Turkish shoe brand Bambi reports breach affecting about 323,000 customers
KVKK says unauthorized access to a data processor's server exposed names, phone numbers, emails and MD5-hashed login credentials of about 323,052 Bambi customers.
At a glance
- KVKK published the notice on September 30, 2026, under Article 12(5) of Law No. 6698.
- The breach involved unauthorized access to a server in the systems of a data processor.
- Bambi learned of the incident on September 21, 2026, when the processor notified it.
- Names, phone numbers, emails and MD5-hashed login credentials of about 323,052 people were affected.
Bambi Deri Mamülleri A.Ş., the company behind Turkish shoe and bag brand Bambi and the online store bambiayakkabi.com.tr, has reported a personal data breach affecting approximately 323,052 customers, according to a public notice from Turkey's Personal Data Protection Authority (KVKK). KVKK, the country's data protection regulator, published the notice on September 30, 2026, under Article 12(5) of Law No. 6698, which obliges data controllers to notify affected individuals and the authority when personal data is unlawfully obtained.
What happened
According to KVKK, the breach occurred after unauthorized access was gained to a server, located in the systems of a data processor, that held the company's data. Bambi learned of the incident on September 21, 2026, when the data processor notified it. The notice does not name the processor, does not say when the unauthorized access began and does not explain how the server was accessed. KVKK notes that its examination of the incident is ongoing.
The notice was published under Board Decision No. 2026/2137, dated September 30, 2026, the same decision number cited in several other e-commerce breach notices published that day. KVKK has not said whether the incidents are related.
Who is affected
KVKK says the breach affects approximately 323,052 people in the customer and potential customer category. The affected data categories are:
- Name and surname
- Phone number
- Email address
- User login credentials hashed with MD5
MD5 is a fast, outdated hashing algorithm that is no longer considered suitable for storing passwords, because weak or common passwords protected with it can often be recovered with offline cracking tools. The notice does not list payment card information among the affected data.
What to do
Customers who have an account on bambiayakkabi.com.tr should change their password there and on any other service where they used the same password. Because names, phone numbers and email addresses were exposed together, they should also watch for phishing messages that impersonate the brand, offer fake discounts or refunds, or ask for verification codes and card details.
For companies, the incident highlights two recurring problems seen in recent Turkish breach notices: dependence on third-party processors whose security the controller does not directly manage, and legacy password storage. Replacing MD5 with a modern, salted password hashing algorithm and reviewing processor contracts and access controls are practical steps to reduce the impact of similar incidents.
Sources
- Kamuoyu Duyurusu (Veri İhlali Bildirimi) – Bambi Deri Mamülleri A.Ş. — Kişisel Verileri Koruma Kurumu (KVKK)
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



