It has been revealed that our current personal data is being sold for $10: No response from the BTK or the Presidential Digital Transformation Office!

It has been revealed that the current personal data of millions of citizens is being sold for $10. Cem Nuri Aldaş, President of the TMMOB Chamber of Computer Engineers, stated that they have received no response to the letters they sent to the Information and Communication Technologies Authority (BTK) and the Presidential Digital Transformation Office.

12punto

The website that stole the personal information of millions of citizens has been found to contain up-to-date data.

According to a report by İsmail Arı from BirGün; On this website where personal data is published, information from the Ministry of Interior's Central Civil Registration System (MERNİS), including "full names, Turkish ID numbers, family, lineage, address, hospital records, and mobile phone numbers," has been shared. Moreover, the site containing all this information can be accessed without even using a VPN.

In the VIP query section, more information can be accessed through a paid membership. With membership fees of $10 weekly, $20 monthly, and $90 annually, one can access "marriage, family tree, land registry, workplace, profession, driver's license, vehicle, license plate, school and university, medication, and IBAN" information. It is also stated that the site has 13,328 users and that no logs are kept.

"MEASURES CAN BE TAKEN"

TMMOB Chamber of Computer Engineers President Cem Nuri Aldaş stated that similar scandals have occurred before, and as a chamber, to the Information and Communication Technologies Authority (BTK) and the Presidential Digital Transformation Officestated that no response was given to the letters they sent.

Aldaş stated the following: “Only Türksat, which manages e-Devlet, responded by saying ‘data is not stored in e-Devlet.’ I do not think it is possible for this much data to be obtained by breaching places outside of e-Devlet, that is, 20-30 separate locations. In the past, we encountered different situations at different times. In 2019, credit card information was stolen. At another time, information spread that voter registries had been stolen. We never received any answers to our questions. Now, it is understood that some data is being sold. Being able to access people's addresses so easily could even lead to murder. It is a dangerous situation for people's addresses and workplaces to be discovered. Measures can easily be taken against such leaks. Security tests of the applications need to be conducted.”

Stating that the Chamber of Computer Engineers should actively participate in this process, Aldaş said, “There must be professional oversight. Now, in this latest scandal, it is understood that there is a vulnerability and that newly updated information is still being accessed, the mechanism is still functioning, and the data flow is continuing. In other words, the vulnerability that caused the data leak has not yet been closed. While the internet is slowed down even during situations like earthquakes, we see that there has been no intervention in the site where personal data is published. Measures must be taken quickly and a statement must be made to the public” he said.

IT CAN BE DETECTED THROUGH EFFECTIVE INVESTIGATION AND IN-DEPTH ANALYSIS

Evaluating the scandal for BirGün, lawyer Gökhan Ahi, founder of the Istanbul Bar Association's Informatics Law Center, said, “Touching upon the "penalties for stealing, disseminating, and selling personal data," he stated, "Crimes related to personal data are defined in Articles 135 and 136 of the Turkish Penal Code. While those who record personal data unlawfully are sentenced to imprisonment from one to three years, this sentence is increased by half if the data in question is sensitive personal data. For those who unlawfully share, disseminate, or seize personal data, a prison sentence of two to four years is stipulated. Furthermore, if crimes related to personal data are committed by public officials or individuals in certain professions, the penalties to be imposed are increased by half." he added.

Stating that "those who allow this data to be seized, either intentionally or through negligence, and those who fail to take the necessary administrative, legal, and technical measures are just as responsible as those who publish and sell personal data," Ahi continued his remarks as follows: "In fact, what needs to be done is to conduct an effective and in-depth investigation from the furthest point to the very first point. The point of vulnerability could be the Ministry of Interior, as well as other public institutions, banks, insurance companies, healthcare institutions, and even political parties. An effective and in-depth investigation"