
KVKK Fines a Platform 250,000 TL for Tying Live Match Streaming to “Explicit Consent”
KVKK fined a platform 250,000 TL for tying live match streaming to marketing consent. What organisations should check on their consent screens.
The US is opening the way for selected private firms to run offensive cyber operations against foreign criminal groups under government oversight.

There is a question the cybersecurity world has debated for years:
When a company is attacked, should it limit itself to defence, or should it be able to pursue the attacker and neutralise their systems too?
Until now, that debate was largely theoretical.
Not any more.
In a highly unusual move against cybercrime, the US administration is opening the door for selected private companies to carry out offensive cyber operations against foreign criminal organisations under government supervision.
In other words:
Cybersecurity companies may no longer sit only on the side that detects and blocks attacks.
Under specific conditions, they may also become the side that intervenes in the attacker's infrastructure.
And this decision pushes "hack-back" — a concept long argued over in cybersecurity — back to the centre of the agenda.
When a ransomware group breaks into a company's systems today, what the defence team can do is broadly settled.
Detect the attack.
Cut off the attacker's access.
Remove the malware.
Isolate affected systems.
Carry out forensic analysis.
Investigate whether data was exfiltrated.
Return systems to a secure state.
But travelling to the attacker's server somewhere else in the world and intervening there?
That is where the line shifts.
Defence ends and an offensive cyber operation begins.
The new US approach redefines precisely that boundary.
Under the regulation announced on 13 August 2026, the US Department of Justice (DOJ) and the Department of Homeland Security (DHS) will establish a new programme in which selected private companies may take part in cyber operations against transnational criminal organisations.
But there is an important detail here:
Not every cybersecurity company will be able to attack any target it wishes.
Participating companies are expected to have their technical competence assessed and their personnel put through security vetting.
Beyond that, the operations themselves must be reviewed by the government.
So the model will not work like this:
"I was attacked, I found the IP address, now I am hacking them back."
Operations must be examined and approved in writing by the DOJ and DHS.
For that reason, the structure that emerges is less a classic, uncontrolled "hack-back" model and better described as:
a government-supervised, private-sector-supported offensive cyber operation model.
This is where the most striking part of the programme begins.
Approved private companies may be permitted to conduct cyber surveillance against foreign criminal organisations.
But the authority does not stop there.
In certain circumstances, operations aimed at disrupting or disabling the digital infrastructure used by criminal organisations may also be carried out.
Consider a ransomware group.
The group may have:
command-and-control servers,
malware infrastructure,
operational servers,
data exfiltration infrastructure,
and other digital resources used in its attacks.
The traditional defensive approach focuses on blocking the attacks coming from that infrastructure.
The new approach raises a far more aggressive question:
Why not neutralise that infrastructure directly?
The step the US has taken is an attempt to institutionalise exactly that idea.
One of the key conditions of joining the programme is financial responsibility.
Participating companies are expected to hold at least one million dollars in collateral or escrow.
If a company breaches the programme's rules, it may forfeit that guarantee.
The reasoning is easy to understand.
Because what is being carried out here is not an ordinary penetration test.
If the wrong target is chosen, another company, an innocent system or a foreign country's infrastructure could be harmed.
The consequences of these operations may therefore not be purely technical.
Legal and even diplomatic consequences can follow.
The new approach does not grant companies unlimited authority to attack.
Operations conducted under the programme are stated to be incapable of causing death or serious injury.
Likewise, the activities carried out must not rise to the level of armed attack or use of force under international law.
Another critical matter is US citizens and systems located in the United States.
If a person or information system in the US is accidentally targeted during an operation, the company must halt its activity and inform the government.
These details in fact show how delicate the new model is.
Because in the cyber world, targets are not separated by boundaries as clear as those in the physical world.
Here one of the programme's greatest problems emerges.
Assuming a cybercrime organisation's infrastructure sits in a single country is often unrealistic.
The attacker may be in Russia.
The command-and-control server may be in another country.
The VPN may operate from somewhere else entirely.
A compromised server may be located in Europe.
The proxy infrastructure may sit in yet another country.
And part of the attack may be routed through the compromised system of a completely innocent company.
So when pursuing the attacker, saying:
"We are attacking the attacker's system."
is not always technically straightforward.
If the wrong system is targeted, an entirely unrelated company may be harmed.
Worse still, another country's infrastructure may have been affected.
This is precisely one of the experts' greatest reservations.
There is another problem that makes matters even more complicated.
In the cyber world, the line between a state-sponsored threat actor and an independent cybercrime organisation is not always clear.
Some hacker groups appear to act independently.
Yet in certain periods they may cooperate with state institutions or carry out operations aligned with their interests.
The new programme is expected to exclude groups that are an institutional part of foreign states or are entirely directed by a foreign government.
Reasonable on paper.
But in the real world, attribution — establishing the attacker's identity with certainty — is one of cybersecurity's hardest problems.
What happens if a company believes it is intervening in a ransomware group's infrastructure but in reality touches a foreign state's operation?
