2026 Yiğit Alışveriş Merkezleri — KVKK notice; 81,593 people
Data compromised
Personal data per KVKK notice; press notes several companies also listed login/password among affected fields
Technical writeup
Verified Turkish KVKK public notice — published September 16, 2026 (Board Decision 2026/2039 cluster). Yiğit Alışveriş Merkezleri: Unauthorized access / third-party software theme in KVKK cluster notices. Affected data: Personal data per KVKK notice; press notes several companies also listed login/password among affected fields. recordsAffected 81593; companyConfirmed true. KVKK stated reviews continue; regulator has not confirmed all 12 notices are a single shared attack despite several citing third-party library/processor themes.
Root cause
Unauthorized access / third-party software theme in KVKK cluster notices
References
- https://www.kvkk.gov.tr/Icerik/8983/kamuoyu-duyurusu-veri-ihlali-bildirimi-yigit-alisveris-merkezleri-day-tuk-mal-ins-tur-san-ve-dis-tic-ltd-sti
- https://www.turkishminute.com/2026/09/17/data-breaches-at-12-turkish-companies-expose-personal-data-of-over-10-million-people/
- https://www.memurlar.net/haber/1178356/kvkk-acikladi-12-sirketin-verileri-calindi-10-milyon-kisi-etkilendi.html