Turkish online retailer Ecenin Butiği reports breach affecting 353,811 customers
Turkey's data protection authority KVKK says a security incident at the e-commerce provider of Efece Ayakkabıcılık exposed names, contact details and hashed passwords of 353,811 people.
At a glance
- KVKK published the notification on September 30, 2026, under Article 12(5) of Law No. 6698.
- The incident occurred in the systems of the company's e-commerce infrastructure provider.
- Names, phone numbers, email and postal addresses and hashed passwords were affected.
- 353,811 customers and potential customers are affected.
Efece Ayakkabıcılık Mağazacılık Sanayi ve Dış Ticaret Limited Şirketi, which operates the online store eceninbutigi.com, has reported a personal data breach affecting 353,811 people, according to a public notice from Turkey's Personal Data Protection Authority (KVKK). KVKK is the regulator that enforces Turkey's data protection law, and it published the notice on September 30, 2026, under Article 12(5) of Law No. 6698, which requires data controllers to notify the authority and affected individuals when personal data is unlawfully obtained by others.
What happened
According to KVKK's announcement, the breach resulted from an information security incident in the systems of the service provider that runs the company's e-commerce infrastructure. The notice does not name the provider and does not give the dates on which the breach began or was detected. It also does not describe how the attackers gained access to the provider's systems.
KVKK published the notice under Board Decision No. 2026/2137, dated September 30, 2026. The same decision number appears on several other breach notices published that day by Turkish online retailers, some of which also cite incidents at e-commerce or data processor systems; KVKK does not say whether these incidents are connected.
Who is affected
KVKK says 353,811 people are affected, all in the customer and potential customer category. The exposed data categories are:
- Name and surname
- Phone number
- Email address
- Postal address
- Password, stored in hashed form
The notice does not mention payment card data among the affected categories.
What to do
According to KVKK, affected individuals can get information about the breach through the company's email address and phone number. Customers who reused their eceninbutigi.com password on other services should change it there, since hashed passwords can sometimes be cracked offline if weak. Because names, phone numbers and addresses were exposed together, affected customers should also be alert to phishing emails, text messages and calls that cite past orders or impersonate the retailer or cargo companies, and should avoid sharing verification codes or payment details in response to unsolicited messages.
For businesses, the case is another reminder that breaches at third-party e-commerce platforms remain the controller's legal responsibility under Turkish law, making vendor security assessments and contractual breach notification terms essential.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Efece Ayakkabıcılık Mağazacılık Sanayi ve Dış Ticaret Limited Şirketi — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



