

Phishing Fraud Against Foreigners in Turkey: Criminal Complaint and Evidence Guide 2026
Victim of phishing fraud in Turkey? Learn how foreign residents, investors and bank customers can preserve fake websites, SMS, email and banking evidence, file a criminal complaint, trace stolen funds and pursue recovery in Turkey in 2026.
A foreign national in Turkey may receive an SMS that appears to come from a bank, courier company, public institution, toll-payment service, cryptocurrency platform or online marketplace. The message contains a link and warns that immediate action is required.
The victim opens the link.
The website looks genuine.
The victim enters a password, card number, banking information or verification code.
Within minutes, money begins leaving the victim’s account.
This is a typical phishing fraud scenario.
Phishing should not be treated merely as a suspicious email or text message. A sophisticated attack may combine a fake website, stolen personal information, malicious software, telephone calls, compromised banking credentials, money-mule accounts and cryptocurrency transfers.
Turkey’s General Directorate of Security expressly describes phishing-style conduct in its explanation of technology-assisted aggravated fraud: fake emails and websites may be used to obtain users’ information and then exploit that information for financial gain.
The risk is particularly current in 2026. In June 2026, the Istanbul Anatolian Chief Public Prosecutor’s Office announced an investigation involving fake websites imitating the identities of the national postal service and highway toll system. Victims allegedly received messages claiming that they had an unpaid toll debt or an undelivered parcel. Prosecutors reported 47 identified victims, extensive digital material and approximately TRY 1 billion in transaction volume in suspect accounts between 2020 and 2026.
For a foreign victim, the immediate strategy should therefore be:
Stop further loss → preserve the phishing evidence → secure compromised accounts → identify every transaction → file a detailed criminal complaint → trace the stolen funds.
Phishing generally involves impersonating a trusted person, company or institution to deceive a victim into revealing sensitive information or transferring money.
The fraudulent message may appear to come from:
The message usually creates urgency.
Examples include:
“Your bank account has been suspended.”
“An unauthorized payment was detected.”
“Your package cannot be delivered.”
“You have an unpaid road toll.”
“Your residence permit payment is outstanding.”
“Your cryptocurrency account requires verification.”
The victim is then directed to a fraudulent website.
A typical chain may be:
SMS or email → Fake website → Credentials entered → Authentication intercepted → Bank account accessed → Money transferred → Mule account → Cash or cryptocurrency
Each stage can generate evidence.
The criminal complaint should reconstruct the complete chain rather than simply stating:
“I clicked a fake link and lost money.”
SMS phishing is often referred to as “smishing.”
A foreign resident may receive:
“Your package could not be delivered. Pay TRY 14.90 here.”
The small amount makes the request appear harmless.
But the purpose may actually be to collect:
The June 2026 official Turkish investigation concerning fake postal-service and toll-system websites demonstrates that this type of impersonation is not merely theoretical. Prosecutors reported that victims had been directed through messages to fraudulent websites created by imitating institutional identities.
Another common message states:
“Your bank account has been restricted due to suspicious activity. Verify immediately.”
The website may copy:
The visual appearance of a website does not prove that it belongs to the genuine bank.
A sophisticated attack may combine phishing and telephone fraud.
For example:
10:00 — Victim receives fake bank SMS.
10:05 — Victim enters information into fake website.
10:15 — Fraudster calls pretending to be bank security.
10:20 — Victim receives genuine SMS verification code.
10:21 — Fraudster asks victim to read the code.
10:25 — Unauthorized transfer occurs.
This chronology can become central evidence.
A March 18, 2026 official investigation described suspects allegedly impersonating bank employees, creating fear by telling victims that suspicious transactions were occurring, obtaining SMS verification codes and accessing bank accounts. Prosecutors stated that bank movements, communications, victim statements and digital evidence were evaluated together.
Foreign investors are another important target.
The victim sees a sponsored advertisement promising substantial investment returns.
After clicking the advertisement, the victim reaches a professional-looking investment platform.
The victim transfers money.
The platform displays fictitious profits.
Withdrawal later becomes impossible.
In April 2026, the Istanbul Anatolian Chief Public Prosecutor’s Office announced an investigation in which suspects allegedly used sponsored social-media advertisements and phishing methods to direct victims to fake investment websites promising high returns. Financial analysis identified 15 bank accounts and four crypto-asset accounts associated with 27 suspects.
This shows why phishing investigations can require both digital evidence and asset tracing.
Phishing can also occur through apparently ordinary online shopping.
The victim sees a product advertisement, clicks a payment link and reaches a website designed to imitate a legitimate marketplace or payment service.
