BreachesMedium

Papara Menkul Değerler reports breach via phishing of overseas processor's Okta SSO

Turkey's data protection authority KVKK published a breach notice for brokerage Papara Menkul Değerler, whose customer data was accessed after a data processor's Okta SSO platform was compromised.

Papara Menkul Değerler reports breach via phishing of overseas processor's Okta SSO

At a glance

  • According to KVKK, the breach began on 4 September 2026, was detected on 5 September and ended on 6 September.
  • Attackers reportedly gained access to an overseas data processor's Okta single sign-on platform through social-engineering phishing emails.
  • Affected data includes customer names, email addresses, phone numbers, addresses, investment profiles and tax status information.
  • KVKK's notice says the accessed data was encrypted and it has not yet been confirmed whether data was exfiltrated.

Turkey's Personal Data Protection Authority (KVKK), the country's data protection regulator, published a public breach notice on 30 September 2026 concerning Papara Menkul Değerler AŞ, an investment services firm. According to the notice, attackers accessed customer data after compromising the Okta single sign-on (SSO) platform of a data processor located outside Turkey. The incident is a fresh reminder that identity providers and third-party processors remain prime targets in attacks on the financial sector.

What happened

According to KVKK's announcement, the breach began on 4 September 2026 and was detected by the data processor on 5 September. The unauthorized access ended on 6 September, and the processor notified Papara Menkul Değerler, the data controller, on 18 September.

KVKK states that the intrusion started with phishing emails crafted through social engineering and sent to employees of the overseas data processor. Through these emails, the attackers obtained unauthorized access to the processor's Okta platform, a multi-factor single sign-on service used to authenticate staff into business applications.

The notice does not name the data processor and does not say how many customers or records were affected.

What data was involved

According to the authority, the affected data belongs to customers and includes:

  • first and last names
  • email addresses and phone numbers
  • postal addresses
  • investment profile information
  • tax status information

KVKK's notice adds that the data accessed was encrypted. It also states that it has not yet been confirmed whether the data was exfiltrated from the processor's environment.

KVKK published the notice under Article 12(5) of Turkey's Personal Data Protection Law No. 6698, which requires data controllers to report breaches to the authority and to affected individuals as soon as possible, and allows the authority to announce them publicly.

Why it matters

The attack pattern described by KVKK, phishing that leads to the takeover of an SSO platform, has been one of the most common routes into corporate environments in recent years. Because a single identity platform grants access to many downstream applications, one compromised session can expose data held in multiple systems. In this case the gap between detection by the processor (5 September) and notification to the data controller (18 September) was nearly two weeks, according to the timeline published by the authority.

What to do

Customers of Papara Menkul Değerler should be cautious about emails, text messages or calls that reference their investment accounts, since contact details and investment profile data are among the categories listed. They should not share passwords or one-time codes with anyone claiming to represent the company and should verify any request through official channels.

For organizations, the incident underlines the importance of phishing-resistant MFA such as FIDO2 security keys for SSO platforms, strict session and device policies on identity providers, monitoring of anomalous Okta sign-ins, and contractual requirements for third-party processors to report security incidents promptly.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.