Turkey's data protection authority, the KVKK, spent the past week publishing breach notices that all say roughly the same thing. A retailer or manufacturer reports that someone reached a server belonging not to the company itself but to the outside firm that processes its data, and took customer names, email addresses, postal addresses, phone numbers and hashed passwords. Seven such notices went up under a single board decision, numbered 2026/2039 and dated September 16. Together they account for more than 6.4 million people.
One notice carries almost all of that total on its own.
Yeni Magazacilik Anonim Sirketi, which trades as the cosmetics chain Eve Kozmetik, told the regulator that 6,263,305 of its customers were affected, exposing names, surnames, email addresses and phone numbers. Its service provider notified it on September 10, and the company attributes the breach to exploitation of a security vulnerability in a third-party software library the provider was using. The other six notices run from 81,593 customers at a shopping-centre operator down to 695 at an agricultural firm.
The same sentence, over and over
What makes this worth flagging is not any one of those numbers. It is that the sentence keeps repeating. Across our incident records for Turkey, 39 KVKK notices since mid-June describe a breach that happened at the data processor rather than at the company that collected the data. One landed in June and two in July. Then 25 arrived in August and 11 more have arrived so far in September. Five of the most recent ones name the same proximate cause, a vulnerability in a third-party software library.
The affected companies are mostly Turkish textile, apparel, cosmetics and retail businesses, with no obvious connection to one another. The exposed data is near-identical from notice to notice, down to the same combination of contact details plus hashed login credentials. In at least one case, Valmenti Magazacilik, the regulator records the passwords as MD5 hashes, an algorithm considered unsuitable for storing passwords for roughly two decades.
The one name nobody has published
The obvious question is whether these companies share a supplier, and the public record does not say. KVKK notices name the data controller, the brand that collected the information, and describe the processor only as a processor. None of the notices we reviewed identifies the third-party firm, and none names the vulnerable software library. Consumers can see that their data leaked from a company they never chose to deal with, without learning which company that was.
We are not asserting a single common supplier on the strength of a repeated phrase. Turkish retail e-commerce leans on a small number of platform and fulfilment providers, so a cluster of this shape is consistent with one upstream compromise, and equally consistent with several processors running the same vulnerable component. Both readings point to the same exposure.
Assume your processor is your attack surface
For companies in this position the immediate work is unglamorous. Establish in writing which third parties hold your customer records and what software they run to do it, rather than assuming your contract answers the question. If your processor stored your customers' passwords as MD5, treat those credentials as public and force a reset, because password reuse turns one retailer's leak into account takeovers everywhere else.
The KVKK deserves credit for publishing these notices individually and named, which is the only reason the pattern is visible at all. It is also incomplete. A regulator that can compel a company to disclose a breach at its processor can, in principle, compel it to name that processor, and until it does, the one party positioned to fix this at scale is the only one whose name stays out of the press. Our earlier coverage of the Hyundai Turkey applicant data breach ran into the same wall.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.