A January 2026 prosecutor’s announcement described alleged fraud involving fake product advertisements and imitation websites designed to resemble secure-payment systems. The investigation also referred to third-party or foreign-registered GSM lines and rented bank accounts used in the alleged scheme.
Foreign consumers should therefore preserve both the advertisement and the payment page.
Once phishing is suspected, do not repeatedly enter the website simply to investigate it yourself.
The site may:
Preserve what you already have.
Where further technical examination is necessary, it should be conducted appropriately rather than by repeatedly submitting personal information.
Do not immediately delete the phishing message.
Preserve:
Take screenshots, but keep the original message where possible.
If phishing occurred through email, retain the original message.
Important information may include more than what is visible on the screen.
Preserve:
A displayed sender name such as:
“XYZ Bank Security”
does not establish that the email genuinely came from the bank.
The exact website address can be highly important.
Fraudsters often use addresses designed to resemble genuine institutions.
For example, the difference may involve:
Do not preserve only a screenshot of the bank logo.
Preserve the actual website address where possible.
Capture relevant pages such as:
A fraudulent site may later disappear.
Browser history may help establish:
when the victim opened the phishing website and which address was visited.
Do not unnecessarily clear browsing history after discovering the fraud.
Some phishing attacks involve attachments or downloads.
Do not delete suspicious files before considering evidence preservation.
At the same time, do not continue opening or executing potentially malicious files merely to inspect them.
The security of the device should be addressed carefully.
The victim may understandably want to erase everything.
But the device may contain:
A factory reset may make relevant evidence more difficult to preserve.
Security measures should be coordinated with evidence preservation.
If the victim entered banking or email credentials into a phishing page, those credentials should be treated as potentially compromised.
Use genuine official channels to secure:
Do not change credentials through another link supplied by the suspicious message.
Where banking information has been compromised, contact the bank through a verified official channel.
Report:
suspected phishing and any unauthorized transactions.
Preserve:
Prompt action can be particularly important if stolen funds remain in identifiable recipient accounts.
Do not merely write:
“About USD 30,000 was stolen.”
Prepare:
| Transaction | Amount | Recipient | Date/Time |
|---|---|---|---|
| 1 | TRY 200,000 | Account A | 10:41 |
| 2 | TRY 350,000 | Account B | 10:46 |
| 3 | TRY 500,000 | Account C | 10:52 |
Also preserve:
This gives investigators a starting point for financial tracing.
The victim may see:
Recipient: Person A
and assume Person A created the phishing website.
That may or may not be correct.
Cyber-fraud schemes can use money-mule accounts.
Turkish prosecutorial authorities have warned that fraud organizations obtain bank accounts, digital banking credentials and GSM lines from third parties, sometimes by promising income or account-rental payments.
The investigation should therefore ask:
Who owned the account?
Who actually controlled it?
Who transferred the money onward?
Who withdrew it?
Who received a commission?
A typical transaction chain may be:
Foreign victim → Account A → Account B → Account C → Cash
or:
Foreign victim → Account A → Cryptocurrency exchange → USDT → Private wallet
The criminal complaint should seek investigation of the complete financial chain.
Preserve:
A blockchain transaction may remain visible even after the phishing website disappears.
But remember:
Wallet address ≠ automatically identified human suspect.
Investigators may need exchange, banking, device and account records to connect a wallet with an individual.
Turkey introduced a significant criminal-procedure mechanism at the end of 2025 addressing rapidly moving proceeds of specified technology-related offences.
Article 128/A of the Criminal Procedure Code created an account-suspension mechanism aimed at situations in which proceeds from cyber-related offences can quickly move through banks, payment institutions and crypto-asset service providers. Academic analysis published in 2026 identifies Law No. 7571 of December 24, 2025 as the legislation introducing the measure.
The availability and continuation of a particular restriction or seizure depend on the statutory conditions and facts of the individual investigation.
For phishing victims, the practical point is straightforward:
reporting quickly can matter when the stolen money is still identifiable.
The exact criminal classification depends on how the attack was carried out.
Potential issues can include:
Not every phishing case involves every offence.
Likewise, not every person appearing in the financial chain is automatically guilty.
The Turkish National Police describes the use of fake emails and fake websites to obtain personal information and use it for financial gain as a form of technology-assisted aggravated fraud, referring to Article 158 of the Turkish Criminal Code.
The exact provision applicable to an individual case must be determined from the specific conduct and the criminal law in force on the relevant offence date.
Suppose the victim voluntarily enters banking information into a fake website.
The fraudster then uses the credentials to access the genuine bank account.
The case may involve both:
deception of the victim
and
unauthorized digital activity.
The investigation should reconstruct each stage instead of reducing the entire case to a single phishing message.
