Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
█ Ransomware ASTRAZENECA-TURKIY 2026-09-20

AstraZeneca Türkiye: N0n Ransomware Leak Site Extortion Claim

"On September 18, 2026, the ransomware group tracked as N0n added AstraZeneca Türkiye, the Turkish arm of the multinational pharmaceutical firm, to its public leak site. Undercode News, citing the ThreatMon Threat…"

On September 18, 2026, the ransomware group tracked as N0n added AstraZeneca Türkiye, the Turkish arm of the multinational pharmaceutical firm, to its public leak site. Undercode News, citing the ThreatMon Threat Intelligence Team, timestamps the listing at 18:25:43 UTC+3 on September 18; DeXpose published its own writeup the following day. Both are OTHER-tier sources, and that framing matters for everything below: as of this writing there is no statement from AstraZeneca, no filing published by Türkiye's Personal Data Protection Authority (KVKK), and no national CERT or vendor advisory corroborating the claim. What exists is an extortion post, a countdown, and two trackers that recorded it.

The actor's own text, reproduced by DeXpose, is unusually specific. N0n claims to hold the "complete internal network-security configuration of all 3 sites (940 MB)," including "every rule, device definition, remote-access mappings," plus "1.35M connection records" drawn from Microsoft 365/Intune, SAP Concur, a UniFi camera estate, and internal applications. The post is tagged "Pharmaceutical manufacturing (GxP) · Türkiye," asserts that "all sites are enforcing a total network blackout until settlement," and carries a deadline of 2026-09-21 03:01 UTC. Every one of those figures originates with the attacker. None has been independently verified.

What Happened

The sequence, as far as the available reporting supports it, is narrow. ThreatMon logged N0n's listing of AstraZeneca Türkiye on September 18 at 18:25:43 UTC+3, several hours before the same tracker recorded an unrelated actor, securotrop, listing Prefix Corp at 23:17:54 UTC+3. Undercode News presents the two as parallel entries in a single day's victim-listing activity rather than as connected incidents, and explicitly notes that the activity entry carries no technical detail about the intrusion.

DeXpose adds the domain (astrazeneca.com.tr) and the verbatim threat-actor statement, and characterises the event as a compromise of internal network security with a threat to leak data absent negotiations. Its report is dated September 19, one day after the listing, and its "Date Reported" field refers to the leak-site posting, not to a confirmed intrusion date. Neither source establishes when access was obtained, how long the actor dwelled, or whether encryption was deployed at all.

That last point deserves emphasis. The phrase "total network blackout until settlement" is the actor's characterisation of the victim's posture. It could describe ransomware encryption, a defensive containment shutdown by AstraZeneca, or pure rhetoric. Accounts do not distinguish between these, and no source reports observed operational disruption at AstraZeneca's Turkish operations.

One further data point sits adjacent to the incident without explaining it: AstraZeneca posted a Data Privacy Partner role in Şişli, Istanbul on September 17, 2026, one day before the listing. The posting describes a position acting as local Data Privacy Officer and as the official VERBIS contact person for AstraZeneca's registered Turkish entities, reporting to the Nominated Signatory & Data Privacy Lead with a dotted line to the Head of Legal, and explicitly tasked to "lead and support the response to incidents and data breaches." The timing is almost certainly coincidental, and we draw no inference from it. It does confirm that AstraZeneca Türkiye is a VERBIS-registered controller with a defined local breach-response function, which is the relevant fact for the regulatory section below.

What Was Taken

If the claim is accurate, the stolen material is not a customer database. It is infrastructure documentation, which carries a different and in some respects worse risk profile.

N0n's inventory, as claimed:

No source provides a competing figure for either the 940 MB or the 1.35M count, so there is no range to report here. That is not reassurance. It reflects that only one source, DeXpose, published the actor's inventory at all, and that inventory is the actor's own marketing copy. Extortion posts routinely inflate volume, overstate breadth ("all 3 sites"), and describe partial pulls as complete exports. Treat 940 MB and 1.35M as claimed ceilings, not measured values.

The sensitivity question turns on composition. Connection records from M365/Intune and an internal application estate can contain usernames, device identifiers, endpoint hostnames, and source addresses, which would constitute personal data of employees under Turkish law even with no patient or customer data involved. SAP Concur is a travel and expense platform, so records referencing it imply employee identity and movement data. A UniFi camera estate implies physical security coverage of facilities. None of that has been confirmed as present in any leaked sample, because no sample has been published.

Why It Matters

The claimed asset class is the story. A firewall ruleset with device definitions and remote-access mappings is a map of how to reach the environment: which segments talk to which, where the VPN and jump-host paths terminate, which management planes are exposed and from where. For a defender, that material is a single-document blueprint of every lateral path. For a second actor buying the leak, it removes most of the reconnaissance cost of a follow-on intrusion. Data that describes the network outlives the incident that produced it, because rules and topology change slowly.

The GxP tag raises a separate concern. In a regulated pharmaceutical manufacturing context, the boundary between IT and the validated OT and laboratory estate is itself a compliance artifact. Configuration documentation covering that boundary is both an attack aid and, if published, a regulatory exposure independent of any personal data.

There is also a market signal. Undercode News frames the listing within a broader pattern of groups using public victim announcements as a pressure instrument: to force negotiation, to generate reputational cost, and to signal that publication follows non-payment. N0n's post fits that model precisely, down to a sub-72-hour countdown clock calibrated to land before most multinationals can complete an internal assessment, let alone a regulatory filing.

