
Dodo Brands breach: financial data listed in KVKK notice
Turkey’s KVKK published a notice about Dodo Brands’ report of unauthorized access. Customers and employees are the affected groups; the number of people affected is still being determined.
The Turkish Personal Data Protection Board decided on 7 October 2026 to publish Dodo Brands International FZCO’s breach notification on the KVKK website. The matter is still under review (KVKK notice).
What was disclosed?
According to the company’s report to KVKK, unauthorized access to systems holding its data caused the breach. It was detected on 28 September 2026. The categories reported as affected are identity, contact, location, customer transaction and financial information. The notice does not specify the fields involved. It does not confirm that payment card details or passwords were exposed, or say that every affected person had data in all five categories.
Customers and employees are the affected groups; work to determine how many people were affected is still under way. The notice does not say which countries those people are in. A 2023 industry report said Dodo Pizza had entered the Turkish market, but that does not establish that people in Turkey were affected by this breach (Horeca Mailing).
KVKK’s website post is a public announcement. The company’s report says affected individuals will be informed through the Dodo Pizza mobile app; the notice does not say this has happened.
What this means for LeakData readers
Dodo Pizza customers and employees in Turkey can watch for the planned notification if they have access to the app. Those without access can read KVKK’s public announcement for general details, but it cannot establish whether they personally were affected. Given the identity and contact categories, watch for suspicious messages. Because financial information was reported, review your financial account activity. You can check whether your email address or password appears in exposed datasets with LeakData; neither a match nor the absence of one establishes whether this breach affected you. If you confirm that a password is exposed, change it on every account where you used it.