A useful phishing complaint should tell the story chronologically.
For example:
September 10, 09:30: SMS received.
09:32: Victim opens link.
09:35: Victim enters banking credentials.
09:42: Fake bank employee calls.
09:45: Victim receives verification SMS.
09:47: First unauthorized login or security event.
09:52: TRY 250,000 transferred.
09:55: TRY 400,000 transferred.
10:10: Victim discovers loss.
10:15: Bank notified.
This timeline allows investigators to compare digital and financial records.
Do not simply say:
“I entered my information.”
Specify whether the victim entered:
This helps investigators understand how the later unauthorized activity may have occurred.
Do not delete:
The timing of these messages can be critical.
For example:
“Your password was changed.”
“A new device has been registered.”
“A transfer has been completed.”
These messages can help reconstruct the attack.
Do not conceal this fact.
The criminal complaint should accurately explain why the victim supplied the code.
A fraudster may have said:
“Read this code so we can cancel the fraudulent transaction.”
The fact that the victim voluntarily disclosed a verification code does not by itself prove that the victim intended to authorize the subsequent theft.
The deception that caused the disclosure remains relevant.
Phishing does not always involve unauthorized access.
Sometimes the fake website or adviser instructs the victim:
“Transfer your funds to this protected account.”
The victim personally authorizes the payment.
That does not automatically prevent a fraud investigation.
Turkey’s Ministry of Justice victim-information service explains that fraud involves deceptive conduct causing the victim to act under deception and resulting in an unjust benefit to the perpetrator or another person.
The key issue is why the victim made the transfer.
The Ministry of Justice’s victim-information service states that fraud victims may make a complaint at a police station or prosecutor’s office.
For substantial phishing cases, especially those involving multiple accounts, cryptocurrency or international transfers, the complaint should ideally contain a structured evidence package from the outset.
Yes.
Foreign nationality does not prevent a person from reporting suspected criminal conduct in Turkey.
A foreign victim should make sure that the complaint accurately records:
A foreign victim may explain:
“I entered my password into the fake site, but I did not make the later transfers.”
This is materially different from:
“I personally transferred the money because the fraudster told me to do so.”
Both may involve fraud, but the technical and evidentiary analysis differs.
The victim should not sign a statement whose factual meaning they do not understand.
Do not assume the investigation is impossible.
Other evidence may remain:
The June 2026 investigation concerning fake institutional websites illustrates that digital-material examination can become a substantial component of phishing investigations.
Foreign hosting or domain registration can complicate evidence collection but does not automatically prevent a Turkish criminal investigation where sufficient connections with Turkey exist.
International evidence may require additional cooperation procedures depending on the service provider and jurisdiction involved.
A foreign victim may still have a case connected with Turkey where, for example:
Representation may be possible subject to the appropriate procedural requirements.
Potentially, but no recovery should be guaranteed.
The practical prospects depend heavily on:
Tracing and recovery are different stages.
A criminal complaint seeks investigation of the alleged crime and responsible persons.
Compensation or recovery may also require examination of additional legal routes depending on:
The Ministry of Justice’s victim-information service notes that victims may seek compensation for losses caused by fraud through civil proceedings against the perpetrator.
The appropriate recovery strategy should be determined from the individual case.
No.
Potential bank liability requires separate analysis.
Relevant issues may include:
The fact that a fraudster committed a criminal offence does not automatically determine whether a bank has separate liability.
Phishing can sometimes lead to malicious software or remote-access activity.
Preserve evidence of:
Do not continue operating potentially malicious software merely to collect evidence.
Digital evidence obtained during a criminal investigation must be collected under the applicable procedural safeguards.
On February 12, 2026, the Constitutional Court annulled specified portions of Article 134 of the Criminal Procedure Code concerning searches, copying and seizure of computers and computer records. The Court identified deficiencies involving matters such as examination of digital data, evidentiary integrity, personal-data safeguards and storage or destruction of forensic copies. The annulment was given delayed effect of nine months from publication in the Official Gazette.
This does not mean that all digital evidence collected in 2026 is unlawful.
It means that the exact legal framework in force when a digital search or seizure occurs should be checked carefully.
Never:
If some evidence has disappeared, state that clearly.
A truthful incomplete record is preferable to manufactured evidence.
Once a victim discovers the fraud, sending:
“I am reporting you to the police right now.”
may cause the fraudster to:
Do not make further payments merely to keep the fraudster talking either.
The communication strategy should be coordinated with evidence preservation and financial tracing.
After the original loss, the victim may receive:
“We recovered your stolen funds.”
“Your money is frozen.”
“Pay the release tax.”
