Bizimle İletişime Geçin
Ana Sayfa/Yayınlar & İçgörüler/Duyurular/The Personal Data Protection Authority Published Twenty-Eight Data Breach Notifications
Duyurular

The Personal Data Protection Authority Published Twenty-Eight Data Breach Notifications

18.09.2026
The Personal Data Protection Authority Published Twenty-eight Data Breach Notifications | Metin–Çiçek Avukatlık Ortaklığı · Attorney Partnership

On September 16, 2026, 28 data breach notifications were shared with the public on the official website of the Personal Data Protection Authority. Twenty-seven of the notifications pertained to a single incident involving the same data processor from whom the data controllers obtained e-commerce infrastructure services; all were announced via a single Board decision numbered 2026/2039. The notification regarding Canva Pty Ltd, however, pertained to a separate incident and was announced via decision number 2026/2037.

The publication of this number of notifications in a single day—and the fact that they all stemmed from a single supplier—is significant in terms of the Authority’s approach to breaches originating from data processors and the duty of care data controllers must exercise in selecting and auditing suppliers. A summary of the notifications is provided below.

A. 27 notifications stemming from a common data processor (2026/2039)

Incident: The breach occurred as a result of unauthorized access to a server in the systems of a data processor from whom data controllers obtained e-commerce infrastructure services, achieved by exploiting a security vulnerability in a third-party software library used by the data processor. The breaches were identified through notifications sent by the data processor to the data controllers on September 9–11, 2026 (August 27, 2026, in the notification from Güneş Engin; some notifications did not specify a date).

Impact: In nearly all of the notifications, first and last names, email addresses, phone numbers, addresses, and hashed username/password information were affected; some also included order information, IP addresses, admin panel account information, and payment API keys. The affected groups consist primarily of customers, members, users, and employees. In the disclosures where the number was disclosed, a total of approximately 10.84 million individuals were affected.

Action: The Board’s review is ongoing for all disclosures; in some cases, the number of affected individuals and the scope of the data have been requested from the data processor.

#

Data controller

Affected individuals

Relevant group of individuals / affected data

1

Yeni Mağazacılık A.Ş. (Eve Kozmetik)

6,263,305

Customers — first name, last name, email, phone number

2

Shaya Mağazacılık A.Ş. (Alshaya)

2,298,726

Employees, customers — first name, last name, email, address

3

Deniz Butik Tekstil San. ve Tic. A.Ş.

1,271,096

Customers — username, phone number, email

4

Locco Elektronik Mağazacılık ve Tic. Ltd. Şti.

517,306

Employees, users — first name, last name, email, phone number, address, hashed login credentials

5

Shaya Kahve San. ve Tic. A.Ş.

133,991

Employees, customers — first name, last name, email, address

6

Haşema Tekstil Turizm Malz. ve Amb. San. Tic. Ltd. Şti.

95,857

Customers — first name, last name, email, address, phone number, hashed login credentials

7

Yiğit Alışveriş Merkezleri Day. Tük. Mal. Ltd. Şti.

81,593

Customers, potential customers — first name, mailing address, email, stored password hashes

8

Ademur Optik San. ve Tic. A.Ş. (Dünya Göz Optik)

35,575

Customers, employees — first name, last name, email, address, phone number, order information, IP

9

Valmenti Mağazacılık Tic. Ltd. Şti.

32,292

Customers/potential customers — first name, phone number, email, login credentials with MD5 hashes

10

Taşkınırmak Giyim San. ve Tic. A.Ş. (imza.com.tr)

29,265

Employees, members, customers, potential customers — first name, last name, phone number, email, address, hashed password, admin panel account information

11

HLY Aromaterapi Hizmetleri Kozmetik San. Tic. A.Ş.

25,088

Employees, users, members, customers, potential customers — identification, contact information, transaction security

12

Bilir Giyim San. ve Tic. A.Ş. (Morven)

20,742

Employees, members, customers — first name, last name, phone number, email, address, hashed password, admin panel account information

13

Tokgözler Civata Tic. ve Paz. A.Ş.

17,615

Customers — first name, last name, phone number, email, address, hashed password

14

İyileştiren Mamuller Gıda San. ve Tic. A.Ş.

