Turkey's Personal Data Protection Authority (KVKK) published 12 separate data breach notifications on September 16, 2026, under Board Decision 2026/2039, disclosing that personal data belonging to at least 10,218,802 customers and employees fell into unauthorised hands. That figure covers only the 11 companies that had determined a victim count by publication; a twelfth, İnternet Tekstil Sanayi ve Ticaret A.Ş., had not yet established how many customers and members were affected, so the real total is higher. Turkish Minute and Yeniçağ, reporting independently from the KVKK notices, agree on the 10,218,802 figure. All sources available for this brief are secondary reporting on the regulator's notices rather than the notices themselves, so figures below are attributed accordingly. KVKK stated that formal investigations into all 12 incidents remain open.
What Happened
The disclosures were not a single intrusion but a batch release of unrelated (and in several cases structurally similar) incidents that the regulator decided should be made public on the same day.
The largest by a wide margin involves cosmetics retail. Turkish Minute names the victim as Eve Kozmetik with 6,263,305 customers affected. Yeniçağ, citing Memurlar.net, attributes the same 6,263,305 figure to Yeni Mağazacılık A.Ş., the corporate entity that holds the Eve Kozmetik brand, and adds that the breach did not extend to customers of Eve Mağazacılık, a merged entity whose systems were kept separate. The count is consistent across both; only the naming convention differs. Per the notification, unauthorised access occurred on a server run by a data processor after attackers exploited a vulnerability in a third-party software library. The processor informed the controller on September 10, six days before publication.
Two entities in the Alshaya group of companies appear on the list. Shaya Mağazacılık A.Ş. reported 2,298,726 customers and employees affected following unauthorised access to systems holding company data, and Shaya Kahve A.Ş. reported a further 133,991. Both are part of Kuwait-based Alshaya Group, which operates Starbucks, Victoria's Secret, Bath & Body Works and Shake Shack franchises in Turkey, meaning the affected population is likely to be loyalty and e-commerce customers of well-known Western consumer brands rather than of an obscure local retailer.
Deniz Deniz Butik reported 1,271,096 affected customers, again attributed to attackers exploiting a vulnerability in a third-party software library on a server that processed the company's data. Smaller disclosed incidents include Haşema Tekstil (95,857) and Yiğit Alışveriş (81,593). The six companies named in available reporting account for 10,144,568 of the 10,218,802 total; the remaining roughly 74,234 records are spread across five companies not detailed in the sources reviewed here.
Two adjacent KVKK actions frame the same period and should be read alongside the batch, though no source states they are part of the 12:
- Canva. Türkiye Today reports a KVKK decision also dated September 16 covering Canva Pty Ltd as data controller, with 424 organisations and institutions in Türkiye affected. Unauthorised access again came through a third-party system, with threat actors exploiting a connection involving a data processor to extract data. The number of individuals affected has not been determined.
- Baydöner. KVKK closed its investigation into the restaurant chain in early September, confirming 505,337 customers compromised and levying 1 million TL in fines. That incident is a separate matter from the September 16 batch.
Separately, Hürriyet Daily News reporting relayed by Rankiteo describes a MİT-led operation with the Cybersecurity Directorate and Gendarmerie General Command that detained five suspects over a breach at Aydo Yazılım, an Ankara software firm serving trade unions. Investigators allege the firm's union software contained a special query interface permitting lookups of non-members by Turkish national ID, returning identity and population registry details including records of minors. Server logs referenced "NVİ," the abbreviation for the Directorate General of Population and Citizenship Affairs, though authorities stated the data was not sourced directly from that agency's systems. Aydo Yazılım also traded as "Clock&Wise," offering KVKK compliance consultancy.
