Turkey’s Personal Data Protection Authority (KVKK) published a public breach notice on September 16, 2026 for this controller as part of a twelve-company disclosure cluster under Board Decision 2026/2039. Combined, the eleven companies that could state a headcount reported 10,218,802 affected people. This file’s published size is not yet established.
This is a verified data breach via regulator publication — not a dark-web rumor. Title in the BreachHistory catalog: 2026 İnternet Tekstil — KVKK notice; count TBD (names/phones/emails/addresses/logins). Canonical record: https://breachhistory.com/internet-tekstil/internet-tekstil-kvkk2026. Primary notice: KVKK public announcement. English-language roundup: Turkish Minute.
What happened
Root cause per notice reporting: Unauthorized access linked to vulnerability in a third-party software library (count under investigation). Data categories: Names, phone numbers, email addresses, postal addresses, and login information may have been affected; headcount not yet established.
KVKK decided the notice should be made public on September 16, 2026 and said its review continues. Controllers remain responsible for notifying affected individuals under Turkish law even after the public post.
Timeline
- Incident / access window: described in the controller’s filing to KVKK (Eve Kozmetik’s processor informed that brand on September 10).
- September 16, 2026: KVKK publishes this notice with eleven others.
- September 17, 2026: Press summarizes the twelve-notice cluster and the combined 10.2 million figure.
- Ongoing: KVKK review; possible individualized notices and count revisions.
How the attack worked
Verified Turkish KVKK public notice — published September 16, 2026 (Board Decision 2026/2039 cluster). İnternet Tekstil Sanayi ve Ticaret A.Ş.: Unauthorized access linked to vulnerability in a third-party software library (count under investigation). Affected data: Names, phone numbers, email addresses, postal addresses, and login information may have been affected; headcount not yet established. recordsAffected 0 (count not yet established); companyConfirmed true. KVKK stated reviews continue; regulator has not confirmed all 12 notices are a single shared attack despite several citing third-party library/processor themes.
Do not invent a shared actor across all twelve companies. Several notices share a third-party library theme; the regulator has not confirmed a single coordinated attack.
What data was exposed
- Names, phone numbers, email addresses, postal addresses, and login information may have been affected; headcount not yet established
- Published population: not yet established
What was not confirmed
Payment-card PAN dumps and national ID numbers are not the headline fields in every English paraphrase of this cluster. Check the KVKK HTML. KVKK has not said the twelve notices are one breach event.
Who is at risk
Customers, members, and — where stated — employees tied to this controller in Turkey. Ask “was I affected” based on membership in these systems during the filing window until a personal letter arrives.
Industry context
The September 16 KVKK cluster is one of the largest single-day retail disclosure dumps Turkey has published in 2026 by combined headcount. Processor and library themes echo global software supply-chain lessons for any brand that outsources loyalty or e-commerce components.
What the company and KVKK said
KVKK published the notice and stated examinations continue. No administrative fine amount appears in the September 16 public post itself.
What you should do
- Change reused passwords; enable MFA on email.
- Treat “KVKK verification,” refund, or cargo SMS as phishing unless you started the contact in the official app.
- Watch for SIM-swap and bank OTP theft if phones were exposed.
- Employees: verify payroll changes out-of-band.
- Keep the KVKK URL and any letter for disputes.
- Sign out other sessions if login fields were involved.
- Rotate shared family passwords used on the brand.
- Report fraud to your bank and, where appropriate, Turkish authorities.
Canonical record and sources
How Turkey’s KVKK disclosure process works
Under Turkey’s Personal Data Protection Law, controllers that learn personal data was obtained unlawfully must notify the affected people and the Personal Data Protection Authority (KVKK) as soon as possible. The Authority may then publish the notice when it decides public disclosure is necessary. Publication is not the same as closing the file: KVKK explicitly said reviews of this September 16 cluster continue.
