

SIM Swap Fraud in Turkey: Criminal Remedies for Foreign Bank Customers — 2026 Guide
Victim of SIM swap fraud in Turkey? Learn what foreign bank customers should do after unauthorized mobile banking transfers, how to preserve telecom and banking evidence, file a criminal complaint, trace stolen money and pursue recovery in Turkey in 2026.
A foreign bank customer living, working, studying or investing in Turkey may suddenly discover that their mobile phone has lost network service. Calls no longer work, SMS messages stop arriving and the device displays “No Service.”
A few hours later, the customer discovers something much more serious: money has disappeared from a Turkish bank account.
This can be a warning sign of SIM swap fraud.
In a SIM swap scheme, criminals may attempt to obtain control of the victim’s mobile telephone number and use that control as part of a broader attack against online banking, email, payment or other digital accounts. Turkey’s official cybercrime investigation guidance expressly recognizes criminals’ attempts to undermine additional authentication measures by exploiting mobile numbers or duplicating SIM cards.
For a foreign bank customer, the first hours can be crucial because the case may simultaneously involve a telecommunications provider, bank, recipient accounts, digital evidence and a criminal investigation.
The practical strategy should usually focus on four priorities:
Secure the mobile number → secure the bank account → preserve technical and financial evidence → trace the stolen money.
SIM swap fraud generally involves unauthorized control over a victim’s mobile telephone number.
Once the criminal gains control of the number, SMS messages and verification codes intended for the genuine customer may be redirected to another SIM.
The attacker may then attempt to use the number to:
SIM control alone does not necessarily give a criminal automatic access to every bank account. A successful attack may also require passwords, identity information, phishing, malware, social engineering or other compromised credentials.
The investigation therefore needs to determine exactly how the attack occurred.
Warning signs may include:
A lost network connection does not automatically prove fraud, but when it coincides with unauthorized banking activity it should be investigated immediately.
Consider a foreign executive who has TRY 2 million in a Turkish bank account.
At 10:30 a.m., the executive’s mobile phone unexpectedly loses service.
At 11:15 a.m., a replacement SIM is activated without the customer’s knowledge.
At 11:40 a.m., mobile banking credentials are reset.
Between noon and 12:20 p.m., four transfers are made:
TRY 300,000 → Account A
TRY 450,000 → Account B
TRY 500,000 → Account C
TRY 600,000 → Account D
The money is then transferred onward.
The case should not be investigated merely as “someone stole my SIM card.”
The complete sequence may be:
Identity compromise → unauthorized SIM replacement → authentication interception → banking access → unauthorized transfers → intermediary accounts → withdrawal or cryptocurrency conversion.
Each stage may generate different evidence.
If the mobile number unexpectedly stops working, contact the telecommunications provider through a verified official channel.
Ask whether:
Turkey’s banking-industry fraud guidance recommends that customers who discover that their SIM is not working promptly check with the operator whether another SIM has been issued and arrange cancellation where appropriate. It also recommends informing banks so protective measures can be taken.
Potentially important records may include:
Not every item will necessarily be directly provided to the customer. Some evidence may need to be obtained during the criminal investigation through the appropriate legal procedure.
The immediate goal is to prevent potentially relevant information from being overlooked.
Do not contact only the bank from which money has already disappeared.
If the compromised mobile number is registered with several Turkish banks, notify each relevant institution.
Tell the bank that:
the mobile number may have been compromised and unauthorized financial activity may have occurred.
Ask the bank to take appropriate security measures.
Preserve the time and reference number of the notification.
Create a transaction table immediately.
For example:
| Time | Amount | Destination | Method |
|---|---|---|---|
| 12:03 | TRY 300,000 | Account A | Transfer |
| 12:07 | TRY 450,000 | Account B | Transfer |
| 12:12 | TRY 500,000 | Account C | Transfer |
| 12:19 | TRY 600,000 | Account D | Transfer |
Do not simply state:
“Approximately TRY 2 million was stolen.”
Exact transactions are much more useful for asset tracing.
Do not automatically factory-reset the device.
The phone may contain:
A destructive reset may make evidence preservation more difficult.
