2026 Baydöner (Turkey) — customer platform intrusion (vendor path; millions of records)
Data compromised
Names, phones, emails, order/loyalty data; passwords in some summaries; national ID numbers in subset per reporting
Technical writeup
Baydöner, a large Turkish restaurant chain, disclosed unauthorized access to a customer-service / call-center platform operated via a vendor environment. Turkish regulator (KVKK) and industry reporting described discovery in March 2026 with activity from mid-February 2026. Public estimates of affected individuals varied (roughly 1.2M–3.7M in secondary sources); KVKK-oriented summaries cited on the order of ~1.49M people in the notification ecosystem. Exposed data types described included contact details, loyalty/CRM fields, and in some summaries password hashes; payment card data was generally described as out of scope.
Root cause
Unauthorized access to customer-service / vendor-managed platform