Turkish restaurant chain Baydöner suffered a data breach that exposed customer information and was later advertised on a public hacking forum. Reporting on the incident said the breach affected up to 3.7 million customer records, while breach-tracking data identified more than 1.2 million unique email addresses in the exposed dataset.
The compromised information included names, email addresses, phone numbers, cities of residence, and plaintext passwords. A smaller subset of records also contained Turkish national ID numbers and dates of birth. Baydöner said in its disclosure notice that payment and financial data were not impacted by the incident.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned cataloged the Baydöner breach and summarized the exposed data types and scale of the incident. Its entry noted more than 1.2 million unique email addresses in the exposed dataset.
In March 2026, Turkish restaurant chain Baydöner experienced a data breach affecting customer data. Baydöner later stated that payment and financial information was not impacted.
Details of the Baydöner breach were publicly posted on a hacking forum, leading to reporting that millions of customer records were exposed. The leaked data included over 1.2 million unique email addresses along with names, phone numbers, cities, plaintext passwords, and for some records Turkish national ID numbers and dates of birth.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.