Cyber ​​Attack Statement by Arçelik – Webtekno

Turkey’s white goods giant Arçelik announced that unauthorized access was provided to the mobile application and website used within the company, and personal data had been seized.

Arçelik, one of Turkey’s largest white goods and technology companies, To the Personal Data Protection Authority (KVKK) announced that he had been hacked. The company explained how its systems were hacked and how many people’s data in total might have been compromised.

In the statement submitted to KVKK by Arçelik, it was reported that the people affected by the incident were limited to dealers and authorized service personnel. Estimated data breach 30 thousand 373 people were affected was clear.

Information provided by Arçelik about the hack:

The aforementioned data breach occurred on Arçelik’s in-house mobile application and website called “Bizbize”. Arçelik does not own the codes and ownership of the system in question, the party that processes the data expressed.

Attackers can access the platform’s admin panel. unauthorized access and collected personal data via an IP address appearing in Germany. The information obtained was shared as follows:

  • Name surname
  • Turkish Identity Number
  • Title
  • Date of birth
  • Gender
  • E-mail address
  • Phone number
  • User password
  • Registration and update date
  • Last login date
  • Account activity status
  • Device model, version, operating system, application version information, notification permission status
  • Points earning and spending information
  • Specialization, education, date of employment
  • Code, name and address of the dealer and store where the person works

Arçelik also shared a form for people affected by the violation to apply to the company.

Arçelik also shared a statement on the subject:

“It has become necessary to make a statement on the posts about accessing the personal data of some of our dealers and authorized service employees.

A cyber attack was carried out on an application used within our company. Access to our application originates from the system of a supplier serving many other companies and brands, and all necessary technical and legal measures have been taken. Protection of personal data and cyber security are among the top priorities of our company. The systems affected by the event do not include payment and financial information. Currently, there are no vulnerabilities related to access to personal data.”

Source :
https://www.kvkk.gov.tr/Icerik/7618/Kamuoyu-Duyurusu-Veri-Ihlali-Bildirimi-Arcelik-AS-


source site-37