Türkiye’s Cyberwarfare Capabilities and Doctrine: Cyber Homeland, Intelligence and Regional Power
An evidence-led journey through Türkiye’s cyber power—from the “cyber homeland” strategy and 2025–2026 reorganization to military cyber operations, NATO integration, domestic industry, Sea Turtle espionage, network-level surveillance, information control, and regional competition.
Begin with a silent conversation: the 2025 Output Messenger operation
Evidence cutoff: 18 September 2026. In April 2024, an operator began exploiting a previously unknown weakness in Output Messenger, an enterprise chat product used on private networks. The intrusion did not announce itself with a defaced page or a citywide blackout. By the time Microsoft disclosed the campaign in May 2025, the operator had used the server-side vulnerability later designated CVE-2025-27920 to reach users associated with the Kurdish military in Iraq, collect data, and move through a communications environment whose users expected privacy.
The Microsoft Marbled Dust investigation matters for two reasons. First, it describes a Türkiye-affiliated actor employing a zero-day and a chain designed for intelligence collection. Second, it links the activity to the cluster also known as Sea Turtle or UNC1326, whose earlier hallmark was manipulation of the Domain Name System. An actor previously associated with compromising the infrastructure that directs internet traffic had moved into a regional organization’s internal messaging.
Microsoft’s wording is precise: Türkiye-affiliated, not a named Turkish ministry or military unit. The victim set is compatible with Ankara’s security focus on Kurdish armed organizations in Iraq and Syria, but strategic alignment is not a personnel roster or an authorization order. No Turkish authority has publicly acknowledged the operation. The public evidence demonstrates a capable cluster, regional intelligence intent, and evolving tradecraft; it does not expose the full sponsor relationship.
This quiet beginning corrects the popular image of cyberwarfare. Strategic value often comes from reading plans, locating people, mapping relationships, and maintaining access rather than creating immediate destruction. A messaging-server compromise may support warning, targeting, diplomacy, counterterrorism, or force protection. Without evidence of how the intelligence was used, analysts must not invent the final effect.
Apply the practical definition of cyberwarfare: identify the authority, objective, target, mechanism, effect, and conflict context. Here, the operator, technical path, victims, and collection purpose are substantially documented; government authority and downstream operational effect remain unproven. That combination—strong technical evidence and incomplete political attribution—will recur throughout Türkiye’s story.
Doctrine by accumulation: resilience, deterrence and the meaning of “cyber homeland”
Türkiye’s public doctrine emerged by accumulation rather than through one military manual. A 2012 cabinet decision established national cybersecurity coordination. USOM, the national cyber incident-response center within the Information and Communication Technologies Authority, followed in 2013. Successive strategies connected government security, critical infrastructure, skills, industry, incident response, and international cooperation. Military structures developed alongside this civilian lane.
The 2024–2028 national strategy is the clearest current statement. It organizes the national project around six goals: cyber resilience; proactive cyber defense and deterrence; a people-centered approach; secure adoption of emerging technologies; domestic and national technology; and a stronger Turkish brand internationally. The government’s official strategy explanation highlights artificial intelligence, big-data analysis, zero-trust approaches for 5G and internet-of-things environments, workforce development, and reduced foreign dependence.
“Siber vatan”—cyber homeland—places digital systems within a wider language of territory, sovereignty, and national power. It makes cybersecurity a matter for the whole state rather than an IT department. That framing can mobilize budgets, public-private cooperation, domestic production, and political attention. It can also blur the boundaries between public-service protection, intelligence collection, military action, law enforcement, platform regulation, and political control. Analysts should treat it as strategic framing, not as a complete targeting doctrine.
The word deterrence requires equal care. Türkiye’s strategy pairs it with proactive defense, but the public text does not reduce either term to offensive intrusion. Deterrence may be built through denial, rapid recovery, intelligence warning, prosecution, diplomatic exposure, alliance response, economic measures, or a communicated capacity to impose costs. Proactive defense may mean hunting inside authorized networks, disrupting malicious infrastructure through legal processes, sharing indicators, or conducting classified operations. The public document does not settle that spectrum.
There is a structural reason for the ambiguity: the detailed action plan is marked for official use and distributed to participating institutions, while the public strategy describes the destination. The government has said the plan contains 18 targets and 61 actions. Citizens can evaluate the declared goals, but not every owner, deadline, performance measure, or operational dependency.
By late 2025 and 2026, military language had become more direct. The defence minister’s 2026 defence capability statement names both cyber-defense and cyber-operation capabilities, alongside AI-supported command and control, autonomy, big-data decision support, and domestic solutions. This is evidence of intended military capability. It still does not reveal authorization thresholds, targets, rules of engagement, or demonstrated wartime effects.
