

Foreign companies targeted by CEO fraud and fake payment instructions in Turkey may face substantial financial losses. Learn about urgent bank action, criminal complaints, digital evidence, account tracing, asset recovery and legal remedies.
CEO fraud has become a serious risk for foreign companies conducting business in Turkey. Criminals may impersonate a chief executive officer, director, shareholder, supplier or senior finance executive and instruct an employee to transfer money to a fraudulent bank account. These schemes may involve fake emails, compromised corporate accounts, forged invoices, manipulated payment instructions, WhatsApp messages, spoofed domains or sophisticated social-engineering techniques.
When money has already been transferred, speed is critical. The affected company should immediately coordinate banking measures, preservation of digital evidence, criminal proceedings and tracing of the transferred funds. Waiting several days before taking action may significantly reduce the possibility of identifying the destination accounts and recovering the money.
CEO fraud is generally a form of impersonation-based financial fraud in which criminals pretend to be a senior corporate officer and persuade employees to make an unauthorized payment.
The fraudster may claim that the payment concerns an urgent acquisition, confidential investment, tax liability, supplier invoice, litigation settlement or another commercially sensitive transaction.
The attacker may imitate the CEO’s email address, compromise a genuine corporate email account, create a similar internet domain, impersonate an existing supplier or send messages through instant-messaging applications.
The employee is usually pressured to act quickly and confidentially.
A similar scheme occurs when criminals impersonate a genuine supplier and inform the buyer that the supplier’s bank account has changed.
The company then pays a legitimate invoice to a fraudulent account.
Foreign companies should therefore investigate whether the incident involves CEO impersonation, supplier impersonation or compromise of an actual corporate email account.
The first priority is to determine where the money was transferred.
Record the beneficiary bank, account holder, account number, transfer date, amount, currency, payment reference and all intermediary-bank information available.
Contact the sending bank immediately.
Where the transfer has only recently occurred, the sending bank should be notified immediately that the transaction resulted from suspected fraud.
Depending on the transaction and banking circumstances, an urgent recall or communication with the receiving bank may potentially prevent further movement of funds.
There is no guarantee that a recall will succeed, so criminal-law measures should not be delayed while waiting for the bank.
Once the destination account is known, urgent legal action may be required to prevent withdrawal or onward transfer of the funds.
Fraud proceeds can move through several accounts within a very short period.
The company may submit a criminal complaint to the competent Turkish authorities where the facts establish a connection with Turkey.
The complaint should explain the fraud chronologically and provide supporting financial and digital evidence.
Important evidence can include emails, email headers, payment instructions, invoices, bank transfer receipts, WhatsApp messages, corporate correspondence, telephone numbers, domain information, employee statements and records showing the company’s genuine payment procedures.
Evidence should be preserved in its original form whenever possible.
Fraudulent messages may contain technical information useful for identifying how the attack occurred.
Deleting the original message and preserving only a screenshot may result in the loss of valuable metadata.
Email headers can contain routing and server information relevant to the investigation.
The company’s information-technology team should preserve the original electronic evidence rather than simply printing the visible message.
Some attacks use a fake address that merely resembles the CEO’s address. Others involve actual unauthorized access to a genuine corporate mailbox.
This distinction is important.
If the real account was compromised, the company should preserve access logs and investigate how unauthorized access occurred.
Attackers who compromise corporate accounts sometimes create hidden forwarding or mailbox rules.
These can allow criminals to monitor negotiations and identify the exact moment when payment instructions are expected.
Where available, preserve login dates, IP-related records, device information, security alerts and other access information.
Do not overwrite potentially relevant logs during the company’s internal response.
Security credentials should be secured quickly, but the company should preserve forensic evidence before systems are unnecessarily reset or wiped.
Cybersecurity remediation and criminal evidence preservation should be coordinated.
Fraudsters frequently register domains differing from a genuine corporate domain by only one letter or character.
Record the fraudulent domain and preserve copies of communications showing how it was used.
The employee who received and followed the payment instruction should prepare an accurate chronology while events remain fresh.
The chronology should identify when each message was received, who appeared to send it, whether telephone confirmation occurred and why the employee believed the instruction was genuine.
The existence of an incorrect payment does not automatically establish employee misconduct.
Sophisticated attacks may involve genuine mailbox compromise and detailed knowledge of confidential transactions.
The company should first reconstruct what actually happened.
Banking records can become important evidence in a criminal investigation. Where legally justified, investigative authorities may obtain information concerning account ownership and transaction movements.
The company should provide complete transfer information to facilitate tracing.
Fraudsters frequently use multiple accounts.
The investigation may therefore need to trace the payment from the first recipient account through subsequent transfers.
Speed becomes particularly important in these cases.
The first recipient may not necessarily be the person who designed the fraud.
Accounts can be provided or controlled by intermediaries commonly described as money mules.
The criminal investigation should therefore distinguish account ownership from the broader organization of the scheme.
Depending on the evidence, procedural stage and applicable legal requirements, judicial measures concerning suspected criminal proceeds may potentially be available.
The company should provide evidence supporting the connection between the transferred funds and the alleged offense as quickly as possible.
Potentially, but recovery depends heavily on whether the funds can still be identified and preserved.
If the money has already been withdrawn, converted, transferred abroad or dispersed through numerous accounts, recovery can become substantially more difficult.
