KVKK’s 500,000 TL Fine and Insider Theft for a Competitor

25.08.2026

Turkish Company Fined After Ransomware Exposed Employee Data

Turkey’s Personal Data Protection Authority, KVKK, fined a manufacturer of automotive safety and electronic systems 500,000 Turkish lira following a personal data breach linked to a ransomware attack. Habertürk reported the case citing Anadolu Agency.

The attack encrypted files in the company’s information systems and gave attackers unauthorized access to personal data, some of which was later published online.

The breach affected representatives of customers and suppliers, as well as current and former employees. Exposed information included identification and contact details, leave records, and certain health-related data. The company said it had notified affected individuals by email.

During the investigation, KVKK focused in particular on the possible initial point of compromise. According to the regulator’s assessment, the attackers may have first gained control of an account belonging to a third-party provider that supplied the company with human resources management software. Once the account had been compromised, the attackers could have used that access to move further into the organization’s infrastructure.

The regulator stressed that outsourcing does not remove a data controller’s responsibility for security. Companies must ensure that processors and service providers also maintain adequate safeguards.

Following its review, KVKK concluded that the company had failed to implement sufficient technical and administrative measures, citing inadequate system monitoring, delayed detection of unusual network activity, and insufficient malware protection. The company was therefore fined 500,000 TL for failing to meet its personal data security obligations.

Philips Engineer Convicted of Stealing X-Ray Trade Secrets

A federal jury in Chicago convicted former Philips Medical Systems engineer Chih Yee Jen for his role in a scheme to steal the company’s trade secrets for the benefit of a Chinese competitor.

Jen worked as an engineer at Philips’ facility in Aurora, Illinois, where the company researched, developed, and manufactured X-ray tubes used in computed tomography scanners. Through its Dunlee brand, Philips had spent years developing proprietary technologies in this field and supplying related equipment to healthcare organizations.

According to the U.S. Department of Justice, the scheme began taking shape in 2017, when Philips was preparing to close its Aurora facility. Chinese company Kunshan GuoLi Electronic Technology Co. Ltd. and its vice president, Xiaoqin Du, began working with Jen on the creation of a U.S.-based company that would help Kunshan GuoLi compete with Philips in the development and manufacturing of X-ray tubes.

A key aspect of the case is that Jen began sharing confidential information with the competitor while he was still employed by Philips. Investigators found that he provided corporate documents to Kunshan GuoLi and Du and also helped recruit several other Philips engineers to the new venture. Jen copied trade secret information directly from Philips’ internal databases. That information was later used in the development of similar technology for the Chinese company.

According to the federal indictment, the stolen information helped accelerate Kunshan GuoLi’s development of X-ray tubes. Prosecutors alleged that the products later manufactured by the company incorporated Philips’ proprietary technology and were subsequently sold in China.

The jury found the 71-year-old Jen guilty on both counts brought against him: conspiracy to steal, misappropriate, or possess trade secrets, and possession or attempted possession of stolen trade secrets. Several other former Philips employees have also been implicated in the case.


SearchInform Risk Monitor helps organizations to mitigate risks, posed to sensitive and confidential data by internal actors, including illicit copying and leaking to customers. 
Try Risk Monitor for free – a Next-Gen DLP platform for comprehensive data security, insider risk management, and business protection.