What Was Taken
Across the September 16 batch, the exposed field sets are consistent and commercially useful rather than catastrophic on their own:
- Eve Kozmetik / Yeni Mağazacılık: name, surname, email address, phone number (6,263,305 people)
- Shaya Mağazacılık: name, surname, email address, home address (2,298,726 customers and employees)
- Deniz Deniz Butik: username, phone number, email address (1,271,096 people)
- Shaya Kahve: name, surname, email address, address (133,991 people)
- Canva-linked exposure: employee names, business email addresses, workplace locations and corporate phone numbers, plus business documents shared with the platform including customer order forms, data protection agreements, master service agreements, invoices and routine correspondence
- Baydöner: full name, gender, email address, phone number and city of residence (505,337 customers)
- Hyundai Motor Türkiye: employee and job candidate data only; DonanımHaber reports KVKK's notice stated customer and prospective-customer data was not accessed, with a stated ceiling of 422 people affected
The Canva component is the most operationally sensitive of the set. Contracts, invoices and DPAs mapped to named employees at 424 Turkish organisations are raw material for business email compromise and vendor-impersonation fraud in a way that a retail marketing list is not. The Aydo Yazılım case is sensitive for different reasons: national ID-keyed population registry lookups, including on minors, sit at the high end of the harm scale.
Where Accounts Differ
Two points deserve explicit flagging rather than smoothing over.
First, naming. Turkish Minute reports the largest breach under the brand name Eve Kozmetik; Yeniçağ reports it under the legal entity Yeni Mağazacılık A.Ş. and adds a carve-out for Eve Mağazacılık customers. These are compatible accounts of the same notification, not competing ones, but anyone matching records to entities should use the legal entity name.
Second, an unverified criminal claim that overlaps this space. Brinztech reports that a threat actor using the alias "CRPxO" advertised 21.6 GB of data on the underground forum altenens.is in August 2026, claiming to have hit recruitment infrastructure and centralised HR assessment portals across 11 organisations including Turkish Airlines, Aselsan, QNB Finansbank, Doğan Holding, Kuveyt Türk, Anadolubank, Anadolu Sigorta, A101, Togg, Johnson & Johnson and Hyundai's Turkey operations. The advertised contents allegedly include executive psychometric assessments, personality profiles, candidate histories and internal HR correspondence, with samples hosted externally and contact via Telegram.
This is a single OTHER-tier report of a criminal's own sales pitch. It is not confirmed, none of the named organisations have corroborated it in the sources reviewed, and it is not part of the KVKK September 16 batch. It is worth logging only because it is thematically adjacent to a confirmed fact: KVKK's Hyundai Motor Türkiye notice names Baltaş Eksen Seçme Değerlendirme Eğitim ve Org. Tic. A.Ş., an assessment and selection vendor, as the data processor in that incident, and restricts the impact to employees and job candidates. Whether the CRPxO listing relates to that ecosystem is unestablished. Treat any connection as a hypothesis to test, not a finding.
Why It Matters
The single most important signal here is not the 10.2 million headline. It is that KVKK's notices repeatedly identify the point of failure as a third-party software library on a data processor's server, not the data controller's own infrastructure. Yeniçağ highlights this as the most striking common element across the batch. In the Eve Kozmetik case the controller did not learn of the compromise until the processor told them on September 10. In the Canva case the regulator describes access obtained through a connection involving a processor.
For defenders this reframes the incident class. Twelve organisations did not independently fail at the same time; a smaller number of shared components and shared processors failed, and the liability landed on twelve balance sheets. Under Turkish law the data controller carries the notification and security obligations regardless of where the vulnerable code ran, and the Baydöner decision shows KVKK is willing to split penalties across both dimensions: 800,000 TL for inadequate technical and administrative measures and 200,000 TL specifically for failing to notify affected individuals, per A Haber's account of the decision.
The Baydöner findings also encode what the regulator considers a baseline. KVKK singled out the absence of any alarm infrastructure to detect unusual system activity as the most serious deficiency, alongside inadequate staff security training. Notably, Baydöner did not detect the intrusion at all; the attackers messaged a senior executive's mobile phone to announce they held the data, and that message is what triggered the notification. Detection failure is now explicitly a finable offence in this jurisdiction, not just bad practice.
The Attack Technique
Four distinct intrusion paths are documented across the confirmed incidents:
Vulnerable third-party library on processor infrastructure. Named explicitly in the Eve Kozmetik and Deniz Deniz Butik notifications and cited by Yeniçağ as the recurring theme of the batch. No CVE, library name or version has been published in available reporting. The controller was in both cases downstream of the actual compromised system.
