Twelve notices in one day, one Board decision: vendor's breach, brand's notice
On September 16, 2026 Türkiye's data protection authority KVKK published 12 separate data breach notices, all dated the same day and based on one Board decision. Each states the breach hit not the company's own systems but a data processor it uses. Eve Kozmetik (6.26 million) and Shaya Mağazacılık (2.30 million) lead the list; the 11 companies that gave figures add up to more than 10 million records.
Twelve notices in a day, one Board decision
Türkiye's Personal Data Protection Authority (KVKK) published 12 separate public notices on its website on September 16, 2026, all dated that day. Every notice rests on a single Personal Data Protection Board decision, number 2026/2039 dated 16.09.2026, issued under Article 12/5 of Law No. 6698, which requires a data controller to notify affected individuals and the Authority as soon as possible when personal data is obtained unlawfully. According to KVKK's Eve Kozmetik notice, the breach happened on the server of a data processor the company uses, where unauthorized access was gained by exploiting "a security vulnerability in a third-party software library". The Shaya Mağazacılık and Shaya Kahve notices describe it as unauthorized access to the data processor's systems. The common thread: in all 12 notices the breach took place not in the controller's own systems but at an outside data processor. The processor notified the companies on September 9, 10 and 11, 2026, most often on September 10. Several notices say the investigation is ongoing.
The companies, the numbers and what leaked
The notices give affected numbers company by company. The largest is Yeni Mağazacılık A.Ş. (Eve Kozmetik): name, surname, email and phone number for 6,263,305 customers. Shaya Mağazacılık A.Ş. follows with 2,298,726 employees and customers (name, surname, email, address) and Deniz Deniz Butik Tekstil A.Ş. with 1,271,096 customers. Shaya Kahve Sanayi ve Ticaret A.Ş. reported 133,991 people, Haşema Tekstil 95,857, Yiğit Alışveriş Merkezleri 81,593, Valmenti Mağazacılık 32,292, Taşkınırmak Giyim 29,265, İyileştiren Mamuller Gıda 6,547, Back and Bond Hazır Giyim 5,435 and Mersin Mana Tarım 695; İnternet Tekstil has not yet determined its number. The 11 companies that gave figures add up to 10,218,802 records; that is our own calculation, not a KVKK figure, and not deduplicated, since a person can appear on more than one list. Beyond contact details, the Haşema, Valmenti, Taşkınırmak, İyileştiren Mamuller, Back and Bond and Mersin Mana notices list hashed passwords or login credentials, Valmenti specifies MD5 as the algorithm, Yiğit lists stored password values and Taşkınırmak adds admin panel account details.
Why it matters: the chain broke at its weakest link
Read one by one, these are routine notices; together, they form the picture of a supply chain incident. The same day, the same Board decision, notification dates within days of each other and nearly identical descriptions of the mechanism suggest the breaches trace back to a shared infrastructure provider; no notice says so explicitly, that is our inference. The identity of the data processor and the name of the vulnerable library are not disclosed anywhere. Whether the Board imposed fines, company statements and technical details are also absent from the sources. First, the central point: although the breach happened at the vendor, every notice was published under the data controller's name. Under Law No. 6698 the duty to notify sits with the controller, and outsourcing part of the operation does not remove it. Second, speed: processor notifications came September 9 to 11, KVKK's notices on September 16, so 12 brands were named publicly within five to seven days. Third, the data itself: beyond names and emails, hashed passwords and admin panel credentials are material for account takeover attempts.
What it means for businesses in Türkiye: your vendor's flaw, your notice
There is no Türkiye boundary to draw here: the whole story takes place in Türkiye, with KVKK as regulator, Law No. 6698 as the basis, Turkish retail, textile, cosmetics, food and agriculture companies as controllers and Turkish consumers as the affected. Four practical points follow. First, for any business that rents its e-commerce infrastructure, membership system or CRM, vendor security is no longer an abstract contract clause but the risk of a notice under its own name; the processor agreement needs written security obligations, a breach notification deadline and responsibility for dependency updates. Second, the duty to notify is yours: once the vendor informs you, the clock to notify KVKK and affected individuals as soon as possible starts, so roles must be decided in advance. Third, password hygiene: one notice mentions MD5; a store that does not hash passwords with a strong, slow algorithm or protect its admin panel with two-step verification amplifies the impact of a leak. Fourth, customer communication: the email, SMS, call center and WhatsApp channels in the notices show that post-breach notification needs a ready template and a current contact list.
The UNALSOFT view
Our reading: the 12 companies named here share one thing, a breach at the data processor they use rather than in their own systems. Renting infrastructure makes the work easier; it does not transfer the responsibility. That is why in our E-Commerce Panel setups we ask clients three things from the start: which algorithm stores the passwords, who logs into the admin panel and with what verification, and how often third-party dependencies are updated. Without those answers, the customer data a successful campaign collects can one day turn into a notice. You may not see your vendor's name in that notice; you will certainly see your own.
Want to see the vendor risk inside your e-commerce stack?
Let's review your password storage, admin panel access and data processor agreement together. A short conversation is enough to start.