Quick Summary
AllegedExecutive Summary
The Doommageddon ransomware group claimed Akpera Gayrimenkul Yatırım A.Ş. as a victim on August 30, 2026. The real estate firm, based in Turkey and operating via akpera[.]com[.]tr, was listed on the group’s leak site, with assertions of unauthorized access to its systems and data. This report treats the incident as alleged, pending independent verification. Real estate firms can be attractive targets for ransomware groups due to the potential for sensitive financial and personal data, as well as the disruption that can be caused to critical transactions. In the past 60 days, Doommageddon has claimed three victims, with a notable concentration of targeting in Turkey. Their operational focus has primarily been on the “Other” and “Transportation” sectors. The inclusion of Akpera Gayrimenkul Yatırım A.Ş. as a real estate entity aligns with the group’s broader pattern of targeting within Turkey and expands their sector reach beyond previously observed industries.
Technical Analysis
SOCRadar CTI’s analysis of infostealer logs did not identify any credential records associated with Akpera Gayrimenkul Yatırım A.Ş., specifically for the domain akpera[.]com[.]tr. This “no_exposure_in_sample” verdict indicates that no relevant credentials were found within the analyzed datasets at the time of the query. However, this null result does not definitively clear the organization of a compromise. It is important to note that the absence of evidence in the sampled data is not evidence of the absence of a compromise. Credential exposure may occur through various means not captured by this specific stealer-log analysis, and threat actors often employ tactics like phishing or the exploitation of public-facing services for initial access, which would not necessarily leave immediate traces in stealer-log datasets. Further monitoring for credential exposure on alternative corporate domains, as well as continued vigilance for any new activity on Doommageddon’s leak site, is recommended. Proactive measures such as reviewing password hygiene, ensuring multi-factor authentication is enabled across all critical systems, and monitoring remote access portals for suspicious activity remain essential to mitigate potential risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.