Ransomware victim disclosure
← All victimsERG Otoyol Yatırım ve İşletme A.Ş.
listed as Erg Otoyol · Claimed by Thegentlemen · listed 4 months ago
Status timeline
- ListedFeb 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Turkey
- Listed on leak site
- Feb 11, 2026
About the victim
AI dossier — public-source company profileERG Otoyol Yatırım ve İşletme A.Ş. is a Turkish infrastructure company responsible for the investment and operation of the Ankara–Niğde Motorway (Otoyolu), a major section of the Trans-European Motorway (TEM) corridor linking northern and southern Turkey. The project connects Ankara to Niğde and is part of a broader route spanning Edirne to Şanlıurfa, also facilitating tourist access to Cappadocia and surrounding regions. The company is headquartered in Gölbaşı, Ankara.
- Industry
- Toll Road Infrastructure & Motorway Operations
- Address
- Gaziosmanpaşa Mahallesi 79/1 Sokak No: 6 M, Gölbaşı / Ankara, Turkey
- Founded
- 2018
Attack summary
Severity: high — The victim is an operator of critical transport infrastructure (a major national motorway in Turkey). Data has reportedly been published, indicating confirmed exfiltration. Compromise of a critical infrastructure operator's systems and data—potentially including land acquisition records, engineering data, customer payment/PII, and operational systems—warrants a high severity rating even without full visibility into the leaked dataset.The ransomware group 'thegentlemen' claims to have compromised ERG Otoyol and has published data (disclosed status: data_published); however, the leak post itself was inaccessible due to a bot-verification challenge, so specific details on encryption, exfiltration volume, or data categories could not be extracted from the post.
What the group claims
ergotoyol.com.tr zoominfo.com/c/erg-otoyol-yatırım-ve-i̇şletme-aş/463324492 ERG Otoyol Yatırım ve İşletme A.Ş. is focused on the Ankara-Niğde Motorway Project, which aims to provide high-standard, safe, and uninterrupted transportation across Turkey. The project is significant for connecting the northern and southern regions of the country and enhancing access to various tourism sites along the route. The company operates in accordance with its corporate values and business principles
The leak post
captured from the group's siteGentlecloud Protection 🛡️ Gentlecloud Verifying your browser... Initializing security checks... I'm not a bot
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

