Hyundai's Turkish distributor has told Turkey's data protection regulator that intruders broke into a web application and took records on its employees and job applicants, including the results of personality tests candidates sat during hiring.
Hyundai Motor Türkiye Otomotiv AŞ reported the breach to the Personal Data Protection Authority, KVKK, which published the notification by board decision on 5 August 2026. The company said its group Security Operation Center flagged the problem on 1 August, and that its data processor, the HR assessment firm Baltas Eksen, confirmed it on 3 August.
What was taken
The notice attributes the breach to exploitation of an SQL injection vulnerability, a long running class of web flaw in which an attacker slips database commands into an ordinary input field and gets the application to run them. Up to 422 people may be affected, though the company says it cannot fix the number exactly.
The exposed categories are unusually personal for a corporate breach: full names, email addresses, usernames, passwords, job titles, and Hogan and BEYT assessment results. Those last two are psychometric and personality inventories used to screen candidates, so the data describes how applicants scored on tests they had every reason to assume stayed with the recruiter. The notice lists passwords among the affected categories without saying how they were stored.
Two more notices in the same week
KVKK published two other breach notifications within days, and together the three describe three separate failure modes rather than one campaign.
The retailer Tamer Tanca Magazacilik Sanayi ve Ticaret AS reported that a cyber attack whose method it has not yet determined exposed customer names, contact details and order details, possibly affecting 50,000 customers and potential customers. The company found out only when a customer reported that their personal data had been used in an attempted fraud.
The third notice is an insider case. Doganay Urgupluoglu, who runs the Red Galaxy game service, told the regulator that a former team member with limited access exceeded it to reach server side code repositories between 2 and 3 August, copied the database without authorization, used it commercially and then deleted it. That breach affects 7,507 players and staff, and the data reaches well past logins to private messages, in game chat, IP addresses, device details, and Google Play and Xsolla payment records.
Is this a spike?
No, and that matters for reading the week correctly. IntelFusions' incident data holds nine KVKK breach notices for July and seven for June, so roughly two a week is the running rate and three is ordinary. What stands out is the spread rather than the volume: an injection flaw in a web application, an attack the victim could not characterize and did not detect itself, and a trusted former insider. Turkey is a heavily targeted country, as our Turkey threat profile sets out, and KVKK's practice of publishing individual breach notifications makes Turkish incidents visible in a way many countries' are not. Extortion crews have been busy there too, as when a new crew claimed Turkey's banks and flag carrier earlier this month.
What you should do
None of these are exotic. SQL injection is prevented by using parameterized queries instead of assembling SQL from user input, and it survives mainly in older applications that nobody has revisited. The Hyundai case is also a reminder that hiring pipelines quietly accumulate sensitive material and often route it through third party assessment providers, which widens the blast radius beyond the company's own systems. The insider case argues for the dull discipline of offboarding: revoking repository and server credentials the day somebody leaves, and alerting on bulk database exports. Anyone who used the Red Galaxy service or shopped with Tamer Tanca should change that password anywhere else they reused it.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.