Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Turkish HR Provider Baltaş Eksen Faces 750-Company Data Exposure Claim

Turkish HR Provider Baltaş Eksen Faces 750-Company Data Exposure Claim

By: Morgan Cipher — Senior Privacy Journalist

Last updated: October 4, 2026

Human Written
Turkish HR Provider Baltaş Eksen Faces 750-Company Data Exposure Claim
  • A hacker claims he stole data from more than 750 Turkish companies and put it up for sale.

  • The claim links back to a cyberattack on Baltaş Eksen, a Turkish HR firm, but the full scale remains unconfirmed.

  • Turkey’s data watchdog confirmed a separate breach at Hyundai Motor Türkiye, affecting up to 422 people.

A hacker says he stole data from hundreds of Turkish companies. He claims he now sells this data on the dark web. But solid proof for the full claim does not exist yet. Only one small piece of the story has official confirmation so far.

A Hacker’s Big Claim Surfaces

The story starts with a June 2026 cyberattack. The target was Baltaş Eksen, a Turkish company that runs HR and personality tests for businesses. Threat intelligence firm ThreatMon tracked the incident and shared what they found.

A hacker claimed he broke into Baltaş Online. He said he spent 47 days inside the system before anyone noticed. He also claimed he grabbed more than 500GB of data during that time.

The hacker’s story grew bigger from there. He said the stolen files touched more than 750 companies across Türkiye. He listed personnel records, executive psychometric test results, candidate files, emails, exam materials, interview recordings, internal notes, and even source code. That is a long list, and it covers a lot of ground.

ThreatMon noted that the hacker posted sample files as proof. But researchers could not confirm the bigger claim. The full scope remains unverified, according to ThreatMon’s report.

Turkish news outlet OdaTV later reported similar claims. The outlet said attackers advertised data tied to roughly 700 companies and 700,000 people. They allegedly sold this data through dark web forums and a special platform built for the leak.

OdaTV’s report named several industries in the data. These included finance, aviation, carmaking, defense, education, and public offices. The report also said the attackers claimed to hold psychometric results and details about senior company leaders.

Baltaş Eksen Pushes Back

Baltaş Eksen did not stay silent. The company confirmed a cybersecurity incident happened in June. It said it reported the matter to Turkish authorities right away. The company also filed a criminal complaint. It hired an outside team to run a forensic investigation into the breach. These steps show the company took the incident seriously.

Still, Baltaş Eksen pushed back hard against the numbers floating around online. The company said the dark web figures do not match what its own review found. Its technical investigation and customer checks told a different story, according to the OdaTV report.

The company added that some customers showed zero signs of being affected. This detail matters a lot. It suggests the hacker’s claim may be larger than the real damage. So two different pictures exist side by side right now. One picture comes from dark web posts and threat researchers. The other comes from the company’s own internal review. These pictures do not fully match yet.

One Breach Gets Official Confirmation

Not everything about this case stays murky, though. One piece has real, confirmed proof behind it. That piece involves Hyundai Motor Türkiye.

Turkey’s Personal Data Protection Authority, known as KVKK, published an official notice about this case. The authorities said hackers broke into Hyundai’s web application. They used a method called SQL injection to get inside.

KVKK said the breach affected employees and job candidates. Up to 422 people may have been affected, according to the notice. That is a much smaller number than the 750+ figure making headlines elsewhere.

The exposed data included names and email addresses. It also included usernames, passwords, and job titles. On top of that, Hogan and BEYT personality test results leaked too. These tests often link back to the Baltaş Eksen platform, which ties this case to the wider story.

This Hyundai case gives researchers a real anchor point. Other cybersecurity investigations have also produced unexpected developments, including a case where cybersecurity workers were arrested while performing a courthouse security test. It proves the attack infrastructure linked to Baltaş Eksen did cause at least one genuine breach. But it does not prove the much bigger claim of 750+ companies losing data.

What This Means Right Now

People who use Baltaş Eksen services should stay alert. Psychometric tests, employee files, passwords, and company documents carry real risk if exposed. Criminals could use this data for phishing emails, fake calls, or identity theft.

Companies linked to the HR firm should check their own records closely. They should also watch for strange login attempts or unusual account activity. Quick action now can reduce damage later. At the same time, nobody should treat the 750+ company claim as fact. The evidence does not support that number yet. One confirmed breach exists. A much larger claim still awaits real proof.

Security researchers will likely keep digging into this case. More facts may surface in the coming weeks. Until then, caution makes more sense than panic, and facts matter more than big, scary numbers.

Share this article

You might also like

Fortinet Warns Hackers are Exploiting Critical FortiMail Vulnerability

Fortinet Warns Critical FortiMail Zero-Day is Under Active Attack

Attackers are using a serious new bug in Fortinet’s FortiMail tool. CISA added the flaw to its danger list right…

October 4, 2026
ShinyHunters Website Goes Offline After FBI Deadline Expires

ShinyHunters Site Goes Dark as FBI Cyber Investigation Intensifies

The hacker group ShinyHunters’ website went offline on September 30, one day after its FBI deadline expired. The group claimed…

October 2, 2026
Russian Hackers Use New RedFlick Attack to Deliver CosmicPulse Backdoor

Russian State Hackers Use New RedFlick Technique to Deploy CosmicPulse Backdoor

Russian state-linked hackers known as Star Blizzard have started using a new attack method called RedFlick to deliver a dangerous…

October 2, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.