

Employee Uses Company Bank Account Without Authorization in Turkey: Criminal Remedies 2026
Employee transferred or withdrew money from a company bank account without authorization in Turkey? Learn how foreign companies can preserve banking evidence, trace stolen funds, file a criminal complaint, investigate digital access and pursue asset recovery in 2026.
Discovering that an employee has accessed or used a company’s Turkish bank account without authorization can create an immediate financial and criminal-law emergency. The employee may have transferred money to a personal account, withdrawn cash, paid fictitious suppliers, redirected company funds to relatives, changed payment instructions, used internet banking credentials without permission or transferred money after their banking authority had been revoked.
For a foreign-owned company, the first question should not simply be:
“Did the employee take money?”
The investigation should determine:
Who accessed the account? What authority did that person have? How was access obtained? Which transactions were made? Where did the money go? What was the stated business purpose? Who benefited? What banking and digital evidence can prove the transaction chain?
Depending on these facts, Turkish criminal law may raise different issues, including breach of trust, fraud, offences involving unauthorized access to information systems or other property-related offences. Turkish judicial materials specifically caution that computer-related conduct may overlap with fraud, theft and breach of trust, and that the correct criminal characterization depends on how the conduct occurred.
For the company, the immediate strategy should usually be:
Secure the bank account → Preserve evidence → Identify unauthorized transactions → Trace the money → Preserve digital access records → Determine individual responsibility → File a structured criminal complaint where appropriate → Pursue recovery in parallel.
There is an important difference between an employee who had legitimate access but allegedly misused company money and an employee who never had authority to access the account in the first place.
Possible scenarios include:
These scenarios should not automatically receive the same criminal classification.
If unauthorized activity is continuing, the company should immediately contact its bank through official channels.
Consider reviewing:
The objective is to prevent additional unauthorized transactions without destroying evidence of what already occurred.
A common mistake is immediately deleting every user account associated with the suspected employee.
Access may need to be suspended, but first preserve available records showing:
The company’s bank may hold additional technical records that the company itself cannot access.
Create a transaction schedule rather than making a general accusation.
| Date | Amount | Recipient | Initiated By | Approved By | Description | Concern |
|---|---|---|---|---|---|---|
| 12.02.2026 | €45,000 | Employee | User A | User A | Advance | No authorization |
| 18.02.2026 | €90,000 | Supplier X | User A | User B | Consulting | Supplier unknown |
| 03.03.2026 | €30,000 | Third Party | User A | User A | Expense | No documents |
This schedule can become the foundation of the internal investigation and criminal complaint.
Suppose an employee transfers TRY 5 million from the company account into their own account.
The investigation should not stop there.
Trace:
Company → Employee → Relative → Cash withdrawal
or:
Company → Employee → Cryptocurrency exchange → Digital asset
or:
Company → Employee → Genuine supplier payment
The final destination can materially change the legal assessment.
A transfer to an employee’s personal bank account is important evidence, but it does not automatically prove criminal conduct.
Possible legitimate explanations can include:
The company should compare the transfer with:
A personal transfer without genuine corporate purpose presents a very different evidentiary picture.
Turkish Criminal Code Article 155 addresses situations involving property belonging to another person that was entrusted for safekeeping or a particular use and is subsequently disposed of contrary to that purpose for the benefit of the person or another.
Official Ministry of Justice training material explains the important distinction between breach of trust and theft: in breach-of-trust situations, possession was initially entrusted to the person, whereas theft involves obtaining possession that the offender did not previously have.
This distinction can be especially important for employees who legitimately controlled company money as part of their employment.
Assume a finance manager is authorized to make supplier payments up to TRY 2 million.
The manager transfers TRY 1.5 million to a company secretly owned by a relative and records the payment as:
“Technical consultancy.”
No consultancy service exists.
The relevant questions include:
Having banking authority does not necessarily mean the employee was entitled to use company money for personal purposes.
This is one of the most important distinctions in internal-fraud cases.
An employee may be technically authorized by the bank to make payments.
But that does not necessarily mean every payment is authorized by the company.
For example:
Bank authority: Employee can transfer up to TRY 3 million.
Internal authority: Employee can transfer only against approved supplier invoices.
If the employee transfers money to themselves, the existence of banking authority does not automatically establish a legitimate corporate purpose.
The analysis can be different where the employee allegedly obtained access without authorization.
Examples include:
Turkish judicial training materials recognize that unauthorized computer-based transfers can require analysis under specific information-system or property offences rather than being automatically treated as ordinary fraud.
The exact access method should therefore be documented.
