

Who pays when cybercriminals empty a foreigner’s Turkish bank account? Learn when the bank, telecom operator, customer or fraudster may be liable for unauthorized transfers, SIM swap attacks, phishing and mobile banking fraud.
When cybercriminals empty a foreigner’s Turkish bank account, liability does not automatically fall on the customer merely because the transfers were completed using online or mobile banking. Depending on the circumstances, the bank, the fraudster, a telecommunications provider or another party may bear responsibility for some or all of the loss.
The central issue is usually whether the disputed transactions were genuinely authorized and whether the bank’s authentication, fraud-detection and electronic banking security systems functioned in accordance with applicable requirements.
Turkey’s banking regulator maintains detailed rules governing information systems and electronic banking services, including identity authentication, transaction security and controls intended to prevent unauthorized access.
Therefore, a case should not be decided merely by saying:
“Someone entered the correct password, so the customer is responsible.”
The technical history of the fraud must be reconstructed.
No.
A bank does not automatically become responsible for every fraudulent transaction affecting a customer.
If the customer intentionally authorized the payment or acted in a manner that materially contributed to the loss, responsibility may be disputed.
However, the opposite is also true.
The bank cannot automatically avoid liability merely because its electronic system recorded technically successful authentication.
The real questions include:
The final allocation of liability depends on the complete factual and technical evidence.
SIM swap fraud is particularly important because Turkish banking rules impose specific controls concerning SIM-card replacement.
Regulatory guidance has long required banks to apply additional protection when a customer’s SIM card changes. Banks must prevent ordinary SMS authentication from being treated as sufficient until the change is appropriately confirmed.
Current electronic banking rules continue to impose detailed security obligations concerning authentication and transaction security.
Therefore, where a customer’s telephone suddenly loses service and criminals immediately gain mobile banking access, the following chronology becomes extremely important:
SIM replacement → mobile banking activation → password reset → beneficiary addition → transfer.
If those events occur within minutes or hours, the bank’s security records should be examined carefully.
Potentially.
If the cyberattack began because a criminal obtained a replacement SIM card without proper authorization, the procedures used by the telecommunications provider may become relevant.
Important questions include how the replacement SIM was issued, what identification was presented, whether the customer requested the replacement and whether required security procedures were followed.
A SIM swap dispute can therefore involve more than the customer and the bank.
The bank may argue that the mobile operator allowed the fraudster to obtain control of the telephone number.
The mobile operator may argue that the bank should nevertheless have detected unusual banking activity.
The correct allocation of responsibility requires examination of both sides.
Potentially, yes, depending on the facts.
The customer’s conduct may become relevant where the customer voluntarily provides banking credentials, authorizes a transaction, ignores repeated warnings or knowingly allows another person to use the account.
However, customer negligence should not automatically be assumed merely because a phishing attack succeeded.
Modern fraud can involve highly sophisticated impersonation, malware, fake banking applications, SIM replacement, remote-access software and social engineering.
The exact sequence of events must therefore be established.
That can make the case more difficult, but it does not necessarily resolve liability by itself.
For example, a fraudster may impersonate a bank employee and tell the customer that a code is required to stop suspicious activity.
The customer provides the code believing that the bank is protecting the account.
The bank may argue that the customer voluntarily disclosed confidential information.
The customer may argue that the transaction should nevertheless have triggered fraud-prevention measures because the device, beneficiary, amount or transfer pattern was abnormal.
Regulatory authorities continue to warn customers that criminals may impersonate banking or regulatory personnel and request passwords, personal information or installation of applications.
Therefore, responsibility should be assessed using the entire factual picture.
This has become an important form of online banking fraud.
A criminal may persuade the victim to install remote-control software on a telephone or computer.
The fraudster can then view banking information, intercept activity or perform transactions.
In such cases, the bank may argue that transactions were completed from the customer’s own registered device.
That does not necessarily end the case.
Technical examination may still be required to determine whether the transactions were consistent with the customer’s normal behaviour and whether unusual security events occurred.
Use of a valid password does not necessarily prove genuine authorization.
Passwords can be stolen.
Malware can capture them.
Fraudsters can obtain them through phishing.
A criminal controlling a replaced SIM card may also be able to reset credentials.
Turkey’s banking regulations require security systems that go beyond reliance on a single piece of customer information. Regulatory materials confirm the use of multi-factor authentication mechanisms in remote banking.
Therefore, the court or dispute-resolution body may need to examine the entire authentication process.
Technical evidence can be decisive.
