Ofix reports breach of 183,873 customers via Elasticsearch access with stolen credentials
KVKK says an unauthorized party used unlawfully obtained credentials to access office supplies retailer Ofix's Elasticsearch service, exposing names and emails of 183,873 customers.
At a glance
- KVKK published the notice on September 30, 2026, under Article 12(5) of Law No. 6698.
- An unauthorized third party accessed Ofix's Elasticsearch service using unlawfully obtained credentials.
- The breach began on September 15 and was detected on September 21, 2026.
- Names and email addresses of 183,873 customers were affected.
Turkish office supplies retailer Ofix Ofis Malzemeleri AŞ has reported a personal data breach affecting 183,873 customers, according to a public notice from Turkey's Personal Data Protection Authority (KVKK). KVKK, the country's data protection regulator, published the notice on September 30, 2026, under Article 12(5) of Law No. 6698, which requires data controllers to inform affected people and the authority when personal data is obtained by others unlawfully.
What happened
According to KVKK, an unauthorized third party gained access to the company's Elasticsearch service by using credentials that had been obtained unlawfully, and through that access reached customers' personal data. The notice says the breach began on September 15, 2026, and was detected on September 21, 2026, a gap of six days. It does not explain how the credentials were obtained, whether through phishing, malware, reuse of leaked passwords or another method.
The notice was published under Board Decision No. 2026/2139, dated September 30, 2026. KVKK notes that its examination of the incident is ongoing.
Who is affected
KVKK says 183,873 people in the customer category are affected. The exposed data is limited to two categories:
- Identity information: name and surname
- Contact information: email address
The notice does not list passwords, addresses or payment information among the affected data.
Technical details
Elasticsearch is a widely used search and analytics engine that companies often deploy to power product search, logging and customer records. Breaches involving Elasticsearch typically stem either from clusters exposed to the internet without authentication or, as in this case, from valid credentials falling into the wrong hands. KVKK's description indicates that the service had authentication in place but that the attacker possessed working credentials.
What to do
Affected individuals can contact Ofix at [email protected] for information about the breach, according to KVKK. Because names and email addresses were exposed together, customers should be cautious of emails that impersonate Ofix, mention orders or invoices, or ask them to log in, make payments or open attachments.
Organizations running Elasticsearch or similar data stores should restrict network access to trusted hosts, enforce strong and unique credentials with regular rotation, apply multi-factor authentication to administrative paths where possible, grant service accounts only the minimum privileges they need, and monitor query and access logs for unusual bulk reads that could indicate data theft.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Ofix Ofis Malzemeleri AŞ — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



