Cyber & AI intelligence
Wasteland.
Briefs indexed2772
Issues28
Published Mondays07:30 CT
█ Ransomware ZORLU-HOLDING-QILI 2026-09-21

Zorlu Holding: Qilin Ransomware Leak Site Claim

"The Qilin ransomware operation added Turkish conglomerate Zorlu Holding to its Tor-based data-leak site on September 20, 2026, according to UNDERCODE NEWS, which cites the Dark Web Intelligence account (@DailyDarkWeb)…"

The Qilin ransomware operation added Turkish conglomerate Zorlu Holding to its Tor-based data-leak site on September 20, 2026, according to UNDERCODE NEWS, which cites the Dark Web Intelligence account (@DailyDarkWeb) and public ransomware-tracking data. The listing reportedly carries video material presented as proof of access. As of publication, no statement from Zorlu Holding, Turkey's data protection regulator (KVKK), or a national CERT has appeared in any of the available reporting, and every source describing this incident is second-tier threat-intelligence coverage rather than a primary disclosure. Readers should treat the intrusion itself as an unverified actor claim. What is well documented is the actor: Qilin has been ranked the most prolific ransomware operation for four consecutive quarters through Q2 2026 (breachnews.com), and Black Kite's 2026 Ransomware Report, cited by Adaptive Security, counts 1,358 Qilin victims between April 2025 and March 2026, a 443 percent year-over-year increase.

What Happened

The core of the claim is narrow. UNDERCODE NEWS reports that Zorlu Holding, one of Turkey's largest diversified industrial groups with interests spanning energy, electronics, textiles and real estate, appeared on Qilin's leak site on September 20, 2026, accompanied by video framed as evidence of access to internal systems. The outlet is explicit that this is an allegation: no ransom note, no file samples, no intrusion timeline, no forensic findings and no technical indicators have been published alongside the listing, and the outlet itself cautions that leak-site entries can be "incomplete, exaggerated, outdated, or otherwise unverified."

That caution is not boilerplate. UNDERCODE's own reporting on the same day shows Qilin adding at least two other organizations, KMLS and Touring Club Suisse, flagged by the ThreatMon Threat Intelligence Team at 18:12:26 and 18:12:24 UTC+3 on September 20 respectively, also with no supporting technical detail. Zorlu appears to be one entry in a publishing burst, not an isolated high-confidence disclosure.

Accounts differ in one respect worth stating plainly: the incident has been described elsewhere as a confirmed breach, but nothing in the available sourcing supports "confirmed." No source in this set quotes Zorlu Holding, cites a regulator filing, or reports encryption, outage, or operational disruption at the company. The verifiable fact is the listing. The breach behind it remains the actor's word plus a video no independent party in these sources has authenticated.

What Was Taken

No source published a record count, data volume, file listing, or data-type breakdown for Zorlu Holding. Anyone citing a figure for this incident is citing something that does not exist in the public reporting.

What can be said is structural. Qilin runs a double-extortion model: data is exfiltrated before encryption, and non-paying victims are published with staged releases, proof samples first and full dumps later (Security Arsenal). On that model, a leak-site listing with video proof-of-access is consistent with successful exfiltration and a failed or stalled negotiation, which is what Brinztech inferred from Qilin's August 2026 additions. Consistent is not the same as demonstrated.

For scale context on a Zorlu-sized target, the group's historical ransom demands run from roughly $50,000 to $5 million and are scaled to victim revenue, with mid-market manufacturing victims typically seeing $250,000 to low seven figures and healthcare or critical-infrastructure cases going far higher. Security Arsenal notes demands in the Synnovis/NHS-adjacent healthcare cases exceeded $50 million. A multi-billion-dollar energy and electronics group sits at the top of that scaling curve.

Separately, and importantly, Zorlu Holding does not appear in the batch of 12 Turkish breach notices published by Turkey's data protection regulator on September 16, 2026. Those notices, reported by Turkish Minute, cover more than 10.2 million affected people (10,218,802 across the 11 companies that could produce a count, with İnternet Tekstil Sanayi ve Ticaret A.Ş. still unable to determine its number), led by cosmetics retailer Eve Kozmetik at 6,263,305 customers. That is a separate wave of incidents, several of them traced to vulnerabilities in third-party software libraries running on processor-operated servers. Do not merge those numbers into the Zorlu story.

Why It Matters

Qilin is currently the highest-volume ransomware brand on the planet, and its cadence is the story. Security Arsenal's leak-site monitoring recorded 28 victims in a single publishing cycle on August 17, including 15 organizations posted within one 24-hour window on August 16, then 15 more victims across 72 hours between August 19 and 21, spanning eight countries and eight verticals. breachnews.com counted 279 victims on the leak site in Q2 2026 alone. Adaptive Security's reading of the Black Kite data puts Qilin at roughly one in every five to six publicly disclosed ransomware victims worldwide.

Against that backdrop, no enforcement pressure exists. Adaptive Security notes that as of August 2026 there has been no arrest, indictment, sanction, or joint government advisory targeting Qilin, while CISA and the FBI have issued #StopRansomware advisories for Akira, Black Basta, BianLian, RansomHub and Gunra. Risk registers that assume a takedown is coming have nothing to lean on. There is also no free decryptor for any Qilin variant, and the strain tracked as Qilin.B uses an encryption scheme built to make recovery without the operator's key infeasible.