Depending on the fraud method, relevant records may include:
login timestamps, device registration information, mobile application activation history, failed login attempts, authentication method, SIM-change records, beneficiary creation history, transfer timestamps and security alerts.
The customer should also preserve all notifications received before and during the fraud.
Electronic banking regulation is built around transaction security and information-system controls, which makes these records highly relevant in disputed unauthorized transactions.
The victim should preserve bank statements, screenshots, transaction notifications, text messages, emails, mobile operator records and communications with the bank.
A detailed timeline should also be prepared.
The timeline should identify the last genuine transaction, time the telephone stopped functioning if relevant, time of any suspicious login notification, time of each unauthorized transfer and time the bank was first informed.
Travel records can also be relevant in certain cases.
For example, where banking records indicate unusual activity inconsistent with the customer’s location or established usage pattern, those circumstances may support further investigation.
That can be particularly important.
Suppose a customer normally makes modest transfers but suddenly:
a new device is activated, several beneficiaries are added, multiple high-value transfers occur and the account balance falls almost to zero.
That transaction pattern may justify close examination of the bank’s fraud-detection systems.
The fact that individual transactions were technically authenticated does not automatically explain whether the overall pattern should have been treated as abnormal.
The customer should request the rejection and reasoning in writing where possible.
The bank’s explanation should then be compared with the technical records.
For qualifying individual banking disputes seeking repayment, the Banking Regulation and Supervision Agency directs customers toward the relevant customer arbitration mechanisms. It also maintains a complaint channel for other matters involving supervised institutions.
The Banks Association of Turkey’s Individual Customer Arbitration Panel examines disputes involving individual customers and member banks.
Judicial remedies remain available where appropriate.
The customer’s nationality is not the decisive issue.
The panel’s jurisdiction is focused on individual banking disputes involving natural persons.
Applications by legal entities are not accepted, and commercial or business-related applications are also outside the panel’s ordinary scope.
Accordingly, a foreign individual whose personal savings were stolen may be in a different procedural position from a foreign-owned company whose corporate account was emptied.
For an application to the Banks Association of Turkey’s individual arbitration mechanism, the customer must first apply to the bank.
The application should include evidence of the bank complaint and documents showing the disputed transactions. The Association also states that the relevant event generally must have occurred within the previous two years for that mechanism.
This makes an immediate written complaint to the bank especially important.
Yes.
The person who steals the funds may face both criminal consequences and a civil obligation to return the money.
However, identifying and recovering money from fraudsters can be difficult.
Cybercriminals frequently route stolen funds through intermediary accounts, withdraw money quickly or move it through multiple payment channels.
For that reason, a victim should not focus exclusively on identifying the criminal.
Potential bank or third-party responsibility should also be examined independently.
That depends on the circumstances.
Some recipient accounts are controlled directly by fraudsters.
Others may belong to people who knowingly allow criminals to use their accounts.
In other cases, an account holder may claim to have been deceived into receiving and transferring the funds.
The knowledge and conduct of the recipient account holder therefore require separate investigation.
Banking records can help trace the money from the victim’s account through subsequent accounts.
No.
A criminal investigation can be extremely important, but it does not automatically result in reimbursement.
Criminal authorities may investigate the cyberattack, identify recipient accounts and obtain technical evidence.
A separate civil or banking-law claim may still be necessary to recover the customer’s loss from a bank or another responsible party.
The two processes should therefore be viewed as complementary rather than interchangeable.
The bank may raise customer negligence as a defense.
But liability cannot necessarily be determined solely from the fact that the customer clicked a link.
The legal analysis should examine what happened afterward.
Did the fraudster obtain only a password?
Was a new device activated?
Was the SIM changed?
Were multiple security barriers bypassed?
Were unusually large transactions completed?
Did the bank’s monitoring systems identify abnormal activity?
The seriousness of each party’s conduct must be evaluated.
A stolen telephone does not automatically make either party responsible.
The investigation should determine whether the device was locked, whether biometric authentication was used, whether mobile banking remained active, whether credentials were known to the thief and whether the bank detected changes in access behaviour.
The speed with which the customer reports the theft is also important.
The analysis may be different.
If the customer personally authorized transfers to a fraudulent investment company, the bank may argue that these were genuine customer-authorized payments even though the customer was deceived about the investment.
That differs from a case where criminals secretly access the account and initiate transfers without the customer’s knowledge.
Distinguishing authorized payment fraud from unauthorized account takeover is therefore critical.
The victim should review the entire account immediately.
Cyber fraud sometimes involves more than stealing an existing balance.
Criminals may activate credit facilities, obtain loans, use overdraft limits or transfer credit-card funds before moving the proceeds away.
