Turkish citizens' personal data offered online after government site hacked
balkaninsight.com
balkaninsight.com
These leaks keep appearing since many years but their origin is not necessarily a hack of the government infrastructure. The leaks usually occur at election cycles because the address based electorate data is handled and processed by the political parties(which are not exactly IT elites) and gets stolen or leaked.
Then there were high profile hacks of large food delivery services or other e-trade platforms.
All this resulted in people collecting and merging data from multiple leaks and re-selling those.
Edit: At some point, all the lawyers were using this data to track down people relevant to their court cases. They were selling it in CD format back then. Scammers and other criminals probably use this data too.
BTW, this data is available for the citizens too during the election cycle so you can check who lives in the same building with you and correct any mistakes. The list of the electorate is also attached at the polls so anyone can check for something fishy.
Then in Turkey there's this obsession with companies about collecting as much as info possible about you, so when the food delivery service is hacked the hackers now can easily add your phone number, update your current address by matching your national identity number because for some reason they need to have that info to deliver some kebab.
Also, this national identity number is generated through some algorithm which gives away your relatives and thanks to this, the hackers can also build your social graph from the leaks. Here is a repo about that algo: https://github.com/kerematam/akrabatcno
AFAIK it’s used in “your grandson had an accident and needs emergency surgery, send this much money ASAP” scams.
Publuc wifi at O2/millenium dome in london us almost as bad.
We really need to make extraneous data a liability and a risk burdain to business.
Sad to hear that that scam is also used in Turkey, some very low and despicable people also use it here, in Romania, targeting elderly people, and it’s really vile. I explicitly warned my parents not to fall for it in case someone calls them.
Why are they crowdsourcing a task that is a basic bureaucratic process in any state?
I mean, is Turkey a state that doesn't know who its citizens are and where they live?
Also, in Turkey the address registration is self declaration based and the government doesn't actually check if you live there. So theoretically, it can be possible for a political party to arrange it's voters distribution in such a way that it is advantageous for them. The idea is that citizens should be able to check against such things.
It seems an easy task to perform.
Do you know that in UK they don't even have such a registry? The government doesn't know where you live(at least officially) and when you need to apply for something that requires proof of address they would use bank statements on your name sent by mail to that address.
I wonder how do you feel about it? Do you think that the Italian approach is better? Why would the government has to know where you live for sure? Is it to prevent benefit frauds?
Edit: there is a difference between the place you live and the place you are registered into. Example: a student is registered at parents' home and goes to study at a university in another city. He rents a room there. He has a contract there and the landlord must notify that the student lives there (since the terrorism laws in the 70s) but the student is still registered and votes at the city of his parents unless he registers at the other city.
This is common also for workers. Maybe they live for years in a city (and the state knows) but they are still registered on their home one.
A lot of places do accept bank statements as a backup if you are not on the electoral roll.
I've read speculation that they were started by telephone spammers to poison the utility of those who-called-me websites that highlighted spammers' phone numbers. I don't think that's the real reason either. It sounds too cute and clever for spammers. (As an aside: nowadays those services are useless since spammers can so easily fake the caller-ID.)
I'm still thinking that there is an interesting story for the original purpose.
you must be crazy if you think this is a good idea
On the other hand, in case of a breach/hack, it becomes a serious problem.
Your comment is not accurate.
check this: https://eksisozluk1923.com/img/bei0vtuj
It's the usual stuff: id number, name, birthday, address, phone.
Then they have the "relatives", which is deductible from the id number.
Then you have some promotional materials advertising the sale of additional data but I have not seen anyone confirming it.
I wrote a blog article about it: https://commit.pizza/2022/10/16/the-only-way-of-being-anonym...
Criminals use it a lot which is increasingly a large problem due to the mass immigration that has sky-rocketed violent crimes in our country. They also use it to hijack peoples identity (haven't happened to me), since the social security number is available to everyone.
Amateurs
Russian citizens' personal data is sold online before government site gets hacked
Russians get hacked by the Terman lab. NSA...CIA...NRLO i think...yeah those guys.
https://www.bellingcat.com/resources/2020/12/14/navalny-fsb-...
To give an example. Since authoritarian regime like databases every hospital have to put data about every appointment or vaccination into regional online database. So every single doctor, technicial or their friend have names, national insurance ID, home adress and passport data for every single person who ever used medical services in that region.
And since every phone number at least supposed to be registered on passport data it's super easy to connect any other non-government data leaks to specific person.
But I think you mean it's not a hack.
Google search for "faegulas" results in many different .tr sites with personal data of USA people. The sites are all of the form
<8randomletters>.<4random>.(info|com|net|gen).tr
All seem to be blocked by Cloudflare though.
[edit -- could be fake, generated data. but why]
"Every Netherlands resident affected by data leak: watchdog" - https://nltimes.nl/2023/06/06/every-netherlands-resident-aff...
"Medical Data of 500,000 French Residents Leaked Online (2021)" - https://www.infosecurity-magazine.com/news/500k-french-medic...
Meanwhile: back in May 2020 a Dutch hacker obtained virtually all Austrians' personal data (full name, gender, address, DOB), police say [1]
[0]: https://www.iamexpat.nl/expat-info/dutch-expat-news/millions...
[1]: https://www.reuters.com/world/europe/dutch-hacker-obtained-v...
There's a special place in hell for people who leak PII.
There should be a clause that governments have to step down if breaches like that happen.
But until leaders, like Erdogan, themselves get doxxed and trolled, probably nothing will be done.
In security you can account for many factors except the human factor.
If there's sufficient incentive like automatically bringing down the government, you are painting a huge target on the hardware & software infrastructure for both internal(political rivals) and foreign entities(think governments with significantly more resources).
There will always be at least one weak human link that can be exploited and that's far less price compared to what was done historically to topple governments.