KVKK Investigates Major Data Breach at Nesine Platform

The Personal Data Protection Authority (KVKK) has officially announced a significant data breach involving D Elektronik Şans Oyunları ve Yayıncılık A.Ş., which operates the popular betting platform Nesine. The incident, which came to light following severe system disruptions on September 30, 2026, originated from a sophisticated cyberattack targeting the third-party call center infrastructure utilized by the company. Attackers successfully encrypted sensitive data, rendering it inaccessible to the service provider. Upon discovering the breach, Nesine immediately initiated legal protocols, notified the KVKK, and deployed specialized technical teams to conduct an exhaustive forensic investigation to assess the full extent of the compromised user information.
- A cyberattack on the third-party call center infrastructure resulted in the encryption of sensitive user data.
- Compromised information likely includes voice recordings, phone numbers, and personal identifiers shared during calls.
- Forensic experts are currently determining whether unauthorized parties successfully exfiltrated the encrypted data.
- Nesine has implemented critical security patches to address vulnerabilities within the affected service provider systems.
The Scope of the Data Breach is Being Determined
Initial forensic analysis indicates that there is currently no concrete evidence suggesting that sensitive data was exfiltrated from the internal systems. However, given the shared nature of the infrastructure and the duration of the unauthorized access, security experts cannot entirely rule out the possibility of data theft. The notification submitted to the KVKK highlights that the breach specifically impacts customers who interacted with the company through its call center services. This includes both existing members who initiated or received calls and potential customers who provided information while inquiring about registration processes.
Forensic Investigations are Continuing Proactively
The company confirmed that various categories of data were affected, including call audio recordings and detailed call logs such as timestamps, call durations, and associated phone numbers. Management at Nesine has emphasized that technical teams are working on a 24/7 basis to restore system integrity and provide clarity on the impact of this incident. The primary objective of these ongoing forensic efforts is to establish whether any personal identity information was compromised. The KVKK continues to monitor the situation closely, ensuring that the company adheres to all regulatory requirements during this recovery phase.
Security Measures are Being Revised Thoroughly
This incident underscores the critical necessity for companies within the financial and gaming sectors to maintain rigorous oversight of third-party vendors. Nesine has announced that it has applied necessary security patches to its partner’s infrastructure and is currently overhauling its systems to prevent future recurrences of such vulnerabilities. The KVKK has issued a stern reminder to all data controllers regarding their legal obligation to audit the security practices of the entities they work with. The authority stresses that robust administrative and technical safeguards must be mandatory to protect user privacy against evolving cyber threats.
How do you feel about the security measures currently implemented by digital platforms to protect your personal information? We invite you to share your thoughts and concerns regarding this incident in the comments section below.
Your comment has been submitted,
it will be published after approval.