The Bootleg CD That Cost Me My Job

Years ago, a CD bought from a street seller as a “real email list” turned out to contain the stolen customer database of my employer, one of Turkey’s first e-commerce startups. My own restaurant deals company sent marketing email to that list. The breach came to light because customers had registered addresses such as name+<ourbrand>@gmail.com.

The company had not detected its database leaving. Its customers did.

When every sale rang a bell

When I joined the private shopping club, e-commerce was barely a thing in Turkey. Online shopping was not common, and Yemeksepeti and Sahibinden.com were among the models people could point to when explaining that internet businesses might actually work.

There were 35 people in total, including cargo staff and the founders. When they had time, or when work continued late, the founders folded shipping boxes and prepared their lids.

A screen on their computer rang a bell for every sale. Sometimes it rang about once every ten minutes, and people would hurry over to see what had sold. Today we watch transaction dashboards with grave expressions; back then, the dashboard was effectively a shop bell and a small office exercise programme.

The technical strategy was completely open source because nobody wanted to spend money on licences. Even the laptops ran Ubuntu. Most of the developers were still studying and worked part-time.

I was the only person there with a corporate IT background. The developers called me “abi” and brought me laptops when they could not install Java. I installed it and returned the machines. This was how I became the corporate elder while still doing work that began with “Java will not install.”

Windows knowledge was almost absent. Nobody knew how to back up the SQL database under the accounting department’s LOGO application, so that was also expected from me.

During my interview, the founders told me they were close to some of Turkey’s few incubator companies and said, “If you have a startup one day, we will support you too.” I accepted a low salary partly on that condition.

I stayed for more than three years. The company grew from 35 people to more than 300. More administrators arrived, all Linux specialists. Our division was clear: I handled Windows and internal users; they kept the sales infrastructure running.

I built the Active Directory structure, managed file sharing on Linux servers and handled access for Mac, Windows and Linux clients. Directors and CTOs appeared above us as the company moved towards a corporate structure. I also built good friendships there.

The period when spam delivery was a technical skill

Over time, I started a vertical daily-deal site for restaurants with people I had met. I was a small shareholder, and there was a major partner.

Deal sites were everywhere then. Our attempt to stand out was to focus on one subject: restaurants. Email marketing was one of the main ways that deal sites and many e-commerce companies attracted customers.

There was no regulation governing how much marketing email we could send. The technical achievement was getting spam into the inbox rather than the spam folder. An administrator who could do that was treated as nearly the most valuable person in the company.

I was genuinely good at it. That sentence has aged about as well as an open mail relay.

While choosing pirated films from a street seller, one of my partners noticed a CD presented as a “real email list.” He bought it for the price of one pirated film so we could try it.

Our reasoning was that anyone who did not want the messages could unsubscribe. We agreed to send restaurant offers and marketing email to the list.

I did not ask where the addresses had come from. I did not inspect the list for clues about its origin. The possibility that it contained stolen data did not even occur to me.

That was not clever growth hacking. It was rookie data handling, helped along by a convenient excuse: people could always unsubscribe.

The customers who traced the database

The list belonged to my employer.

I had no access to its customer email database. The key was kept by the boss and was not given to anyone else. Yet someone had stolen the database, sold it and made money from those addresses. I still do not know who took it or how.

The source became visible through plus-addressing. Some careful customers had registered using addresses in the form name+<ourbrand>@gmail.com. When our restaurant deals company sent messages to those addresses, the tag identified the company that had originally collected them.

Complaint emails and telephone calls began arriving at my employer. During the internal check, they found that I was a shareholder in the company sending the messages.

“Did you steal the emails?”

“No. My partner bought them from a pirate film seller.”

It was the truth. It was also the kind of truth that sounds worse with every word.

The company did not take legal action because it did not want the incident becoming a public embarrassment. Instead, I was told that corporate policy did not allow an employee to be a shareholder in another company. I was dismissed.

The founders who had said they would support me if I started a business fired me for having one. The irony is obvious, but it does not remove my share of responsibility. I had accepted a list of unknown origin and helped use it.

The part that did not fit into an incident ticket

I also lost the friendships I had made at the company. People believed I had stolen the addresses and accused me of stealing their work. I understand why the situation looked that way. I do not speak with any of them today; their choice, and I cannot say anything about it. On the other side, the major partner in my startup cleaned me out. I lost all the savings I had then, took on heavy debt and needed exactly six years to repay it.

Two rookie mistakes, one visible bill

My mistake was a failure of data provenance. Before accepting a list, I should have asked who collected it, for what purpose, with what consent and through which transfer. I asked none of those questions.

“Anyone can unsubscribe” was self-deception. An unsubscribe link does not clean the history of a stolen address. Nor does it make an unknown data source legitimate. The first control belongs before import and before sending, not after the recipient complains.

The employer made a different mistake. Keeping the database key with one person restricted access, but restricted access alone did not reveal that the data had left. If nobody watches the door, holding the only key is not enough. Data can reach the street, and the first detection may come from a customer rather than an internal control.

I cannot claim from this incident who bypassed which safeguard. I can say that the organisation did not detect the loss before tagged customer addresses exposed it. Access ownership needs monitoring, audit trails and a response process that treats unusual extraction as an event worth investigating.

For anyone accepting marketing data, I would now insist on a short record before the first import:

  • Who originally collected the addresses?
  • What were people told when they provided them?
  • How did the list reach us?
  • Who approved its use?
  • Can we prove those answers without relying on a partner’s assurance?

Plus-addressing also remains a free personal leak detector. Register at each site with a unique address such as [email protected]. If mail later arrives at that tagged address from somewhere else, you have a useful clue about where the address travelled.

This was not simply bad luck. It was inexperience on both sides: I failed to question the supply chain of the data, while the company protected possession of a key without detecting the database’s departure. The financial and professional cost, however, landed on one side.

Bad luck, or rookie mistake? What do you think?

On Monday, give every new registration a unique plus-address and require a written source for every marketing list you accept.

Sources

  • Çetin’s personal account and notes, provided 28 September 2026; no public URL.