Global Scam IntelligenceDaily updates on global scam news and tactics
← Back to home
PhishingPublished: September 25, 2026Türkiye

Turkish Authorities Bust Illegal Query Panel 'Dragon Hackerz' Exposing Personal Data of Over 100 Million People

Turkish authorities have arrested two operators of an illegal query panel called 'Dragon Hackerz' that provided unauthorized access to the personal identification data of over 101 million people and 118 million phone numbers. The system was being used for phishing and fraud schemes.

How the Scheme Operated

The 'Dragon Hackerz' illegal query panel discovered in Turkey represents a massive personal data breach. The system provided unauthorized access to identification data for over 101 million people and 118 million mobile phone numbers.

The system was designed and operated to facilitate phishing fraud, unauthorized data access, and financial scams. Investigators determined that beyond simply providing illegal access to personal data, the platform was directly integrated with online fraud and phishing operations.

Division of Roles

The two arrested individuals had distinct responsibilities:

  • E.C.:Founder and system administrator responsible for building and maintaining the illegal database
  • A.K.:Marketing and distribution agent responsible for promoting and spreading the illegal panel to users

By dividing responsibilities, they attempted to reduce individual liability and avoid detection.

Scope of Risk

This incident extends far beyond simple data leakage. The compromised personal information poses risks for multiple types of fraud:

  • Phishing scams:Fraudulent emails and SMS messages using stolen personal data
  • Romance scams:Relationship-based fraud and impersonation schemes
  • Unauthorized access:Illegal login attempts to bank accounts and online services
  • Targeted attacks:Coordinated cyberattacks against specific individuals

Warning Signs

Be alert if you receive:

  • Unexpected account verification emails from unfamiliar services
  • SMS messages claiming to be from government agencies requesting ID numbers or banking details
  • Messages from apparent friends/acquaintances requesting financial assistance or personal information
  • Emails promising refunds or bonuses from unknown sources

Prevention and Protection Measures

  1. Safeguard Personal Information

    • Never voluntarily provide ID numbers or banking details
    • Limit personal data entry to trusted websites only
  2. Verify Emails and SMS Messages

    • Always check sender email addresses carefully
    • Hover over links before clicking to preview actual URLs
    • Independently verify official notifications through official websites
  3. Protect Authentication Credentials

    • Change passwords regularly
    • Use unique passwords for each online service
    • Enable two-factor authentication when available
  4. Monitor Regularly

    • Review bank and credit card statements periodically
    • Check for unauthorized changes to online account settings

Reporting and Support Resources

If you suspect unauthorized access or fraud:

  • National Police Cybercrime Division
  • Your bank or financial institution security department
  • Internet service provider
  • National Police fraud hotline (varies by country)

Given the scale of such illegal database operations, compromised data can be exploited for months or years. Report any suspicious contact to authorities without hesitation.

Source: SacitAslan.com

Share