🇹🇷 🚨 TURKEY IYS MESSAGE-PERMISSION PLATFORM DATA ALLEGEDLY LISTED (~302K)
A threat actor on an underground forum claims to be sharing a dataset allegedly associated with Turkey’s IYS (İleti Yönetim Sistemi / Message Management System) — the national platform that regulates commercial electronic messages and recipient permissions (iys[.]org[.]tr).
Claimed listing details:
* ~302.377 records (CSV)
* Alleged fields include names, email addresses, phone numbers, usernames, and home addresses
* Listing frames the material as a 2021-dated dump; Slack brief cites an alleged ~June 2022 ElasticSearch exposure (older claim — not breaking)
The claim has not been independently verified.
⚠️ Analyst Note:
IYS is a Turkish national message-permission / commercial-email consent platform (non-US). Underground “database” posts that cite older ElasticSearch exposures are frequently recycled, incomplete, or mixed with unrelated records — the visible sample on the listing also showed Azerbaijan-addressed rows alongside Istanbul, which raises questions about scope and packaging.
We assess this as an unverified threat-actor claim involving alleged IYS[.]org[.]tr-associated data, NOT confirmation of a fresh compromise of Turkey’s national messaging-permission infrastructure. Treat volume, freshness, and field accuracy as unproven.
If authentic and non-public, contact and address material could support phishing, fraud, and targeting of individuals on commercial messaging lists.
#DDW #DarkWeb #Turkey #IYS #DataLeak #ThreatIntelligence #CyberSecurity