That is the point at which a technical operation can turn into a diplomatic crisis.
This debate also has an interesting historical parallel.
In the past, states could grant certain private vessels the authority to attack enemy ships in wartime.
These were known as privateers.
The state did not carry out the attack directly.
But it granted a private actor the authority to attack within defined limits.
That is why some experts today describe the new US approach as "cyber privateering".
The computer has taken the place of the warship.
The internet has taken the place of the seas.
Ransomware groups have taken the place of pirate ships.
And centuries later, the idea of the state-backed private actor is being debated again in the digital world.
One of the main reasons the US is putting such a radical model on the table is the sheer scale the cybercrime economy has reached.
Ransomware groups are no longer small hacker crews.
Some operate like professional companies.
They have software developers.
They have operations teams.
They have affiliate models.
They have payment infrastructure.
Some even have support systems resembling customer service.
On top of that, the entry of artificial intelligence into attack operations may enlarge the scale of these threats further.
Reconnaissance is becoming automated.
Phishing content can be produced rapidly.
Vulnerability research is accelerating.
Attack operations can be scaled.
So for states, the question is steadily shifting:
Is it more effective to keep blocking attacks, or to remove the attacker's operational capacity?
The new US approach shows that more weight is being given to the second option.
There is no easy answer to this question.
The argument in favour is strong:
Cybercriminals have operated at relatively low risk for years.
When their infrastructure is taken down, they build new infrastructure.
When their servers are blocked, they move to another server.
When a domain is closed, they open a new one.
For that reason, staying purely on defence is seen as failing to raise the attacker's costs enough.
If offensive operations succeed, attackers may find that:
their infrastructure is disrupted,
their operating costs rise,
their data or tools are rendered unusable,
their activities can be monitored,
and their attack capacity is reduced.
But the counter-argument is at least as strong.
What happens if the attacker retaliates?
What if the wrong target is hit?
What if innocent systems are harmed?
What if the operation collides with another state's intelligence activity?
What if a private company unwittingly triggers an international crisis?
This is why "hack-back" remains one of the most contested topics in cybersecurity.
Granting the authority is one thing; companies wanting to take that risk is another.
A company conducting offensive cyber operations is not only taking technical risk.
It is taking legal risk.
It is taking reputational risk.
It is taking operational risk.
It is taking the risk of potential retaliation.
Moreover, because of the covert nature of these operations, its ability to use the work for commercial marketing may be quite limited.
So one of the most closely watched questions in the coming period will be how many companies join the programme.
Perhaps the most important consequence of this decision lies here.
For many years the cybersecurity world has been split into two separate domains:
Defence and offence.
Private companies remained largely on the defensive side.
SOC teams monitored attacks.
SIEM systems analysed events.
EDR and XDR solutions detected attacks.
Threat Intelligence teams tracked threat actors.
Incident Response teams handled post-attack response.
Offensive operations, meanwhile, were largely the domain of states' intelligence and military units.
The new US approach may change that boundary.
For the first time, the private sector may become part of state-backed offensive cyber operations in a far more systematic way.
Treating this US step merely as a new cybersecurity programme may fall short.
The real change is bigger.
States have spent years trying to increase their defensive capacity against cyberattacks.
But the growth of ransomware, financial fraud, data theft and organised cybercrime is putting a new approach on the agenda:
not only stopping the attack, but also disrupting the attacker's operational capacity.
If this approach succeeds, it would not be surprising to see other countries develop similar models.
Yet its uncontrolled spread could also turn the internet into a far more complex arena of conflict.
Government institutions.
Cybercrime organisations.
Intelligence services.
Private cybersecurity companies.
Defence industry firms.
AI-supported attack systems.
In a world where all of these run active operations in the same digital space, attribution, authorisation, accountability and international law will become far more critical than they are today.
For years, the basic advice given to companies was fairly simple:
Now a new and highly contested option is being added to that list:
Disrupt the attacker's operation.
It is still early to say whether the model the US has launched will succeed.
DHS and the DOJ have 60 days to establish the programme's operational procedures.
But one thing is already clear:
The traditional boundaries between defence and offence in cybersecurity are being redrawn.
And one of the biggest debates of the coming years may be this:
Is the best way to stop a cyberattack to wait for the attacker to arrive at your door, or to knock on their digital door first?
At SecureSys we follow global cybersecurity policy, emerging attack methods and the shifting threat landscape closely, and we help organisations strengthen their cyber resilience through penetration testing, Red Team, SOC, SIEM, EDR/XDR, NDR, threat intelligence and incident response services.
Cybersecurity is no longer only about reinforcing walls; it is about seeing and understanding the threat in front of you, and being prepared before an attack happens.
Get weekly threat intel, case studies, and technical content delivered to your inbox.
No spam. Unsubscribe anytime.

KVKK fined a platform 250,000 TL for tying live match streaming to marketing consent. What organisations should check on their consent screens.

Hitting a holding company does not need hundreds of hacked servers. We follow what an attacker can do in the first 60 minutes after reaching one account.

Up to eight autonomous AI agents took part in the attack on Taiwanese public institutions. The way cyberattacks are run is changing.