The Personal Data Protection Authority Published Twenty-Eight Data Breach Notifications
On September 16, 2026, 28 data breach notifications were shared with the public on the official website of the Personal Data Protection Authority. Twenty-seven of the notifications pertained to a single incident involving the same data processor from whom the data controllers obtained e-commerce infrastructure services; all were announced via a single Board decision numbered 2026/2039. The notification regarding Canva Pty Ltd, however, pertained to a separate incident and was announced via decision number 2026/2037.
The publication of this number of notifications in a single day—and the fact that they all stemmed from a single supplier—is significant in terms of the Authority’s approach to breaches originating from data processors and the duty of care data controllers must exercise in selecting and auditing suppliers. A summary of the notifications is provided below.
A. 27 notifications stemming from a common data processor (2026/2039)
Incident: The breach occurred as a result of unauthorized access to a server in the systems of a data processor from whom data controllers obtained e-commerce infrastructure services, achieved by exploiting a security vulnerability in a third-party software library used by the data processor. The breaches were identified through notifications sent by the data processor to the data controllers on September 9–11, 2026 (August 27, 2026, in the notification from Güneş Engin; some notifications did not specify a date).
Impact: In nearly all of the notifications, first and last names, email addresses, phone numbers, addresses, and hashed username/password information were affected; some also included order information, IP addresses, admin panel account information, and payment API keys. The affected groups consist primarily of customers, members, users, and employees. In the disclosures where the number was disclosed, a total of approximately 10.84 million individuals were affected.
Action: The Board’s review is ongoing for all disclosures; in some cases, the number of affected individuals and the scope of the data have been requested from the data processor.
|
# |
Data controller |
Affected individuals |
Relevant group of individuals / affected data |
|
1 |
Yeni Mağazacılık A.Ş. (Eve Kozmetik) |
6,263,305 |
Customers — first name, last name, email, phone number |
|
2 |
Shaya Mağazacılık A.Ş. (Alshaya) |
2,298,726 |
Employees, customers — first name, last name, email, address |
|
3 |
Deniz Butik Tekstil San. ve Tic. A.Ş. |
1,271,096 |
Customers — username, phone number, email |
|
4 |
Locco Elektronik Mağazacılık ve Tic. Ltd. Şti. |
517,306 |
Employees, users — first name, last name, email, phone number, address, hashed login credentials |
|
5 |
Shaya Kahve San. ve Tic. A.Ş. |
133,991 |
Employees, customers — first name, last name, email, address |
|
6 |
Haşema Tekstil Turizm Malz. ve Amb. San. Tic. Ltd. Şti. |
95,857 |
Customers — first name, last name, email, address, phone number, hashed login credentials |
|
7 |
Yiğit Alışveriş Merkezleri Day. Tük. Mal. Ltd. Şti. |
81,593 |
Customers, potential customers — first name, mailing address, email, stored password hashes |
|
8 |
Ademur Optik San. ve Tic. A.Ş. (Dünya Göz Optik) |
35,575 |
Customers, employees — first name, last name, email, address, phone number, order information, IP |
|
9 |
Valmenti Mağazacılık Tic. Ltd. Şti. |
32,292 |
Customers/potential customers — first name, phone number, email, login credentials with MD5 hashes |
|
10 |
Taşkınırmak Giyim San. ve Tic. A.Ş. (imza.com.tr) |
29,265 |
Employees, members, customers, potential customers — first name, last name, phone number, email, address, hashed password, admin panel account information |
|
11 |
HLY Aromaterapi Hizmetleri Kozmetik San. Tic. A.Ş. |
25,088 |
Employees, users, members, customers, potential customers — identification, contact information, transaction security |
|
12 |
Bilir Giyim San. ve Tic. A.Ş. (Morven) |
20,742 |
Employees, members, customers — first name, last name, phone number, email, address, hashed password, admin panel account information |
|
13 |
Tokgözler Civata Tic. ve Paz. A.Ş. |
17,615 |
Customers — first name, last name, phone number, email, address, hashed password |
|
14 |
İyileştiren Mamuller Gıda San. ve Tic. A.Ş. |
6,547 |
Users, customers/prospective customers — first name, last name, phone number, email, address, hashed password |
|
15 |
Back and Bond Hazır Giyim A.Ş. |
5,435 |
