MediumII Cyber Warfare & Critical Infrastructure25 September 2026, Friday
Espionage probe into MASAK's EMIS system: 22 suspects, protection for politically exposed persons disabled, TMSF appointed trustee of 2 software firms
On 25 September the Istanbul Chief Public Prosecutor's Office launched proceedings against 22 suspects over allegations that unauthorised queries were run in MASAK's EMIS software between 2012 and 2018. Five people were detained and arrest warrants were issued for 16 abroad; 3 former MASAK presidents will give statements on 28 September.
According to a Cumhuriyet report published at 09:25 on 25 September, the investigation is being conducted on charges of political or military espionage over unauthorised operations and security weaknesses in the Financial Crimes Investigation Board's (MASAK) Integrated Financial Intelligence System (EMIS). The technical examination found that the protection mechanism for the politically exposed persons (PEP) list had been disabled and that queries had been run on President Erdoğan, his relatives and certain ministries. Of the 22 suspects, 5 were detained, arrest warrants were issued for 16 found to be abroad, and 1 person is being sought; the suspects include MASAK's then vice-president.
According to the same report, the EMIS software was developed from 2012 by AGMLAB A.Ş., together with MRD A.Ş. and Barış Ata A.Ş., the latter closed by emergency decree after 2016; the prosecution alleges that the individuals and companies that developed the infrastructure during this period were linked to FETÖ/PDY. AGMLAB and MRD were seized by court order and the TMSF was appointed as trustee. According to a 25 September Turkish Minute report, there are findings that records may have been altered or deleted, and administrator access logs do not exist. Former MASAK presidents Mürsel Ali Kaplan, İbrahim Hakkı Polat and Osman Dereli will give statements on 28 September. It should be noted that the allegations have not been verified by a court and that the suspects' defence has not yet been made public.
Talay assessment
Bottom line
The investigation sets out the allegation that public financial data was open to unauthorised queries via external software suppliers between 2012 and 2018; the absence of administrator access logs makes the allegation harder to prove both technically and legally. The statements of the 3 former presidents on 28 September will determine whether responsibility is sought with the supplier or with the institution's management.
Likely effects
- Public sector cybersecurityNegative1–6 months
That PEP protection could be disabled and that no access logs exist show that logging and supplier oversight remain weak in critical public software; demands for audits at other institutions may follow.
- TürkiyeNegative1–6 months
The TMSF trusteeship over 2 software firms raises contract and security investigation risk for domestic public software suppliers.
- Financial crime oversightUncertainWeeks
With the reliability of the system being questioned in a week when fund crisis investigations rely on MASAK, the institution needs to provide assurance on data integrity.
Possibilities, ranked
- 1Investigation widens55%
New detentions and action against additional firms follow the 28 September statements.
Watch: Chief Public Prosecutor's statement after 28 September
- 2Technical audit and regulation30%
A regulation is drafted mandating access logs and supplier audits for critical public software.
Watch: Public information security regulation in the Official Gazette
- 3Case stays limited15%
Evidence proves insufficient owing to missing logs, and the investigation proceeds limited to the 22 suspects.
Watch: Number of arrest and judicial control decisions
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Number of suspects▲ 22
- Arrest warrants abroad▲ 16
- Firms placed under trustee▲ 2