Jump to

Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect?

Ransomware and Unauthorised Access Decisions — Vircon Legal

The five decisions in this instalment concern incidents in which servers were compromised and encrypted with ransomware. What they have in common is that the reasoning behind the fine rests less on the breach itself than on the measures not taken beforehand: penetration tests never commissioned, test findings left unresolved, predictable passwords and credentials saved in browsers.

This article is part 1 of a ten-part series examining, section by section, the 47 decision summaries published by the Turkish Personal Data Protection Board on 10 August 2026. For the overall assessment of the set, see our review of all 47 decisions.

Every decision follows the same structure: the facts, the Board’s assessment, why the decision matters, and the practical implications for organisations. The “Vircon Legal assessment” headings contain our own commentary apart from the fine amount; they are not part of the text of the decision.

Decisions covered in this article

Ransomware and Unauthorised Access: Which Technical Measures Does the Board Expect? — the decisions reviewed in this instalment.
Decision Date Subject Outcome
2024/1898 7 November 2024 Assessed the Role of Generic and Predictable Passwords in a Ransomware Attack TRY 350,000
2024/1899 7 November 2024 Imposed a High Fine on Account of Systemic Vulnerabilities Despite a Relatively Mild Data Category TRY 700,000
2023/1017 8 June 2023 Treated the Fact That No Penetration Test Had Ever Been Commissioned as the Decisive Factor in Its Decision TRY 1,500,000
2022/1375 23 December 2022 Treated Unremediated Penetration Test Findings as an Aggravating Factor TRY 1,000,000
2024/133 25 January 2024 Showed That the Absence of Cost-Free Security Measures Can Also Lead to a High Fine TRY 250,000

The Board Assessed the Role of Generic and Predictable Passwords in a Ransomware Attack

Decision no: 2024/1898  ·  Date: 7 November 2024  ·  Outcome: TRY 350,000

The facts

In the incident under examination, the servers of a pharmaceutical and healthcare products company were infiltrated and the servers were encrypted with ransomware and thereby rendered inaccessible. The method by which the attackers first infiltrated the company’s system could not be established with certainty; the possible access methods considered included a brute-force attack against the remote desktop protocol (RDP) or a password-guessing attack against the database server.

520 people were affected by the incident; of these, 196 are current employees, 303 are former employees and 17 have the status of customer or business partner. The affected data include identity, contact, personnel file and customer transaction information. The digital forensic examination commissioned by the company after the cyber incident revealed that the passwords of certain platform accounts consisted of easily predictable elements such as a name, a city and a year.

What the Board held

The Board found that the network security, server security, user security and testing/audit measures recommended in the Cyber Incident Response Report had not been sufficiently implemented. The fact that the initial access method could not be determined with certainty (the possibilities of an RDP brute-force attack or a database password-guessing attempt) was considered an indication of general carelessness in the monitoring of personal data security.

Why this decision matters

The decision is instructive in that it sets out the use of weak/generic passwords through concrete examples (name + city + year); it also shows that whether the recommendations of a technical report prepared after a breach have actually been implemented is likewise part of the Board’s review.

What organisations should watch for

  • Password policies are required to include complexity rules that prevent predictable patterns such as a name, a city or a year.
  • It is recommended that the recommendations in technical/forensic examination reports prepared after a cyber incident are not merely reported but that their actual implementation is documented.
  • It is recommended that remote access protocols such as RDP (remote desktop) be supported by additional protection against brute-force attacks (IP restriction, MFA).

Vircon Legal assessment

An administrative fine of TRY 350,000 was imposed. It is considered that the decision offers data controllers in the healthcare and pharmaceutical sector a concrete checklist in terms of both password hygiene and the follow-up of post-incident reports.

The Board Imposed a High Fine on Account of Systemic Vulnerabilities Despite a Relatively Mild Data Category

Decision no: 2024/1899  ·  Date: 7 November 2024  ·  Outcome: TRY 700,000

The facts

In the case at hand, an account used for marketing purposes belonging to a company providing corporate support services to group companies in Europe was compromised; the examination established that this account had been accessed via an IP address that had been blacklisted as suspicious from a security perspective. Using this access, the attackers also obtained unauthorised access to certain file folders of the company that had been misconfigured as “public”, and additionally to an FTP server.

