Skip to content
Ransomware News

Ransomware Group Barracuda Hits: i2i-systems

Admin
HookPhish team
Target organization i2i-systems i2i-systems.com Technology

Summary

In the latest cybersecurity news, i2i-systems — an organization based in TR — has fallen victim to a ransomware attack conducted by the group Barracuda. This data breach, discovered on 2026-09-13T09:20:21.439464+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.

Incident Report

Attribute Information
Target Organization i2i-systems
Threat Group Barracuda
Summary This is one of the most poorly secured companies we have ever encountered. Over the course of a week, we analyzed the infrastructure and moved freely across their network. The infrastructure lacked proper security configurations, and the IT department showed a complete disregard for the data. As a result of the attack, 693 gigabytes of data were exfiltrated.
We downloaded the complete source code for the following projects:

Caplan
DataGov-Dev-Docker
DDR
DDR-Veriskop
DFE-Dev
Kangal-Dev
SDD-DEV-DOCKER
SDD-MAIN
commonprojects.zip
Copycat.zip
CopycatLive.zip
datacat.war
datagov.war
Kangal-Dev.zip
Kangal-Master.zip
[email protected]
smartdq.war

The volume of exfiltrated source code totaled 44 gigabytes. The data includes a full snapshot of the latest releases from the development repository. i2i-systems has a direct connection to the information security company Veriskop; therefore, this breach directly affects them as well. In addition, i2i-systems engaged in joint projects with partners such as Vodafone, Etiya, Bouygues, Freedom Mobile, and others; this is evidenced by the Linux servers located within the i2i-systems infrastructure:

1864654005 backup_Veriskop-SQA1.local_2026-08-31_203808.tar.gz
3292962897 copycat2019.i2isystems.local_critical_backup_2026-08-31_19-30-29.tar.gz
18422354 critical_backup_bouygues_fcbs_batch2.local_20260830_221815.tar.gz
2231188487 etiya-mobile-test-01.local_backup_20260831_213207.tar.gz
20546323810 freedom-mobile1-critical-vault.tar.gz
1050673952 freedom-mobile2-secrets-20260830-232814.tar.gz
721661 maya-redhat7-9_2026-08-30_233036.tar.gz
22966288270 ol8-10-innobi_full_backup_20260831_022640.tar.gz
529695763 veriskop-db-critical-backup-2026-08-31_234418.tar.gz
13012999372 veriskop-fiziksel-yedek-20260831023535.tar.gz
309528511 veriskop-oracle-critical-backup-2026-08-31_203340.tar.gz
633604141 veriskop-rhel-7.local_critical_backup.tar.gz
4878999722 Veriskoptest01.local_backup_20260831_213236.tar.gz
238487575 Veriskoptest02.local_critical_backup_20260831_213052.tar.gz
33936543608 veriskoptest03_critical_backup_2026-08-31.tar.gz

We have extracted absolutely all critical data from these infrastructure Linux systems and created a snapshot of the databases.
In addition, i2i-systems recently launched a joint project with Turk Telekom—we have downloaded the database containing all their customers.
The data will be published soon… | Severity: HIGH | Size: 643 GB | Status: selling | 300000$

Date of Breach 2026-09-13T00:00:00+00:00
Discovery Date 2026-09-13T09:20:21.439464+00:00
Region TR
Target Domain i2i-systems.com
Business Sector Technology

 

How to reduce your ransomware risk

Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:

Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.

Disclaimer

HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

Related articles

Security training designed for people.

See how HookPhish turns phishing simulation, training and threat monitoring into measurable human-risk reduction.

Book a demo Explore solutions