Qilin Attacks Zorlu Holding and Touring Club Suisse

On September 20, Qilin named the Turkish conglomerate and the largest Swiss mobility club with 1.6 million members. Neither organization has commented.
On September 20, the ransomware group Qilin published claims of attacks against Zorlu Holding, a Turkish industrial conglomerate, and the Touring Club Suisse, Switzerland's largest mobility club, on its leak site. Both listings were recorded on the same date by public trackers of extortion sites, including Ransomware.live and RedPacket Security. The Vietnamese ShopDunk and KMLS, also attributed to Qilin, appeared in the same scan.
Zorlu Holding had not made a public statement by the time this article was closed. The Touring Club Suisse had also not made a public statement by the time this article was closed. No Swiss or Turkish regulators issued announcements regarding these cases, and no news agencies have independently verified the incidents aside from the criminal post. For now, only the group's claims exist.
What the Listings Say and What They Don't
The publication regarding the Touring Club Suisse offers little more than the name of the entity and the claim, according to the trackers that archived it. There is no indication in the material that systems were encrypted, data was extracted, or any volume specified. Analysts monitoring Qilin note that listings attributed to the group have included unverified and, in some cases, fabricated claims, recommending treating each entry as uncorroborated until independent evidence emerges.
This caution is not a legal formality. In an extortion market that relies on reputation, publishing a big name serves as pressure, even when access obtained has been marginal. The gap between a listing and a proven breach is exactly the space where the target's response team needs to operate.
The size of the two mentioned organizations explains why the entries drew attention. Established in 1953, Zorlu Holding comprises over 60 companies, about 34,000 employees, and exports to more than 160 countries, engaging in textiles, electronics, energy, real estate, and financial services. Its subsidiary Vestel, headquartered in Manisa, employed 20,438 people and recorded $4.07 billion in revenue in 2024. The Touring Club Suisse has around 1.6 million members and 1,900 employees distributed across 23 regional sections and operates as the country's largest travel insurance provider in addition to roadside assistance services.
Turkey and Switzerland: Two Exposure Profiles
The two names represent risks of distinct nature, and this difference matters more to a CISO than the name of the criminal group. Zorlu is an industrial operation: its relevant exposure lies in supply chain data, product specification, and contractual relations with European retailers selling televisions and appliances manufactured by Vestel. A disruption in Manisa does not remain in Manisa. It reaches German, British, and French shelves that depend on that production line.
The Touring Club Suisse is the opposite. It does not manufacture anything and holds personal data of one in five Swiss citizens, including policy information, assistance history, and location of emergency activation. In Switzerland, the revised Federal Data Protection Act requires the responsible party to notify the federal supervisor when a breach poses a high risk to data subjects. As part of the members travel and invoke coverage in the European Union, there is possible overlap with the GDPR regime, which changes deadlines and penalties from country to country.
Qilin is not a marginal player. The group claimed 1,358 victims between April 2025 and March 2026, a 443% increase over the previous twelve months, and led the ransomware operation rankings for four consecutive quarters until the second quarter of 2026, when its site recorded 279 names, a 17% decline in quarterly comparison. Trackers have accumulated over two thousand records attributed to the group, distributed across more than 50 countries.
The choice of a Turkish industrial conglomerate and a Swiss mobility association on the same day does not outline a sectoral pattern. It sketches a pattern of opportunity, which is how ransomware affiliates have operated since the model became franchised. For the executive reading this list on a Monday morning, the useful question is not whether the company is on someone's radar. It's how long it would take, from an anonymous post with the company's name, for the team to say with evidence what happened. In both listings from September 20, that interval is still running.