Spirit Cultural Exchange breach exposes passports and criminal records of 7,591 applicants
KVKK says an unauthorized party used automated requests against unauthenticated URLs to download application documents, including passport details and criminal records, of 7,591 people.
At a glance
- KVKK published the notice on September 30, 2026, under Article 12(5) of Law No. 6698.
- Application document URLs lacked authentication, letting a third party collect files with automated requests.
- The breach began on September 4 and was detected on September 9, 2026.
- Passport details, criminal records, diplomas, references and photos of 7,591 customers were affected.
Spirit Cultural Exchange, Inc., a cultural exchange program provider, has reported a data breach that exposed sensitive application documents of 7,591 people, according to a public notice from Turkey's Personal Data Protection Authority (KVKK). KVKK, the country's data protection regulator, published the notice on September 30, 2026, under Article 12(5) of Law No. 6698, which requires data controllers to inform affected people and the authority when personal data is obtained unlawfully. The breach stands out because of the sensitivity of the documents involved, which include passport details and criminal record documents.
What happened
According to KVKK, a security weakness in the URLs of the company's application submission system meant that no authentication was performed when stored documents were requested. An unauthorized third party exploited this by sending automated requests and collecting the stored application documents. The notice says the breach began on September 4, 2026, and was detected on September 9, 2026.
This type of flaw, often described as an insecure direct object reference or broken access control, allows anyone who can guess or enumerate a file address to download it without logging in. KVKK published the notice under Board Decision No. 2026/2140, dated September 30, 2026.
Who is affected
KVKK says 7,591 people in the customer category are affected. The exposed data covers a wide range of categories:
- Identity information: name, date of birth, signature, passport details and financial guarantor details
- Legal records: criminal record and security investigation documents
- Education records: diplomas, transcripts and equivalency certificates
- Professional experience: employment and reference letters
- Visual records: photographs
The combination of passport data, signatures and photographs is particularly valuable to fraudsters, as it can be used for identity fraud, fake applications or highly targeted phishing.
What to do
Affected individuals can request information from the company at [email protected], according to KVKK. Applicants who used the service should be wary of messages that reference their application, visa or program status and request payments or additional documents, and should consider contacting the authority that issued their passport for guidance if they suspect misuse.
For organizations that collect documents online, the incident underlines basic controls: every file request should be checked against an authenticated session and the requester's permissions, file identifiers should not be predictable, and rate limiting and monitoring should flag bulk automated downloads.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Spirit Cultural Exchange, Inc. — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