And the incident lands in an already saturated Turkish breach environment. KVKK published 12 breach notices on September 16, disclosed by Turkish Minute and Ekovitrin on September 17; the 11 companies that could quantify impact reported a combined 10,218,802 affected people, with İnternet Tekstil Sanayi ve Ticaret A.Ş. still unable to determine its number. Both outlets report identical figures: Eve Kozmetik (Yeni Mağazacılık A.Ş.) at 6,263,305 customers, Shaya Mağazacılık at 2,298,726, Deniz Deniz Butik at 1,271,096, Shaya Kahve at 133,991, Haşema Tekstil at 95,857, and a tail running from Yiğit Alışveriş Merkezleri (81,593) down to İyileştiren Mamuller Gıda (6,547). Xen Bilişim reports two earlier waves: 33 notices published September 2, of which 22 shared near-identical vendor-compromise wording and the nine that disclosed counts totalled 74,600 people, followed by six more on September 9 flagging ransomware and unauthorised server access. Three disclosure waves in roughly two weeks is the baseline N0n is operating against.

The Attack Technique

Unknown. This is the honest answer and it should not be dressed up.

Undercode News states directly that the ThreatMon entry contains no technical detail about the intrusion. DeXpose reproduces the actor's claims and appends generic ransomware hygiene guidance, but publishes no initial access vector, no malware family, no infrastructure, and no indicators of compromise. There is no reported vulnerability, no phishing lure, no credential-stuffing claim, and no named third party.

What can be inferred from the claimed loot is limited and speculative. An actor holding complete firewall configurations across three sites plausibly reached a network management platform, a configuration backup repository, or an administrator workstation with access to both, rather than compromising three sites individually. Connection records spanning M365/Intune, SAP Concur, and a camera estate point toward a centralised logging, SIEM, or monitoring aggregation point as a single collection source. That is a hypothesis consistent with the claim, not a finding.

Worth noting as ambient context rather than attribution: the dominant pattern in KVKK's recent disclosures is third-party compromise. Turkish Minute reports Eve Kozmetik's breach followed exploitation of a vulnerability in a third-party software library on a server run by a data processor, with the processor notifying the controller on September 10; Ekovitrin attributes a third-party library vulnerability to the Deniz Deniz Butik breach as well. Xen Bilişim's count of 22 notices sharing one vendor-compromise sentence, with no notice naming the vendor, describes an ecosystem where a single processor failure surfaces as two dozen separate controller breaches. Nothing in the sources connects AstraZeneca Türkiye to a processor compromise. But any investigation of this claim should scope third parties from the outset rather than assume a direct intrusion.

What Organizations Should Do

  1. Treat leaked network configuration as a credential event. If configuration exports are confirmed missing, rotate every shared secret they contain: VPN pre-shared keys, SNMP community strings, RADIUS secrets, management-plane accounts, and any API tokens embedded in device definitions. Configuration files are secret stores that most organisations do not inventory as such.
  2. Audit the remote-access paths the documents describe. Remote-access mappings tell an attacker exactly which routes exist. Re-scope them: remove stale site-to-site tunnels, enforce phishing-resistant MFA on every external entry point, and restrict management interfaces to dedicated administrative networks rather than general corporate segments.
  3. Centralise and then harden your configuration repositories. The claimed scope, all three sites in one 940 MB package, is the signature of a single aggregation point being looted. Inventory where device backups, network diagrams, and SIEM exports live, put them behind separate authentication from the general estate, and alert on bulk read or export from those stores.
  4. Do not let the countdown drive the legal clock, and do not let it drive the technical one either. N0n's 2026-09-21 03:01 UTC deadline is an engineered pressure device. Scoping an intrusion across three sites takes longer than 72 hours; settle into the investigation and communicate on facts you have verified.
  5. Know which Turkish notification standard actually binds you, because the sources differ. KEYDAL's reading of Law No. 6698 is that Article 12(5) contains no numerical deadline at all, stating only "as soon as possible," with notice owed to both the data subject and the Board. Vircon Legal, reviewing Board decisions published August 10, 2026, describes a 72-hour deadline enforced in practice and penalised separately from the underlying security failure. Both are correct in their frame: the statutory text sets no figure, and Board practice has settled on 72 hours. Plan to the 72-hour standard.
  6. Keep your statements consistent from the first hour. Vircon Legal's summaries include a TRY 250,000 fine (decision 2024/2196) for contradictory statements made during the breach process, a TRY 350,000 fine (2024/790) rejecting the "the data was not corrupted" defence as grounds for skipping notification, and a TRY 500,000 fine (2024/1718) in a multinational breach requiring notification to 19 separate authorities. That last decision is the relevant shape here: a compromise at a multinational's local arm is rarely a single-regulator problem.
  7. Verify before you self-report, but document the verification. Vircon Legal also cites decision 2022/1087, in which the Board declined to characterise an unproven "data has been leaked" allegation as a breach, with no fine imposed. A leak-site listing is an allegation. Organisations named in one should investigate hard and fast, and should be able to show their work either way.

For anyone tracking this specific incident: the next meaningful data point is either a sample publication by N0n after the September 21 deadline, a KVKK notice naming an AstraZeneca entity, or a statement from the company. Until one of those lands, the confirmed facts are that a listing exists and that a tracker recorded it. Everything else is the attacker talking.

Sources: N0n Ransomware Group Compromises AstraZeneca Türkiye - DeXpose | N0n and Securotrop Add New Victims as Ransomware Pressure Reaches A... | Data Privacy Partner at AstraZeneca | Data breaches at 12 Turkish companies expose personal data of over... | KVKK açıkladı: 12 şirkette milyonlarca kişiyi etkileyen veri ihlali... | How Do You Notify a Personal Data Breach in Turkey? KEYDAL | KVKK Breach Notification: 72 Hours and Transparency - Vircon Legal | Vendor Breach, Who's Liable Under KVKK? Xen Bilişim