KVKK announced that there was a data breach on the PTT

Personal Data Protection Authority (KVKK) filed two different data breach notifications today. While the first of these notifications points to a tourism company, the other is directly PTTIt shows . KVKK constantly shares such information on its official website.

KVKK announced that there was a data breach at the PTT

The fact that an institution such as the PTT was included in a data breach notification was surprising. The following statements are included by KVKK in the violation notification published for the Post and Telegraph Organization Saving and Aid Fund:

As it is known, paragraph (5) of Article 12 of the Law on Protection of Personal Data No. 6698, titled “Obligations regarding data security”, states that “In case the processed personal data is obtained by others illegally, the data controller shall notify the relevant person and the Board as soon as possible. If necessary, the Board may announce this situation on its own website or by any other method it deems appropriate.” its ruling.

In summary, in the data breach notification submitted to the Board by the Post and Telegraph Organization Savings and Assistance Fund;

  • Unauthorized access to the system where members’ information is provided through malicious software,
  • It is claimed that personal data of PTT employees such as mother’s maiden name, skin serial number, 3.2 gb database backup and all files of the site were seized by unauthorized persons,
  • The violation occurred between 29.08.2022 and 30.08.2022 and it was detected on 30.08.2022,
  • The personal data affected by the violation is the information about identity and membership transactions,
  • Approximately 38,000 records were affected by the breach,
  • The work on the violation is ongoing.

information is included.

Although the investigation on the subject continues, with the Decision of the Personal Data Protection Board dated 01.09.2022 and numbered 2022/891, it was decided to announce the aforementioned data breach notification on the Institution’s website. It is announced to the public with respect.

European country banned Google for alleged data breach!

Google is awash with alleged data breaches. Denmark has banned Chromebook and Workspace, saying they leak data.

Another violation notice Byblos Alaçatı Tourism Investments Inc. made on behalf of KVKK The following statements were used in the official article shared by:

As it is known, paragraph (5) of Article 12 of the Law on Protection of Personal Data No. 6698, titled “Obligations regarding data security”, states that “In case the processed personal data is obtained by others illegally, the data controller shall notify the relevant person and the Board as soon as possible. If necessary, the Board may announce this situation on its own website or by any other method it deems appropriate.” its ruling.

Having the title of data controller, Biblos Alaçatı Turizm Yatırımları A.Ş. In summary, in the data breach notification submitted by the Board to the Board;

  • The source of the breach is ransomware attack and password attack,
  • The breach started on 19.08.2022, and the cyber attack was detected through the messages sent to the work phones of the data controller and the e-mails sent to the personnel on the same date,
  • Personal data categories affected by the breach are identity, communication, customer transaction, finance, marketing, visual and audio records,
  • The categories of sensitive personal data affected by the breach are health information and biometric data,
  • On the other hand, it is possible that personnel payroll records, guest data and financial data of the company are subject to breach through programs used in human resources, front office and finance departments,
  • The relevant person groups affected by the breach are employees, customers and potential customers,
  • The estimated number of people affected by the breach is 450, but the inventory work on the hacked programs and data continues,
  • It is not possible to notify due to the deletion of the data of the relevant persons as a result of the cyber attack.I

information is included. Although the investigation on the subject continues, with the Decision of the Personal Data Protection Board dated 01.09.2022 and numbered 2022/882, it was decided to announce the data breach notification on the website of the Authority. It is announced to the public with respect.

In order to inform the public periodically by KVKK such posts is being done. So what do you think about the data breach in the PTT institution? You can share your views with us in the comments section.

source site-28