

Foreigners’ Bank Accounts Emptied Through Cyber Fraud in Turkey: Who Can Be Prosecuted? 2026
Was your Turkish bank account emptied through cyber fraud? Learn who may be investigated or prosecuted, including callers, hackers, money mules, account holders and organizers, how stolen funds can be traced, and what foreign victims should do in Turkey in 2026.
A foreign resident, investor, employee, student or business owner in Turkey may open their mobile banking application one morning and discover that the account balance has disappeared.
The unauthorized transactions may have followed a fake bank call, phishing link, SIM swap, stolen password, malicious software, compromised email account or fraudulent mobile-banking access.
The victim’s immediate question is usually:
“Who stole my money?”
Legally, however, the investigation may involve several different people.
The person who contacted the victim may not be the person whose bank account received the stolen money. The receiving account holder may not be the person who withdrew the cash. Another participant may have supplied GSM lines, banking credentials or cryptocurrency accounts. Organizers may remain behind several layers of intermediaries.
Official Turkish investigations in 2026 illustrate this structure. In a March 2026 case, the Istanbul Anatolian Chief Public Prosecutor’s Office reported that suspects allegedly impersonated bank employees, obtained victims’ SMS verification codes, accessed their accounts and moved the proceeds through different accounts. Prosecutors stated that victim statements, banking movements, communication records and digital evidence were evaluated together, and an indictment was prepared under the aggravated-fraud provision.
For foreign victims, the criminal complaint should therefore focus not only on the first person or IBAN discovered, but on reconstructing the entire fraud network.
Depending on the evidence and each person’s conduct, an investigation may examine:
Being investigated does not itself establish guilt.
Criminal responsibility must be assessed individually according to each person’s acts, knowledge, intent and the evidence.
One common structure begins with a telephone call.
The caller says:
“I am calling from your bank’s fraud department.”
The caller may know the victim’s:
The caller then creates panic:
“Someone is trying to empty your account.”
The supposed solution may actually enable the fraud.
If evidence identifies the person who deliberately deceived the victim to obtain money or banking access, that person may become a central suspect.
Official Turkish prosecutorial material from March 18, 2026 describes precisely this type of investigation. Suspects allegedly presented themselves as bank personnel, falsely told victims that suspicious transactions were occurring, obtained SMS verification codes and accessed the victims’ accounts. The proceeds were allegedly moved through different accounts to conceal the financial trail.
This demonstrates why a foreign victim should preserve more than the bank statement.
Preserve:
Call → SMS → Verification code → Banking access → Transfer → Recipient account → Subsequent movement.
Another suspect may have sent:
“Your bank account has been restricted. Verify your identity here.”
The link opens a fake website resembling the genuine bank.
The victim enters:
The attacker then uses those credentials.
Where the evidence establishes deliberate participation, the person responsible for creating, distributing or operating the fraudulent infrastructure may be investigated according to their actual role.
The person who deceived the victim and the person who actually accessed the banking system may be different.
Investigators may therefore examine:
The objective should be to identify the person or device associated with the unauthorized banking activity rather than assuming that the caller performed every technical step.
If the victim’s telephone suddenly stopped receiving calls and SMS messages shortly before the bank account was emptied, SIM swap or another form of number takeover may need to be investigated.
The relevant questions include:
Was a replacement SIM or eSIM activated?
When did the genuine SIM lose service?
Who requested the change?
What authentication occurred afterward?
When was mobile banking accessed?
The telecommunications timeline should be compared with the banking timeline.
Suppose the foreign victim loses TRY 750,000.
Bank records show:
Victim → Account A: TRY 750,000
It is tempting to conclude:
“Account A belongs to the fraudster.”
That conclusion may be premature.
The account holder may be:
The investigation should establish the account holder’s actual conduct.
A bank statement can prove that money entered a particular account.
It does not automatically establish that the registered account holder:
called the victim, created the phishing website, knew the money was criminal proceeds or personally controlled the account when the transfer occurred.
Those questions require further evidence.
At the same time, the registered account holder cannot necessarily avoid scrutiny merely by saying:
“Someone else used my account.”
The explanation must be tested objectively.
Cyber-fraud organizations frequently need bank accounts that are not registered directly to the organizers.
They may recruit people with offers such as:
“Let us use your account for one day.”
“Receive money and keep 5%.”
“We need your IBAN for company payments.”
“Just withdraw the money and give it to us.”
Turkish prosecutors have continued to warn in 2026 that fraud organizations obtain bank accounts, GSM lines and digital banking access from third parties, including through promises of income or account rental.
