Skip to main content
Hacker Behind 2025 Cyprus Airways Breach

Hacker Behind 2025 Cyprus Airways Breach

Turkish Hacker Behind The 2025 Cyprus Airways Data Breach
#


This article is part of a joint investigation. For the complete technical analysis and indicators, see the full report by Covert Security linked at the end of this post.

In June of 2025, a threat actor operating under the alias Rip_Real_World claimed responsibility for breaching Cyprus Airways in DarkForums.

Alt text
The Cyprus Airways breach claim — 41GB of data alleged, posted on DarkForums.

While the breach itself attracted significant attention, it was not an isolated event. It represented another chapter in a long-running campaign by an actor who has steadily built a reputation within underground communities through a combination of website defacements, data breaches, credential theft, and increasingly public disclosures.

A Familiar Name
#

This is not the first time Rip_Real_World had appeared on Covert Security radar.

Covert Security had been documenting the actor’s activities across multiple underground forums and platforms, revealing an individual with a consistent operational footprint and years of activity. Rather than emerging overnight, Rip_Real_world appeared to have gradually established credibility through persistent participation in cybercriminal communities.

Previous research had identified:

  • A long-standing presence across multiple underground forums.
  • Repeated involvement in website compromises and data leak publications.
  • Consistent use of the Rip_Real_World persona across different platforms.
  • Public promotion of successful intrusions to build reputation within the underground ecosystem.

Understanding this historical context was important because threat actors rarely operate in isolation. Their previous campaigns, relationships, and online behavior often provide valuable insight into future targeting and operational patterns. This gave us the opportunity to put a real world named to the underground alias.

The Cyprus Airways Breach
#

Our joint investigation focused specifically on the alleged compromise of Cyprus Airways in 2025 and in identifying the person hiding behind the Rip_Real_World alias, responsible for the breach.

The investigation reconstructs the threat actor’s digital footprint using open-source intelligence (OSINT), correlating activity across multiple platforms to better understand attribution, infrastructure, and historical behavior.

Rather than treating the incident as a single isolated breach, the investigation demonstrates how publicly available information can be combined to build a richer picture of an adversary’s operations, helping defenders understand not only what happened, but also who may be behind it and how they operate.

Alt text
The row that matters: First Name — Mehmet — High confidence.

The findings also highlight an increasingly common reality in modern cyber investigations: threat actors leave extensive traces across forums, messaging platforms, breached datasets, social media, and archived web content. Individually these artifacts may seem insignificant, but together they can reveal valuable intelligence about an adversary’s identity, capabilities, and operational history.

Why Historical Attribution Matters
#

Threat intelligence is most valuable when viewed longitudinally rather than as isolated incidents.

By connecting historical research with newly observed activity, investigators can:

  • Track the evolution of threat actors over time.
  • Correlate aliases and online identities.
  • Understand operational patterns and preferred tactics.
  • Better assess future risks and potential targeting.

The Cyprus Airways case illustrates how combining historical OSINT with current incident analysis produces significantly stronger attribution than examining a single breach in isolation.


Read the Full Investigation
#

For the discovered identity, complete technical analysis, timeline, supporting evidence, and attribution methodology, read the original joint investigation: