Turkish retailer Deve Yükü reports breach affecting about 133,000 people
KVKK says unauthorized access to a server in a data processor's systems exposed contact details, login credentials and order data of about 133,031 Deve Yükü customers and members.
At a glance
- KVKK published the notice on September 30, 2026, under Article 12(5) of Law No. 6698.
- The breach stemmed from unauthorized access to a server in a data processor's systems.
- The company learned of it on September 24, 2026, after the processor notified it.
- Contact details, user and administrator login data, and order and delivery information were affected.
Deve Yükü Dayanıklı Tüketim Malları Limited Şirketi, which runs the online store deveyuku.com, has reported a personal data breach affecting approximately 133,031 people, according to a public notice from Turkey's Personal Data Protection Authority (KVKK). KVKK is Turkey's data protection regulator; it published the notice on September 30, 2026, under Article 12(5) of Law No. 6698, which requires data controllers to notify affected people and the authority when personal data is obtained unlawfully.
What happened
According to KVKK, the breach occurred when unauthorized access was gained to a server in the systems of a data processor that held the company's data. Deve Yükü detected the incident on September 24, 2026, after being notified by the data processor. The notice does not name the processor, does not say when the unauthorized access started and does not describe the technique used.
The notice was published under Board Decision No. 2026/2137, dated September 30, 2026. The same decision number appears in several other e-commerce breach notices that KVKK published the same day, some of which also point to incidents at processors or e-commerce infrastructure providers. KVKK has not said whether these cases are linked.
Who is affected
KVKK says approximately 133,031 people are affected, in the subscriber/member and customer/potential customer categories. The exposed data includes:
- Name and surname
- Phone number and email address
- Postal address
- User and administrator login information
- Order and delivery information
The notice does not say whether passwords were stored in hashed form, and it does not list payment card data among the affected categories.
What to do
According to KVKK, affected individuals can find information about the breach on the company's website, deveyuku.com. Customers should change their password on the site and on any other service where they reused it. The combination of addresses with order and delivery details makes convincing scams easier, so recipients should be wary of messages about delayed shipments, customs fees, refunds or order problems, and should verify such claims through official channels rather than links in messages.
Because administrator login information was also among the affected data, the incident is a reminder for online retailers to rotate administrative credentials after any processor-side incident, enforce multi-factor authentication on management panels and review access logs for unusual activity.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Deve Yükü Dayanıklı Tüketim Malları Limited Şirketi — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