70,000 people were affected by the incident and the affected data remained limited to name and surname, e-mail, contact and address information; no special categories of personal data or credit card information were affected. When the breach began could not be precisely determined, owing to the inadequacy of the company’s log records.

What the Board held

The Board stated that, although the affected data category was relatively mild, the systemic vulnerabilities (folders configured as publicly accessible, the failure to block access from a blacklisted IP address) and the fact that the start date of the breach could not be determined raised the amount of the fine. The Board also considered the fact that the log retention period had been increased from 90 days to 1 year after the breach to be an aggravating factor, since this indirectly demonstrates that the log retention period before the breach was inadequate.

Why this decision matters

The decision shows that a “mild” data category does not, on its own, mean a guarantee of a low fine; systemic vulnerabilities and detection/monitoring inadequacies affect the amount of the fine in a decisive manner. The discussion of the log retention period in concrete terms (90 days → 1 year) is a rarely encountered and directly applicable technical detail.

What organisations should watch for

  • It is recommended that “public” configurations in cloud storage and file sharing systems be scanned regularly and that unnecessary open access be closed.
  • Retaining log records for at least one year is recommended for the purposes of post-breach forensic analysis; this period is required to have been documented before the breach.
  • It is recommended that a threat intelligence/firewall mechanism that blocks access coming from blacklisted IP addresses be in place.

Vircon Legal assessment

An administrative fine of TRY 700,000 was imposed. It is considered that the decision is important in showing that, even where the data category appears mild, systemic and recurring configuration errors (such as a publicly accessible folder, see 2022/711, 2023/1796) may lead to a high fine.

The Board Treated the Fact That No Penetration Test Had Ever Been Commissioned as the Decisive Factor in Its Decision

Decision no: 2023/1017  ·  Date: 8 June 2023  ·  Outcome: TRY 1,500,000

The facts

In the case at hand, a digital gaming and entertainment platform operating on a global scale and having a user base of over 69 million worldwide was subjected on two separate occasions to a cyberattack arising from the same security vulnerability. The attack was not detected by the platform’s own security systems; it came to light through a post made by the attackers on a forum site.

90,182 people in Türkiye were affected by the attack, and children are among the affected users. The fact that the same security vulnerability was exploited a second time shows that the platform did not close the vulnerability after the first attack, or that its attempt to close it was insufficient.

What the Board held

The decisive factor in the Board’s assessment is that the company had never commissioned a penetration test to date. In addition, it was established that security monitoring and log tracking were not carried out, that patch management was initiated after the breach, and that the same vulnerability was allowed to be exploited a second time.

The fact that data belonging to children was also within the affected scope was taken into account as a separate factor aggravating the Board’s risk assessment.

Why this decision matters

This decision stands out in that it is the subject of the highest single administrative fine among the 47 decisions examined. The characterisation of the complete failure to commission a penetration test as, on its own, a decisive aggravating factor turns the penetration test into a periodic compliance obligation.

The exploitation of the same vulnerability a second time was considered a concrete indication that no lessons had been drawn from the earlier incident, and this repetition was decisive in the size of the fine.

What organisations should watch for

  • It is recommended that a penetration test be commissioned at regular intervals (at least once a year), irrespective of the company’s scale, and that its results be documented.
  • Security monitoring and log tracking systems are required to have been established in advance as a preventive measure, and not after a breach.
  • It is recommended that the closure of a security vulnerability be confirmed by verifying that a similar attack is not repeated.

Vircon Legal assessment

An administrative fine of TRY 1,500,000 was imposed. Having regard to the size of the fine and the impact on children’s data, it is considered that this decision will be frequently cited, particularly for platforms operating on an international scale.

The Board Treated Unremediated Penetration Test Findings as an Aggravating Factor

Decision no: 2022/1375  ·  Date: 23 December 2022  ·  Outcome: TRY 1,000,000

The facts

In the incident under examination, a ransomware attack was carried out against the information systems of an industrial company; the attackers infiltrated the systems, encrypted the databases and demanded a ransom in return for the data. 4,885 people were affected by the attack, and the affected data categories include both general and sensitive data such as identity information, address, IBAN, telephone number, photograph, passport information and blood type.