Potentially relevant technical evidence may include:
Ask the bank what records exist and how long they are retained.
Technical evidence should be interpreted carefully.
A corporate office may use:
Therefore:
Account + IP address ≠ automatic identification of the human user.
Combine technical evidence with device, access, timing and workplace records.
Many companies require two employees to approve large transfers.
If a suspicious transaction passed through two approvals, determine:
Who initiated?
Who approved?
What information did the second approver see?
Was the supporting invoice fake?
Were credentials compromised?
The second approver should not automatically be treated as a participant merely because their credentials appear in the transaction.
Suppose a finance employee knows the managing director’s password and uses it to approve a transfer.
Preserve evidence concerning:
Do not fabricate a cybersecurity explanation after discovering the transaction.
Travel records can become useful evidence.
If a disputed payment was supposedly approved from a Turkish office computer while the manager was abroad, preserve:
Travel evidence may be significant, although it does not alone prove who actually initiated the transaction.
Cash transactions can be particularly difficult to trace.
Preserve:
Where relevant and legally available, investigators may seek additional banking or surveillance evidence.
Act quickly because some records may not be retained indefinitely.
Suppose the employee transfers company money to:
The relationship can be relevant, but it does not by itself prove criminal participation by the recipient.
Investigate:
Why was the payment made?
Was there a genuine commercial relationship?
What happened to the money afterward?
An employee may create or use a supplier to extract money from the company.
Investigate:
Do not assume every unfamiliar supplier is fictitious.
Another common scheme involves altering legitimate supplier banking details.
Example:
Real supplier invoice → Employee changes IBAN → Company pays fraudster-controlled account.
Preserve:
Determine whether the change originated internally or through an external cyberattack.
This distinction is critical.
A suspicious transfer may result from:
Dishonest employee
or
External attacker compromising the employee’s email
or
External attacker working with an insider.
Do not accuse the employee solely because their account was used.
Investigate the technical evidence.
A company may discover transactions made after an employee:
Determine:
When did employment end?
When was bank authority revoked?
When were credentials disabled?
When was the transaction made?
This chronology can be central to both criminal and internal-control analysis.
An employee may send customers unauthorized payment instructions.
Example:
“Our bank account has changed. Please pay this new IBAN.”
The account belongs to the employee.
Preserve:
Identify all customers who may have received altered instructions.
Do not accept or reject the explanation automatically.
Check:
The question is whether the claimed entitlement genuinely existed at the time.
An employee may say:
“The company owed me expenses, so I paid myself.”
Even if an underlying receivable existed, unilateral use of company banking authority may raise separate questions.
Determine:
Where the employee allegedly uses deceptive conduct to cause another person to authorize or execute a payment, fraud provisions may become relevant depending on the precise facts.
The classification should follow the evidence.
Do not automatically label every unauthorized company transfer as fraud.
Where an employee accesses banking or company systems without authority, alters data or uses technical access to move funds, information-system offences may also require analysis.
Ministry of Justice judicial materials specifically note that computer-related offences can be confused with or coexist with fraud, theft and breach of trust.
This makes the access method legally significant.
The reverse scenario can also occur.
Suppose company money is transferred to Employee A’s bank account, but Employee A claims someone else controlled the account.
Recent official prosecutorial warnings demonstrate the serious criminal risks associated with allowing third parties to use bank accounts and explain that accounts used for fraud can lead to investigations involving fraud and money-laundering allegations.
Nevertheless, in a criminal case, the evidence should still establish the individual’s actual role rather than relying solely on a bank-account name.
Relevant communications may include:
Preserve complete conversations.
Do not rely only on cropped screenshots.
If the employee used a company laptop or phone, relevant corporate data may need preservation.
Consider:
Evidence collection should respect applicable criminal, employment, privacy and personal-data rules.
Do not attempt to obtain evidence by:
Preserve evidence the company lawfully controls and identify additional evidence for investigators to obtain through lawful procedures.
A useful complaint should be transaction-specific.
For each transaction explain:
Avoid vague statements such as:
“Our employee stole everything.”
A chronology can show:
Employment begins → Banking authority granted → Suspicious supplier created → Transfers begin → Internal audit discovers issue → Access suspended → Complaint filed.
This is often more useful than hundreds of unsorted attachments.
Where money was taken from a Turkish subsidiary’s bank account, the subsidiary itself will ordinarily be central to the loss analysis.
A foreign parent company should therefore review:
Do not assume parent-company ownership automatically eliminates the subsidiary’s separate legal position.