If immediate security measures are necessary, they should be considered together with the need to preserve relevant evidence.
Record when the phone stopped functioning.
Useful material can include:
A contemporaneous record can help establish the timeline.
A SIM swap investigation should compare telecommunications events with banking events.
For example:
09:45 — Victim receives phishing call
10:30 — Genuine SIM loses service
11:12 — Replacement SIM activated
11:35 — Banking password reset
11:41 — New banking session begins
12:03 — First unauthorized transfer
12:19 — Final unauthorized transfer
12:30 — Funds begin moving through intermediary accounts
That chronology can be significantly more useful than evaluating each event separately.
Potentially, yes.
A criminal investigation can examine relevant telecommunications, financial and digital evidence under the applicable legal procedures.
The Ministry of Justice’s cybercrime investigation guidance specifically identifies SIM duplication as a method criminals may use to undermine verification systems.
The precise evidence available depends on the operator, the method used and the facts of the case.
That may become an important part of the investigation.
Traditional SIM-replacement fraud can involve an attacker impersonating the genuine subscriber to obtain another SIM. Turkey’s banking-sector fraud guidance describes schemes in which criminals use fraudulent identification while claiming that the genuine customer’s phone was lost or stolen.
Investigators may therefore need to determine:
Where was the replacement requested?
What identity information was presented?
What verification process was used?
Who performed or approved the transaction?
What records remain?
The same broad investigative principle applies: establish how control of the telephone number was changed and what authentication events followed.
Do not assume that every number-takeover incident requires a physical plastic SIM card.
The technical process should be established from the operator’s records.
Unauthorized use of identity information may extend beyond the known SIM.
BTK states that subscribers can check active mobile lines registered in their names through the relevant government electronic service.
For a foreign customer who suspects identity misuse, checking for unknown registered lines can therefore be relevant.
A criminal may already possess:
The SIM takeover may merely provide the final authentication component.
A complete investigation should therefore ask how the attacker obtained the other credentials.
Review the period before the attack.
Did the victim receive:
The SIM swap may have been preceded by social engineering.
Foreign customers should also be cautious where a caller appears to use a genuine-looking Turkish telephone number.
Official information provided to the Turkish Parliament in 2026 explains that caller-line information can technically be manipulated and that regulatory measures are used to address calls that create the appearance of originating from Turkish banks or public institutions.
A displayed telephone number should therefore not be treated as definitive proof that a call genuinely came from a bank or government institution.
Depending on the precise conduct and statutory elements, technology-assisted banking fraud can potentially be investigated under aggravated-fraud provisions.
The Turkish National Police describes aggravated interactive fraud as fraud committed through information systems or banks and credit institutions, including schemes where fake websites obtain personal information that is then used to obtain a benefit.
The final criminal classification, however, depends on the specific acts and evidence.
SIM swap should not automatically be treated as one predetermined offence in every case.
Depending on the facts, investigators may need to examine conduct involving:
Each person’s role must be established separately.
The account receiving the stolen money, for example, may belong to an intermediary rather than the person who engineered the SIM takeover.
Potentially.
Suppose the money moves:
Victim → Account A → Account B → Account C
The investigation can focus on the financial trail.
Recent Turkish prosecutorial warnings also describe the use of bank accounts and GSM lines obtained from third parties as part of fraud structures.
This makes it important to investigate beyond the first receiving account.
The person whose IBAN received the money may claim:
“I gave my account to someone else.”
That claim does not automatically resolve the case.
Investigators may examine:
For the victim, the practical point is that the first IBAN may be only the beginning of the asset-tracing process.
Identify the withdrawal quickly.
Relevant evidence may include:
Because surveillance footage may not be retained indefinitely, delay can matter.
The investigation should preserve the transition from banking to cryptocurrency.
For example:
Victim account → Mule account → Crypto exchange → USDT → Private wallet
Relevant evidence may include:
Cryptocurrency conversion does not automatically erase the financial trail.
Turkey’s Financial Crimes Investigation Board updated suspicious-transaction reporting guidance in September 2025 following the updated National Risk Assessment. Obliged institutions continue to operate within this framework in 2026.
This does not mean that every unusual transaction is automatically criminal or recoverable.