The 2025 reorganization: a powerful civilian center beside protected operational lanes
On 8 January 2025, Presidential Decree No. 177 created a new Cybersecurity Presidency attached to the President, with public legal personality, a special budget, and headquarters in Ankara. The Cybersecurity Presidency founding record assigns it policy coordination, strategy and action planning, legislative work, ecosystem development, and support for domestic technology.
Parliament then adopted Cybersecurity Law No. 7545 on 12 March 2025; it was published on 19 March. Its scope reaches public and private organizations and natural persons operating in cyberspace. It establishes a Cybersecurity Board chaired by the President, with senior political, security, intelligence, defense-industry, and cyber officials. The Presidency can maintain inventories, set standards, inspect regulated entities, support threat detection, coordinate incident capacity, and apply or initiate sanctions under defined provisions.
The Presidency institutional FAQ shows how broad the civilian mission has become: critical-infrastructure security, vulnerability management, threat analysis, secure use of AI and data, government-service support, standards, audits, and the national Cybersecurity Incident Response Platform. Public bodies and critical sectors are required to participate. After a December 2025 decree, the Presidency also assumed operation and development of the e-Devlet gateway and common digital-state integration services. That can improve coordination, but it also concentrates responsibility for security and a nationally important service dependency.
The boundaries are as revealing as the powers. Law No. 7545 excludes intelligence activities of the police, gendarmerie, coast guard, and National Intelligence Organization, as well as Turkish Armed Forces activities. Those exclusions do not imply absence of oversight under other laws; they show that the civilian cyber statute is not the complete map of operational authority. A single box labeled “Cybersecurity Presidency” would therefore misrepresent military and intelligence missions.
The older response architecture remains essential. USOM coordinates sectoral SOMEs and thousands of institutional SOMEs. An official 2025 USOM and SOME figures report lists 14 sectoral teams, 2,374 institutional teams, and 8,237 specialists. The USOM capability profile describes domestically developed tools named Avcı, Azad, Kasırga, and Atmaca for detecting malicious code, exposed systems, and vulnerabilities.
Official metrics require denominators. Statements about millions of blocked malicious requests or hundreds of daily “major attacks” describe filtering workload under government definitions; they are not counts of unique state campaigns or successful compromises. Organizational reach is a capability. Its real test is whether warnings reach asset owners, vulnerabilities are fixed, sectors recover, and mission services continue.
The Cybersecurity Board’s 2026 Cybersecurity Board meeting prioritized critical infrastructure, digital-system security, and domestic technology. This demonstrates that the 2025 design had moved into governance. It does not yet provide a public performance record long enough to show how the new center resolves overlapping roles in a major national crisis.
Inside the military lane: defend the force, support operations, learn with NATO
Türkiye’s visible military center is the Turkish Armed Forces Cyber Defence Command. A NATO Cooperative Cyber Defence Centre of Excellence NATO CCDCOE Türkiye study, published in 2021, describes it as the top military cyber-defense authority and places TAF-CERT at the apex of military incident response, interfacing with NATO, the national CERT, and subordinate military CERTs. The study is useful institutional evidence, but it is a dated public snapshot rather than a current classified order of battle.
The military problem is wider than protecting office email. Modern Turkish forces depend on command networks, satellite and radio links, air defense, intelligence feeds, logistics, weapons maintenance, bases, ports, contractors, and civilian telecommunications. Cyber defense must preserve confidentiality and availability while formations deploy across the country and region. Cyber operations may support reconnaissance, force protection, deception, or effects in another domain. Public sources do not explain which command plans those missions or how intelligence access is transferred into military action.
The defence-industry project SİSAMER provides a concrete piece of the architecture. The SİSAMER project record says domestic systems were developed for the Cyber Defence Command to secure armed-forces information systems and enable immediate incident response and mitigation. Türkiye’s broader defense ecosystem—among it ASELSAN, HAVELSAN, STM, and TÜBİTAK BİLGEM—supplies communications, command systems, research, training, and security engineering. Domestic production reduces some external dependencies; it does not automatically eliminate vulnerable components, open-source software, foreign chips, or supply-chain trust.
NATO adds interoperability, exercises, doctrine exchange, threat information, and collective-defense context. Türkiye has participated in Locked Shields since 2014. In the Locked Shields 2024 record, a joint Türkiye–Albania blue team included the military command, public agencies, and companies defending simulated national services and critical infrastructure. Exercises reveal teamwork under designed conditions; they do not prove access to adversary networks or success in combat.