The group has also demonstrated it will name targets that invite state attention. breachnews.com reports Qilin claimed an intrusion at the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, and in that case the agency did independently confirm that a standalone system was compromised, with senior Department of Justice officials designating it a "major incident." That is the one case in this source set where a Qilin claim was validated by the victim, which is a useful calibration point: the claims are sometimes real, and they are also sometimes thinner than the listing implies.

For Turkish enterprises specifically, the regulator's September 16 disclosure wave establishes that KVKK is now publishing breach notices for large consumer-data incidents. If Zorlu Holding determines that personal data was affected, a regulatory notice is the realistic path to independent confirmation, and its absence so far is a genuine data point rather than proof of anything either way.

The Attack Technique

Nothing is known about how Zorlu Holding was allegedly accessed. What follows is Qilin's documented tradecraft, which is where defensive planning should start.

Qilin has run as a ransomware-as-a-service operation since mid-2022, first under the name Agenda, rebranding later that year. Core operators maintain the encryptor, leak site and negotiation infrastructure; affiliates run intrusions under a revenue split reported at 80/20 by Security Arsenal's August 22 brief and as a range of 80/20 to 85/15 in its August 17 brief. Encryptors exist in both Go and Rust, with builds targeting Windows, Linux and VMware ESXi hypervisors.

Initial access is credential-led more often than exploit-led. Adaptive Security's incident-response data indicates Qilin intrusions frequently begin with valid credentials leaked on criminal channels roughly one week to three months before use. Brinztech describes compromised VPN credentials, phishing, and purchases from initial access brokers as the common footholds. Security Arsenal adds exploitation of perimeter appliances, RDP credentials bought from brokers, and increasingly supply-chain and developer-tool compromise, and flags Check Point Security Gateway, ConnectWise ScreenConnect and Microsoft Exchange as CISA KEV entries with confirmed ransomware use that align with Qilin's documented access patterns.

Post-access, Brinztech describes living-off-the-land tooling including renamed PsExec and custom credential dumpers used to map Active Directory and stage data before encryption.

Dwell-time figures differ across sources and the difference matters operationally. Security Arsenal reports an observed median of 5 to 14 days from initial access to detonation. Adaptive Security reports something narrower from 2025 casework: ransomware executed an average of 6.1 days after the intrusion was first detected. Those measure different clocks, one from compromise and one from detection, and neither should be quoted as the other. The practical read is that defenders typically have days, not hours, and often burn most of that window unaware.

What Organizations Should Do

  1. Hunt for pre-positioned credentials, not just intrusions. Given the one-week-to-three-month gap Adaptive Security documents between credential leak and use, run continuous monitoring for your domains and VPN accounts across criminal marketplaces and combolists, and force rotation on any hit. Assume a leaked credential is a scheduled intrusion.
  2. Enforce phishing-resistant MFA on every remote-access path. VPN concentrators, RDP, VDI gateways and remote-management tools are Qilin's primary doors across all four tradecraft sources. SMS and push-approval MFA are insufficient; use FIDO2 or certificate-based authentication, and eliminate any remaining single-factor or legacy-protocol exceptions.
  3. Patch the KEV overlap first. Prioritize Check Point Security Gateway, ConnectWise ScreenConnect and Microsoft Exchange, the three CISA KEV entries Security Arsenal ties directly to Qilin-aligned access, along with any other internet-facing appliance in your KEV inventory. Treat perimeter appliance patching as an emergency-change class, not routine maintenance.
  4. Harden ESXi and hypervisor infrastructure as a distinct tier. Qilin ships Linux and ESXi encryptors specifically to collapse virtualized estates in one action. Isolate hypervisor management interfaces on a dedicated network, require separate credentials with no Active Directory trust path, disable SSH when not actively used, and enable lockdown mode.
  5. Make backups immutable and test restoration under time pressure. With no free decryptor available for any Qilin variant, recovery capability is the entire negotiating position. Keep offline or immutable copies outside the production identity domain and rehearse full restoration, including hypervisor and domain controller rebuilds, against a stopwatch.
  6. Instrument for the days-long staging window. Alert on renamed administrative binaries such as PsExec under non-standard names, LSASS access from unexpected processes, and large outbound transfers to cloud storage or unfamiliar ASNs. The dwell-time data from both Adaptive Security and Security Arsenal says detection is possible in that window; most organizations simply are not watching for it.
  7. Extend all of the above to subsidiaries, suppliers and data processors. Both the conglomerate structure implied in the Zorlu listing and the Turkish regulator's September 16 notices, where multiple breaches traced back to third-party software libraries on processor-operated servers, point the same way: the weakest entity in the group or supply chain sets the effective security posture for everyone connected to it.

Sources: Qilin Ransomware Claims Zorlu Holding: What We Know About the Alleg... | Qilin Ransomware Explained: Attack Chain, Victims, and Defenses Ad... | Qilin Ransomware: Attacks, Victims and Latest Activity | Qilin Ransomware Claims Two More Victims: KMLS and Touring Club Sui... | Qilin Ransomware Group Expands Extortion Targets to Include Federal... | QILIN Ransomware Gang: 15 New Victims Posted in 72 Hours — Cross-Se... | QILIN Ransomware Gang: 28 New Victims Posted in 24 Hours — Cross-Se... | Data breaches at 12 Turkish companies expose personal data of over...