24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
/References

The results are concrete. The names are confidential.

29 real cases · 12 critical findings · 0 ransoms paid · 800 endpoints recovered in 9 days. Per our NDAs, the numbers speak, not the names.

99.4%
Data recovery success rate
0
Cases where ransom was paid
Very fast
Incident response speed
5.0 / 5
Customer satisfaction

Which one does your case resemble?

Free assessment · a detailed response within 48 hours.

+90 536 662 38 09
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Adli Bilişim
  • Veri Kurtarma
  • KAOS Yerel Yapay Zekâ
  • Siber Güvenlik
  • KVKK-GDPR Danışmanlık
  • DSET Akademi
  • Olay Simülatörü & Tehdit Heatmap
  • Web Sitesi Güvenliği
  • Bilgi Güvenliği
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
Automotive Manufacturing · 2025

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

An automotive supplier in the Marmara region was hit by a LockBit variant on a Friday evening. 800 endpoints + 12 PLCs were encrypted and the production line stopped for 9 days. DSET delivered a full recovery without paying ransom through an incident response + digital forensics + hardening process.

Duration
9 days
Scope
800 endpoints · 12 PLCs · 4 plants
0.2%Data Loss
0 USDRansom Payment
9 daysProduction Downtime
Review the case
Public Administration · 2024

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

An APT group that had stayed active for 14 months in the systems of a metropolitan municipality was detected by the DSET threat hunting team. Finance · archive · waste management data had been exfiltrated. A comprehensive cleanup in coordination with USOM.

Duration
3 months (hunting + cleanup)
Scope
2,400 endpoints · 14-month intrusion
14 months → 3 weeksDetection Time
47 hosts cleanedAffected Endpoints
~340 GB (detected)Data Leakage
Review the case
Finance · 2025

A 9-day Red Team engagement at one of Turkey's top 5 banks

A 9-day Black Box Red Team engagement for a mega-bank. Phishing → endpoint → AD → core banking jump server. 12 critical · 28 high findings. All vulnerabilities were closed in 30 days · stayed clean for 18 months.

Duration
9 days + 21 days of reporting
Scope
Top 5 bank · 50,000-endpoint scope
12 critical · 28 highFindings
17% (improved → 78%)Detection Rate
30 daysCritical Closure
Review the case
Healthcare · 2024

Ransomware at a 250-bed private hospital · full recovery within 48 hours

A private hospital in Anatolia was hit by a Conti variant at 23:00 on a Friday. 1,200 endpoints were encrypted · the HIS · PACS · LIS systems went offline. The emergency department ran on pen and paper for 30 hours. DSET recovered all systems in 48 hours.

Duration
48 hours
Scope
1,200 endpoints · 250 beds · 4 buildings
48 hoursOperational Return
0% (DB complete)Patient Data Loss
4% (only the last 12 hours)PACS Image Loss
Review the case
E-Commerce · 2025

Top 3 marketplace · a 4-week Red Team before Black Friday

A 4-week Red Team for one of Turkey's top 3 e-commerce marketplaces before Black Friday. Pentest of the payment flow · admin panel · vendor portal · return system. 23 findings · 4 critical · closed in 10 days · 0 incidents on Black Friday.

Duration
4 weeks of pentest + 10 days of remediation
Scope
Top 3 marketplace · ~5M MAU
23 (4 critical · 12 high)Total Findings
10 daysCritical Closure
0Black Friday Incidents
Review the case
Finance · 2025

RAID-5 with 3 failed disks on a bank BRSA archive server · 99.4% recovery in 48 hours

On the archive server of a mid-to-large-scale Turkish bank, a 4× 4 TB Enterprise SAS RAID-5 array · first one disk died and a rebuild started, then 2 more disks died. 7 TB of BRSA compliance records were at risk. A 99.4% recovery in 48 hours with a clean room + mathematical reconstruction.

Duration
48 hours
Scope
4× 4 TB SAS · 7 TB of data · BRSA archive
99.4%Recovery Success
48 hoursTotal Time
SHA-256 verifiedData Integrity
Review the case
Law · Court · 2025

Corporate espionage evidence on an iOS 17 device · a court report in 72 hours

An investigation of suspected corporate espionage on an iPhone 15 Pro Max (iOS 17.2.1) urgently served by the public prosecutor's office. WhatsApp + Signal + Photos metadata · a 72-hour court deadline · compliance with CCP Article 134 + ISO/IEC 27037. The DSET digital forensics team produced a full image + an expert report without breaking the chain of evidence.

