forumNew topic

Our customer data was found online — I know sites are scanning, what do I need to do immediately?

SSultan Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
early-stage startup
Joined
Feb 2023
Message
10
#1

Got an email from a friend today: 'Customer data found on a platform'. It has addresses, phone numbers, emails, even the last 4 digits of credit cards. I panicked. I don't know where this data leaked from — was the website hacked, is there an API vulnerability, or was it an employee's computer?

What's the first thing we should do? Are there any logs in my database, how do I check? Should I warn all customers immediately? Or should I investigate and verify first before announcing?

Do I need to notify the police? The tax office? How will we verify that the data has been completely deleted?

GGizem E***Veteran
Job title
Social media manager
Sector
Food wholesale
Organization type
sole proprietorship
Joined
Sep 2024
Message
161
Most Helpful#2

Rapid response is critical when a data breach is discovered (72-hour notification period). Steps: 1) Assemble incident response team immediately (IT, legal, PR), 2) Verify data exfiltration (when did the leak start, how much data, what type of data), 3) Identify source (log analysis, forensic investigation), 4) Initiate overwrite work on leaked data (all data sources, overwrite frequency), 5) Prepare customer notification (within 72 hours), 6) Notify Data Protection Authority (DPA - KVKK) (72 hours), 7) Media and communication strategy (proactive communication), 8) Offer credit monitoring/identity theft protection to customers. Source identification: web application logs (nginx, apache), database audit logs (MySQL binlog, PostgreSQL WAL), API logs (request patterns), email server logs (phishing attacker). Customer communication: be specific (what type of data, how many customers, timeline), advice (password change, credit card monitoring). Legal: KVKK Article 49 (notification requirement), GDPR Article 33-34 (if EU data involved).

GGökhan D***Member
Job title
Business Owner
Sector
Machinery manufacturing
Organization type
40-person manufacturing company
Joined
Oct 2025
Message
416
#3

do incident response immediately bro. grab logs analyze code, measure the size of leaked data. you need to notify customers within 72 hours it gets worse after that. notify police file a complaint...

TTolga K***ExpertCommunity member
Joined
Apr 2025
Message
24
#4

Data breach investigation steps: 1) Timeline: When did the breach occur (log review), 2) Scope: How many records were affected (database query counts), 3) Data classification: What types (PII, payment, health), 4) Attack vector: Web app vulnerability (SQL injection, XSS), API key leak, phishing, malware, 5) Containment: Patch the vulnerability, update antivirus, revoke tokens, 6) Forensic evidence: Preserve logs (chain of custody), disk images (read-only), 7) Third-party forensics firm (if needed). Tools: Log scanning with grep, regex pattern matching (email, credit card patterns), SIEM correlation (if available). Notification: 72-hour GDPR/KVKK requirement, sooner if there's a risk of media exposure.

MMelis A***Member
Job title
Operations manager
Sector
Plastic
Organization type
120-person company
Joined
Feb 2023
Message
94
#5

boss this is an emergency. honestly first thing to do: assemble incident team, analyze logs find the source but notify customers and authorities within 72 hours, prepare statements. go to the police station file a complaint. then technical intervention, vulnerability patching, password rotation...

edit: fixed a few typos.

EEmre P***Member
Job title
Field sales representative
Sector
Cosmetics
Organization type
medium-sized business
Joined
Nov 2022
Message
55
#6

Breach response guide: 1) Discovery (confirmation, scope), 2) Investigation (root cause, timeline), 3) Containment (stop ongoing access, patch), 4) Communication (internal, customers, authorities, media), 5) Recovery (return to normal ops), 6) Improvement (lessons learned, security upgrades). KVKK timeline: 72-hour notification (to the authority + individuals), written communication (notification method). Digital forensics: hire a certified firm (ISO 27035 incident response), evidence preservation (read-only imaging, timestamps), chain of custody docs.

PPınar U***MemberCommunity member
Joined
Mar 2023
Message
188
#7

20 years in cybersecurity, been through many breaches. Most important thing: fast action. First 72 hours are critical — if customers aren't notified upfront, brand damage is huge. Hire legal counsel, forensic firm, PR firm. If things are bad, manage the crisis, communicate properly with the media.

edit: fixed a few typos.

UUğur E***MemberCommunity member
Joined
Jan 2023
Message
17
#8

Let me clarify the technical side. If you scold false alarms, nobody will report again.

That's all, sorry if I went on too long.

GGökhan G***MemberCommunity member
Joined
Mar 2023
Message
4
#9

Let's separate the concepts, they're getting mixed up. Solutions that work at a small scale collapse when you grow; I learned this late.

That's all, sorry if I went on too long.

DDoruk Ş***MemberCommunity member
Joined
Oct 2024
Message
218
#10

Let me summarize the topic, since several different answers were given. The real issue isn't the number, but what it's based on.

MMeryem S***Member
Job title
System administrator
Sector
Electrical-electronics
Organization type
two-branch business
Joined
Mar 2026
Message
398
#11

Let me summarize what's been said so far. When you try to change everything at once, nothing settles.

Just leaving this note, it might be useful.

JJülide U***MemberCommunity member
Joined
Feb 2024
Message
346
#12

Good call starting this thread.

YYağmurNew member
Job title
Travel blogger
Joined
Oct 2024
Message
46
#13

My question might sound amateurish, sorry about that. btw the harder it is to reverse a decision the slower you should make it.

If you scold false alarms nobody will report again. honestly if you have questions, write them; I'll answer as best I can.

FFiliz A***ExpertCommunity member
Joined
May 2025
Message
14
#14

There's one point I'm curious about. Forgotten test environments are more often the entry point than live systems.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. Just leaving this note, it might be useful.

SSena K***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
boutique agency
Joined
Feb 2025
Message
2
#15

Let me summarize what's been said so far. Most time waste accumulates in tasks waiting for approval.

If I were you, I'd go this route.

OOkan K***Member
Job title
Store associate
Sector
Healthcare services
Organization type
8-person team
Joined
Aug 2023
Message
5
#16

This approach has a cost, which isn't discussed. Don't rely on a single measure; go layer by layer.

If you get three different answers on a topic, the question was asked wrong. This is my opinion, I'm not claiming it's absolute truth.

LLale B***MemberCommunity member
Joined
Oct 2025
Message
282
#17

We've heard this a lot but it never happened like that for us. If you don't write this down from the start, it leads to arguments later.

Taking notes for two weeks yields better results than a six-month estimate.

GGökhan Y***MemberCommunity member
Joined
Sep 2023
Message
223
#18

This thread is archived.

BBarış S***MemberCommunity member
Joined
Mar 2023
Message
79
#19

I didn't know that.

ÜÜlkü Ç***Member
Job title
Operations director
Sector
Consulting
Organization type
20-person company
Joined
Dec 2023
Message
19
#20

You're right.

Reply