top of page

Cybercrime in Turkey: What to Do After a Hack, Data Breach or Online Fraud

  • Writer: Zeynep Atım Kurucuk
    Zeynep Atım Kurucuk
  • 3 hours ago
  • 14 min read

When a person discovers that their email account has been taken over, a company's website suddenly stops working, money disappears from an online account, or confidential customer information has been accessed without permission, the first reaction is usually the same: What should we do now?


That question has both a technical and a legal answer.


In Turkey, cyber-related incidents can involve the Turkish Penal Code, criminal procedure, personal data protection legislation, internet law, financial crime rules and international cooperation mechanisms. The right legal response depends on what happened, what evidence remains available and whether the person involved is a victim, a business, or someone facing a criminal investigation.


This article explains the main legal issues in straightforward terms and focuses on the practical questions that commonly arise in Turkish cybercrime cases.


What Is Cybercrime Under Turkish Law?

There is no single Turkish statute that contains every possible offence committed online.


Instead, Turkish law deals with different types of cyber-related conduct through several pieces of legislation. The Turkish National Police Cybercrime Department describes cybercrime as conduct targeting an information system, its security, data or users and distinguishes genuinely system-dependent cyber offences from ordinary crimes that merely happen to be committed using the internet. The Turkish Cybercrime Department's explanation of cybercrime provides useful official background.


This distinction is important.


For example, someone using the internet to commit fraud does not necessarily make every element of the offence a separate "hacking" offence. On the other hand, unauthorized access to a computer system, deletion of data or disruption of a server may fall directly within provisions dealing with information systems.


The legal question is therefore not simply:


"Was the internet involved?"


It is:


"What exactly happened, and which legal provisions apply to that conduct?"


Which Turkish Laws Deal With Cybercrime?

Several areas of Turkish law can become relevant to a single incident.


Turkish Penal Code

The Turkish Penal Code (Law No. 5237) contains important provisions concerning information systems, data, communications, fraud and financial instruments.


Articles 243 and 244 are particularly important in cases involving unauthorized access and interference with information systems. The Turkish National Police also identifies Articles 243 and 244 among the principal provisions relevant to cybercrime. Official Turkish Cybercrime Department information explains these categories.


Code of Criminal Procedure

The Code of Criminal Procedure (Law No. 5271) becomes important once a matter enters the investigation or prosecution stage.


It governs important procedural matters, including investigative measures and the handling of evidence.


The Turkish Ministry of Justice provides access to official information concerning the Turkish justice system and legislation.


Personal Data Protection Law

If personal information is involved, Law No. 6698 on the Protection of Personal Data (KVKK) may also apply.


The official English text of the Personal Data Protection Law explains that the legislation is intended to protect fundamental rights and freedoms, particularly privacy, in relation to the processing of personal data.


Electronic Communications Legislation

Certain cyber investigations may also involve electronic communications legislation and rules concerning telecommunications data.


The Turkish Cybercrime Department's official FAQ refers to the Electronic Communications Law No. 5809 together with the Code of Criminal Procedure in connection with certain telecommunications-related investigative measures.


Unauthorized Access: Is Hacking a Crime in Turkey?

Yes, unauthorized access to an information system can constitute a criminal offence under Turkish law.


Article 243 of the Turkish Penal Code addresses entering all or part of an information system without authorization and remaining there. The Turkish Cybercrime Department specifically identifies this provision in its explanation of "bilişim sistemine girme" — entering an information system.


But a criminal case should not be reduced to the statement:


"Someone logged into the system, therefore that person is guilty."

There are usually several questions behind that allegation.


Was There Actually Unauthorized Access?

A person may have had legitimate credentials or authorization.


An employee may have had access to a database as part of their job.


A contractor may have been permitted to access a particular server but not another part of the network.


A former employee's credentials may not have been properly disabled.


The circumstances surrounding the authorization can therefore matter considerably.


Who Actually Used the Account?

An account can be compromised.


A password can be shared.


A device can be infected.


A corporate network can be used by numerous employees.


For that reason, identifying an account or IP address is not necessarily the same thing as proving who personally performed the alleged act.


What Happens When Someone Deletes or Changes Data?

Cybercrime cases can become more serious when the alleged conduct affects the data or operation of a system.