6,547

Users, customers/prospective customers — first name, last name, phone number, email, address, hashed password

15

Back and Bond Hazır Giyim A.Ş.

5,435

Customers — first name, last name, email, address, phone number, hashed login credentials

16

Seyfettin Çaylak (hoodiemouse.com)

5,246

Customers, dashboard users — identity, contact information, customer transactions, transaction security

17

Mehmet Salih Araç (piposavinelli.com)

~1,800

Customers — first name, last name, address, email, phone number, stored password values, admin accounts, payment API keys (exact number not disclosed; number of store members)

18

Alfa Öncü Global Otomotiv Mobilya San. Tic. Ltd. Şti. (bahceme.com)

1,520

Customers, users — first name, last name, phone number, email, shipping/billing address, hashed password

19

Çiğdem Kaya (Ortobella Comfort Medikal)

874

Users, members — first name, last name, email, phone number, address, hashed password, session data

20

Ekmaş Gıda Makinaları San. ve Tic. Ltd. Şti.

707

Customers/prospective customers, employees — first name, last name, phone number, email, address, hashed password

21

Mersin Mana Tarım San. ve Tic. Ltd. Şti.

695

First name, last name, email, phone number, hashed password (information regarding address data was requested from the data processor)

22

Agr Industries Tekstil Ltd. Şti. (blondiofficial.com)

56

56 end-user accounts + 1 admin panel account — first name, last name, phone number, email, address, hashed password

23

Brinda Tekstil San. ve Tic. Ltd. Şti. (canzetta.com)

21

Customers, employees — first name, last name, phone number, email, address, hashed password (exact number requested from the data processor)

24

Desa Deri San. ve Tic. A.Ş.

Could not be determined

Customers, users — first name, last name, email, account verification information

25

Samsonite Seyahat Ürünleri San. ve Tic. A.Ş.

Could not be determined

Customers, users — first name, last name, phone number, email, account authentication information

26

İnternet Tekstil San. ve Tic. A.Ş.

Could not be determined

Customers, members — first name, last name, phone number, email, address, hashed login credentials

27

Güneş Engin (Karum Rouge)

Could not be determined

Users, members — first name, last name, email, address, phone number, hashed password

 

Note: A total of 10,843,552 individuals were affected across the 22 notifications for which numbers were disclosed; the number of affected individuals in five notifications has not yet been determined.

B. Standalone notification

28. Canva Pty Ltd (2026/2037)

Incident: Unauthorized access to a third-party tool used by the data controller; it is assessed that the threat actor exported (leaked) some personal data via a connection with the data processor.

Impact: Data associated with 424 organizations/entities located in Turkey was affected; the number of affected individuals has not yet been determined.

The breach involved employees’ names, work email addresses, workplace locations, and work phone numbers—as well as, to the extent shared with the data controller, customer order forms, contracts, invoices, data protection agreements, master service agreements, and routine business correspondence.

Action: The investigation is ongoing; affected individuals can obtain information through the help center and at privacy@canva.com.

Key points

(i) The fact that all 27 reports stem from a vulnerability in a third-party software library within a single e-commerce infrastructure provider implies that data controllers will be questioned regarding whether they exercised due diligence in selecting and supervising data processors under Article 12(1) of the Personal Data Protection Law (KVKK); security commitments and audit rights in supplier contracts must be reviewed.

(ii) The Board announced all 27 notifications in a single decision numbered 2026/2039—indicating that the incident was treated as having a single source. Clients using the same infrastructure are advised to assess their own notification obligations (72 hours).

(iii) The companies with the highest number of affected individuals are: Eve Kozmetik (6.26 million), Shaya Mağazacılık (2.3 million), Deniz Butik (1.27 million), and Locco Elektronik (517,000). Although storing passwords as hashes reduces the risk, notifications involving the use of weak algorithms such as MD5 (Valmenti) make it critical to notify affected individuals and recommend password resets.

(iv) The Canva notification warrants special attention because it involves a data controller based abroad affecting its corporate customers in Turkey; the affected data includes commercial documents such as contracts and invoices.