A May 2026 prosecution announcement from Trabzon also described an investigation in which a suspect allegedly collected and rented bank accounts and supplied those accounts to people committing technology-assisted fraud.
Potentially, depending on what the person intentionally did and knew.
The fact that an account holder never contacted the victim can be important, but it does not automatically end the criminal analysis.
Investigators may ask:
Why did you provide your account?
Who had your mobile banking password?
Did you receive a commission?
Did you transfer the money onward?
Did you withdraw cash?
Were similar transactions repeated?
Did you know the source of the money?
The answers can help distinguish an innocent account holder from a knowing participant.
Suppose a university student responds to a fake employment advertisement:
“International payment assistant needed. Salary plus commission.”
The student is instructed to receive money and forward it.
The student may later discover that the incoming funds came from cyber-fraud victims.
That does not mean the student’s explanation must automatically be accepted.
But it also does not mean criminal intent should automatically be inferred merely because the money entered the student’s account.
Relevant evidence may include:
Individual criminal responsibility requires an individual evidentiary assessment.
Suppose:
Victim → Account A → ATM withdrawal
The person visible at the ATM may become highly relevant.
Investigators may examine:
If Account A belongs to one person but another person repeatedly withdraws the proceeds, that can help investigators reconstruct actual control over the account.
Another common chain is:
Victim → Account A → Account B → Account C
The investigation should determine why each transfer occurred.
A person who knowingly transfers criminal proceeds onward may have a materially different position from someone whose account was accessed without authorization.
Bank records provide the financial path.
Messages, devices, authentication records and surrounding circumstances can help explain why the transfers occurred.
Cyber-fraud proceeds may be moved:
Victim → Mule account → Cryptocurrency exchange → USDT → Private wallet
The people involved in acquiring, transferring or controlling the crypto assets may also become relevant to the investigation.
Preserve:
A wallet address shows a blockchain destination.
It does not automatically prove the real-world identity of its controller.
Potentially.
Blockchain records may allow investigators or forensic specialists to reconstruct movements between wallets.
If funds enter an identifiable cryptocurrency service provider, account records may create additional investigative leads.
But three questions must remain separate:
Can the transaction be traced?
Can the person controlling the wallet be identified?
Can the asset ultimately be recovered?
A positive answer to the first question does not guarantee the other two.
Cyber-fraud networks may be divided into roles.
One person may recruit account holders.
Another may make calls.
Another may manage phishing infrastructure.
Another may coordinate bank transfers.
Another may convert proceeds into cryptocurrency.
An organizer therefore should not automatically escape investigation merely because the stolen money never entered an account registered in that person’s name.
The relevant issue is whether evidence establishes intentional participation in the criminal conduct.
A fraud scheme may use a corporate bank account rather than a personal account.
The investigation should distinguish between:
the company, shareholders, directors, authorized banking users, employees and the people who actually controlled the transaction.
Corporate status does not automatically make every director or shareholder personally criminally responsible.
Investigators should determine who authorized, controlled or knowingly facilitated the relevant transactions.
Recent 2026 enforcement demonstrates the scale such investigations can reach.
In a 2026 Adana-centered operation concerning alleged technology-assisted aggravated fraud and laundering of criminal proceeds, the Ministry of Interior reported that suspects allegedly used shell companies described as investment, finance and cryptocurrency advisory businesses. Following financial analysis, authorities reported seizure measures involving 692 bank accounts and eight cryptocurrency accounts, together with other assets.
Similarly, Bursa police reported a 2026 investigation involving alleged investment fraud and laundering in which hundreds of bank accounts connected with suspects and legal entities became subject to judicial seizure measures.
For a foreign victim, this demonstrates why a complaint should seek investigation beyond a single recipient IBAN where the evidence suggests a broader network.
The exact legal classification depends on the conduct.
Depending on the facts, a cyber-fraud investigation may involve allegations concerning:
It would be incorrect to assume that every person in the transaction chain committed every possible offence.
Each suspect’s conduct must be classified separately.
Article 158 of the Turkish Criminal Code regulates aggravated forms of fraud, including fraud committed by using information systems or banks or credit institutions as instruments. The current consolidated text should always be checked against the date of the alleged offence because criminal provisions can be amended over time.
In the March 2026 bank-impersonation investigation discussed above, prosecutors specifically reported preparing an indictment under Article 158/1-l based on the alleged conduct in that case.
The precise subsection applicable to another cyber-fraud case depends on its facts.
