Cybercrime organization dismantled: MIT operation against PTT and HGS scammers

In an Istanbul-based operation, an internationally linked cybercrime organization that defrauded citizens by using the names of PTT and HGS was dismantled. Following a joint effort by the MIT, MASAK, and the Gendarmerie, 12 suspects were apprehended; 10 were arrested and sent to prison.

İHA

Within the scope of a large-scale investigation conducted by the Istanbul Anatolian Chief Public Prosecutor's Office, an organized cybercrime group that defrauded citizens using the PTT and HGS brands was exposed through a coordinated operation by the MIT, the Financial Crimes Investigation Board (MASAK), and the Gendarmerie General Command.

During the operation, which followed six months of technical and intelligence work, 12 suspects were apprehended, 10 of whom were arrested by the court and sent to prison.

PHONES COMPROMISED WITH MALICIOUS SOFTWARE

According to information obtained by the MIT, the organization members gained full control of Android devices by installing malicious software. Through this, fake SMS messages containing content such as "You have an HGS debt" or "Your PTT package was not delivered" were sent from citizens' phones without their knowledge.

Citizens who clicked on the links in the messages were directed to fake websites that were identical to the real ones, where they were coerced into sharing their credit card and identity information. Investigations by MASAK determined that the proceeds obtained from the fraud were converted into cryptocurrency and laundered through international networks.

GEORGIA CONNECTION REVEALED

As the investigation deepened, it was determined that the organization was managed through Georgia-based extensions and received orders via Telegram channels. With the intelligence support of the MIT, the identities of the individuals involved in the Georgia leg were identified, and it was learned that efforts to apprehend them are ongoing.

SIMULTANEOUS RAIDS IN 6 PROVINCES

Operations against the identified suspects were carried out simultaneously in Istanbul, as well as in İzmir, Van, Elazığ, Bingöl, and Hakkâri. During the dawn raids, 12 suspects were captured; numerous digital materials, cash, foreign currency, and cryptocurrency wallets were seized during searches of the homes.

318 FAKE WEBSITES SHUT DOWN

Within the scope of the operation, 318 websites used by the organization for fraudulent activities were blocked. Additionally, a special "control panel" used by the hackers to manage the phones was seized. It was revealed that through this system, SMS messages could be sent, calls could be redirected, cameras and screens could be monitored, and even real-time location information could be tracked without the users' knowledge.

According to the MIT report, the software also recorded keyboard keystrokes. In this way, the most sensitive data, including passwords and one-time verification codes, were captured. In some cases, it was determined that data was collected not only for financial purposes but also for blackmail and espionage.

CYBERSECURITY WARNING FROM THE MIT

MIT officials emphasized that all resources are being mobilized to prevent citizens from becoming victims of the recent rise in cyber fraud incidents.

While it was stated that such operations, carried out in coordination by state institutions, will continue uninterrupted, the following warnings were issued to citizens:

Do not download applications from unknown sources.

Do not click on links from numbers you do not recognize.

Perform your financial transactions only through official applications.