started · updated
Hyundai Motor Turkey data breach affects up to 422 people
A SQL injection vulnerability on Hyundai Motor Turkey’s website was exploited on 1 August 2026, allowing attackers to access internal personnel records. Hyundai Group’s Security Operation Center detected the intrusion and, together with data processor Baltaş Eksen Seçme Değerlendirme Eğitim ve Org. Tic. A.Ş., launched a detailed investigation on 3 August.
The Personal Data Protection Authority (KVKK) announced the breach on 5 August, stating that up to 422 individuals – current employees and job applicants – may have had their personal data exposed. Leaked information includes names, e‑mail addresses, usernames, passwords, job titles and results from Hogan/BEYT personality assessments. No customer data was reported to be compromised. KVKK’s inquiry is ongoing and no administrative fine has been issued yet.
Entities
Baltaş Eksen Seçme Değerlendirme Eğitim ve Org. Tic. A.Ş. · Hyundai Motor Turkey · KVKK (Personal Data Protection Authority of Turkey)