Article 244 of the Turkish Penal Code deals with conduct involving interference with information systems and certain forms of destruction, alteration, deletion, transfer or inaccessibility of data. The official Cybercrime Department identifies these activities as falling within the scope of Article 244.


This can become relevant in incidents such as:


  • Deleting company databases;

  • Changing website content;

  • Destroying electronic records;

  • Encrypting business files;

  • Disabling a server;

  • Interfering with a company's information system;

  • Sending or transferring data without authorization.


The precise legal classification depends on the facts rather than the technical label used to describe the attack.


What About DDoS Attacks?

A DDoS attack is designed to make a service difficult or impossible for legitimate users to access.


The Turkish Cybercrime Department describes botnet-based DDoS activity as a method in which compromised computers are directed to send large numbers of requests toward a target system. The Department's explanation of DDoS and botnets provides an official description.


For a business, a DDoS incident can cause much more than temporary inconvenience.


It can result in:


  • Lost sales;

  • Website downtime;

  • Contractual problems;

  • Customer complaints;

  • Reputational damage;

  • Loss of business data;

  • Additional technical expenses.


A company affected by such an attack should think about evidence preservation at the same time as technical mitigation.


The official Cybercrime Department guidance concerning hacked websites specifically advises affected website operators to contact their hosting provider and obtain access logs.


Online Fraud and Phishing in Turkey

Not every cybercrime case involves someone breaking into a server.


Sometimes the technology is simply the tool used to deceive the victim.


A fake website may be created to obtain banking credentials. A fraudulent email may direct a person to a malicious login page. Someone may impersonate a business on social media and ask customers to make payments.


The Turkish Cybercrime Department identifies qualified fraud involving information systems, banks and credit institutions among the cyber-related offences it handles and gives phishing-style examples involving fake emails and websites.


These cases may require analysis of:


  • Domain registration;

  • Website hosting;

  • Email headers;

  • Payment records;

  • Bank accounts;

  • IP information;

  • Messaging records;

  • Social-media accounts;

  • Telephone numbers;

  • Cryptocurrency transactions; and

  • Device evidence.


Bank and Credit Card Cybercrime

Financial information is a frequent target of digital attacks.


Article 245 of the Turkish Penal Code addresses certain offences involving bank and credit cards. The Turkish Cybercrime Department also specifically lists bank and credit-card offences among matters within its field.


A case may involve several stages:


  1. Obtaining card or account information;

  2. Using the information without authorization;

  3. Transferring or spending money;

  4. Moving the proceeds through another account;

  5. Attempting to conceal the transaction.


The legal assessment should follow the entire sequence rather than focusing only on the final transaction.


Personal Data Breaches Can Create a Separate Legal Problem

This is where many businesses make a mistake.


A company may correctly regard itself as the victim of a cyberattack, but that does not necessarily end the legal analysis.


If personal data has been exposed, the company may also have obligations under the Turkish personal-data protection framework.


The Personal Data Protection Law No. 6698 imposes obligations concerning the protection of personal data.


The Personal Data Protection Authority (KVKK) publishes decisions and guidance that help explain how these obligations are applied in practice.


Is a Data Breach Reportable to KVKK?

Potentially, yes.


The Turkish Personal Data Protection Board has stated that data controllers are required to notify the Board without delay and, under the Board's established 72-hour rule, no later than 72 hours after becoming aware of a data breach.


This makes the early response to a data breach particularly important.


A company should not wait until every technical question has been completely resolved before considering its legal obligations.


At the same time, an incident should not be reported carelessly or inaccurately.


The better approach is usually to coordinate:


  • Technical incident response;

  • Evidence preservation;

  • Legal assessment;

  • Data-protection analysis;

  • Internal management;

  • Communications strategy.


The official KVKK data-breach resources should be checked for the current requirements applicable to the particular incident.


What Should a Company Do Immediately After a Cyberattack?

There is a natural temptation to "clean everything up" after an attack.


That can sometimes create a second problem.


For example, formatting a computer, deleting logs or reinstalling a server may remove information that could later help identify the attacker or establish what happened.


The Turkish Cybercrime Department's official FAQ specifically warns in certain ransomware circumstances against immediately formatting the computer and advises preserving relevant information.


A sensible incident-response plan may therefore include the following.


Secure the System

Stop continuing unauthorized access and work with qualified cybersecurity professionals.