It means that banks and other obliged entities operate within anti-money-laundering monitoring and reporting obligations that can intersect with fraud investigations.
Depending on the circumstances and applicable statutory conditions, Turkish criminal procedure provides mechanisms for restricting accounts and securing suspected criminal proceeds.
For a victim, speed can be critical.
Consider:
Scenario A: TRY 500,000 remains in the first receiving account.
Scenario B: TRY 500,000 has moved through five accounts, been withdrawn and converted into cryptocurrency.
Scenario B is ordinarily much more complicated.
Prompt criminal reporting cannot guarantee recovery, but delay can materially affect the practical tracing situation.
Potentially, but recovery should never be guaranteed.
The answer depends on questions such as:
Criminal investigation and money recovery are closely related, but they are not the same thing.
This is a critical issue in a SIM swap case.
The existence of a technically valid SMS authentication event does not by itself answer:
Who controlled the telephone number when the code was received?
The timeline should compare:
If the genuine customer had already lost control of the mobile number before the authentication event, that fact can become highly relevant.
Again, the technical mechanism should be examined.
The investigation may need to determine whether:
“Authenticated transaction” and “transaction personally authorized by the genuine customer” are not necessarily identical factual propositions.
Possible claims against a bank require a separate legal assessment.
Relevant questions can include:
A criminal complaint against the fraudsters does not automatically establish bank liability.
Likewise, the bank’s rejection of reimbursement does not necessarily determine the criminal case.
Potential claims involving the telecommunications provider also require case-specific analysis.
Important questions may include how the unauthorized SIM change occurred, what identity verification was performed, what records exist and whether applicable duties were followed.
Criminal responsibility of fraudsters, potential bank liability and potential telecommunications-provider liability are legally distinct issues.
Keep:
These documents can later help establish when each institution was notified and how it responded.
The complaint should reconstruct the attack rather than merely state:
“My SIM was copied and my money was stolen.”
Explain chronologically:
Normal use of telephone → suspicious contact if any → loss of mobile service → unauthorized SIM/eSIM event → banking security event → unauthorized transactions → discovery → bank notification → operator notification → subsequent money movements.
Attach the supporting evidence in the same order.
A practical evidence file may contain:
Evidence 1: Passport/identification information
Evidence 2: Proof of ownership/use of mobile number
Evidence 3: Operator records available to customer
Evidence 4: Screenshot showing service loss
Evidence 5: Bank security notifications
Evidence 6: Password-reset notifications
Evidence 7: Unauthorized transaction list
Evidence 8: Bank statements
Evidence 9: Recipient IBAN information
Evidence 10: Suspicious SMS, email or WhatsApp messages
Evidence 11: Bank complaint record
Evidence 12: Operator complaint record
Evidence 13: Cryptocurrency records, if applicable
Yes. Foreign nationality does not prevent a person from reporting suspected criminal conduct connected with Turkey.
The jurisdictional and procedural route depends on the individual facts.
Foreign victims should ensure that their telephone number, passport information, bank details, transaction amounts and dates are recorded accurately.
The investigation may still have substantial Turkish connections where:
Cross-border evidence may require additional procedures depending on where relevant persons, service providers and records are located.
If phishing messages, emails or communications are in English, Arabic, Russian, Persian, French or another language, preserve the originals.
Translations can be prepared where necessary, but the original evidence should remain available.
Do not replace the original with a translated screenshot.
Once passwords and accounts are secured, victims sometimes delete everything associated with the fraud.
Avoid destroying potentially relevant evidence.
Preserve suspicious:
A victim may locate the name attached to the receiving IBAN and immediately send:
“Return my money or I will have you arrested.”
That may not be strategically useful.
The recipient could be a money mule, identity-theft victim or active participant.
Uncoordinated contact may also cause funds or evidence to move.
SIM swap victims can become targets of a second scam.
Someone may claim:
“We recovered your bank funds.”
“Pay a processing fee.”
“We work with the prosecutor.”
Do not send money to an unknown person merely because they claim to be able to recover the original loss.
The exact time can be critical.
Obtain confirmation where possible.
This may require operator evidence.
Investigators may need to examine the verification process.
