Walke Sport reports breach at e-commerce provider affecting 3,642 customers
Turkey's data protection authority KVKK says a security incident at Walke's e-commerce infrastructure provider exposed customer names, emails, addresses and transaction data.
At a glance
- The incident occurred in the systems of Walke's e-commerce infrastructure service provider
- 3,642 users and subscribers/members are affected
- Exposed data: names, email addresses, postal addresses and customer transaction data
- KVKK published the notice on September 30, 2026 under Article 12(5) of Law No. 6698
Walke Spor Ürünleri Dış Ticaret A.Ş., the Turkish sporting goods retailer behind walkesport.com, has reported a data breach affecting 3,642 customers after a security incident in the systems of its e-commerce infrastructure provider, according to a public notice published on September 30, 2026 by KVKK, Turkey's Personal Data Protection Authority. The notice was published under Article 12(5) of Personal Data Protection Law No. 6698, which requires data controllers to report breaches and allows the authority to announce them publicly.
What happened
According to KVKK's notice, the breach stemmed from a security incident in the systems of the service provider that runs Walke's e-commerce infrastructure, rather than in Walke's own systems. The notice does not name the provider, describe how the attackers gained access, or say when the incident began or was detected.
What data was exposed
KVKK lists the following affected data categories:
- Identity data (first and last name)
- Contact data (email address and postal address)
- Customer transaction data
The notice does not mention payment card data, passwords or national identity numbers among the affected categories.
Who is affected
According to the authority, 3,642 people were affected. The affected groups are listed as users and subscribers/members of the online store. KVKK's notice directs affected individuals to the company's website and its general information email address for questions.
What to do
Customers of walkesport.com should be cautious of emails, text messages or calls that reference recent orders, returns or deliveries, since names, contact details and transaction information were exposed together and can make phishing messages more convincing. Customers should avoid clicking links in unexpected messages and should verify any request by contacting the company through its official website. Retailers that rely on outsourced e-commerce platforms should review their contracts and incident notification terms with providers, limit the personal data shared with them and monitor provider security advisories.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



