forumNew topic

Data leak happened, what do I tell my customers? Should I be upfront or downplay it?

LLale A***Member
Job title
Site Manager
Sector
IT services
Organization type
cooperative
Joined
Jul 2023
Message
86
#1

Attack happened, data of 1000 customers might have leaked. Should I notify them immediately? Or wait for the investigation to finish? What info should I share?

How should the notification email look? If I write it too scary, customers might leave. If I write it too lightly, I'll lose trust. What's the balance?

Who do I notify first: PR firm, legal counsel, or HR?

NNihal T***Veteran
Job title
CPA
Joined
Jul 2023
Message
129
Most Helpful#2

Data Breach Crisis Communication: Must be written with transparency and empathy, complying with the KVKK 72-hour notification period. Notification steps: 1) Internal coordination (IT, legal, PR, HR): incident response team meeting (hour 1), 2) Verify scope of data (how many customers, what type of data), 3) Prepare notification text (use a template), 4) Customer segmentation (affected vs. unaffected: write only to the affected group, providing confidential info), 5) Chairman/CEO signature (to show authority), 6) Channel selection (email is safest, SMS for additional notification). Template structure: 1) Statement of fact (attack occurred, accept responsibility), 2) Explanation of affected data (name, email, etc. — specificity increases trust), 3) Immediate steps (password change, credit monitoring check), 4) Measures the company will take (investigation, remediation), 5) Communication channel (support email, hotline). Timing: Notify customers within 72 hours (KVKK), simultaneously or later (depending on legal advice). PR strategy: proactive (notify customers before public news of the attack), transparent (all info open), empathetic (help the customer). HR coordination: internal employee communication (expect questions from reporters, social media).

TTaner Y***Expert
Job title
Regional Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Sep 2025
Message
3

Doki · Vulnerability scanning · 2025

#3

notify customers immediately, transparency is best but speak openly — attack happened, this data might have leaked, recommend credit monitoring, tell them to change passwords. btw don't write it too lighly you'll lose even more trust...

HHavva O***Expert
Job title
Marketing manager
Sector
Construction
Organization type
sole proprietorship
Joined
Nov 2023
Message
230
#4

Incident communication framework: 1) Initial statement (within 24h): acknowledge breach, confirm investigation underway, no premature details, 2) Detailed notification (within 72h KVKK deadline): affected individuals, data types, timeline, remediation timeline, customer actions (password reset, antivirus product, credit monitoring), 3) Follow-up (weekly initially): investigation progress, patch status, any new findings. Message crafting: avoid jargon (technical terms → plain English), avoid blame (active voice: 'system patched' vs. passive 'system was vulnerable'), show empathy (our responsibility, customer support). Channel: email (official record), SMS (urgency), phone call (VIP customers). Escalation: media statement (if public reporting occurs), legal notice (KVKK notification template), insurance notification (simultaneously).

RRecepNew member
Job title
Plumber
Organization type
20-person company
Joined
Dec 2024
Message
22
#5

talk to customers fast and straight and say there was an attack, data mightve leaked heres how well help. dont do spin PR be transparent. offer credit monitoring for free. rebuilding trust takes a long time but transparecny has to be top priority from the start...

ZZehra A***Expert
Job title
Hotel owner
Organization type
regional distributor
Joined
May 2023
Message
184

Doki · E-commerce infrastructure · 2025

#6

Crisis communication playbook: pre-incident (template ready), during (incident response: initial statement within 4h preliminary details within 24h), post (follow-up, resolution communication). Stakeholder matrix: customers (notification + support), regulators (KVKK report), media (proactive statement if external news), employees (internal comms avoid confusion). Message testing: legal review (liability exposure), customer review (clarity + empathy) media simulation (hostile questions). Long-term recovery: consistent updates demonstrated improvements (security upgrades), customer appreciation (discount, service enhancement).

NNuri K***Member
Job title
Product Manager
Sector
Real estate
Organization type
sole proprietorship
Joined
Apr 2023
Message
3
#7

Thanks for writing this, that's the right way. Start with a small trial; don't commit to everything at once.

If you have questions, write them; I'll answer as best I can.

İİlker C***MemberCommunity member
Joined
May 2023
Message
29
#8

Exactly, and not many people know this. Taking notes for two weeks yields better results than a six-month estimate.

Good luck with that.

DDoruk U***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2025
Message
137
#9

Thanks for posting. When making decisions, write down the worst-case scenario too, not just the best.

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#10

i've been down this road, let me tell you. btw if you scold false alarms, nobody will report again.

correct me if I'm wrong.

KKemal Ç***Member
Job title
Field sales representative
Sector
Plastic
Organization type
120-person company
Joined
Oct 2022
Message
140

Doki · Interface design · 2023

#11

I'd appreciate it if you shared the outcome.

GGökhan C***Member
Job title
Studio Founder
Sector
Education
Organization type
chain store
Joined
Jan 2023
Message
64
#12

You're right, I've been down that road too. The harder it is to reverse a decision, the slower you should make it.

ZZübeyde C***MemberCommunity member
Joined
Jun 2024
Message
104
#13

I'd say don't rush. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

AAleyna E***MemberCommunity member
Joined
Aug 2024
Message
80
#14

The discussion got scattered, let me summarize. Taking notes for two weeks yields better results than a six-month estimate.

BBaranMember
Job title
Game developer
Organization type
120-person company
Joined
Jun 2024
Message
98
#15

The answer above hits the nail on the head. If you get three different answers on a topic the question was asked wrong.

Forgotten test environments are more often the entry point than live systems. If you have questions, write them; Ill answer as best I can.

BBeyza K***Member
Job title
Field sales representative
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Feb 2024
Message
6

Doki · Log management setup · 2026

#16

This approach has a cost, which isn't discussed. Solutions that work at a small scale collapse when you grow; I learned this late.

People defend habits, not processes. Resistance comes from there.

RRıdvan Ö***MemberCommunity member
Joined
Apr 2025
Message
5
#17

You're right, I've been down that road too. If 2FA is on, a stolen password alone is useless.

BBarış B***Member
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Aug 2024
Message
77
#18

It's rare to find an explanation this clear.

MMehmet A***Expert
Job title
Agency owner
Organization type
early-stage startup
Joined
Sep 2023
Message
187
#19

Noted, thanks. Payment information changes are never verified through the channel they came from.

If you have questions, write them; I'll answer as best I can.

GGamzeMember
Job title
HR Specialist
Organization type
120-person company
Joined
Jul 2024
Message
104
#20

Let me speak from the other side; I'm on the supplier side. If permission and scope aren't in writing, don't start that test.

Don't rely on a single measure; go layer by layer. Of course, it varies if your situation is different.

Reply