Preserve Evidence

Keep relevant logs, emails, messages, transaction records and other material in their original form where possible.


Record the Timeline

Write down when the incident was discovered, what happened beforehand and what was done afterwards.


Identify the Affected Information

Determine whether the incident involved:


  • Personal data;

  • Financial information;

  • Trade secrets;

  • Customer records;

  • Employee information;

  • Intellectual property;

  • Confidential communications.


Consider Criminal Reporting

Depending on the incident, a criminal complaint may be appropriate.


Consider Data-Protection Obligations

If personal data is involved, the KVKK position should be assessed promptly.


What Evidence Is Important in a Cybercrime Case?

Digital evidence can look convincing while still requiring careful interpretation.


A cybercrime investigation may involve:


  • IP addresses;

  • Login records;

  • Server logs;

  • Email headers;

  • Browser history;

  • Mobile-phone data;

  • Cloud records;

  • Database logs;

  • Payment records;

  • CCTV;

  • Messaging applications;

  • Social-media records;

  • Domain information;

  • Malware analysis;

  • Forensic images of devices.


The question is not simply whether a record exists.


The more important questions may be:


Where did it come from?


Who created it?


Has it been altered?


How was it obtained?


Who had access to the relevant device or account?


Does it actually prove the allegation being made?


Can an IP Address Prove Who Committed a Cybercrime?

An IP address can be valuable evidence, but it should not automatically be treated as the identity of an offender.


Imagine a company with 100 employees using the same internet connection.


An IP address may identify the company's connection, but it does not necessarily tell investigators which employee was sitting at the computer.


The same problem can arise with:


  • Shared Wi-Fi;

  • Public networks;

  • Dynamic IP addresses;

  • Compromised devices;

  • Shared accounts;

  • Corporate VPNs;

  • Remote working systems.


A proper investigation therefore looks at the wider evidentiary picture.


Digital Forensics and Expert Reports

Cybercrime cases often require technical expertise.


A forensic examination may seek to establish what happened on a computer, telephone, server or other device.


But a technical report should still be read critically.


A lawyer may need to ask:


  • What material was examined?

  • Was the original device available?

  • Was the evidence preserved correctly?

  • What methodology was used?

  • Are the conclusions supported by the underlying data?

  • Are alternative explanations possible?

  • Does the technical conclusion actually establish the legal element of the offence?


This is one reason why cybercrime litigation often requires close cooperation between lawyers and digital-forensics professionals.


What If You Are Accused of Cybercrime in Turkey?

Being accused of hacking or another cybercrime can be frightening, particularly when the allegation is based on technical information that may appear difficult to challenge.


The first step is not to assume that the allegation is correct.


The evidence should be examined.


For example:


Check the Alleged Account

Was the account actually controlled by the accused?


Check the Device

Who had physical or remote access to the computer or telephone?


Check the Network

Was the connection shared?


Check the Timeline

Was the accused actually present or able to perform the alleged activity?


Check the Digital Evidence

Does the evidence establish the specific conduct alleged?


Check the Procedure

Were the relevant investigative measures and evidence-gathering procedures conducted in accordance with applicable Turkish law?


The Turkish Ministry of Justice and official Turkish legislation resources should be consulted for the current procedural framework.


What If Your Email or Social-Media Account Has Been Stolen?

This is one of the most common situations faced by individuals.


If someone takes control of an email or social-media account, the victim should first try to regain control through the platform's official recovery process and secure the account from a trusted device.


The Turkish Cybercrime Department provides specific guidance for situations where an email or social-media account has fallen into someone else's hands. Official account-takeover guidance is available through the Department's FAQ resources.


After that, the victim should preserve evidence showing:


  • When access was lost;

  • Security alerts received;

  • Password-reset messages;

  • Unauthorized messages sent;

  • Unauthorized transactions;

  • Changes made to the account;

  • Any demands for money;

  • Relevant usernames, URLs and profile information.


Do not assume that a screenshot is the only useful evidence. Original communications and platform records may also matter.


What If Someone Uses Your Hacked Account to Defraud Other People?

This can become particularly stressful because the victim may suddenly be treated as the person responsible for messages or transactions they did not make.


For example, an attacker may take over a person's social-media account and send messages to friends asking for money.


