BreachesMedium

Medikalyapı and Ortadoğu Holding report encryption attacks on the same day

Turkey's data protection authority published two near-identical notices saying outside attackers accessed and encrypted the companies' systems on October 3, 2026.

Medikalyapı and Ortadoğu Holding report encryption attacks on the same day

At a glance

  • Both breaches began and were detected on October 3, 2026, according to KVKK's notices.
  • Attackers accessed the companies' systems from outside, encrypted data and made it inaccessible.
  • Employees, users and customers are affected; data includes personnel, financial, legal and audiovisual records.
  • The number of affected people could not be estimated, and the investigation continues.

Medikalyapı Sağlık Yatırımları A.Ş. and Ortadoğu Holding A.Ş. have reported attacks in which outside actors accessed their systems and encrypted data, according to two notices published on October 7 by KVKK, Turkey's Personal Data Protection Authority. Both incidents began and were detected on October 3, 2026, and the two notices describe them in almost identical wording, though KVKK does not state whether they are linked.

What happened

According to KVKK's announcements, access to the data controllers' systems was obtained from outside, and the data was encrypted and made inaccessible, a pattern consistent with a ransomware attack, although the notices do not use that term. The announcements do not explain how the attackers got in, whether data was copied before encryption, or whether any ransom was demanded. No group's claim of responsibility is mentioned.

The Personal Data Protection Board ordered the notices published on October 7, 2026, under Article 12(5) of Law No. 6698; the Ortadoğu Holding notice carries decision number 2026/2216.

Who is affected

Both notices list employees, users and customers as affected groups. The personal data categories involved are location, personnel, legal transaction, risk management, financial, professional experience and marketing data, along with visual and audio recordings. Because the companies could not estimate how many people may have been affected, no figure is given. KVKK says the examination is continuing, and the notices do not list concrete remediation steps.

What to do

Employees, customers and business partners of the two companies should watch for phishing messages that reference the incident or use internal details such as personnel or contract information, and should verify any request for payment changes or credentials through a known contact. Companies facing similar attacks should isolate affected systems, rotate privileged credentials, review remote access logs for the period before encryption and restore from offline backups only after confirming the attackers no longer have access. Notifying affected individuals promptly and clearly about which data was involved helps them protect themselves against follow-on fraud.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.