Duration
72 hours
Scope
iPhone 15 Pro Max · 256 GB · iOS 17.2.1
68 hours / 72 hoursDelivery Time
Keychain + Signal + WhatsApp completeData Recovery
Never broken · SHA-256 verifiedChain of Evidence
Review the case
E-Commerce · 2025

OWASP ASVS L2 pentest on a PCI-DSS scope e-commerce platform · 3M customers · 14 business days

A full-scope Red Team over 14 business days before Black Friday for one of Turkey's top 5 e-commerce platforms. 12 services · web + mobile + API · payment + coupon + cart + admin. PCI-DSS scope · 3M MAU · 8M card records. 3 Critical + 7 High + 12 Medium · all closed before Black Friday.

Duration
14 business days + 4 days of retest
Scope
3M MAU · 8M cards · 12 services · PCI-DSS scope
30 (3C + 7H + 12M + 8L)Total Findings
T+12 (6 days before BF)Critical Closure Time
28/30 (93%)Re-test Closure
Review the case
Textile Export · 2026

WhatsApp Business account takeover at a 47-employee textile exporter · recovered in 22 minutes

On Monday morning at 08:14 a 47-employee textile exporter in the Marmara region lost its WhatsApp Business account to a social-engineering OTP transfer attack. "IBAN has changed" messages were sent to 280 customers and 12 frauds were completed. With Meta Business support DSET recovered the account in 22 minutes and the forensic investigation laid the groundwork for the indictment of 4 perpetrators.

Duration
22 minutes · 7 weeks of containment
Scope
47 employees · 280 affected customers · 312K TL fraud
22 minAccount recovery
312K TLTotal fraud
62%Insurance reimbursement rate
Review the case
Logistics & Cargo · 2026

Akira ransomware on ESXi vCenter at a regional logistics firm · 47 VMs · 94% data in 5 days

The VMware vCenter of a regional logistics firm operating in 8 provinces was encrypted by an Akira variant at 04:17. 47 VMs (ERP, warehouse management, driver tablets, file servers) were affected and the NAS replica had already been encrypted 4 hours earlier. The demand was 320K USD in bitcoin. With hybrid recovery (tape + LFE + log replay) DSET restored 94% of the data in 5 days and no ransom was paid.

Duration
5 days · 30 days of hardening
Scope
47 VMs · operations in 8 provinces · 18K € operational loss per hour
94%Data recovery
5 daysRestore time
0 USDRansom payment
Review the case
Industry & Manufacturing · 2026

CFO whaling at an industrial company · fake CEO mail · 380K TL transfer prevented

On Friday at 16:42 the CFO of an industrial company received a look-alike domain mail "from the CEO": "Urgent supplier payment, 380K TL to this IBAN, reporting on Monday." On DSET's advice an out-of-band verification was performed and the attack was prevented. After the DKIM/SPF/DMARC setup, 18 months clean and the following 4 fake mails were blocked automatically.

Duration
30-minute prevention · 7 days of hardening
Scope
380K TL transfer pressure · mid-sized industry
380K TLTransfer prevented
30 minVerification time
4 (18 months)Fake mail attacks blocked
Review the case
Services & Consulting · 2026

O365 mailbox takeover + auto-forward · 11-month supplier BEC · 2.6M TL loss detected

The O365 mailbox of an accounting assistant at a services firm was compromised via phishing 11 months earlier. The attacker used an "Inbox rule" to forward all supplier invoices to themselves, changed the IBAN and sent fake invoices. DSET detected 11 months of losses, the insurance reimbursement of 58% was approved, and the KVKK penalty risk was avoided.