The case becomes more complex where the person is both:
Employee + Director + Authorized signatory.
Banking authority may have been broad.
The investigation should separate:
Technical authority to make the transaction
from
lawful corporate purpose for making it.
Position alone does not prove guilt.
The company should determine:
Individual responsibility matters.
Suppose management initially believes an employee stole €100,000.
Further investigation reveals:
Company → Employee → Supplier
and the employee had been instructed to make an emergency supplier payment using an approved advance.
Bank records can therefore prove innocence as well as wrongdoing.
Even a strong criminal complaint does not guarantee immediate repayment.
The company should consider a parallel recovery strategy.
Depending on the circumstances, this may involve:
Criminal proceedings and financial recovery should be coordinated rather than treated as identical.
Identify whether suspected proceeds may have moved into:
Do not make unsupported allegations about assets.
Build the trace from evidence.
The company may possess its own statements, but additional evidence may be held by the bank.
Potentially relevant records may include:
The criminal complaint can identify the importance of these records so that investigators can consider obtaining them under applicable procedures.
Official Turkish prosecutorial authorities have continued issuing warnings in 2026 concerning misuse of bank accounts in fraud schemes. A February 2026 prosecutor’s announcement specifically warned that third-party use of bank accounts can expose account holders to investigations involving aggravated fraud and laundering allegations.
For companies, this reinforces a practical point: banking authority, actual account control, transaction purpose and the identity of the ultimate beneficiary should be documented carefully.
Recent 2026 Court of Cassation decisions also demonstrate the continuing importance of completing the evidentiary investigation rather than reaching conclusions from incomplete records. In one February 2026 decision involving alleged aggravated fraud and a disputed cheque, the Court required additional investigation into signature authority, the cheque’s origin, genuine comparison signatures and the parties’ commercial relationship.
The same evidence-driven approach is important in internal banking cases:
Do not stop at the account name.
Determine who actually performed, authorized and benefited from the transaction.
After containing the immediate case, review internal controls.
Consider:
A criminal complaint addresses past conduct. Better controls reduce the next loss.
Potentially. The criminal characterization depends on how the employee obtained control of the funds, the scope of authority, purpose of the transfer, recipient, benefit obtained and other evidence. Breach of trust, fraud or computer-related offences may become relevant depending on the facts.
Banking authority does not necessarily authorize use of company money for personal purposes. The permitted corporate purpose and actual transaction should be compared.
Potentially. Article 155 concerns entrusted property used contrary to the purpose for which possession was transferred. The exact application depends on the employee’s relationship with the property and the particular conduct.
The method of unauthorized system access becomes important and may require analysis of information-system and property offences in addition to the financial transaction itself.
The company should use records it lawfully possesses. Additional banking information concerning personal accounts generally requires an appropriate legal basis and may need to be obtained by competent authorities through criminal proceedings.
Check expense records, approvals, receipts, accounting treatment and the amount claimed. The explanation should be tested against contemporaneous evidence.
The relationship is relevant but does not by itself prove criminal participation. Determine the purpose of the transfer, commercial basis and subsequent movement of the money.
Not necessarily. If evidence or assets could disappear, secure lawful access, preserve records and assess the transaction first.
No. Criminal proceedings and financial recovery are related but distinct. Civil, enforcement, employment and protective remedies may also need to be considered.
The strongest cases usually combine bank records, authorization documents, accounting records, digital access evidence, communications and the ultimate destination of the money rather than relying on one piece of evidence.
Unauthorized use of a company bank account can develop rapidly from an internal-control problem into a criminal investigation involving employees, managers, accountants, suppliers, relatives, digital systems and multiple bank accounts.
Fırat Fesih Kaya Law Office provides legal assistance to foreign companies, multinational groups, foreign shareholders and investors dealing with suspected employee fraud and unauthorized banking transactions in Turkey.
Lawyer Fırat Fesih Kaya assists foreign clients with internal investigations, criminal complaints, unauthorized company transfers, breach-of-trust allegations, employee fraud, banking evidence, digital evidence, fictitious suppliers, asset tracing and coordination of criminal and financial recovery proceedings.
Early intervention can be particularly important where the suspected employee still has access to company bank accounts, accounting systems, corporate devices or funds that may be transferred before evidence is secured.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower No:148, 06520 Balgat, Çankaya, Ankara, Turkey
This publication is provided for general informational purposes and does not constitute legal advice. The correct criminal characterization of unauthorized company banking activity depends on the employee’s authority, method of access, purpose of the transaction, recipient, benefit, digital evidence and circumstances of the individual case.