Compromised supplier connection. In the Canva-linked disclosure, KVKK describes threat actors exploiting a connection involving a data processor to extract data from the platform, exposing employee directory data and shared business documents for 424 Turkish customer organisations.
SQL injection against a public web application. DonanımHaber reports that Hyundai Group's Security Operation Center identified exploitation of a SQL injection flaw on Hyundai Türkiye's website on August 1, 2026, with the processor (Baltaş Eksen) and controller (Hyundai Motor Türkiye) opening a detailed investigation on August 3. Impact was confined to employees and candidates, capped at 422 people.
Infostealer to credential reuse. The Baydöner chain is the most instructive for the average enterprise. Per A Haber's reporting of the KVKK decision, attackers deployed malware onto the computer of an employee in the company's IT department, harvested usernames and passwords saved in the browser, and used those credentials to reach company systems. English-language reporting via Haberler describes this more generally as attackers obtaining an employee's access credentials; the Turkish account is more specific and should be preferred. Data was copied, then the attackers contacted an executive directly. No alarm fired at any stage.
The Aydo Yazılım case is not an intrusion at all in the technical sense. The allegation is an intentionally built query interface enabling national ID lookups against population registry data for individuals with no union affiliation, which is a design and governance failure rather than an exploited vulnerability.
What Organizations Should Do
- Inventory your processors, then inventory their dependencies. KVKK's notices point at libraries running on processor-operated servers. Contractual assurance is not evidence. Require an SBOM from every processor handling your customer data, and require notification SLAs measured in hours from their detection, not from their internal decision to tell you. The Eve Kozmetik timeline shows a controller learning of a 6.26 million record exposure from a supplier phone call.
- Treat HR and assessment platforms as crown-jewel systems. Psychometric assessments, candidate pipelines and employee directories concentrate exactly the data that enables targeted social engineering, and the Hyundai incident confirms that this tier of vendor is being reached through ordinary web vulnerabilities. Scope them into your highest assurance tier, not your procurement long tail.
- Kill browser-stored credentials on privileged endpoints. The Baydöner compromise ran straight from an infostealer on an IT staffer's machine to saved browser passwords to production systems. Enforce policy-level disabling of browser credential storage for administrative accounts, move to a managed secrets vault, and require phishing-resistant MFA on every internal system an IT credential can reach.
- Deploy and tune anomaly alerting, then prove it fires. KVKK named the absence of an alarm mechanism as the single most serious deficiency in the Baydöner case and fined on it. Bulk record reads, off-hours database access and unusual egress volumes should generate alerts that a named human owns. Run a tabletop that verifies the alert actually reaches someone.
- Patch and test public web applications for injection flaws. A SQL injection vulnerability on a corporate marketing site was sufficient to reach employee and candidate records at a major automotive brand. Put every internet-facing property, including ones owned by marketing rather than engineering, into a recurring authenticated scanning and pentest cycle.
- Audit your own query interfaces for over-broad access. The Aydo Yazılım allegations concern functionality that was built, not breached. Review every administrative lookup, support tool and reporting interface for whether it can return records on individuals outside the population it is meant to serve, and log and rate-limit every identity-keyed query.
- Rehearse the notification obligation separately from the technical response. A fifth of the Baydöner penalty was for failing to inform affected individuals. Have templated notification content, a decision owner and a regulator contact path ready before you need them.
Sources: Data breaches at 12 Turkish companies expose personal data of over... | Threat Actor 'CRPxO' Claims 21.6 GB Data Breach Exposing HR and Exe... | Fine for famous kebab chain that allowed theft of 500 thousand cust... | Canva breach hit 424 organizations in Türkiye, data authority says... | Baydöner’de büyük veri ihlali: 505 bin 337 müşterinin bilgileri çal... | KVKK açıkladı: Hyundai Türkiye çalışanlarının bilgileri sızdı Dona... | Aydo Yazılım: MİT-led operation nets five suspects over trade union... | KVKK açıkladı: 12 Şirketin verileri çalındı