Ransomware victim disclosure
← All victimsÇekok Gıda
listed as Cekok · Claimed by Dragonforce · listed 2 days ago
Status timeline
- ListedJun 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- Türkiye
- Listed on leak site
- Jun 11, 2026
About the victim
AI dossier — public-source company profileÇekok Gıda is a leading fruit and vegetable producer in Turkey and Europe with 65 years of operating history. The company cultivates 35 types of fruits and vegetables across 13,500 decares of farmland in multiple Turkish regions, operates 110,000 m² of factory facilities, and maintains a fleet of 170+ refrigerated trucks for cold-chain logistics. It is the second-largest kiwi producer in Europe and fifth globally.
- Industry
- Agriculture & Food Production - Fruits and Vegetables
- Address
- Turkey (multiple regions)
- Founded
- 1959
Attack summary
Severity: medium — Data has been published by the threat actor, indicating confirmed exfiltration. However, the specific nature and sensitivity of the data disclosed is not detailed in the available post excerpt, and no regulated data (PII at scale, financial records, etc.) is explicitly mentioned. The company operates in food production, not a critical infrastructure sector.The dragonforce group claims to have compromised Çekok Gıda and published exfiltrated data. The group post references the company's operations but does not explicitly detail what data was stolen or the attack method.
Data the group says was taken
AI dossier — extracted from the leak post- Operational/logistics data
- Production records
- Business information
What the group claims
Çekok Gıda is a leading fruit and vegetable producer in Turkey and Europe, known for its commitment to sustainable agriculture and high-quality products. The company cultivates 35 types of fruits and vegetables across 13,500 decares of farmland, utilizing advanced technology and adhering to strict environmental and safety
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

