← Blog

Northern Cyprus Health Breach: 364K Records Allegedly on Dark Web

Share on X

June 2026: The personal and medical records of more than 364,000 people registered in the Turkish Republic of Northern Cyprus (KKTC) public health system have allegedly been exposed on the dark web—a incident Turkish Cypriot officials are now investigating after months of forum availability.

What reporting describes

Per Cyprus Mail and Turkish Minute, newspaper Yenidüzen reported that highly sensitive data belonging to 364,036 people appeared on a dark-web forum on January 8, 2026. Dutch cybersecurity experts cited in reporting reviewed samples and described the file as easily accessible.

Allegedly exposed fields include names, identity and passport numbers, dates and places of birth, addresses, parents' names, phone numbers, and vaccination records—spanning citizens of 202 nationalities, including foreign nationals who received healthcare in northern Cyprus.

Official response

KKTC public works minister Erhan Arıklı told legislators the allegation is under investigation and acknowledged "Is it possible? Yes, it is." Officials initially found no evidence but later confirmed an inquiry, requested cybersecurity support from Turkey, and are establishing a dedicated cyber defense unit. Opposition parties criticized the public for not being informed sooner given the data was reportedly online for nearly six months.

Why this is high severity

Health ministry data paired with identity numbers and addresses enables identity theft, fraud, blackmail, and stalking at scale. A separate actor claim of an HIV/AIDS database has not been independently verified.

What to do

  1. Do not download alleged health archives from criminal sites.
  2. Monitor official KKTC communications for confirmed notice.
  3. Foreign nationals who used north Cyprus healthcare should watch for fraud referencing real medical visits.

Canonical record: KKTC health leak 2026 on BreachHistory.