BreachesMedium

Call center attack hits Nesine and 4 Race customer data, says KVKK

Two Turkish betting companies report that their call center provider's systems were encrypted in a cyberattack, potentially exposing call recordings and identity details.

Call center attack hits Nesine and 4 Race customer data, says KVKK

At a glance

  • D Elektronik Şans Oyunları (Nesine) and 4 Race Teknoloji ve Yazılım reported the same type of incident at their call center data processor.
  • The processor noticed a service outage on September 30, 2026; data was encrypted and made inaccessible.
  • Initial checks found no evidence of exfiltration, but unauthorized access cannot be ruled out, the notices say.
  • Call recordings may include birth dates and Turkish ID numbers, and a limited number may contain disability information.

Two Turkish online betting companies, D Elektronik Şans Oyunları ve Yayıncılık A.Ş., which uses the nesine.com contact addresses, and 4 Race Teknoloji ve Yazılım A.Ş., have reported a cyberattack on the systems of the call center provider they both use, according to notices published on October 7 by KVKK, Turkey's Personal Data Protection Authority. The two notices describe the incident in nearly identical terms.

What happened

According to KVKK's announcements, attackers gained unauthorized access to the call center data processor's infrastructure and encrypted data, making it inaccessible. The processor noticed the attack after a service outage on September 30, 2026, and informed the companies. The notices do not give the date the attack began.

Initial examinations found no evidence that data was exported, the notices say, but given how long the attacker remained in the system and the shared nature of the infrastructure, unauthorized access cannot be fully ruled out. A forensic investigation is under way to establish the outcome. The Personal Data Protection Board ordered the notices published with decisions 2026/2212 and 2026/2211, under Article 12(5) of Law No. 6698.

Who is affected

Affected people are customers who called or were called by the call center, as well as prospective customers who called about membership. The data involved includes phone numbers in call detail records, names and identity verification details given during calls, request and complaint contents, transaction information and call recordings. Depending on the conversation, recordings may also include birth dates and Turkish identity numbers. Because support for visually impaired members is handled through the call center, a limited number of calls may contain statements about disability, which is special category data under Turkish law.

The number of affected people and records has not yet been determined, since it is not yet clear which files were encrypted or whether data was obtained by third parties.

What to do

Customers of both platforms should be wary of calls or messages that cite past support conversations and ask for passwords, verification codes or payments. According to the notices, affected people can contact the companies through their call centers, "Write to Us" channels and the support email addresses listed in the announcements, and can use the application forms on their websites to exercise their rights under Article 11 of Law No. 6698.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.