NATO’s NATO cyber-defence policy treats cyberspace as a domain of operations and allows a serious cyberattack or cumulative malicious activity to contribute to an Article 5 decision. That political framework can strengthen deterrence and shared defense. It does not turn NATO into the owner of Turkish national offensive operations, nor does it validate every Turkish attribution.
A measured assessment is therefore possible. Türkiye has institutionalized military network defense, command-and-control support, national industrial integration, and alliance training. Its government now publicly claims cyber-operation capability. The public record is insufficient to rank its offensive force, measure destructive reliability, or determine how well cyber activity is synchronized with drones, electronic warfare, intelligence, and conventional fires.
Follow Sea Turtle upstream: when the road to a target ran through DNS trust
Sea Turtle became publicly visible through an operation against the trust infrastructure of the internet. Cisco Talos’ 2019 Sea Turtle investigation assessed with high confidence that an advanced state-sponsored actor had targeted at least 40 organizations in 13 countries, principally in the Middle East and North Africa, from at least January 2017 into 2019. Rather than attack only the final victim, the operator compromised registrars, registries, or organizations able to change domain records.
The logic was elegant and dangerous. If an attacker changes authoritative DNS records, users can be directed to an attacker-controlled service while typing the correct domain name. A convincing certificate and login page can then capture credentials. Restoring one victim workstation does not solve the problem if the upstream record, registrar account, or registry remains compromised. The route itself has become cyber key terrain.
Targets included ministries of foreign affairs, military and national-security organizations, intelligence-linked entities, energy organizations, and telecommunications providers. The Sea Turtle follow-up documented continued activity and compromise affecting country-code top-level-domain infrastructure; Greece’s registry acknowledged a breach in April 2019. Campaign breadth and patient infrastructure targeting support an intelligence purpose, not opportunistic crime.
Attribution still has levels. Talos used “state-sponsored” and linked the target set to Turkish interests. Microsoft’s current naming system associates the overlapping Marbled Dust cluster with Türkiye in its Microsoft threat-actor index. Neither source publicly names MİT, the armed forces, or another tasking body. Confidence in a national nexus may be high while confidence in the responsible institution remains low.
The move from DNS compromise to the Output Messenger zero-day shows evolution rather than abandonment. Both paths exploit concentrated trust. A registrar can redirect many users; a messaging server can expose many conversations. Both reward patience, knowledge of regional organizations, and disciplined cyber access stewardship. Neither requires spectacular malware on every endpoint.
Defenders should take the upstream lesson literally. Protect registrar and registry accounts with phishing-resistant authentication, restricted administrative paths, change notifications, registry locks where available, certificate-transparency monitoring, and independent validation of DNS changes. For self-hosted collaboration tools, inventory versions, monitor server-side processes and outbound connections, centralize authentication, and assume that compromise of the server can expose every user—not merely the first account that alerts.
A second boundary: surveillance and information control are capabilities, but not synonyms for war
Türkiye’s security environment also includes network surveillance, content blocking, bandwidth throttling, and legal pressure on platforms and users. These mechanisms affect crisis communications and state power, but analytical precision matters. A platform restriction imposed by a regulator is not automatically a cyberattack. Spyware against a political target is not automatically a military operation. Both can still be coercive, rights-affecting, and relevant to conflict readiness.
The strongest technical case comes from Citizen Lab. Its Citizen Lab network-injection investigation reported that PacketLogic devices on Türk Telekom’s network redirected users downloading legitimate software toward versions bundled with spyware. The observed targeting extended into Türkiye and Syria, and the injected software resembled the StrongPity/PROMETHIUM toolset. Citizen Lab found evidence consistent with a government customer and noted earlier Turkish use of commercial surveillance technology. The research did not publish an operator’s written order or prove that every StrongPity operation is controlled by one Turkish agency.
This technique is strategically important because a telecommunications position can turn routine traffic into an access opportunity. It can support domestic surveillance, counterterrorism, foreign intelligence, or repression. The same national network is also a critical dependency whose compromise by an adversary would harm citizens and government alike. Ownership of a chokepoint creates capability and responsibility.
Information control became especially visible after the 19 March 2025 detention of Istanbul mayor Ekrem İmamoğlu and the protests that followed. A Human Rights Watch 2026 country review records 42 hours of bandwidth reduction that made major social and messaging platforms inaccessible without circumvention, alongside account blocking and continuing legal pressure. Similar restrictions occurred during later political tension. These measures impeded access to news and communication at a moment of public importance.