Customers — first name, last name, email, address, phone number, hashed login credentials |
|
16 |
Seyfettin Çaylak (hoodiemouse.com) |
5,246 |
Customers, dashboard users — identity, contact information, customer transactions, transaction security |
|
17 |
Mehmet Salih Araç (piposavinelli.com) |
~1,800 |
Customers — first name, last name, address, email, phone number, stored password values, admin accounts, payment API keys (exact number not disclosed; number of store members) |
|
18 |
Alfa Öncü Global Otomotiv Mobilya San. Tic. Ltd. Şti. (bahceme.com) |
1,520 |
Customers, users — first name, last name, phone number, email, shipping/billing address, hashed password |
|
19 |
Çiğdem Kaya (Ortobella Comfort Medikal) |
874 |
Users, members — first name, last name, email, phone number, address, hashed password, session data |
|
20 |
Ekmaş Gıda Makinaları San. ve Tic. Ltd. Şti. |
707 |
Customers/prospective customers, employees — first name, last name, phone number, email, address, hashed password |
|
21 |
Mersin Mana Tarım San. ve Tic. Ltd. Şti. |
695 |
First name, last name, email, phone number, hashed password (information regarding address data was requested from the data processor) |
|
22 |
Agr Industries Tekstil Ltd. Şti. (blondiofficial.com) |
56 |
56 end-user accounts + 1 admin panel account — first name, last name, phone number, email, address, hashed password |
|
23 |
Brinda Tekstil San. ve Tic. Ltd. Şti. (canzetta.com) |
21 |
Customers, employees — first name, last name, phone number, email, address, hashed password (exact number requested from the data processor) |
|
24 |
Desa Deri San. ve Tic. A.Ş. |
Could not be determined |
Customers, users — first name, last name, email, account verification information |
|
25 |
Samsonite Seyahat Ürünleri San. ve Tic. A.Ş. |
Could not be determined |
Customers, users — first name, last name, phone number, email, account authentication information |
|
26 |
İnternet Tekstil San. ve Tic. A.Ş. |
Could not be determined |
Customers, members — first name, last name, phone number, email, address, hashed login credentials |
|
27 |
Güneş Engin (Karum Rouge) |
Could not be determined |
Users, members — first name, last name, email, address, phone number, hashed password |
Note: A total of 10,843,552 individuals were affected across the 22 notifications for which numbers were disclosed; the number of affected individuals in five notifications has not yet been determined.
B. Standalone notification
28. Canva Pty Ltd (2026/2037)
Incident: Unauthorized access to a third-party tool used by the data controller; it is assessed that the threat actor exported (leaked) some personal data via a connection with the data processor.
Impact: Data associated with 424 organizations/entities located in Turkey was affected; the number of affected individuals has not yet been determined.
The breach involved employees’ names, work email addresses, workplace locations, and work phone numbers—as well as, to the extent shared with the data controller, customer order forms, contracts, invoices, data protection agreements, master service agreements, and routine business correspondence.
Action: The investigation is ongoing; affected individuals can obtain information through the help center and at privacy@canva.com.
Key points
(i) The fact that all 27 reports stem from a vulnerability in a third-party software library within a single e-commerce infrastructure provider implies that data controllers will be questioned regarding whether they exercised due diligence in selecting and supervising data processors under Article 12(1) of the Personal Data Protection Law (KVKK); security commitments and audit rights in supplier contracts must be reviewed.
(ii) The Board announced all 27 notifications in a single decision numbered 2026/2039—indicating that the incident was treated as having a single source. Clients using the same infrastructure are advised to assess their own notification obligations (72 hours).
(iii) The companies with the highest number of affected individuals are: Eve Kozmetik (6.26 million), Shaya Mağazacılık (2.3 million), Deniz Butik (1.27 million), and Locco Elektronik (517,000). Although storing passwords as hashes reduces the risk, notifications involving the use of weak algorithms such as MD5 (Valmenti) make it critical to notify affected individuals and recommend password resets.
(iv) The Canva notification warrants special attention because it involves a data controller based abroad affecting its corporate customers in Turkey; the affected data includes commercial documents such as contracts and invoices.