Unigen data breach exposes contact details and password values of 27,163 customers
Turkey's data protection authority says a flaw in third-party software libraries let attackers reach Unigen servers holding customer data, including stored password values.
At a glance
- A vulnerability in third-party software libraries enabled unauthorized access to Unigen's servers
- The breach was detected on September 24, 2026, after being reported by a data processor
- 27,163 end customers and 11 admin panel accounts are affected
- Exposed data includes names, addresses, emails, phone numbers and stored password values
Unigen Yapı Malzemeleri AŞ, a Turkish building materials company, suffered a data breach affecting 27,163 customers after a vulnerability in third-party software libraries allowed unauthorized access to its servers, according to a public notice published on September 30, 2026 by KVKK, Turkey's Personal Data Protection Authority. The notice was published under Article 12(5) of Personal Data Protection Law No. 6698, which requires data controllers to report breaches and allows the authority to announce them publicly.
What happened
According to KVKK's notice, a security vulnerability in third-party software libraries enabled unauthorized access to Unigen servers containing customer data. The breach was detected on September 24, 2026, after it was reported by the company's data processor, the authority said. The notice does not state when the unauthorized access began or which software component was involved.
The Personal Data Protection Board approved the public announcement with its decision numbered 2026/2137, dated September 30, 2026, according to KVKK.
What data was exposed
KVKK's notice lists the following affected data categories:
- Customer first and last names
- Postal addresses
- Email addresses
- Phone numbers
- Stored password values
- Admin panel user accounts and credentials
The notice does not specify whether stored passwords were hashed or in what format they were kept.
Who is affected
According to the authority, 27,163 end customers and 11 admin panel accounts were affected. The affected groups are listed as employees, subscribers/members and customers or potential customers. KVKK's notice includes an email address and phone number that affected individuals can use to contact the company.
What to do
Customers who have an account with Unigen should change their password and, if the same password is used on other services, change it there as well. Because names, addresses, email addresses and phone numbers were exposed together, affected people should be wary of phishing emails, text messages and calls that appear to come from the company or from delivery services. Organizations running e-commerce or customer portals should keep an inventory of third-party libraries, track security advisories for them and apply updates promptly; storing passwords only with strong, salted hashing limits the damage when a database is accessed.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



