Skip to content
RegionTürkiye and Its Neighbourhood

MediumII Cyber Warfare & Critical Infrastructure16 September 2026, Wednesday

KVKK announced data breaches at 12 companies: the personal data of 10,218,802 people was affected

The Personal Data Protection Authority made 12 separate breach notifications public on 16 September; 10,218,802 people were affected at the 11 companies where a figure could be established.

ANKARA

On 16 September 2026, the Personal Data Protection Authority (KVKK) published, as a public announcement, breach notifications relating to 12 companies under Board Decision no. 2026/2039. At the 11 companies where the number of people affected could be established, a total of 10,218,802 people were affected; the figure for İnternet Tekstil San. ve Tic. A.Ş. has not yet been determined. The largest breach occurred at Yeni Mağazacılık A.Ş., which operates the Eve Kozmetik brand: the names, surnames, email addresses and telephone numbers of 6,263,305 customers were affected. It was followed by Shaya Mağazacılık A.Ş. with 2,298,726 people and Deniz Deniz Butik Tekstil with 1,271,096.

Across the rest of the list, Shaya Kahve reported 133,991 people, Haşema Tekstil 95,857, Yiğit Alışveriş Merkezleri 81,593, Valmenti Mağazacılık 32,292, Taşkınırmak Giyim 29,265, İyileştiren Mamuller Gıda 6,547, Back and Bond 5,435 and Mersin Mana Tarım 695. The common cause standing out in the notifications was recorded as exploitation of a security weakness in a third-party software library and unauthorised access to data-processing systems; the leaked data included names, surnames, telephone numbers, email addresses and addresses, and at some companies hashed login and password information. The Authority said its examinations were continuing. Whether these 12 incidents are part of a single attack campaign could not be independently verified.

Talay assessment

Bottom line

Twelve notifications published together in a single day, and a total of 10,218,802 people, show that mid-sized companies in Türkiye, mainly in retail and textiles, are being broken into systematically through supply chain software. The common cause being a third-party software library indicates that a single weakness exposed many companies at once. The most likely path is that further notifications from the same source will be added in the coming weeks.

Likely effects

  • Turkish retail sectorNegativeWeeks

    The combination of name, telephone number and email address can be used directly for targeted fraud and phishing; the companies affected face the risk of losing customer trust and of administrative fines.

  • Supply chain securityNegative1–6 months

    A shared software library weakness shows that a single component can expose dozens of companies at once; that increases the pressure for independent audits and component inventories.

  • Türkiye's regulatory frameworkUncertain1–6 months

    The Board making 12 notifications public in a single decision indicates that the transparency threshold has risen and that the cost of notification for companies has increased.

Possibilities, ranked

  1. 1
    Further notifications are added55%

    Other companies affected by the same chain of weaknesses file notifications and the total number affected grows.

    Watch: The third-party library explanation recurring in KVKK's subsequent public announcements

  2. 2
    The examination ends in enforcement30%

    The Authority completes its examinations and administrative fines are imposed on the companies affected.

    Watch: Board decisions to be announced concerning Yeni Mağazacılık and Shaya Mağazacılık

  3. 3
    The file closes quietly15%

    No further notifications arrive and the examinations conclude without producing any public enforcement.

    Watch: No new public announcement being published in the coming weeks

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • People affected 10,218,802
  • Public announcement 12 companies

Sources

  1. Memurlar.Net — KVKK announces: data stolen from 12 companies
  2. Yeniçağ — KVKK announces: data stolen from 12 companies