
Barracuda Ransomware Group Targets Turkish Telecom Firm i2i-systems in Major Data Exfiltration Attack
The Barracuda ransomware group has claimed responsibility for a breach of Turkish telecommunications provider i2i-systems, exfiltrating 693GB of sensitive data including proprietary source code.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Turkey
- Confidence:
- Confirmed
- Source:
- DeXpose
- Read Time:
- 4 min
Executive Summary
On September 13, 2026, the ransomware collective known as Barracuda successfully breached the network infrastructure of i2i-systems, a prominent telecommunications software provider based in Turkey. The attackers have confirmed the exfiltration of 693 gigabytes of sensitive corporate data. This incident highlights the ongoing trend of threat actors targeting critical infrastructure and technology suppliers to leverage double-extortion tactics against downstream clients.
Threat Analysis
The Barracuda group continues to demonstrate a high level of operational maturity, focusing on high-value targets within the telecommunications and critical infrastructure sectors. By exfiltrating proprietary source code, the group aims to maximize pressure on the victim, forcing a ransom payment to prevent the public release of intellectual property that could facilitate further supply chain attacks.
Technical Details
Initial reports indicate that the attackers gained unauthorized access to i2i-systems' internal servers, bypassing perimeter defenses to move laterally through the network. The exfiltrated data includes critical project source code, which poses a significant risk to the integrity of the software supply chain. The group is currently utilizing standard double-extortion methods, threatening to publish the stolen data on their dedicated leak site if their financial demands are not met within the specified timeframe.
Attribution Assessment
Barracuda is identified as an active cybercriminal ransomware group. While the group has been linked to various attacks throughout 2026, their TTPs (Tactics, Techniques, and Procedures) align with professionalized RaaS (Ransomware-as-a-Service) operations that prioritize data theft over simple encryption to ensure higher ransom conversion rates.
Implications
The breach of a telecommunications software provider like i2i-systems carries severe implications for the broader industry. The exposure of source code could potentially be weaponized by other threat actors to identify zero-day vulnerabilities in the software used by i2i-systems' global client base. Organizations relying on third-party software providers must urgently review their vendor risk management protocols.
Recommendations
- Immediate Audit: Organizations should conduct an immediate audit of all third-party software dependencies and verify the security posture of their vendors.
- Enhanced Monitoring: Implement robust EDR (Endpoint Detection and Response) solutions to monitor for anomalous lateral movement and unauthorized data staging.
- Data Protection: Ensure that sensitive source code and intellectual property are stored in encrypted, air-gapped, or highly restricted environments with strict access controls.
- Incident Response: Review and update incident response plans to specifically address potential supply chain compromises and data exfiltration scenarios.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Barracuda Ransomware Group Targets i2i-systems in Major Data Exfiltration Attack

Barracuda Ransomware Group Escalates Operations with Massive Data Exfiltration at i2i-systems

