Baltas Eksen Seçme Değerlendirme Eğitim ve Org. Tic. A.Ş. (“Baltas”), a Turkish HR and executive assessment provider, officially disclosed a personal data breach to Türkiye’s Personal Data Protection Authority (KVKK). Shortly after, a threat actor surfaced on an underground forum claiming responsibility for the breach and asserting that data belonging to more than 750 corporate clients had been exposed. Days later, a separate leak-site listing from a newly emerged ransomware group, CRPxO, named 11 Turkish organizations as victims publishing sample documents that ThreatMon researchers assess share strong similarities with the material referenced in the earlier forum claim.
While Baltas has confirmed a breach occurred, the link between the forum actor, the 750-company claim, and CRPxO’s leak-site listings has not been independently verified. ThreatMon treats this as a probable “not confirmed” connection based on document-level overlap, and continues to monitor for further indicators.
1. Official disclosure (confirmed): Baltas notified KVKK of a personal data breach involving unauthorized access to systems processing customer information.
2. Underground forum claim (unverified): A threat actor posted on a known cybercrime forum claiming to have compromised “Baltas Online,” alleging a 47-day intrusion window with root-level access and full data exfiltration exceeding 500 GB. The actor claimed the exposed data included personnel records, executive psychometric assessments, personality analysis reports, candidate profiles, email archives, examination materials, interview recordings, internal notes, and source code, and asserted the data related to more than 750 corporate clients in Türkiye. Sample files were shared as claimed proof of access.
3. CRPxO leak-site listings (observed, attribution unconfirmed): A newly identified ransomware operation, CRPxO, launched a data leak site and listed 11 organizations in Türkiye across the finance, defense, automotive, aviation, retail, insurance, media, and manufacturing sectors. Documents published on the leak site include Hogan Assessment reports and executive evaluation materials bearing Baltaş Group branding, matching the types of documents referenced in the earlier forum post.
While this overlap may indicate a connection between the forum actor and CRPxO, there is currently no evidence confirming they are the same actor or part of the same operation. Another possibility is that the data was shared, sold, or otherwise obtained from the same breach by different actors.
Comparing the publicly observable samples from both the forum claim and the CRPxO leak-site postings, ThreatMon researchers identified recurring overlaps, including:
These similarities are notable but are pattern-level indicators rather than confirmed attribution. ThreatMon’s analysts first surfaced the underground forum claim through the Dark Web Intelligence module, which continuously monitors cybercrime forums and leak-site activity for mentions tied to monitored organizations, and continues to track CRPxO’s infrastructure and victim disclosures for additional corroborating evidence.
A note on sourcing: this assessment deliberately does not reproduce the forum actor’s download links, decryption passwords, contact details, or the full list of allegedly affected companies. Republishing that material would materially assist further distribution of the leak; readers seeking that level of detail should rely on their own vendor risk / breach-notification channels rather than a public blog post.
The significance of this incident extends beyond the compromise of a single organization. HR and executive assessment providers maintain trusted relationships with hundreds of companies and process highly sensitive business and personnel information including data on C-level executives. A compromise affecting one such provider can introduce downstream risk across multiple sectors, including finance, manufacturing, healthcare, telecommunications, and critical infrastructure.
This is a defining characteristic of modern supply chain attacks: adversaries achieve outsized impact by targeting organizations that serve many others, rather than pursuing each downstream victim individually.
Continuous visibility into vendor risk rather than one-off assessments is what allows organizations to catch incidents like this before they cascade. See ThreatMon’s Supply Chain Risk Management module.
Recruitment and executive assessment firms store information that is particularly attractive to threat actors, including:
This data can support phishing campaigns, business email compromise (BEC), identity theft, executive impersonation, and other social engineering attacks the psychometric and personality-profile angle in particular gives attackers unusually rich material for targeting senior executives.
CRPxO is a newly observed ransomware operation that has rapidly begun targeting organizations in Türkiye.
Observed characteristics:
ThreatMon continues to track the group’s infrastructure, victim disclosures, and operational evolution through its Cyber Threat Intelligence capabilities, and organizations concerned about exposure to CRPxO or similar groups can use Ransomware Prevention monitoring to catch early indicators exposed RDP ports, leaked credentials, or unusual encryption activity before an intrusion escalates to a leak-site listing.
The Baltas incident illustrates a broader shift in the ransomware landscape: rather than targeting organizations one by one, attackers increasingly focus on trusted third-party providers capable of unlocking access to extensive business ecosystems. The exact relationship between the original forum claim and CRPxO’s leak-site activity remains under investigation, but the pattern is already clear vendor risk is business risk.
Organizations that continuously monitor their third-party ecosystem, leverage cyber threat intelligence, and strengthen supply chain visibility will be better positioned to detect and respond to emerging threats before they escalate into wider organizational impact. Learn how continuous vendor monitoring helps identify supply chain exposure before attackers do.