Quick Summary
AllegedExecutive Summary
Zorlu Holding, a prominent Turkish manufacturing conglomerate operating at zorlu[.]com, was identified on a qilin ransomware leak-site on September 20, 2026. The listing is supported by evidence of compromised credentials, including 9 employee credentials on organizational systems, 2 customer records on company infrastructure, and 10 corporate credentials on third-party services, all dated September 2026. This date range aligns closely with the leak listing, suggesting a potential overlap between the data exposure and the ransomware group’s activity. As a major player in the manufacturing sector, Zorlu Holding represents a high-value target that could attract ransomware operations seeking significant financial gains. The qilin ransomware group has demonstrated significant operational tempo, claiming 243 victims in the preceding 60 days. Their primary targets are the Manufacturing, Professional Services, and Other sectors, with a strong focus on the United States, Germany, and the United Kingdom. While Turkey is not among qilin’s most frequently targeted countries, the direct overlap with the Manufacturing industry makes this claim consistent with their known targeting patterns. The sheer volume of claims indicates qilin’s capacity for large-scale extortion campaigns.
Technical Analysis
The infostealer sample associated with this incident contained login information for several key Zorlu Holding domains, including login.microsoftonline[.]com, sso.zorlu[.]com, mail.zorlu[.]com, and owa.zorlu[.]com. The presence of credentials for Single Sign-On (SSO) and webmail services is particularly concerning, as this combination can provide threat actors with a viable access package for pre-ransomware reconnaissance, potentially enabling them to map out network defenses and identify further vulnerabilities. The mixed nature of the compromised credentials—spanning employee, customer, and third-party data—suggests that the threat actors may have achieved broad coverage across Zorlu Holding’s digital assets. The September 2026 activity indicated in the stealer logs directly corresponds with the timing of the qilin listing, reinforcing the possibility that these exposed credentials were used to facilitate the observed or claimed intrusion. Infostealer-sourced credentials are a known initial access vector for the qilin ransomware group. This observation strongly suggests that organizations should immediately investigate whether any of the compromised accounts were leveraged to establish a foothold within their network prior to the leak site listing. Continued monitoring of dark web forums and stealer logs for additional Zorlu Holding related credentials, as well as proactive credential hygiene checks, password rotations, and multi-factor authentication reviews, are recommended actions.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.