Potentially, where the statutory elements are supported by the evidence.
Cyber-fraud proceeds may be moved through multiple accounts, companies, cash withdrawals or cryptocurrency in an attempt to conceal their origin or ownership.
But the mere fact that money passed through several accounts should not automatically be described as money laundering.
Knowledge, conduct and the applicable statutory elements still need to be established.
Official 2026 operations show that laundering allegations can accompany technology-assisted fraud investigations where financial evidence supports that broader theory.
Yes, potentially, as part of reconstructing the crime.
Investigators may need records from the victim’s account to establish:
Obtaining and examining the victim’s banking records does not mean the victim is accused of the offence.
Turkey’s current Criminal Procedure Code contains Article 128/A, which establishes a mechanism concerning qualifying accounts at banks, payment service providers and crypto-asset service providers where the statutory conditions are satisfied.
The provision also addresses situations in which suspected criminal proceeds are transferred to another financial institution before the suspension process is completed.
This is particularly relevant to cyber fraud because money can move rapidly from the first recipient to several additional accounts.
Potentially.
Current Article 128/A provides that where seized criminal proceeds are determined to belong to the injured victim, they can be returned to the owner during the investigation or prosecution.
This does not guarantee that every cyber-fraud victim will recover the stolen money.
The proceeds must first be identified, located and secured, and the factual and legal requirements must be satisfied.
Consider two cases.
The foreign victim discovers the fraud within an hour.
Victim → Account A
The money remains there.
The victim discovers the fraud several weeks later.
Victim → Account A → Account B → Account C → Crypto exchange → Private wallet
The second case can be significantly more difficult.
Prompt reporting cannot guarantee recovery, but delay can materially complicate asset tracing.
A serious investigation may combine:
Banking evidence
Incoming and outgoing transactions, recipients, withdrawals and subsequent transfers.
Telecommunications evidence
Relevant telephone and subscriber information.
Digital banking evidence
Login events, authentication records and device information.
Digital devices
Phones, computers, routers and other equipment.
Communications
WhatsApp, Telegram, SMS, email and other messages.
ATM evidence
Withdrawal information and available surveillance footage.
Cryptocurrency evidence
Exchange accounts, wallet addresses and transaction hashes.
Victim statements
How the deception occurred.
The March 2026 Istanbul investigation is a useful practical example: prosecutors stated that victim statements, bank movements, communication records and digital evidence were evaluated together.
A bank statement may show:
Victim → Ahmet’s account
But the investigation may later establish:
Fraud organizer → Account recruiter → Ahmet’s account → Another person withdraws cash.
That is why the criminal complaint should not stop at:
“Prosecute the owner of this IBAN.”
It should request investigation of the entire transaction and communication chain.
That possibility should be objectively investigated.
Relevant evidence may include:
A genuine compromise and a fabricated “my account was hacked” explanation can produce very different evidentiary pictures.
This increases the need for careful investigation.
Questions include:
Why was access provided?
For how long?
Was money expected?
Was commission paid?
Did the account holder monitor transactions?
Did they withdraw or transfer funds?
Did they continue after becoming suspicious?
No single answer automatically determines criminal liability.
Suppose one person receives a single unexplained payment.
That may require investigation.
Now suppose the same account receives payments from 40 unrelated fraud victims and immediately transfers each payment onward while retaining a percentage.
The evidentiary picture is materially different.
Patterns can matter.
Possible recovery routes depend on the circumstances and should be analyzed separately from criminal guilt.
Questions can include:
A criminal complaint should therefore be coordinated with the money-recovery strategy.
No automatic conclusion should be drawn.
Potential bank responsibility requires separate analysis of matters such as:
Criminal prosecution of fraudsters and a potential claim involving the bank are distinct legal questions.
Potential telecommunications-provider issues may also require separate examination.
Relevant questions include:
The timeline can be crucial.
If the fraudster communicated in English, Arabic, Russian, Persian, French or another language, preserve the original messages.
Translations can later be prepared where necessary.
Do not replace the original evidence with translated screenshots.
Do not:
Necessary account-security measures should be taken without unnecessarily destroying evidence.
A victim who discovers the recipient’s name may want to send:
“Return my money immediately or I will have you arrested.”
This can be counterproductive.
It may cause funds to move, accounts to close or communications to disappear.
The recovery strategy should be coordinated with evidence preservation and the criminal process.
Telephone, SMS, WhatsApp, email, website or another channel?
Fake bank security warning, investment opportunity, phishing or another method?
