Menu
Browse
Date:

Apr 2021

Location:

Turkey

Summary

A joint venture responsible for a major bridge and motorway project experienced a ransomware attack that encrypted servers and files, compromising personal data of approximately 20,000 individuals. The breach impacted employees, their relatives, and subcontractor personnel, with potentially exposed data categories including identity, communication, health, financial, and legal information, though specific affected records remained undetermined. The company notified Turkey's data protection authority upon detecting the incident, confirming ongoing investigations into the attack, which involved ransom demands from the perpetrators.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 24, 2021, the DLSY joint venture—comprising Turkish and South Korean firms Daelim, Limak, SK E&C, and Yapı Merkezi—detected a cyberattack targeting its infrastructure supporting the 1915 Çanakkale Bridge and Motorway Project. Attackers encrypted servers and files using ransomware, disrupting operations tied to a project involving 25 financial institutions across 10 countries. The breach was identified on the same day it commenced, prompting immediate notification to Turkey’s Personal Data Protection Authority (KVKK). Initial assessments indicated approximately 20,000 individuals were affected, though the partnership could not definitively identify compromised records or specific data categories at the time of reporting. Investigations revealed the attackers demanded ransom, though the amount and payment status were undisclosed.

Cyber Incident Image

The incident impacted personal data categories including identity, communication, health, financial, and legal records, though the exact scope remained undetermined. Affected individuals were believed to include DLSY employees, their relatives, and subcontractor personnel. Despite uncertainty regarding which specific data types were accessed or exfiltrated, the breach exposed sensitive information such as union memberships, criminal convictions, and professional experience. The partnership’s disclosure emphasized ongoing efforts to assess the full extent of the compromise, with no public confirmation of data recovery or system restoration. Regulatory inquiries continued as of the notification date, with no attribution to a specific threat actor or disclosure of operational disruptions beyond the encryption event.

Sources
Sources available to members
1 source