Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [BUSINESS]
2 clusters · 4 sources · 10 days · First seen · Last updated
KVKK enforcement following industrial ransomware attacks
Overview
The Turkish Personal Data Protection Authority (KVKK) has issued administrative fines to industrial companies following significant ransomware attacks and subsequent data breaches.
In the first instance, an automotive security and electronic systems manufacturer was fined 500,000 Turkish Lira. The breach, potentially originating from a compromised service provider account, resulted in the encryption of server files and the online publication of identity, contact, and health data belonging to customers, suppliers, and employees. The KVKK cited failures in monitoring information systems and detecting unusual network activity.
Subsequently, a global industrial company received a 1 million lira fine after ransomware spread across 797 servers. The attack was triggered by an employee in the United States downloading a program from the internet, compromising the data of 4,885 individuals, including passport numbers and IBAN details. The KVKK noted that the company had failed to resolve previously identified vulnerabilities, maintained weak password policies, and failed to report the breach within the required timeframe.
Entities
Timeline
-
14 days ago
[TECHNOLOGY] 4 sourcesKVKK fines global company 1 million lira after data breachTurkey’s KVKK fined a global industrial firm 1 million lira after a ransomware attack compromised the personal data of 4,885 people due to critical security vulnerabilities and delayed reporting.
-
24 days ago
[BUSINESS] 2 sourcesAutomotive company fined 500,000 TL following ransomware attackTurkey's KVKK fined an automotive electronics manufacturer 500,000 TL after a ransomware attack led to the theft and online publication of customer and employee personal data.
Sources
ekonomist.com.tr · gzt.com · merhabahaber.com · sondakika.com