The Turkish Cybercrime Department provides guidance for this type of situation and explains that victims may need to make a signed application to the relevant police station, Public Prosecutor's Office or Cybercrime Branch in circumstances where a personal complaint is required.


The precise procedural route depends on the offence and circumstances.


Reporting a Cybercrime in Turkey

The Turkish Cybercrime Department indicates that victims may, depending on the circumstances, apply to the relevant police station, Public Prosecutor's Office or Cybercrime Branch.


The official Cybercrime Department website provides current information about the Department and its activities.


For a serious incident, legal advice before or alongside the complaint can help ensure that the chronology, evidence and legal issues are presented clearly.


Why Evidence Should Be Preserved Before Making Major Changes

Suppose a website has been hacked.


The instinct may be to immediately reinstall everything.


Technically, that may sometimes be necessary.


Legally, however, it can be important to preserve the available evidence first.


The official Cybercrime Department's guidance for hacked websites recommends obtaining access logs from the hosting provider.


The same principle can apply to other incidents.


Before deleting:


  • Emails;

  • Server logs;

  • Chat messages;

  • Device data;

  • Account records;

  • Payment information;

  • Security alerts;


consider whether the information may later be needed as evidence.


Cybercrime and Confidential Business Information

A cyberattack does not have to involve customer personal data to cause serious legal problems.


A company may lose:


  • Trade secrets;

  • Pricing information;

  • Product designs;

  • Source code;

  • Customer lists;

  • Contracts;

  • Business strategies;

  • Research and development material.


Depending on the circumstances, the incident may therefore involve criminal law, commercial law, intellectual property and data protection simultaneously.


For intellectual-property matters, the Turkish Patent and Trademark Office (TÜRKPATENT) is an important official source concerning industrial property rights.


Cybercrime and Cryptocurrency

Cryptocurrency can make an investigation more complicated, particularly where funds move rapidly between wallets and exchanges.


At the same time, blockchain transactions can create a permanent record of transfers.


A cryptocurrency-related cybercrime investigation may therefore involve:


  • Wallet addresses;

  • Transaction hashes;

  • Exchange accounts;

  • Bank transfers;

  • Identity information;

  • Communications;

  • Device evidence.


The existence of a blockchain transaction does not automatically establish who controlled a wallet. Additional evidence may be required to connect a digital wallet to a particular individual.


Cross-Border Cybercrime in Turkey

Modern cybercrime frequently crosses borders.


A victim may be in Istanbul.


The attacker may be somewhere else.


The server may be located in another country.


The relevant platform may be operated by a company headquartered in a fourth jurisdiction.


This can make evidence collection particularly challenging.


Turkey is a party to the Budapest Convention on Cybercrime. The Council of Europe records Turkey's ratification of the Convention in 2014.


The Council of Europe's Budapest Convention page explains that the Convention provides a framework for criminalization, procedural powers concerning electronic evidence and international cooperation.


The Convention's framework is relevant not only to classic hacking cases but also to investigations involving electronic evidence more generally. The Council of Europe identifies areas including phishing, identity theft, malware, DDoS attacks and ransomware within its cybercrime guidance. Council of Europe cybercrime guidance provides further material.


Cybercrime Cases Involving Foreign Companies

Foreign companies operating in Turkey can face additional considerations.


For example, a company may have:


  • Employees in Istanbul;

  • A Turkish subsidiary;

  • Customer data in Turkey;

  • Cloud infrastructure abroad;

  • Foreign service providers;

  • International payment systems.


The incident may therefore require both Turkish legal advice and coordination with lawyers or investigators in other jurisdictions.


This is particularly important where evidence must be obtained from a foreign service provider.


Cybercrime Is Not Always Just a Criminal-Law Problem

One of the biggest practical lessons from cyber incidents is that the criminal investigation is often only one piece of the puzzle.


A single incident can produce:


Criminal issues — Was an offence committed?


Data-protection issues — Was personal data affected?


Commercial issues — Were contracts or business relationships disrupted?


Employment issues — Did an employee misuse access?


Intellectual-property issues — Were protected materials stolen?


Civil issues — Has someone suffered financial or reputational damage?


International issues — Is relevant evidence located abroad?


The best legal strategy often begins by identifying all of these questions rather than treating the matter as simply a "hacking case."


How a Cybercrime Lawyer Can Help

A cybercrime lawyer in Istanbul may assist at different stages of an incident.


