Ransom! i2i-systems (SEP-2026)
Threat actor Barracuda targeted i2i-systems (TR) through poorly secured infrastructure, enabling unrestricted lateral movement over a week and resulting in 693 GB of data exfiltration. They stole 44 GB of development source code and created full snapshots of critical Linux system data and databases, including customer data from a Turk Telekom joint project, with the stolen data reportedly being sold. #Turkey

Incident Details

Information

  • The target was described as one of the least secure organizations encountered, with weak infrastructure and poor IT security practices.
  • Over the course of a week, the attackers moved freely through the network and exfiltrated 693 GB of data.
  • Complete source code was obtained for multiple projects, including development and production-related repositories and packages.
  • In total, 44 GB of source code was taken, including a full snapshot of the latest releases from the development repository.
  • The breach also affected Veriskop due to its direct connection with the organization.
  • Evidence of joint work with partners such as Vodafone, Etiya, Bouygues, and Freedom Mobile was found in Linux server backups and related infrastructure data.
  • Critical data was extracted from Linux systems, and database snapshots were created.
  • A database containing customer data from a joint project with Turk Telekom was also downloaded.
  • The stolen data was reportedly being prepared for publication.
  • The incident was assessed as HIGH severity, with the data currently listed for sale at $300,000.

Disclaimer: This post is based on public claims made by the ransomware group "Barracuda". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live