Şimşek Pharmacy
Incident posture
Linked entities
- Victim
- Şimşek Pharmacy
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A Turkish pharmacy suffered a data breach caused by the misconduct of a former employee, who obtained patient identification numbers and transferred them to another pharmacy without the patients' knowledge in order to supply drugs from other pharmacies. The Turkish data protection authority (KVKK) disclosed the incident, noting that the unauthorized activity had been ongoing for an extended period. The breach exposed personal data including ID numbers, telephone numbers, and special category health data, affecting the pharmacy's patients.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 18 August 2020, the Turkish data protection authority, known as KVKK, publicly announced a personal data breach involving Rezzan Günday, who operates under the business name Şimşek Pharmacy. The disclosure followed an internal investigation and regulatory review, and it represented one of the official breach notifications issued by the KVKK during that period. According to the authority, the breach stemmed from the misconduct of a former employee of the pharmacy, who had continued to misuse internal records even after the employment relationship had ended. The announcement detailed both the nature of the unauthorized activity and the categories of personal data that had been exposed, underscoring the regulatory significance of the incident for healthcare providers handling sensitive patient information.
The unauthorized conduct reportedly began in October 2019 and continued until it was eventually identified. During that period, the former employee obtained the national identification numbers of patients associated with Şimşek Pharmacy and transferred them to another pharmacy without the knowledge or consent of the affected individuals. The apparent motivation behind this activity was to facilitate the supply of medications from the receiving pharmacy, suggesting that the data transfer was intended to enable that entity to process prescriptions or dispense drugs on behalf of the patients whose identification details had been taken. In addition to identification numbers, the breach also involved the exposure of telephone numbers and special category health data, the latter of which is considered particularly sensitive under data protection regulations due to its capacity to reveal information about an individual's medical conditions, treatments, or prescriptions. The KVKK's communication emphasized that the violation had persisted for several months before being detected, indicating that the misuse of patient data had gone unnoticed by the pharmacy for an extended period.
The regulatory response from the KVKK consisted of formally acknowledging the breach through its public announcement mechanism, which serves to inform both the affected data subjects and the broader public about incidents involving personal data. By issuing this notification, the authority confirmed that it had reviewed the circumstances of the incident and determined that the criteria for a reportable event had been satisfied. The announcement did not specify any immediate sanctions, fines, or remedial orders directed at Şimşek Pharmacy, but it placed the incident on record as an official data breach under Turkish law. The disclosure also served to highlight the responsibilities of data controllers in the healthcare sector, particularly pharmacies that routinely handle both identification data and health data as part of their daily operations.
The scope of the incident, as confirmed by the KVKK, encompassed three categories of personal data. First, the national identification numbers of patients were taken, which in Turkey serve as a primary identifier linked to a wide range of public and private services. Second, telephone numbers were included among the compromised data, raising potential concerns about unsolicited contact or further attempts at social engineering. Third, and most significantly, special category health data was affected, which carries heightened protections because of its intimate connection to an individual's physical and mental wellbeing. The combination of these data types amplified the potential consequences for the affected patients, as the misuse of identification numbers together with health information could enable identity-related fraud, unauthorized access to medical services, or other forms of exploitation. The transfer of these data elements to a separate pharmacy entity indicated that the breach was not merely an incidental disclosure but a deliberate act of data extraction aimed at enabling unauthorized transactions on behalf of the affected patients.
Detection of the misconduct appears to have occurred after the former employee's departure from Şimşek Pharmacy, suggesting that the unauthorized access and transfer of patient data continued beyond the formal end of the employment relationship. Once the breach was identified, the matter was referred to the KVKK, which then carried out its review and issued the public notification on 18 August 2020. The announcement did not provide specific details about how the breach was technically discovered, the volume of affected patients, or the specific measures taken by the pharmacy to contain the incident, as those particulars were not included in the source reporting. Nevertheless, the formal acknowledgment by the regulatory authority confirms that the incident was treated as a qualifying data breach under Turkish data protection legislation and that it met the threshold for public disclosure.
The broader implications of the incident centered on the vulnerability of healthcare-related data when handled by personnel with internal access privileges. Pharmacies, like other healthcare providers, routinely process sensitive personal data as part of their core functions, and the Şimşek Pharmacy case illustrated how that data could be misused for unauthorized commercial purposes when internal controls were insufficient to prevent post-employment access. The breach also underscored the importance of monitoring former employees' access to systems and records, as well as the need for technical and organizational measures that limit the ability of any single individual to extract and transfer patient data without authorization. While the source material does not detail specific containment actions, remedial steps, or communications sent directly to affected patients, the KVKK's public announcement served as the primary documented response to the incident and provided a factual record of its occurrence, scope, and regulatory handling.
Sources
Sources available to members: 1 source.