Massive Data Breaches Expose Over 10 Million Records Across 12 Turkish Companies
Turkey’s data protection regulator revealed on September 16 that 12 companies suffered data breaches affecting over 10.2 million customers and employees, with one firm still unable to determine the full scope of the exposure. The incidents, disclosed under Turkey’s Personal Data Protection Law, highlight widespread vulnerabilities in third-party software and data processing systems.
The largest breach occurred at Eve Kozmetik, a cosmetics retailer, where 6.26 million records including names, email addresses, and phone numbers were compromised. The company reported that attackers exploited a vulnerability in a third-party software library on a server operated by a data processor, with the breach detected on September 10.
Two subsidiaries of Kuwait-based Alshaya Group Shaya Mağazacılık and Shaya Kahve also reported significant breaches. Shaya Mağazacılık exposed 2.3 million records (names, emails, and home addresses), while Shaya Kahve affected 133,999 individuals. The group operates major brands in Turkey, including Starbucks, Victoria’s Secret, and Bath & Body Works.
Other notable breaches included:
- Deniz Deniz Butik: 1.27 million records (usernames, phone numbers, emails) compromised via a third-party software vulnerability.
- Haşema Tekstil: 95,857 affected.
- Yiğit Alışveriş Merkezleri: 81,593 affected.
- Valmenti Mağazacılık: 32,292 affected.
- Taşkınırmak Giyim: 29,265 affected.
- İyileştiren Mamuller Gıda: 6,547 affected.
- Back and Bond: 5,435 affected.
- Mersin Mana Tarım: 695 affected.
İnternet Tekstil Sanayi ve Ticaret A.Ş. reported potential exposure of names, phone numbers, emails, postal addresses, and login credentials but has not yet confirmed the number of affected individuals. Like several other breaches, the incident stemmed from a vulnerability in a third-party software library.
While the regulator has not confirmed whether the breaches were part of a coordinated attack, multiple incidents involved unauthorized access to third-party systems. Under Turkish law, companies must notify affected individuals and the regulator "as soon as possible" when personal data is unlawfully obtained. The regulator’s investigations into the breaches remain ongoing.
Back and Bond TPRM report: https://www.rankiteo.com/company/evolvebackresorts
"id": "evo1789691791",
"linkid": "evolvebackresorts",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '6.26 million',
'industry': 'Retail',
'location': 'Turkey',
'name': 'Eve Kozmetik',
'type': 'Cosmetics Retailer'},
{'customers_affected': '2.3 million',
'industry': 'Retail',
'location': 'Turkey',
'name': 'Shaya Mağazacılık',
'type': 'Retail Subsidiary'},
{'customers_affected': '133,999',
'industry': 'Food & Beverage',
'location': 'Turkey',
'name': 'Shaya Kahve',
'type': 'Café Subsidiary'},
{'customers_affected': '1.27 million',
'industry': 'Retail',
'location': 'Turkey',
'name': 'Deniz Deniz Butik',
'type': 'Retail'},
{'customers_affected': '95,857',
'industry': 'Textile',
'location': 'Turkey',
'name': 'Haşema Tekstil',
'type': 'Retail'},
{'customers_affected': '81,593',
'industry': 'Retail',
'location': 'Turkey',
'name': 'Yiğit Alışveriş Merkezleri',
'type': 'Retail'},
{'customers_affected': '32,292',
'industry': 'Retail',
'location': 'Turkey',
'name': 'Valmenti Mağazacılık',
'type': 'Retail'},
{'customers_affected': '29,265',
'industry': 'Apparel',
'location': 'Turkey',
'name': 'Taşkınırmak Giyim',
'type': 'Retail'},
{'customers_affected': '6,547',
'industry': 'Food & Beverage',
'location': 'Turkey',
'name': 'İyileştiren Mamuller Gıda',
'type': 'Food'},
{'customers_affected': '5,435',
'industry': 'Retail',
'location': 'Turkey',
'name': 'Back and Bond',
'type': 'Retail'},
{'customers_affected': '695',
'industry': 'Agriculture',
'location': 'Turkey',
'name': 'Mersin Mana Tarım',
'type': 'Agriculture'},
{'customers_affected': 'Unknown',
'industry': 'Textile',
'location': 'Turkey',
'name': 'İnternet Tekstil Sanayi ve Ticaret A.Ş.',
'type': 'Retail'}],
'attack_vector': 'Third-party software vulnerability',
'customer_advisories': 'Affected individuals notified as required by law',
'data_breach': {'number_of_records_exposed': 'Over 10.2 million',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'Personally Identifiable Information '
'(PII)',
'type_of_data_compromised': ['Names',
'Email addresses',
'Phone numbers',
'Home addresses',
'Login credentials',
'Postal addresses']},
'date_detected': '2023-09-10',
'date_publicly_disclosed': '2023-09-16',
'description': 'Turkey’s data protection regulator revealed that 12 companies '
'suffered data breaches affecting over 10.2 million customers '
'and employees, with one firm still unable to determine the '
'full scope of the exposure. The incidents highlight '
'widespread vulnerabilities in third-party software and data '
'processing systems.',
'impact': {'data_compromised': 'Over 10.2 million records',
'identity_theft_risk': 'High',
'systems_affected': 'Third-party data processing systems'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'root_causes': 'Vulnerabilities in third-party '
'software libraries'},
'references': [{'date_accessed': '2023-09-16',
'source': 'Turkey’s Data Protection Regulator'}],
'regulatory_compliance': {'regulations_violated': 'Turkey’s Personal Data '
'Protection Law',
'regulatory_notifications': 'Yes'},
'response': {'communication_strategy': 'Notified affected individuals and '
'regulator as required by law'},
'title': 'Massive Data Breaches Expose Over 10 Million Records Across 12 '
'Turkish Companies',
'type': 'Data Breach',
'vulnerability_exploited': 'Vulnerability in third-party software library'}