Duration
11-month detection · 3 months of hardening
Scope
38 affected suppliers · 2.6M TL total · 280 fake invoices
2.6M TL11-month loss detected
58%Insurance reimbursement
0KVKK penalty
Review the case
Manufacturing & Industry · 2026

200-endpoint manufacturer · AD Kerberoast + Cobalt Strike · eradication before the DA hash was cracked

At a 200-endpoint manufacturer a SOC analyst noticed anomalous Kerberos TGS requests: 280 TGS-REQs for SPNs in 12 minutes. BloodHound showed the first attempt 3 weeks earlier. With a rapid krbtgt double-rotation + full eradication DSET kicked out the attacker before the DA hash was cracked, ensuring 24 months of clean operation.

Duration
7 days · 30 days of hardening
Scope
200 endpoints · 47 SPNs · 6 weeks of initial access
PreventedDA hash cracking
7 daysEradication time
0Reinfection (24 months)
Review the case
E-Commerce · 2026

Magento store with 8M TL monthly revenue · Magecart skimmer · 840 cards leaked in 14 days

A Magecart skimmer was added to the checkout.js of a Magento store with 8M TL in monthly revenue 14 days earlier. 840 cards had flowed to a Latvian C2. DSET cleaned it in 4 hours; after the PCI-DSS notification + coordination with banks + a DSET pentest a PCI-DSS Level 1 certificate was obtained, with 18 months of clean operation.

Duration
4 hours of cleanup · 30 days for PCI-DSS certification
Scope
840 leaked cards · 8M TL monthly revenue · 14 days of exposure
4 hoursSkimmer cleanup
85%Visa fraud reimbursement
CertifiedPCI-DSS Level 1
Review the case
Healthcare · 2026

Cryptomining botnet on MR/CT devices at a 300-bed hospital · ICU monitors protected

At a 300-bed public hospital, IT noticed packet delay on ICU monitors from the medical device network. 47 devices (MR, CT, biochemistry) were cryptomining with a Mirai variant + Monero miner. DSET isolated the medical device VLAN, secured the ICU; after IEC 80001 + ISO 27799 compliance, 24 months clean, and the Ministry of Health awarded a "model hospital" title.

Duration
2 hours of containment · 90 days of IEC 80001 compliance
Scope
47 infected medical devices · 300 beds · 0 packet loss in the ICU
0ICU packet loss
2 hoursContainment time
FullIEC 80001 compliance
Review the case
Manufacturing & Industry · 2026

SQL Server LockBit + RAID-5 degraded at a manufacturer · DSET dual-channel recovery 96%

A manufacturer's SQL Server 2019 was encrypted by LockBit while at the same time the RAID-5 array had one failed disk (DEGRADED). If a second disk crashed, the data would be completely lost. By freezing the array, DSET restored 96% of the data with hybrid recovery (tape + log replay) and no ransom was paid.

Duration
5 days of recovery · 30 days of hardening
Scope
8 days of ERP data at risk · last clean backup 6 days earlier
96%Data recovery
5 daysRestore time
0Ransom payment
Review the case
Retail & Shopping Mall · 2026

Fake top-cover skimmer on a shopping mall POS terminal · 47,000 cards read over 8 weeks · 4 perpetrators indicted

The mall management noticed 8 weeks later that a POS terminal's top cover had been replaced with a fake device (observed by cleaning staff). It contained a Bluetooth chip + a magstripe reader. 47,000 cards were read and 1,200 frauds confirmed. With a DSET forensic investigation + mall CCTV facial recognition + a joint indictment by 3 malls, the gang was arrested.

Duration
5 days of forensic investigation · 90 days for certification
Scope
47K cards read · 1,200 frauds · 4 perpetrators · 3-mall gang
4 (gang)Perpetrators caught
47K customersCompensation distribution
2 (caught)New skimmer attempts
Review the case
Software & Technology · 2026

B2B software company WordPress backdoor + 120 JP SEO spam · Google rank back in 4 weeks

A B2B software company's WordPress corporate site was compromised 6 months earlier. A Google Search Console "JP spam content" warning appeared. 14 backdoor PHP files were added to wp-includes/ and 12,000 hidden posts were added to the DB. The site's Google rank dropped 78%. With a clean install + WAF + reconsideration request DSET regained the rank in 4 weeks, with 18 months clean.