This may identify another participant.
Compare telecommunications and banking records.
Technical records may help.
Identify the complete IBAN.
Ownership and control should be distinguished.
This can be relevant to knowledge and intent.
Trace every subsequent transfer.
Identify ATM activity.
Preserve blockchain evidence.
Identify directors and actual banking users separately.
Patterns can reveal a larger scheme.
This can lead beyond intermediaries.
This question is central to recovery.
Technology-assisted fraud remains an active enforcement area in Turkey in 2026.
Official investigations this year have involved fake bank calls, investment fraud, rented bank accounts, shell companies, hundreds of bank accounts, cryptocurrency accounts and alleged laundering of criminal proceeds.
The current criminal-procedure framework also includes Article 128/A, which provides mechanisms for rapid action concerning qualifying suspicious financial accounts and for seizure of suspected proceeds under the conditions specified by law. The provision further permits return of seized proceeds when they are established to belong to the victim.
For foreign victims, the key lesson is:
Do not investigate only the caller.
Do not investigate only the first IBAN.
The complete chain may be:
Fraud organizer → Caller or phishing operator → Banking-access participant → Money-mule account → Transfer intermediary → Cash withdrawal or crypto conversion → Ultimate beneficiary.
Each person’s potential criminal responsibility must then be determined from their own conduct, knowledge, intent and the evidence.
Potential suspects can include the person who deceived you, people who obtained or used your banking credentials, knowing account providers or money mules, people who transferred or withdrew the proceeds, organizers and other intentional participants. Criminal responsibility must be established individually.
No. The account owner is an important investigative lead, but ownership alone does not establish that the person personally deceived you or knowingly participated in the fraud.
Potentially, depending on what they knowingly and intentionally did. Turkish authorities are actively warning about bank-account rental and money-mule arrangements in 2026.
Potentially, yes. A victim can voluntarily execute a transfer because of intentional deception. The relevant representations, intent and surrounding evidence must be examined.
Potentially. Official 2026 investigations show extensive examination of banking movements and multiple accounts in technology-assisted fraud cases.
Yes, potentially. Exchange records, wallet addresses and transaction hashes may provide investigative leads. Tracing a transaction, identifying a wallet controller and recovering the asset are separate questions.
Potentially, where the statutory requirements for the applicable suspension or seizure mechanism are satisfied. Article 128/A is particularly relevant to qualifying technology-related offences.
Article 128/A provides for return of seized criminal proceeds where they are established to belong to the victim. Application in an individual case depends on the facts and procedural status.
Potentially, but bank responsibility requires a separate analysis of authentication, security measures, transaction circumstances, notifications and applicable legal rules. Criminal prosecution of fraudsters does not automatically establish bank liability.
Secure the bank and related digital accounts, preserve the phone and communications, document every unauthorized transaction, identify recipient accounts, preserve telecom and crypto evidence where relevant, and consider prompt criminal reporting and asset tracing.
When a foreigner’s Turkish bank account is emptied through cyber fraud, identifying the first recipient is only the beginning.
A comprehensive investigation may require analysis of fake bank calls, phishing messages, SIM changes, mobile-banking access, authentication records, recipient accounts, money mules, ATM withdrawals, companies, cryptocurrency exchanges, private wallets and the people coordinating the scheme.
The essential questions are:
Who deceived the victim? Who obtained the banking credentials? Who accessed the account? Who received the stolen money? Who actually controlled the receiving accounts? Who transferred or withdrew the proceeds? Who ultimately benefited? Which proceeds or other assets can still be identified and secured?
Fırat Fesih Kaya Law Office provides legal assistance to foreign residents, investors, executives, employees, students, tourists and international business owners whose Turkish bank accounts have been targeted by cyber fraud.
Lawyer Fırat Fesih Kaya assists foreign victims with criminal complaints, prosecutor proceedings, bank and digital evidence preservation, recipient-account tracing, money-mule investigations, SIM swap cases, cryptocurrency transactions, asset tracing and legal strategies for recovery of identifiable proceeds.
Early intervention can be especially important because cyber-fraud proceeds may move through several accounts, cash withdrawals or cryptocurrency transactions within a short period.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower No:148, 06520 Balgat, Çankaya, Ankara, Turkey
This publication is provided for general informational purposes and does not constitute legal advice. Criminal responsibility, bank or telecommunications-provider liability and recovery possibilities depend on the conduct of each participant, available evidence, location of the proceeds, applicable law and procedural stage of the individual case.