“We work with Turkish cyber police.”
This may be another fraud.
Never send additional money merely because an unknown person claims they can recover the original loss.
SMS, email, advertisement, WhatsApp or another method?
Bank, courier, government institution, marketplace or investment company?
Preserve it accurately.
Specify each credential.
Preserve relevant evidence.
Record the number, time and conversation.
Explain why.
Identify security events.
List every transaction.
Record each recipient.
Trace the complete chain where possible.
Preserve wallet and transaction information.
Record exact timing.
Preserve available evidence without exposing additional credentials.
This is central to the recovery strategy.
Phishing remains a significant component of technology-assisted fraud investigations in Turkey.
In June 2026, prosecutors publicly described an investigation involving fake websites imitating postal-service and toll-system identities, messages directing victims to those sites, extensive stolen personal and GSM data, and approximately TRY 1 billion in transaction volume identified in suspect accounts.
In April 2026, prosecutors reported a separate phishing-based investment scheme allegedly using sponsored advertisements to direct victims to fraudulent investment websites; financial analysis identified both bank and crypto-asset accounts associated with suspects.
Turkey’s criminal-procedure framework also entered 2026 with a new Article 128/A account-suspension mechanism introduced in late 2025 to address rapidly moving proceeds of specified technology-related offences. At the same time, the Constitutional Court’s February 2026 decision concerning Article 134 created an important transition in the rules governing forensic searches and seizure of computer data.
For foreign phishing victims, the practical approach in 2026 is therefore:
Preserve the phishing message → preserve the fake website → secure compromised accounts → preserve the device → document every banking transaction → identify recipient accounts → file a structured criminal complaint → trace onward transfers → evaluate available recovery routes.
Yes. Foreign nationality does not prevent a victim from reporting suspected fraud. The Ministry of Justice states that fraud complaints may be made through the police or prosecutor’s office.
No. Preserve the original message, sender information, link, date and time because it may become evidence.
Yes. The fact that information was voluntarily entered does not by itself eliminate fraud where the disclosure was induced through intentional deception.
Potentially. Investigators may examine recipient accounts and subsequent transfers. Official 2026 cases demonstrate the use of financial analysis alongside digital evidence in technology-assisted fraud investigations.
Potentially. SMS, emails, browser records, screenshots, bank transactions, authentication events and digital evidence from suspects or other victims may remain relevant.
Preserve the exchange, asset, blockchain network, wallet addresses and transaction hashes. Cryptocurrency conversion can complicate recovery but does not necessarily eliminate transaction evidence.
Not before considering evidence preservation. Necessary security measures should be taken, but a reset may destroy information relevant to the investigation.
Recovery may be possible but cannot be guaranteed. The result depends heavily on where the money went, reporting speed, whether assets can be identified and secured, and the evidence available.
Potential bank liability requires a separate assessment of authentication, security procedures, transaction circumstances, customer notification and applicable legal rules. A criminal complaint against the fraudsters does not automatically establish bank liability.
The original phishing message, exact website address, browser evidence, banking security notifications, complete transaction records, recipient accounts and any subsequent cryptocurrency or financial movements can all be important. The strongest case usually reconstructs the entire sequence rather than relying on one screenshot.
A phishing case should not be treated simply as a fake SMS or fraudulent website.
A comprehensive investigation may require analysis of the phishing domain, SMS or email, stolen credentials, telephone communications, banking authentication, recipient accounts, money-mule structures, cryptocurrency transactions, malicious software and the subsequent movement of criminal proceeds.
The essential questions are:
Who created or operated the deception? What information was stolen? How was the bank account accessed? Which account received the money? Who actually controlled the receiving account? Where did the funds move afterward? Can the proceeds or other suspect assets still be identified and secured?
Fırat Fesih Kaya Law Office provides legal assistance to foreign residents, investors, executives, employees, students, tourists and international business owners affected by phishing, online banking and cyber fraud connected with Turkey.
Lawyer Fırat Fesih Kaya assists foreign victims with criminal complaints, prosecutor proceedings, phishing evidence preservation, fake website evidence, unauthorized bank transfers, recipient-account tracing, money-mule structures, cryptocurrency transactions and legal strategies concerning recovery of identifiable proceeds.
Early intervention can be particularly important because phishing websites can disappear rapidly while stolen funds may move through several bank accounts or cryptocurrency transactions within hours.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower No:148, 06520 Balgat, Çankaya, Ankara, Turkey
This publication is provided for general informational purposes and does not constitute legal advice. Criminal remedies, evidentiary issues and recovery possibilities depend on the specific phishing method, financial transaction chain, available digital evidence, applicable law and procedural stage of each case.