
KVKK Fines a Platform 250,000 TL for Tying Live Match Streaming to “Explicit Consent”
KVKK fined a platform 250,000 TL for tying live match streaming to marketing consent. What organisations should check on their consent screens.
Hitting a holding company does not need hundreds of hacked servers. We follow what an attacker can do in the first 60 minutes after reaching one account.

Does targeting a holding company's finance operations require hacking hundreds of servers?
Not always.
Sometimes all an attacker needs is access to the right person's account.
Compromising the account of a CFO, finance director, accounting manager or any employee authorised in payment processes can let an attacker see the organisation's internal financial relationships, suppliers, payment habits and executive communications.
Let us now look at the first 60 minutes of a cyberattack a holding company could experience, through an entirely illustrative scenario.
The finance director begins the day by checking the inbox.
A short message that appears to come from a supplier they have worked with before catches their attention:
"The July reconciliation file has been updated. You can access the current document via the link below."
The language of the message is correct.
The company name is right.
The subject line is familiar.
The attacker may even have referenced a genuinely ongoing project, thanks to information obtained earlier.
The finance director clicks the link.
A page closely resembling the Microsoft 365 sign-in screen appears.
And the first stage of the attack is complete.
In modern attacks a username and password are not always enough.
Because many organisations now use MFA.
For that reason, in some scenarios attackers target users' active sessions or session tokens.
If successful, a far more valuable door can open for the attacker:
the user's existing corporate session.
From this point on, the aim of the attack begins to expand from the finance director's computer towards the company's digital identity infrastructure.
If the attacker gains access to the corporate account, Outlook is not all they find.
Depending on privileges and the organisation's configuration,
Outlook, Teams, OneDrive, SharePoint and other corporate resources can all become a potential source of information for the attacker.
But something interesting happens.
The attacker deletes no files.
Shuts down no systems.
Leaves no ransom note.
Sends no threatening message to anyone.
Because the aim is not yet to stop the company.
The aim is to understand the company.
The attacker may start searching the finance director's mailbox for particular words:
Payment.
Invoice.
IBAN.
Transfer.
Bank.
Contract.
Approval.
The correspondence containing these words can give the attacker important clues about how the organisation works financially.
Who issues payment instructions?
Who performs the second approval?
Which executives communicate with each other regularly?
Which companies receive payments continuously?
What payment sizes are considered normal?
The attacker is no longer analysing the technical infrastructure but the company's behavioural model.
Company documents may be next.
Depending on the user's access rights, platforms such as SharePoint may hold
budget files, management reports, contracts, supplier lists, project documents or information about group companies.
For a holding company the risk here is even greater.
Because a single account sometimes carries information about more than one company.
The correspondence the same user conducts with different group companies, subsidiaries and suppliers can give the attacker the opportunity to map a significant part of the organisation.
By the end of the first 40 minutes the attacker may hold an important advantage:
context.
This is extremely valuable in financial fraud.
Because a poorly prepared phishing message is relatively easy to spot.
But if the attacker knows
the real project,
the real executive,
the real supplier,
the real payment timing
and the style of correspondence inside the organisation, a far more convincing attack can emerge.
The message the attacker will prepare no longer needs to look "suspicious".
On the contrary, it needs to look as normal as possible.
The attacker selects a genuine payment process already under way.
The project is real.
The supplier is real.
The invoice may be real.
The payment amount is ordinary for the company.
The tone of the correspondence matches corporate communication.
But one critical detail is changed:
the bank account.
The message sent to accounting is quite simple:
"There has been an update to our payment account. Could you make today's transfer to the account below?"
This is where the financial dimension of the attack begins.
The message arriving on the accounting employee's screen may look nothing like classic phishing examples.
The sender may be familiar.
The project may be correct.
The amount is plausible.
The correspondence has a history.
The request appears to be a natural part of the company's daily operations.
So in modern cyberattacks it may not be enough to ask only:
"Is this email genuine?"
The real question is:
"Is the person requesting this transaction really who we think they are?"
An hour ago the company was operating normally.
The firewall was active.
EDR was running.
Antivirus was up to date.
MFA was in use.
SIEM was collecting logs.
Thousands of events were flowing across the SOC screens.
Yet despite all of this, one critical question may still be unanswered:
One of the most important problems in cybersecurity today emerges precisely here.
Owning a security product and being able to detect an attack in time are not the same thing.
This attack chain could in fact have been broken at many points.
Advanced email security could have blocked the first message.
Identity security and correctly configured MFA controls could have reduced the risk of account takeover.
Conditional Access policies could have restricted unusual access.
EDR/XDR solutions could have made suspicious behaviour visible.
SIEM and SOC correlation could have detected unusual sessions and activity.
PAM solutions could have limited uncontrolled use of critical privileges.
And dual verification plus independent payment confirmation in the finance department could have prevented the money being transferred even if the attacker had bypassed the technical controls.
For finance and holding structures, cybersecurity is therefore no longer a technology problem consisting of a firewall, antivirus or a handful of security products.
Identity + user + device + data + privilege + financial process + continuous monitoring must be assessed together.
Attackers do not always need to bring systems down.
Sometimes the most successful attack is the one nobody notices.
Systems keep running.
Employees do their jobs.
Emails arrive.
The ERP works.
Banking systems are open.
Yet the attacker is inside, learning how the organisation works.
It is therefore not enough for boards and senior executives to ask their security teams only:
"Do we have security products?"
There may be a far more important question:
"If an attack like this one, beginning at 09:02, happened in our holding company, at what time would our security team notice?"
Because in cybersecurity the critical difference is sometimes not whether the attack happens;
it is the time between the attacker and the defence team.
At SecureSys we assess not only whether organisations own security products, but how quickly they can notice and stop an attack. Through identity security, email security, EDR/XDR, SIEM/SOAR, 24/7 SOC monitoring, social engineering tests and penetration testing, we help organisations break the attack chain early.
Because in cybersecurity what usually matters is not whether the attack happens, but how long it takes to be noticed.
Get weekly threat intel, case studies, and technical content delivered to your inbox.
No spam. Unsubscribe anytime.

KVKK fined a platform 250,000 TL for tying live match streaming to marketing consent. What organisations should check on their consent screens.

Up to eight autonomous AI agents took part in the attack on Taiwanese public institutions. The way cyberattacks are run is changing.

Spam calls are no longer just annoying: they can be the opening move of fraud and social engineering. Seven practical ways to protect yourself.