BreachesMedium

Akkoyunlar malware attack exposes data of an estimated 1,690 employees

Turkey's data protection authority KVKK says malware delivered through a third-party application hit Akkoyunlar, exposing employee identity, contact and audiovisual records.

Akkoyunlar malware attack exposes data of an estimated 1,690 employees

At a glance

  • The breach began on September 23, 2026 and was detected the next day
  • KVKK says the company was hit by malware originating from a third-party application
  • An estimated 1,690 employees are affected; duplicate records are still being reviewed
  • Exposed data includes identity, contact, and visual and audio records

Akkoyunlar Otomotiv İletişim Tekstil San ve Dış Ticaret A.Ş., a Turkish company, suffered a cyberattack involving malware that originated from a third-party application, exposing data on an estimated 1,690 employees, according to a public notice published on September 30, 2026 by KVKK, Turkey's Personal Data Protection Authority. The notice was published under Article 12(5) of Personal Data Protection Law No. 6698, which requires data controllers to report breaches and allows the authority to announce them publicly.

What happened

According to KVKK's notice, the breach began on September 23, 2026 and was detected on September 24, 2026. The authority says the data controller was subjected to a cyberattack through malware originating from a third-party application. The notice does not name the application or the type of malware, and does not say whether data was encrypted, stolen or published.

The Personal Data Protection Board approved the public announcement with its decision numbered 2026/2138, dated September 30, 2026, according to KVKK.

What data was exposed

KVKK lists the affected personal data categories as:

  • Identity data
  • Contact data
  • Visual and audio records

The authority says the breach covered data on personnel who worked at the company in 2025, other company data, and outdated legacy documentation.

Who is affected

The affected group consists of the company's employees, according to KVKK. The number of affected people is estimated at 1,690, and the notice states that a detailed review is continuing because the data contains duplicate records. The final number could therefore change.

What to do

Current and former employees of the company should be alert to phishing emails, text messages and calls that use their personal details, and should not share passwords or verification codes with anyone claiming to represent the employer. Because visual records were among the affected categories, people should be cautious of attempts to misuse photos or identity documents. Organizations should vet third-party applications before installing them, restrict software installation rights on endpoints, keep endpoint detection tools up to date, and apply retention policies that remove outdated personnel documents no longer needed.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.