According to information obtained from sources in Turkey’s security services, five suspects, including the owner and employees of the Ankara-based company Aydo Yazılım, were detained as part of a cyber-espionage operation coordinated by the National Intelligence Organization (MIT) with support from the Cybersecurity Directorate and the General Command of the Gendarmerie.
Aydo Yazılım is a Turkish firm that focuses on delivering software solutions for labor unions.
Based on the findings of MIT’s investigative operations, a specialized query interface had been built into the union software developed by Aydo Yazılım, giving access to the personal data of third parties who were not union members.
The investigation showed that this system was used to run queries against datasets that had previously leaked into the public domain from various sources.
Queries carried out using Turkish citizen identification numbers could open up access to details about individuals’ identities and demographic data, while larger troves of personal information sat in the system’s underlying databases.
It was established that the query system was used to verify and fill in membership records when people were brought into unions. Investigators also turned up records in the databases relating to individuals under the age of 18.
A check of the servers showed that system logs containing personal information consistently used the abbreviation NVI, which gave the appearance that the data came from the General Directorate of Civil Registration and Nationality.
However, a technical analysis carried out as part of the investigation indicates that the data did not come directly from the information systems of that General Directorate.
The investigation is ongoing, aimed at determining which unions used the system, how deeply they were involved, and what purposes the data obtained through it served.
