started · updated
Automotive company fined 500,000 TL following ransomware attack
The Personal Data Protection Authority (KVKK) has imposed an administrative fine of 500,000 Turkish Lira on an automotive security and electronic systems manufacturer following a ransomware attack. The breach resulted in the encryption of files on the company's servers and unauthorized access to personal data, some of which was subsequently published online by the attackers.
The affected data includes identity and contact information for customers, supplier representatives, and current and former employees, as well as certain health data and permission records. Investigations suggest the attack may have originated from the compromised user account of a service provider used for the company's human resources software.
In its decision, the KVKK concluded that the company failed to implement necessary technical and administrative measures to ensure data security. Specific shortcomings cited include a failure to regularly monitor information systems, an inability to detect unusual network activity in a timely manner, and insufficient protection against malicious software.