In a conflict, communications control can suppress panic, impede hostile coordination, limit operational-security leaks, or contest influence. It can also obstruct emergency information, journalism, human-rights documentation, civilian warning, and legitimate political participation. A government’s security rationale does not remove civilian harm and reverberating effects. Analysts must record the legal basis, geographic scope, duration, affected services, technical mechanism, stated objective, and observed human effect.
Türkiye also has active official communication institutions, media ecosystems, party networks, and patriotic online communities. Their activity can intersect with cyber-enabled influence operations, especially during elections, military operations, or regional disputes. But message similarity is not command evidence. The correct task is to map accounts, infrastructure, funding, privileged information, synchronized release, and measurable audience effect—not to convert political sympathy into a secret org chart.
Regional power in a crowded battlespace: Syria, Iraq, the Eastern Mediterranean and NATO
Geography gives Turkish cyber priorities a distinctive shape. Türkiye is a NATO member bordering Syria, Iraq, Iran, the Black Sea, the Caucasus, and the Eastern Mediterranean. It has fought the PKK for decades, conducted cross-border military operations, supported partners in Azerbaijan and Libya, managed difficult relations with Russia, Greece, Cyprus, and several Middle Eastern governments, and hosted major telecommunications, energy, logistics, and refugee flows.
That environment creates persistent intelligence requirements: Kurdish armed groups and their political networks; Syrian actors; neighboring military and diplomatic plans; energy and maritime negotiations; NATO and Russian activity; sanctions and procurement; diaspora politics; and threats to Turkish forces overseas. Sea Turtle’s government, telecom, DNS, and security targets fit this regional collection logic. Marbled Dust’s Kurdish-linked Iraqi victims fit it even more directly. Target alignment supports an assessment of purpose, but it still does not prove which institution issued a task.
Türkiye’s relationship with Russia shows why capability cannot be read as a simple alliance chart. Ankara is a NATO ally, supports Ukraine’s territorial integrity, controls access through the Turkish Straits under the Montreux Convention, cooperates with Moscow in some theaters, and competes with it in others. Defenders must prepare for sophisticated Russian espionage and influence while policy makers preserve diplomatic and military channels. The separate analysis of Russia’s cyberwarfare capabilities illustrates the scale of that challenge.
The Eastern Mediterranean and Aegean add politically charged disputes over territory, airspace, maritime zones, energy, and Cyprus. During tension, defacements and denial-of-service claims from self-described Turkish, Greek, Armenian, Kurdish, or other patriotic groups can dominate the public picture. These operations may embarrass a ministry, interrupt a website, or amplify a narrative. They rarely prove military penetration, and group branding can be copied or invented.
Proxy analysis should therefore use an evidence ladder. At the lowest level is ideological alignment. Above it are repeated target selection, synchronized timing, access to non-public information, shared infrastructure, personnel overlap, financing, tasking, and operational deconfliction. State responsibility should not be asserted merely because an action benefits Ankara. Nor should patriotic activity be ignored: even autonomous actors can complicate diplomacy, destroy evidence, trigger retaliation, or create cover for a professional operation.
Effective cyber campaign design begins with the political purpose. Espionage may reduce uncertainty before talks or operations. Network defense may preserve command. A limited disruption may delay an adversary. Influence may seek domestic cohesion or international legitimacy. If the activity cannot be connected to an end, an audience, an expected effect, and a way to measure it, the analysis is cataloguing events rather than explaining strategy.
The 2026 assessment: capable, increasingly centralized, and intentionally difficult to measure
By September 2026, Türkiye can credibly be described as an established regional cyber power. It has political attention at the presidency, a current national strategy, a new civilian authority and board, a mature incident-response network, military cyber-defense organization, NATO interoperability, domestic defense and security suppliers, extensive telecommunications infrastructure, and technically sophisticated espionage activity assessed by major vendors as Türkiye-affiliated or state-sponsored.
Four evidence bins keep the conclusion honest:
- Demonstrated: the Cybersecurity Presidency, USOM/SOME structure, military Cyber Defence Command, SİSAMER, NATO exercises, domestic security tools, documented DNS-hijacking and messaging-server campaigns, network-level injection, and actual platform restrictions.
- Assessed: state sponsorship of Sea Turtle, Türkiye affiliation of Marbled Dust, the strategic purpose of regional targeting, and possible relationships among government customers, surveillance technology, and intrusion clusters.
- Declared: cyber homeland, proactive defense, deterrence, technological independence, AI-supported command, and cyber-operation capability.
- Unknown: force size, budgets divided by mission, exact intelligence tasking, offensive tool inventories, persistent accesses, authorization thresholds, targeting rules, wartime deconfliction, collateral-risk processes, and reliable strategic effects.