Preserve them.
Record the time.
This can be an important technical event.
Compare them with the SIM takeover timeline.
List every one separately.
Record each IBAN.
Follow the transaction chain.
Identify ATM information.
Preserve exchange and blockchain evidence.
Document exact times.
SIM takeover can extend beyond one bank.
SIM swap fraud sits at the intersection of cybercrime, telecommunications evidence, banking authentication and financial tracing.
Turkey’s official cybercrime investigation guidance recognizes SIM duplication as a method criminals may use to defeat additional authentication measures. Turkey’s banking-sector fraud guidance likewise describes fraudulent replacement-SIM scenarios and recommends immediate contact with both the telecommunications provider and banks when a customer discovers a possible SIM compromise.
Current prosecutorial warnings also emphasize that fraud organizations can obtain and use third-party bank accounts, digital banking credentials and GSM lines to obscure the identity of the principal offenders.
For a foreign bank customer in 2026, an effective response should therefore not focus exclusively on the stolen SIM.
It should reconstruct the complete chain:
Identity compromise → SIM takeover → banking authentication → unauthorized transfer → recipient account → onward transfer → cash or cryptocurrency → suspect identification and asset recovery.
Contact your mobile operator and relevant banks through verified official channels immediately. Secure the affected accounts while preserving evidence of the SIM failure and unauthorized transactions.
Potentially, yes. Relevant operator, financial and digital evidence can be investigated through applicable criminal-procedure mechanisms.
Potentially. Investigators can examine the financial trail through recipient and subsequent accounts. The practical difficulty increases as funds are withdrawn, transferred repeatedly or converted into other assets.
Not necessarily. In a genuine SIM takeover case, a central question is who controlled the mobile number when the authentication code was received.
Recovery may be possible, but it cannot be guaranteed. Speed, location of the proceeds, recipient accounts, subsequent transfers and identifiable assets can all affect the outcome.
Potential bank liability requires a separate assessment of the authentication process, security measures, transaction pattern, notification timeline and applicable legal framework. Criminal liability of the fraudster and civil or contractual liability of the bank are distinct questions.
Potential liability requires analysis of how the replacement occurred, the applicable verification process and the evidence available in the individual case.
Preserve the exchange information, blockchain network, wallet address and transaction hash. Cryptocurrency conversion may complicate recovery but does not necessarily eliminate the transaction trail.
Not before considering evidence preservation. A reset may destroy information relevant to the investigation. Necessary security measures should be coordinated with preservation of potentially important evidence.
Potentially, yes. A Turkish bank account, Turkish mobile number, recipient accounts, suspects or assets can create significant connections with Turkey. The appropriate procedure depends on the individual facts.
A SIM swap case should not be treated merely as a telecommunications complaint.
A substantial case may require coordinated examination of the SIM replacement, identity-verification process, banking authentication, password resets, new device registrations, SMS codes, unauthorized transfers, money-mule accounts, ATM withdrawals, cryptocurrency transactions and other digital evidence.
The central questions are:
Who obtained control of the mobile number? How was control obtained? When did the genuine customer’s SIM stop working? How was banking access achieved? Which accounts received the stolen money? Where did the proceeds move afterward? Can the proceeds or other assets still be identified and secured?
Fırat Fesih Kaya Law Office provides legal assistance to foreign bank customers, foreign residents, investors, executives, employees, students and international business owners affected by SIM swap, online banking and identity-related fraud connected with Turkey.
Lawyer Fırat Fesih Kaya assists foreign victims with criminal complaints, prosecutor proceedings, preservation of telecom and banking evidence, unauthorized-transfer investigations, recipient-account tracing, money-mule structures, cryptocurrency transactions and strategies concerning recovery of identifiable proceeds.
Early action can be particularly important because stolen funds may move through several accounts within hours while telecommunications and digital records can become increasingly difficult to reconstruct as time passes.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower No:148, 06520 Balgat, Çankaya, Ankara, Turkey
This publication is provided for general informational purposes and does not constitute legal advice. Criminal remedies, potential claims against financial or telecommunications institutions and money-recovery options depend on the facts, evidence, transaction structure, applicable law and procedural stage of each individual case.