For customers, the practical effect of a public KVKK notice is that you no longer need to wonder whether a rumor is real. The controller has already told the regulator enough for the Authority to post a named announcement with an affected-person count, or an explicit statement that the count is still being determined. Controllers should still send individualized notices where risk warrants it.
A KVKK homepage link is a transparency tool for the public; it does not replace the controller’s duty to speak directly to people whose records were touched. Keep the notice URL, any letter you receive, and screenshots of phishing attempts in one folder for bank disputes.
Third-party libraries and processor risk
Several notices in the September 16 cluster describe unauthorized access via a vulnerability in a third-party software library or on a processor’s server. KVKK has not declared that all twelve companies were hit by one coordinated campaign. Treat the shared technical theme as a supply-chain warning, not as proof of a single actor or a single CVE across every brand.
Defenders should inventory which marketing, loyalty, or e-commerce components sit on shared processors; require software-bill-of-materials style library inventories; and demand breach-notification SLAs that do not wait for a regulator’s public post. In the Eve Kozmetik file, the processor informed the brand on September 10 — days before the September 16 public notices — which is the window where customer communications should already have been drafting.
If your organization buys Turkish retail media, loyalty, or marketplace plugins, ask vendors whether they were the processor named in any September 16 KVKK notice and whether the same library build is still in production today.
Fraud and phishing after Turkish retail breaches
When names, emails, and phones leave a retailer, the follow-on crime is usually smishing and email phishing that spoofs cargo tracking, refunds, or loyalty points. If home addresses or login identifiers are also in the set, expect account-reset and confirm-your-address lures. Do not use links in unexpected SMS messages that cite the brand; open the official app or type the known domain by hand.
Employees named in retailer or franchise breaches should assume HR and payroll phishing will rise. Verify any bank-detail change request by phone using numbers from internal directories, not from the email footer. Franchise partners should confirm whether their local customer lists were in the relevant Shaya filings rather than assuming every store banner was hit.
Banks and e-wallet providers in Turkey should expect a wave of social-engineering tickets that cite KVKK urgency. Train agents to authenticate callers without reading back full identity elements that attackers already hold from the dump.
Comparing the twelve-notice cluster
The largest files by published headcount are Eve Kozmetik at 6,263,305, Shaya Mağazacılık at 2,298,726, and Deniz Deniz Butik at 1,271,096. Mid-tier notices include Shaya Kahve (133,991), Haşema Tekstil (95,857), and Yiğit Alışveriş Merkezleri (81,593). Smaller but still verified counts cover Valmenti, Taşkınırmak, İyileştiren Mamuller, Back and Bond, and Mersin Mana Tarım. İnternet Tekstil’s notice is verified without a finished headcount.
That spread matters for prioritization: a multi-million cosmetics file and a sub-thousand agriculture file are both real KVKK publications, but the customer-communication load and fraud surface differ. BreachHistory catalogs each as its own row so searchers land on the correct brand page instead of a blended mega-article.
What remains open
KVKK’s continuing review may revise field lists or counts. Controllers may still owe individualized notices beyond the public Authority post. Exact CVE identifiers, processor legal names, and whether login secrets were hashed or plaintext are not fully spelled out in every English secondary summary. This article tracks the September 16 public snapshot; updates should follow the primary KVKK HTML notices, not social-media screenshots or leak-site marketing.
Security teams should keep a dated evidence folder with the KVKK URL, the published count, and any later amendment. When journalists ask whether a dark-web dump matches this breach, answer only from those artifacts and refuse to equate unverified actor marketing with KVKK counts.
Operational evidence note 1: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 2: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 3: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 4: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 5: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 6: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 7: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 8: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 9: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 10: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 11: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 12: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 13: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 14: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 15: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 16: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 17: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 18: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 19: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 20: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 21: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 22: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 23: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 24: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 25: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.
Operational evidence note 26: keep the KVKK URL, published count (not yet established), and root-cause sentence together. Brief executives from those artifacts only. If KVKK amends the HTML, update BreachHistory from the primary notice rather than secondary paraphrases.