For Victims

Legal assistance may include:


  • Assessing the potential offences;

  • Preparing a criminal complaint;

  • Organizing evidence;

  • Liaising with technical experts;

  • Advising on data-protection implications;

  • Following a criminal investigation;

  • Assessing possible civil remedies;

  • Addressing cross-border issues.


For Accused Persons

A defense may involve:


  • Reviewing the investigation file;

  • Examining digital evidence;

  • Challenging attribution where appropriate;

  • Reviewing expert reports;

  • Assessing procedural issues;

  • Preparing defense submissions;

  • Representing the accused during criminal proceedings.


For Businesses

Companies may need coordinated advice concerning:


  • Cyber incidents;

  • Data breaches;

  • Internal investigations;

  • Employee access;

  • Confidential information;

  • Regulatory obligations;

  • Criminal complaints;

  • Litigation.


Why Early Legal Advice Can Make a Difference

Cybercrime cases often become harder when evidence disappears.


A server log may be overwritten.


A cloud account may be deleted.


A social-media profile may disappear.


A compromised computer may be reformatted.


A payment may be moved through several accounts.


Early legal advice does not guarantee a particular result, but it can help ensure that important decisions are made with the eventual legal process in mind.


Frequently Asked Questions


Is hacking illegal in Turkey?

Unauthorized access to an information system can constitute a criminal offence under Article 243 of the Turkish Penal Code, depending on the facts and legal requirements.


What is Article 243 of the Turkish Penal Code?

Article 243 addresses unlawful entry into all or part of an information system and remaining within it. The precise application depends on the circumstances of the case.


What is Article 244 of the Turkish Penal Code?

Article 244 addresses certain forms of interference with information systems and data, including conduct involving disruption, destruction, alteration, deletion or making data inaccessible.


Can an IP address prove that I committed a cybercrime?

An IP address may be important evidence, but it does not necessarily prove which individual performed the activity. Additional evidence may be required to establish attribution.


What should I do if my company has been hacked?

Secure the affected systems, preserve relevant evidence, obtain appropriate technical assistance and promptly assess criminal, contractual and personal-data protection obligations.


What should I do if my email account is hacked?

Attempt account recovery using the platform's official procedures, secure the account from a trusted device, preserve relevant evidence and consider obtaining legal advice if criminal conduct or financial loss is involved.


Can a data breach lead to a KVKK investigation?

Potentially. A personal-data breach may create obligations under Law No. 6698, and the Personal Data Protection Board may examine compliance with applicable requirements.


How quickly must a Turkish data breach be reported?

The Turkish Personal Data Protection Board has stated that data controllers must notify the Board without delay and, under its established rule, no later than 72 hours after becoming aware of the breach.


Can a cybercrime lawyer represent the victim?

Yes. Depending on the circumstances, a lawyer can assist with evidence preservation, criminal complaints, investigations, data-protection matters and related civil proceedings.


Can a lawyer defend someone accused of hacking?

Yes. A defense lawyer can examine the investigation, technical evidence, expert reports, attribution issues and procedural aspects of the case.


Does Turkish cybercrime law apply when the attacker is abroad?

It can, depending on the circumstances and the relevant jurisdictional connections. Cross-border cybercrime cases may also involve international cooperation and electronic-evidence mechanisms.


Cybercrime Legal Assistance in Istanbul, Turkey

Cybercrime cases are rarely as simple as they first appear.

A person may think an account was "hacked," while the underlying case involves unauthorized access, fraud, personal-data issues, unlawful disclosure, financial crime or several offences at once.


A business may think it has suffered a cyberattack, while also facing urgent questions about customer information, regulatory obligations and evidence preservation.


And a person accused of hacking may discover that the central issue is not whether a particular IP address appears in an investigation file, but whether the available evidence actually connects that person to the alleged conduct.


That is why cybercrime cases require a fact-specific legal and technical assessment.


Kurucuk & Associates provides legal assistance in Istanbul concerning Turkish cybercrime, criminal investigations, digital evidence, cyber-related fraud, unauthorized system access, data breaches and related technology-law matters.



The legal position can depend on the date of the incident, subsequent legislative amendments, judicial interpretation, the available evidence and the procedural stage of the matter. This article is intended for general information and does not replace advice based on the particular facts of a case.


bottom of page