Duration
4 weeks of SEO recovery · 90 days of hardening
Scope
120 spam URLs · 12K hidden posts · 78% rank loss
100%Backdoor cleanup
4 weeksSEO rank recovery
118% (previous+18%)Final rank
Review the case
Cement & Heavy Industry · 2026

Cement plant OT pentest · Siemens S7-1500 + WinCC · 14 critical findings · IEC 62443 SL3

A cement plant requested an authorized OT pentest from DSET. Target: Siemens S7-1500 PLCs, WinCC HMI, the ICS DMZ. Rule: production must not be stopped (a 1M TL/hour penalty risk). With passive recon + lab exploitation DSET reported 14 critical findings, production was never touched, and an IEC 62443 SL2→SL3 transition certification was achieved.

Duration
14 business days of pentest · 90 days of IEC 62443 transition
Scope
47 PLCs · 12 HMIs · 4 production lines
14 critical · 8 highFindings
SL2 → SL3IEC 62443 SL
0Production downtime
Review the case
Banking & Finance · 2026

Top 5 bank mobile banking · OWASP MASVS L2 pentest · 7 critical findings · BDDK compliance

One of Turkey's top 5 banks requested an authorized mobile banking pentest from DSET. Target: iOS+Android jailbreak/root detection bypass, MitM, cert pinning, secure storage. With the full MASVS L2 procedure DSET identified 7 critical findings, the bank fixed them, the BDDK audit was passed, and a 3-year strategic partnership began.

Duration
21 business days of pentest · 30 days of remediation
Scope
iOS+Android · 8M active users · BDDK scope
7 critical + 12 highFindings
ApprovedMASVS L2 certificate
SuccessfulBDDK audit
Review the case
Crypto & FinTech · 2026

Turkish crypto exchange with 8M users · API + cold wallet Red Team · 9 critical findings · MASAK compliance

A leading Turkish crypto exchange requested a Red Team from DSET. Target: the REST/WebSocket API, withdrawal flow logic, the cold wallet HSM signing flow. Rule: loss of funds is FORBIDDEN, with an anomaly ban risk. Using a graduated read-only-first method DSET reported 9 critical findings (race + IDOR + signature replay), no funds were lost, and MASAK compliance was achieved.

Duration
14 business days of Red Team · 30 days of remediation
Scope
8M users · REST + WebSocket + cold wallet
9 criticalFindings
0Loss of funds
0Anomaly ban
Review the case
Telecommunications · 2026

GSM operator Pulse Connect VPN intrusion · BloodHound 4-hop DA path · 11 critical findings

One of Turkey's top 3 GSM operators requested an authorized red team from DSET. Target: external intrusion → VPN exploit → AD lateral → the core OSS system. Rule: impact on the production OSS system is FORBIDDEN. DSET reported a BloodHound 4-hop DA path + 11 critical findings, with no production impact; BTK gave its appreciation and a 3-year contract was signed.

Duration
30 business days of Red Team · 90 days of hardening
Scope
Turkey top 3 GSM · OSS + AD + VPN gateway
11 criticalFindings
0Production impact
Critical infrastructure vendorBTK approval
Review the case
Smart Building & IoT · 2026

A+ office complex IoT pentest · 480 cameras + BMS + elevators · 14 critical findings · TSE approval

A newly built A+ office complex requested an acceptance test from DSET. CCTV (ONVIF, 480 Hikvision cameras), BMS (BACnet, HVAC + elevators + access control), 1,200 IoT devices. Rule: impact on elevators/HVAC/access control is FORBIDDEN (human safety). With passive analysis DSET reported 14 critical findings + IEC 62443 SL2 recommendations, and the TSE acceptance test was passed.

Duration
10 business days of pentest · 60 days of IEC 62443
Scope
480 cameras · 1,200 IoT devices · a 47-floor complex
14 critical · 22 highFindings
0Human safety impact
PassedTSE acceptance test
Review the case
Law & Legal Practice · 2026

DNS tunneling exfiltration at an upscale law firm · 8 GB of client files leaked in 3 months

An anomalous DNS query pattern was detected at the firewall of an upscale law firm: a single endpoint making 12,000 TXT record queries per day, a subdomain pattern of 60-char base64-like text (a DNS tunnel signature). 8 GB of client files had leaked in 3 months. With a DNS firewall + a forensic investigation + KVKK compliance, DSET achieved a 50% insurance reimbursement and 18 months of clean operation.