Türkiye’s strengths reinforce one another. Central leadership can align regulation and investment. A large state and commercial network provides telemetry and incident experience. The defense industry can adapt systems to national requirements. NATO participation supplies exercises and standards. Regional military activity gives clear intelligence priorities. Technical universities and a substantial technology market provide talent. These ingredients are more meaningful than a count of patriotic hacking claims.
The same system has constraints. Centralization can create a high-value organizational and technical dependency. Public bodies and small suppliers will not mature uniformly. Domestic branding does not remove foreign chips, libraries, cloud services, or global supply chains. Skilled personnel can move to better-paid private or foreign roles. Secrecy protects sources but makes effectiveness, legality, and oversight difficult to test. Domestic surveillance and throttling can erode public trust, harm crisis reporting, and conflict with rights commitments.
Türkiye’s international position provides a standard for comparison. In Türkiye’s UN cyber statement, Ankara supported an open, free, stable, and secure cyberspace, the UN framework of responsible state behavior, international law and the UN Charter, protection of critical infrastructure, capacity building, and cooperation. Those commitments should guide both foreign operations and domestic resilience. NATO membership adds consultation and collective-defense obligations, but not automatic public attribution or permission for any national operation.
For defenders, Türkiye-linked risk is best translated into observable priorities: protect DNS and registrar administration; patch self-hosted collaboration systems; monitor identity providers and telecom dependencies; apply phishing-resistant authentication to diplomats, defense personnel, researchers, and Kurdish-interest organizations; retain server and network telemetry; validate certificates and resolution paths; and plan for both intrusion and deliberate communications restriction. Organizations in Iraq, Syria, Cyprus, Greece, the Caucasus, and Turkish diaspora environments should model regional intelligence requirements rather than wait for a malware family name.
For analysts, record each proposition and its confidence. “Microsoft calls this cluster Türkiye-affiliated” is evidence. “The target serves a Turkish interest” is context. “MİT ordered the operation” is a different claim requiring different proof. This discipline is the heart of cyber attribution, and it prevents technical reporting from becoming geopolitical certainty by repetition.
Türkiye’s journey is not a story of one secret cyber army. It is the construction of a national system in which civilian coordination, military defense and operations, intelligence collection, telecom control, domestic industry, diplomacy, and alliance participation meet—but do not become identical. Its most persuasive public operational evidence is quiet: upstream trust compromised, conversations collected, systems monitored, institutions connected. The mature assessment is therefore neither dismissal nor mythology. Türkiye possesses consequential cyber capability; the exact reach, command relationships, and strategic effectiveness of its most sensitive operations remain deliberately outside public view.
Frequently asked questions
What are Türkiye’s principal cyberwarfare capabilities?
Public evidence supports centralized national cyber coordination, a military Cyber Defence Command, NATO-integrated training and incident response, domestic command-and-control and security engineering, large-scale monitoring through USOM and sectoral response teams, and regional espionage capability. Security vendors attribute sophisticated campaigns including Sea Turtle and Marbled Dust to Türkiye-affiliated actors. The responsible government units, force size, accesses, wartime authorities, and destructive capabilities are not publicly established.
Does Türkiye have a published offensive cyber doctrine?
Not in a detailed public form. The 2024–2028 National Cyber Security Strategy names proactive defense and deterrence, while the defence minister has publicly referred to both cyber-defense and cyber-operation capabilities. The restricted action plan and the absence of published targeting, authorization, or escalation rules prevent these statements from being treated as a complete military offensive doctrine.
What is the “cyber homeland” or “siber vatan”?
It is an official political-security framing that treats national digital assets, services, data, infrastructure, and technological capacity as a domain of sovereignty requiring coordinated protection. It communicates strategic priority, but it is not by itself a precise operational doctrine and does not specify when offensive operations are authorized.
Are Sea Turtle and Marbled Dust proven Turkish government units?
No public evidence identifies either as a formally acknowledged unit. Cisco Talos assessed Sea Turtle as an advanced state-sponsored actor, and Microsoft assesses Marbled Dust—its name for an overlapping cluster—as Türkiye-affiliated. Their target alignment and tradecraft support a state-interest assessment, but the public record does not disclose a tasking agency or complete command chain.
Are Turkish patriotic hacktivist groups state controlled?
A patriotic identity, pro-government messaging, or targeting aligned with Turkish foreign policy does not prove state control. Some groups may amplify state narratives or create useful pressure, but persistent direction requires evidence such as tasking, financing, privileged access, personnel overlap, or coordinated operational timing. Public claims should be evaluated campaign by campaign.