security enhancements. The stolen recipient information posed risks of phishing and social engineering attacks against affected parties, though no secondary incidents were documented in the available reporting.

Sources

Sources available to members: 1 source.

CSIDB