Digital signage at Northern Cyprus airport hacked again after June malware attack
2026-09-17 · via AV Magazine

Digital advertising screens in the departure lounge at Ercan Airport in Northern Cyprus displayed unauthorized content earlier this month, according to local news outlet Kibris Postasi. The screens showed an image of an unidentified person alongside a phone number and a message in Turkish that translates as "call for passive Cyprus." Other local reports described the content passengers saw as offensive and sexually explicit.
T&T Airport Management, which operates Ercan, apologized for the incident. In a written statement the company said the content shown on the screens had been prepared, procured and broadcast by a contracted company rather than by T&T itself. It said it has opened an investigation, warned the contractor, and started procedures meant to stop the incident from happening again. The statement does not specify what those procedures involve or name the contractor.
For anyone running a digital signage estate, the split of responsibility described here is worth noting. T&T is pointing at a third-party content partner rather than its own network or CMS as the source of the problem. That distinction matters for liability and for how operators structure contracts with content suppliers, but it does not tell readers whether the unauthorized message was inserted through a compromised upload credential, a breach of the contractor's own systems, or something else. The announcement does not say.
This is also not the airport's first security problem this year. In June, Ercan's main server was hit by malware designed to delete data, according to a report submitted to a court in Nicosia. T&T officials told police that remote access had been gained to the server's operating system. A suspect was detained for two days in connection with that case. It is not clear from available reporting whether the two incidents are related or whether the June breach exposed a vulnerability that made the September content substitution possible.
Airports are high-profile targets for this kind of disruption because departure lounge screens reach a captive, often bored audience, and any unauthorized content gets photographed and shared quickly, as happened here via social media. For signage operators in transport hubs, the case is a reminder that content supply chains are part of the attack surface, not just the CMS or player hardware. Vetting how contracted content partners authenticate uploads, and what access they retain to playback systems once a campaign is live, is as relevant to security planning as patching the network itself.
The announcement in full
Reproduced from AV Magazine for reference. Digital Signage Magazine did not write the text below.
By AV Magazine in Digital Signage and DOOH , Europe , Transport September 16, 2026 0
Screens in the airport’s departure lounge displayed an image of an unknown person alongside a phone number and a message that translates from Turkish as ‘call for passive Cyprus’.
Digital advertising screens at Ercan Airport in Northern Cyprus were reportedly hacked earlier this month.
Screens in the airport’s departure lounge displayed an image of an unknown person alongside a phone number and the message ‘Kıbrıs pasif için arayın’ , which local reports translates from Turkish as ‘call for passive Cyprus’, according to the Kibris Postasi news website.
Elsewhere it was reported that passengers has been upset by an “offensive and sexually explicit” message.
A post shared by Northern Cyprus News (@cyprusnews247)
T&T Airport Management, which operates Ercan, apologised for the incident .
In a written statement, it said that the preparation, procurement and broadcasting of the content was carried out by a contracted company.
T&T said it has launched an investigation and that the contractor has been warned, with procedures initiated to ensure there is a not repeat of the incident.
It is not the first time Ercan Airport has been targeted, with malware designed to delete data uploaded to its main server in June .
T&T Airport Management officials reported to police that remote access had been gained to the server’s operating system, according to information submitted to a court in Nicosia. The suspect held in connection with the incident was given a two-day detention order.