BreachesMedium

Dodo Pizza and three pizza companies report unauthorized access to customer data

Turkey's data protection authority published four breach notices involving Dodo Brands and three pizza businesses, citing exposure of identity, contact, location and financial data.

Dodo Pizza and three pizza companies report unauthorized access to customer data

At a glance

  • Dodo Brands International FZCO detected unauthorized access to systems holding personal data on September 28, 2026.
  • Deniz Pizza, DDP Temizlik Pizza and Smart Delivery Pizza reported unauthorized access to data processor systems holding their data.
  • All four notices list identity, contact, location, customer transaction and financial data of customers and employees.
  • The number of affected people has not yet been determined; Dodo says it will notify people via the Dodo Pizza mobile app.

Dodo Brands International FZCO, the company behind the Dodo Pizza brand, and three pizza businesses operating in Turkey have reported unauthorized access to systems holding customer and employee data, according to four notices published on October 7 by KVKK, Turkey's Personal Data Protection Authority. The notices list the same categories of personal data, though KVKK does not explicitly state how the four cases are related.

What happened

According to KVKK, Dodo Brands International FZCO detected on September 28, 2026, that unauthorized access had been gained to systems containing personal data belonging to the company. The notice does not say when the breach began or how the access was obtained.

The other three notices, filed by Deniz Pizza Restoranları ve Ticaret, DDP Temizlik Pizza Gıda Sanayi ve Ticaret and Smart Delivery Pizza Yemekçilik Gıda E-Ticaret Reklamcılık ve Ticaret, state that unauthorized access was gained to data processor systems holding the companies' data. Deniz Pizza and Smart Delivery Pizza say the processor informed them on September 30, while DDP says it was notified on October 1. The notices do not name the data processor.

The Personal Data Protection Board ordered the notices published under Article 12(5) of Law No. 6698 with decisions 2026/2199, 2026/2198, 2026/2197 and 2026/2200 respectively.

Who is affected

All four notices list customers and employees as affected groups. The data involved includes identity, contact, location, customer transaction and financial information. The notices do not specify what the financial data consists of, for example whether card details are involved. Work to determine the number of affected people is still under way in each case, and KVKK says its examination continues.

Dodo Brands said affected individuals will be informed through the Dodo Pizza mobile app. The notices do not describe other remediation steps.

What to do

Customers who have ordered from Dodo Pizza or these businesses should be cautious of messages that reference recent orders or delivery addresses and ask for payment or card details, review bank statements for unfamiliar transactions and change the password of their food ordering accounts, especially if it is reused elsewhere. Notifications from the Dodo Pizza app and the companies' official channels should be followed for details about the scope of the incident.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.