Skip to content
RegionTürkiye and Its Neighbourhood

LowII Cyber Warfare & Critical Infrastructure30 September 2026, Wednesday

Türkiye's data regulator discloses nine breaches affecting over a million people

Türkiye's Personal Data Protection Authority (KVKK) disclosed data breaches at 9 companies on 30 September. Where the number could be determined, the data of at least 1,033,853 people were affected; at one brokerage the figure was not disclosed.

Location: ANKARA

According to a Memurlar.net round-up of 30 September, the largest breach, affecting 353,811 people, hit the e-commerce infrastructure of a footwear company. At a leather goods company, second on the list, the names, phone numbers, email addresses and MD5-hashed login details of 323,052 people were affected. MD5 is an old password hashing method now considered easy to crack. At an office supplies company, the data of 183,873 people were taken through unauthorised access to an unprotected Elasticsearch database.

The list also includes Papara Menkul Değerler from the financial sector. A phishing email sent to staff targeted the identity management platform Okta. Customer names, investment profiles and tax status were affected, but the number of people was not disclosed. At a building materials company, about 27,163 people were affected through a flaw in a software library. A week earlier, on 23 September, KVKK had disclosed 16 breach notifications affecting at least 923,522 people.

Talay assessment

Bottom line

Weekly KVKK disclosures show small and medium-sized e-commerce companies in Türkiye losing data continuously through infrastructure weaknesses. What sets the 30 September list apart is a brokerage appearing on it after a phishing attack aimed at Okta. A leak of investor data while the fund crisis continues raises the risk of fraudulent phishing.

Likely effects

  • Financial sectorNegativeWeeks

    The leak of investment profiles and tax status at a brokerage could pave the way for fraud that targets investors with fake investment offers.

  • E-commerceNegative1–6 months

    With most of the 9 breaches at e-commerce and retail companies, weaknesses in shared infrastructure and software libraries remain widespread in the sector.

  • RegulationPositive6 months+

    KVKK's disclosure of 25 breaches in total on 23 and 30 September shows the authority using public disclosure to push companies into security investment.

Possibilities, ranked

  1. 1
    Weekly flow continues65%

    KVKK keeps publishing new breach notifications every week, and e-commerce continues to dominate.

    Watch: New entries on KVKK's data breach notifications page

  2. 2
    Spreads to finance25%

    Phishing aimed at Okta or similar identity platforms leads to breaches at other brokerages and banks.

    Watch: New KVKK notifications concerning financial institutions and warnings from the Capital Markets Board (SPK)

  3. 3
    Regulatory tightening10%

    After a string of breaches, KVKK or the SPK announces new technical security requirements.

    Watch: KVKK board decisions and SPK rules on information systems

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • People affected (at least)▼ 1,033,853
  • Breaches disclosed▼ 9
  • Largest single breach▼ 353,811 people

Sources

  1. Memurlar.net — KVKK publishes data breaches at 9 companies, 1 million people affected
  2. KVKK — Data breach notifications
  3. Memurlar.net — KVKK: data of at least 923,000 people stolen at 16 companies