From One Vendor to Hundreds of Organizations: What a Turkish HR Provider Breach Reveals About Supply Chain Cyber Risk

From One Vendor to Hundreds of Organizations: What a Turkish HR Provider Breach Reveals About Supply Chain Cyber Risk

Executive Summary

Baltas Eksen Seçme Değerlendirme Eğitim ve Org. Tic. A.Ş. (“Baltas”), a Turkish HR and executive assessment provider, officially disclosed a personal data breach to Türkiye’s Personal Data Protection Authority (KVKK). Shortly after, a threat actor surfaced on an underground forum claiming responsibility for the breach and asserting that data belonging to more than 750 corporate clients had been exposed. Days later, a separate leak-site listing from a newly emerged ransomware group, CRPxO, named 11 Turkish organizations as victims publishing sample documents that ThreatMon researchers assess share strong similarities with the material referenced in the earlier forum claim.

While Baltas has confirmed a breach occurred, the link between the forum actor, the 750-company claim, and CRPxO’s leak-site listings has not been independently verified. ThreatMon treats this as a probable “not confirmed” connection based on document-level overlap, and continues to monitor for further indicators.

Timeline of Events

1. Official disclosure (confirmed): Baltas notified KVKK of a personal data breach involving unauthorized access to systems processing customer information.

2. Underground forum claim (unverified): A threat actor posted on a known cybercrime forum claiming to have compromised “Baltas Online,” alleging a 47-day intrusion window with root-level access and full data exfiltration exceeding 500 GB. The actor claimed the exposed data included personnel records, executive psychometric assessments, personality analysis reports, candidate profiles, email archives, examination materials, interview recordings, internal notes, and source code, and asserted the data related to more than 750 corporate clients in Türkiye. Sample files were shared as claimed proof of access.

3. CRPxO leak-site listings (observed, attribution unconfirmed): A newly identified ransomware operation, CRPxO, launched a data leak site and listed 11 organizations in Türkiye across the finance, defense, automotive, aviation, retail, insurance, media, and manufacturing sectors. Documents published on the leak site include Hogan Assessment reports and executive evaluation materials bearing Baltaş Group branding, matching the types of documents referenced in the earlier forum post.

While this overlap may indicate a connection between the forum actor and CRPxO, there is currently no evidence confirming they are the same actor or part of the same operation. Another possibility is that the data was shared, sold, or otherwise obtained from the same breach by different actors.

ThreatMon Intelligence Assessment

Comparing the publicly observable samples from both the forum claim and the CRPxO leak-site postings, ThreatMon researchers identified recurring overlaps, including:

  • Executive assessment reports
  • Hogan Assessment documents
  • Baltaş-branded files
  • Personnel evaluation reports
  • HR-related documentation and candidate exam materials

These similarities are notable but are pattern-level indicators rather than confirmed attribution. ThreatMon’s analysts first surfaced the underground forum claim through the Dark Web Intelligence module, which continuously monitors cybercrime forums and leak-site activity for mentions tied to monitored organizations, and continues to track CRPxO’s infrastructure and victim disclosures for additional corroborating evidence.

A note on sourcing: this assessment deliberately does not reproduce the forum actor’s download links, decryption passwords, contact details, or the full list of allegedly affected companies. Republishing that material would materially assist further distribution of the leak; readers seeking that level of detail should rely on their own vendor risk / breach-notification channels rather than a public blog post.

Why This Is More Than a Data Breach

What a Turkish HR Provider Breach Reveals About Supply Chain Cyber Risk

The significance of this incident extends beyond the compromise of a single organization. HR and executive assessment providers maintain trusted relationships with hundreds of companies and process highly sensitive business and personnel information including data on C-level executives. A compromise affecting one such provider can introduce downstream risk across multiple sectors, including finance, manufacturing, healthcare, telecommunications, and critical infrastructure.

This is a defining characteristic of modern supply chain attacks: adversaries achieve outsized impact by targeting organizations that serve many others, rather than pursuing each downstream victim individually.

Continuous visibility into vendor risk rather than one-off assessments is what allows organizations to catch incidents like this before they cascade. See ThreatMon’s Supply Chain Risk Management module.

The Growing Value of HR Providers for Threat Actors

Recruitment and executive assessment firms store information that is particularly attractive to threat actors, including:

  • Executive profiles and psychometric/personality assessments
  • Candidate evaluations
  • Organizational structures
  • Recruitment documentation
  • Corporate contact information

     

This data can support phishing campaigns, business email compromise (BEC), identity theft, executive impersonation, and other social engineering attacks the psychometric and personality-profile angle in particular gives attackers unusually rich material for targeting senior executives.

The Defensive Reality

CRPxO is a newly observed ransomware operation that has rapidly begun targeting organizations in Türkiye.

Observed characteristics:

  • Primary focus on Turkish organizations
  • Public leak site with victim listings (11 organizations as of the latest observation, spanning finance, defense, automotive, aviation, retail, insurance, media, and manufacturing)
  • Publication of sample documents as proof of compromise
  • Countdown timers and extortion messaging; following timer expiry on some listings, the group has publicly stated that affected companies “don’t care about their clients’ or users’ privacy and security”
  • Double-extortion tactics, with claims that full datasets are withheld from public release and shared only with parties who contact the group directly

ThreatMon continues to track the group’s infrastructure, victim disclosures, and operational evolution through its Cyber Threat Intelligence capabilities, and organizations concerned about exposure to CRPxO or similar groups can use Ransomware Prevention monitoring to catch early indicators exposed RDP ports, leaked credentials, or unusual encryption activity before an intrusion escalates to a leak-site listing.

Recommendations

  • Assess third-party cyber risk on a continuous basis, not just at onboarding a Supply Chain Risk Management program can maintain an always-current risk score for every vendor rather than relying on point-in-time questionnaires.
  • Monitor ransomware leak sites and underground forums for exposure tied to your vendors especially HR, assessment, and recruitment providers.
  • Strengthen supply chain security assessments and require breach-notification clauses in vendor contracts.
  • Review vendor access privileges and minimize data shared with third-party assessment providers where possible.
  • Monitor external attack surface exposure tied to vendor-facing integrations; Attack Surface Intelligence can flag unmanaged or shadow assets on both your own and your vendors’ infrastructure before attackers find them.
  • Leverage threat intelligence to identify emerging ransomware campaigns targeting suppliers before they escalate.

Conclusion

The Baltas incident illustrates a broader shift in the ransomware landscape: rather than targeting organizations one by one, attackers increasingly focus on trusted third-party providers capable of unlocking access to extensive business ecosystems. The exact relationship between the original forum claim and CRPxO’s leak-site activity remains under investigation, but the pattern is already clear vendor risk is business risk.

Organizations that continuously monitor their third-party ecosystem, leverage cyber threat intelligence, and strengthen supply chain visibility will be better positioned to detect and respond to emerging threats before they escalate into wider organizational impact. Learn how continuous vendor monitoring helps identify supply chain exposure before attackers do.

More posts

This image is about monthly vulnerabilities for September 2024.
This image is about the ServiceNow data leak.
This image is about monthly vulnerabilities for July 2024.
This image is about Securing the Games- cyber strategies for the Paris Olympics 2024.
Hunter’s Lens: Russian Influence Operations Targeting the Paris Olympics 2024
advanced divider

Share this article

Found it interesting? Don’t hesitate to share it to wow your friends or colleagues

advanced divider

Subscribe to our blog newsletter to follow the latest posts