MIT operation exposes FETO's ByLock network hierarchy
01:45, 14/07/2026, TuesdayU: Update: 02:03, 14/07/2026, Tuesday
AA

AA
File photoTürkiye’s National Intelligence Organization obtained a database containing 215,000 users from an encrypted messaging platform operated by the Fetullah Terrorist Organization, exposing the group’s covert cell structure months before the defeated July 15 coup attempt.
Türkiye’s National Intelligence Organization (MIT) obtained a database containing 215,092 users from a server in Lithuania operated by the Fetullah Terrorist Organization (FETO), exposing the hierarchy and covert networks of the group behind the defeated July 15, 2016 coup attempt, according to Anadolu. The application, known as ByLock, was designed around anonymity and exclusivity unlike globally available platforms such as WhatsApp or Telegram, requiring users to know each other’s system-generated identification numbers and mutually add one another without telephone numbers, email addresses or SMS verification.
The closed architecture prevented outsiders from randomly joining the network, effectively limiting access to people admitted through organizational referrals. MIT first learned of ByLock in July 2014 through intelligence assets who had infiltrated FETO, discovering that the software had been developed under special instruction issued in November 2013 prior to the group’s judicial and police operations of Dec. 17-25 that year.
Christmas Eve server breach
MIT established a specialist team within its Cyber Defense and Security Department comprising database specialists, cryptanalysts and ethical hackers to dismantle the covert network. The team identified the main server as being operated by a Lithuania-based company named Bastic Servers through nine IP addresses rented by FETO administrators using anonymous payment methods. An initial cyberattack was launched in August 2015 to test vulnerabilities before the firewall was breached on Dec. 25, 2015, anticipating that company employees would be distracted by Christmas celebrations.
After gaining access, the team hacked an email account used by the company to communicate with customers and sent false messages to the FETO-linked software administrator indicating no server problems. Cyber specialists also used social engineering to access the computer of a data security employee by sending photographs in the name of the employee’s girlfriend, giving the intelligence team control of monitoring screens and allowing the extraction of millions of records without detection.
Covert hierarchy mapped
Cryptological analysis of the compiled source code identified Turkish terms including "dosya," "posta" and "sesli arama." One of the clearest indications that the application had been designed specifically for users in Türkiye was an error message written in Turkish that read: "Yetkiniz yok. (You are not authorized.)" The operation uncovered 60,748 internet subscriptions, more than 17 million messages, nearly 4.7 million emails and 111,637 telephone numbers, revealing for the first time the communications system used by FETO's "covert services structure," according to Anadolu.
Analysis showed that members were assigned identification numbers beginning with one and extending beyond 215,000, with investigators determining that the numbers reflected users’ seniority, importance and position within the organization rather than being issued randomly. Users assigned numbers among the first 100 were found to include some of the group’s most important operational figures, while technical work conducted in early 2015 identified the group’s 81 provincial imams and 160 country imams. On July 12, 2016, three days before the coup attempt, authorities identified 600 senior-ranking military personnel linked to FETO through ByLock correspondence and notified the Turkish General Staff.
Comments you share on our site are a valuable resource for other users. Please be respectful of different opinions and other users. Avoid using rude, aggressive, derogatory, or discriminatory language.