Duration
22-minute tunnel cut · 21 days of legal process
Scope
8 GB of leaked data · 680 affected clients · APT41 TTP
22 minTunnel cut
8 GBLeaked data detected
50%Insurance reimbursement
Review the case
Software & Technology · 2026

200-endpoint software company · PowerShell Empire fileless C2 · undetected for 90 days

At a 200-endpoint software company a SOC analyst had been seeing anomalous PowerShell activity for weeks. AV/EDR kept coming back clean. With memory forensics DSET revealed an Empire C2 beacon, 47 endpoints were fully cleaned; after a ZTNA + EDR + Sysmon + KQL architecture, 12 months clean and a MITRE ATT&CK simulation was passed.

Duration
1 week of eradication · 30 days of architecture
Scope
47 infected endpoints · 90 days of exposure · DA 2 hops
47 endpointsEmpire eradication
1 weekPassive observation
5 minSentinel detection
Review the case
Investment & Holding · 2026

Investment holding · Cobalt Strike Malleable C2 · APT41 · undetected for 4 months · USOM coordination

An investment holding's SOC analyst noticed an anomalous jitter pattern in HTTPS traffic: a Cobalt Strike Malleable C2 profile (Amazon mimicking) had been used. Inside for 4 months, 23 endpoints infected. An APT41 TTP match. With 2 weeks of passive observation + USOM coordination + coordinated eradication DSET achieved 24 months of clean operation and national threat intel sharing.

Duration
2 weeks of observation · 30 days of eradication
Scope
23 infected endpoints · CFO+CEO included · APT41
23 endpointsAPT41 eradication
2 weeksPassive observation
ActiveUSOM coordination
Review the case
Forensics & Court · 2026

Forensics of a DJI Mavic 3 seized by the Coast Guard · 3D flight simulation · defendant conviction

A forensic unit handed DSET the memory of a DJI Mavic 3 seized by the Coast Guard. Drone flight history + video recording + telemetry analysis were needed in court. Following the ISO 27037 procedure DSET produced a bit-perfect image, carved deleted video, and prepared a 3D flight simulation. The court accepted the technical expert opinion 100%; the defendant received a 4-year prison sentence.

Duration
3 hours of imaging · 14 days of analysis · 3 months of court
Scope
DJI Mavic 3 + 64GB SD + 8GB internal · 14 deleted videos
3 hoursImaging time
14Recovered video
100%Court acceptance
Review the case
Forensics & Expert Witness · 2026

iPhone 15 Pro Pegasus-like spyware · 4 IOCs matched · UN archive · journalist compensation

An investigative journalist's iPhone 15 Pro had a complaint of "excessive battery + heating + background data traffic." A court-approved forensic request. With MVT (Mobile Verification Toolkit) + the ISO 27037 procedure DSET detected a BlastDoor bypass, 4 IOCs matched the Citizen Lab list, it entered the UN Special Rapporteur's archive, and the journalist received compensation.

Duration
7 days of analysis · 3 months of international litigation
Scope
iPhone 15 Pro · iOS 17.4.1 · 4 zero-click IOCs
4Pegasus IOC match
State-sponsoredApple notification
ApprovedUN archive
Review the case
Insurance and Individual · 2025

Locked iPhone forensics for a life insurance claim, 2.4M TL to the family in 14 days

After the death of a 17-year-old in a motorcycle accident, a 2.4M TL life insurance claim process was opened. The insurance adjuster requested the iPhone's contents to distinguish accident, suicide or intentional death. The device had been on a muddy road at the scene for 11 hours, the screen was cracked, Face ID was unusable, Activation Lock was active, and because the owner had died the PIN was unknown. The DSET mobile forensics team prepared an ISO 27037 and ISO 27042 compliant insurance technical expert opinion in 14 days, and the compensation was paid to the family within 48 hours.

Duration
14 days
Scope
iPhone 14 Pro Max, 256 GB, iOS 17.4.1, paired Apple Watch, Activation Lock active
2.4M TLCompensation paid
14 days (within the 30-day insurance window)Duration
256 GB, SHA-256 verifiedFull data image
Review the case
Contact form
Privacy
KVKK
GDPR
Cookies
Terms