Ransomware hits Yıldız Technical University, data of up to 144,500 people at risk
Turkey's data protection authority says a ransomware attack on Yıldız Technical University's virtualization infrastructure may affect about 140,000 students and 4,500 staff.
At a glance
- The attack hit the university's virtualization infrastructure and the servers running on it on October 1, 2026.
- About 140,000 students and 4,500 staff may be affected; the number of visitors has not been determined.
- The categories of personal data affected have not yet been determined, according to the notice.
- KVKK published the notice on October 7 under Article 12/5 of Law No. 6698.
Yıldız Technical University (YTÜ), one of Istanbul's major public universities, has reported a ransomware attack that may have affected personal data of roughly 140,000 students and 4,500 staff members, according to a notice published on October 7 by KVKK, Turkey's Personal Data Protection Authority. The breach began on October 1, 2026, and was detected the same day.
What happened
According to KVKK's announcement, the university's virtualization infrastructure and the servers running on it were affected by a ransomware attack. The notice does not say how the attackers gained access, which ransomware strain was used, whether data was exfiltrated or whether a ransom was demanded. No group's claim of responsibility is mentioned.
The Personal Data Protection Board decided on October 7, 2026, with decision number 2026/2203, to publish the breach notification on the authority's website. Such notices are published under Article 12(5) of Law No. 6698 on the Protection of Personal Data, which requires data controllers to notify both the authority and affected individuals of breaches.
Who is affected
The notice lists students, staff and visitors as the affected groups. Based on current records, about 140,000 students and 4,500 employees may be affected, while the number of visitors has not yet been determined.
KVKK's notice states that the categories of personal data involved have not yet been identified, and that the investigation is ongoing. The announcement does not list specific remediation measures taken by the university.
What to do
Until the scope is clarified, current and former students and staff should be cautious about emails, text messages or calls that reference the incident or appear to come from the university and ask for passwords, identity numbers or payment. They should change passwords used for university systems, especially if reused elsewhere, enable multi-factor authentication where available and follow official announcements from the university.
For institutions, attacks on virtualization platforms are particularly damaging because a single compromise can encrypt many servers at once. Isolating hypervisor management interfaces, enforcing multi-factor authentication for administrators, patching virtualization software promptly and keeping offline, tested backups are key defenses.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Yıldız Teknik Üniversitesi — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