Every disputed credit and transfer should be separately identified.
The original currency should be documented.
If the account contained euros, dollars or another currency, statements should show the exact amounts removed.
Currency conversion issues can become important when determining the financial loss and any later reimbursement.
Potentially, depending on the legal basis and proof.
For example, a customer may allege that cyber fraud caused not only loss of the stolen balance but also interest losses, contractual penalties or loss of another transaction.
Additional damages generally require clear evidence of causation and amount.
The customer should therefore preserve documents showing consequential financial loss.
Generally, legal representation can be arranged.
A foreign customer who has returned to another country does not necessarily need to abandon the claim.
Bank correspondence, evidence collection, formal complaints and relevant proceedings can often be handled through appropriately authorized representation.
A foreign customer suddenly loses mobile service.
Shortly afterward, a new mobile banking activation occurs and the account is emptied.
The investigation should compare the mobile operator’s SIM replacement records with the bank’s activation and authentication records.
Specific regulatory safeguards concerning SIM replacement can be central to determining responsibility.
A customer receives a telephone call from someone claiming that suspicious activity has been detected.
The caller convinces the customer to install remote-access software.
Large transfers are then made.
The bank may argue that the customer enabled the attack, but the transaction history and banking security controls should still be examined before responsibility is determined.
A foreign-owned company discovers that several unauthorized transfers occurred overnight.
The account had previously never transferred money to those beneficiaries.
The company should immediately preserve corporate banking authorization records, administrator logs, user-access information and transfer details.
Corporate claims require separate procedural assessment because consumer arbitration procedures are generally intended for individual customers rather than legal entities.
No. Liability depends on the fraud method, authentication process, bank security controls, customer conduct and available evidence.
Not necessarily. Passwords can be stolen or obtained through phishing and malware.
Potentially the fraudster, bank, telecommunications provider or more than one party, depending on the circumstances.
Yes. Turkish banking regulations contain detailed information-system, authentication and electronic transaction-security requirements.
Yes. Depending on the customer’s status and dispute, customer arbitration, regulatory complaint or judicial remedies may be available.
Generally no. The Banks Association of Turkey states that legal entities and commercial disputes are outside that panel’s scope.
Yes. Prior application to the bank and evidence of that application are required.
Not necessarily. Separate civil or banking claims may still be required.
Such records can become important evidence and may be requested through the appropriate legal procedure.
Foreign nationality alone does not determine responsibility. The dispute turns on the banking relationship, security measures, authorization and evidence.
The first priority is to stop further transactions.
The customer should contact the bank immediately, suspend compromised digital banking access and identify every disputed transaction.
If SIM swap is suspected, the mobile operator should also be contacted immediately.
The victim should then create a detailed technical chronology and preserve every available piece of evidence.
A formal written objection should be submitted to the bank rather than relying only on telephone calls.
If the bank refuses reimbursement, the written response should be reviewed against the authentication history, transaction records and applicable electronic banking security requirements.
For qualifying individual customers, banking arbitration procedures may also be available after prior application to the bank.
The key question is not merely whether a password or code was used. The real issue is whether the foreign customer actually authorized the transfers and whether the security systems that were supposed to prevent unauthorized account takeover operated properly.
Firat Fesih Kaya Law Office provides legal assistance to foreign individuals, investors and foreign-owned companies whose Turkish bank accounts have been emptied or otherwise compromised through SIM swap fraud, phishing, remote-access attacks, stolen credentials or unauthorized electronic transfers.
Legal assistance may include reviewing disputed transfers, preparing objections to banks, examining mobile banking authentication records, analyzing SIM replacement issues, requesting technical evidence, assessing bank and telecommunications responsibility, pursuing appropriate banking dispute mechanisms and representing victims in related civil and criminal proceedings.
Foreign victims should obtain legal assessment quickly where substantial money has been stolen, the attack involved a SIM change or new-device activation, the bank rejects reimbursement solely because valid credentials were used or the stolen funds were connected with an important investment or commercial obligation.
Phone: +90 312 434 22 22
Mobile / WhatsApp: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Office: Mevlana Boulevard No:221, Yildirim Tower, Balgat, Cankaya, Ankara, Turkey
The key 2026 principle is clear: when cybercriminals empty a foreign customer’s Turkish bank account, liability cannot be determined solely from the fact that electronic authentication succeeded. The fraudster is primarily responsible for the theft, but the bank, telecommunications provider or customer may also bear responsibility depending on the authentication process, security failures, SIM replacement procedure, customer conduct and transaction history. A proper claim requires reconstruction of the attack through technical evidence rather than assumptions.