The company notified the Board of the breach; however, during the examination it emerged that the notification had been made 23 days after the incident (with a delay of 20 days), exceeding the period prescribed by law.

What the Board held

In its examination, the Board identified numerous deficiencies in technical and administrative measures, such as a weak password policy, the absence of network segmentation, patch management not being carried out regularly, faulty network configuration and the absence of protection against brute-force attacks. In addition, it was found that the vulnerabilities identified in a penetration test previously commissioned by the company had not been closed.

The Board also considered the fact that the breach had been notified after the period prescribed by law had been exceeded (with a delay of 20 days, 23 days in total) to be a separate violation.

Why this decision matters

This decision is one of those that set out in the most detailed manner the catalogue of technical and administrative measures the Board expects of a data controller; the item-by-item reference in the reasoning to the Personal Data Security Guide makes the decision directly usable in practice as a checklist.

It was also clearly established that having commissioned a penetration test is not sufficient on its own, and that the vulnerabilities identified in the test are also expected to be actually closed.

What organisations should watch for

  • It is required that penetration test results are not merely reported, but that the closure of the identified vulnerabilities is separately documented.
  • It is recommended that basic measures such as password policy, network segmentation, patch management and protection against brute-force attacks be audited periodically.
  • A predefined internal process must be in place so that breach notifications can be made within the period prescribed by law (72 hours).

Vircon Legal assessment

An administrative fine of TRY 800,000 for the security deficiencies and a further TRY 200,000 for the notification delay, amounting to a total of TRY 1,000,000 (the statutory upper limit), was imposed. It is considered that the decision constitutes a multi-faceted reference point in terms of both the catalogue of measures and discipline as to the notification period.

The Board Showed That the Absence of Cost-Free Security Measures Can Also Lead to a High Fine

Decision no: 2024/133  ·  Date: 25 January 2024  ·  Outcome: TRY 250,000

The facts

In the incident giving rise to the application, a food ordering and courier delivery platform was subjected to a composite cyberattack involving more than one element: the attackers first launched a DDoS (distributed denial of service) attack, then accessed the platform’s database, deleted the data and demanded a ransom from the company. The identity, contact and address information of 1,362 users was affected by the attack.

The technical examination carried out revealed that the attack had been performed not by a sophisticated method, but through the exploitation of basic-level security vulnerabilities.

What the Board held

Among the deficiencies identified by the Board are the fact that the administration panel password had been saved in the browser and that phpMyAdmin access had been left open to everyone without any IP restriction.

In its decision the Board emphasised in particular that security measures do not always require high cost; that even free arrangements such as not storing passwords in the browser or limiting access by IP constitute a basic security hygiene.

Why this decision matters

This decision is particularly instructive for small and medium-sized data controllers: the Board has clearly established that a “resource constraint” defence does not constitute a justification for neglecting basic security hygiene. The fact that the amount of the fine remains relatively high in relation to the size of the company reinforces this message.

What organisations should watch for

  • It is recommended that access to administration panels and database management interfaces (phpMyAdmin and the like) be limited by IP restriction or VPN.
  • It is recommended that a policy be established for employees against saving corporate account credentials in the browser and that this setting also be restricted technically.
  • It is recommended that whether such low-cost measures have been implemented be audited regularly by means of a minimum checklist, irrespective of the size of the budget.

Vircon Legal assessment

An administrative fine of TRY 250,000 was imposed. It is considered that the decision constitutes a directly applicable and low-cost compliance checklist for SME-scale data controllers with resource constraints.

Other parts of this series

The starting point of the series is our overall review: The 47 decision summaries published by the KVKK — a consolidated review. A Turkish version of this article is also available: Fidye Yazılımı ve Yetkisiz Erişim: Kurul Hangi Teknik Tedbirleri Arıyor?.

For the compliance programme as a whole, see our KVKK and GDPR compliance page, and for the decisions we cover as they are published, KVKK Tracker.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 14 August 2026 · last updated: 13 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.