Some fraud proceeds are transferred from bank accounts into cryptocurrency.
Where evidence indicates this occurred, wallet addresses, exchange information and transaction records should be preserved immediately.
CEO fraud often involves several jurisdictions.
The victim company may be located abroad, the employee may work in another country, the fraudulent account may be in Turkey and the funds may subsequently move internationally.
The criminal complaint should clearly explain these cross-border connections.
A foreign corporate victim can potentially pursue remedies in Turkey where Turkish jurisdiction and procedural requirements are satisfied.
Corporate authority documents should be prepared carefully when representation is required.
Foreign companies pursuing proceedings in Turkey should ensure that corporate authorization and representation documentation are prepared correctly.
This should not delay urgent evidence-preservation and banking measures.
Foreign emails, contracts, bank documents and corporate records may require appropriate translation during proceedings.
Important documents should be organized chronologically before submission.
If criminals altered an invoice by replacing genuine bank details, preserve both the authentic invoice and fraudulent version.
A side-by-side comparison can demonstrate how the payment instructions were manipulated.
Prepare a simple table identifying the genuine beneficiary, genuine bank account, fraudulent beneficiary, fraudulent account, invoice number and amount.
This can make a complex fraud easier for investigators to understand.
Sometimes the foreign company’s systems were never compromised. The attack may originate from the supplier’s email environment.
Both sides should therefore preserve their digital evidence.
This is a separate civil and commercial question.
Where a legitimate invoice was paid to a fraudster, the parties may dispute whether the buyer’s payment obligation was discharged and which party’s cybersecurity failure caused the loss.
The answer depends on the contract and factual circumstances.
A criminal complaint against the fraudsters does not necessarily resolve the contractual dispute between buyer and supplier.
Companies should protect both criminal and commercial remedies.
An employee who is genuinely deceived by sophisticated fraud is in a different position from someone who intentionally participates in the scheme.
Evidence concerning intent, knowledge, communications and financial benefit must be examined before criminal conclusions are drawn.
Some fraud schemes involve persons with access to internal transaction information.
Unusual disclosure of confidential payment dates, invoice amounts or executive schedules may justify examination of potential insider involvement.
However, allegations should be evidence-based.
If the fraudster called the employee while impersonating an executive or supplier, preserve telephone numbers, call times and available communication records.
Voice messages should also be retained.
Screenshots can be useful, but the original device and complete conversation may contain additional context.
Messages should not be edited or selectively reconstructed.
Using a genuine executive’s photograph or publicly available corporate information does not prove that the executive participated in the transaction.
The investigation should focus on account control, communications and digital evidence.
Public information about management structures can help criminals identify finance personnel and executives.
Companies should consider how publicly available corporate information affects social-engineering risks.
The company should identify every employee who may have received similar messages.
A fraud attempt against one employee may be part of a wider campaign.
Before making any additional supplier or executive-directed transfers, verify payment instructions through an independent communication channel.
This can prevent a second loss while the first incident is being investigated.
Foreign companies conducting business with Turkish counterparties should establish a rule requiring independent verification whenever a supplier changes bank details.
Confirmation should use previously verified contact information rather than telephone numbers contained in the suspicious email.
High-value transfers should generally require approval by more than one authorized person.
The company should also consider different approval thresholds depending on payment amount.
Investigators should be able to understand the incident quickly.
The complaint should identify the first fraudulent contact, subsequent communications, payment authorization, bank transfer, discovery of fraud, bank notifications and current location of funds if known.
Keep bank statements, payment receipts, exchange-rate information, investigation costs and other evidence demonstrating the financial consequences of the fraud.
After discovering the scheme, employees should avoid uncontrolled communications that could alert suspects or compromise investigative measures.
Further contact should be strategically assessed.
The first hours after discovery can be decisive.
The company should simultaneously notify its bank, preserve digital evidence, identify the destination account, secure compromised systems, contact relevant counterparties and prepare urgent criminal-law measures.
The company should preserve the original fraudulent email, full email headers, genuine correspondence, invoices, payment instructions, transfer receipt, bank account details, telephone numbers, messaging records, login logs, security alerts, supplier communications and internal approval records.
CEO fraud is an impersonation scheme in which criminals pretend to be a senior executive and induce employees to make unauthorized payments.
Contact the bank, attempt an urgent recall where possible, preserve digital evidence and assess immediate criminal-law measures.
Bank-account and transaction records can potentially become part of a criminal investigation where the applicable legal requirements are satisfied.
Depending on the evidence and procedural requirements, judicial measures concerning suspected criminal proceeds may potentially be available.
No. Original electronic evidence should be preserved because metadata and other technical information may be important.
Potentially, where the circumstances establish the necessary Turkish jurisdictional and procedural connection.
The criminal case and the commercial dispute concerning whether the invoice remains payable should be analyzed separately.
That depends on the evidence. An employee genuinely deceived by fraud should not automatically be treated in the same way as someone who knowingly participated.
Tracing may need to continue through subsequent accounts or other financial channels. This makes immediate action especially important.
Act immediately and preserve the complete digital and financial trail. CEO fraud cases are time-sensitive because criminal proceeds can be transferred through multiple accounts very quickly.
CEO fraud and fake payment instructions can create urgent issues involving criminal complaints, bank-account tracing, preservation of digital evidence, suspected criminal proceeds, cross-border transfers, supplier disputes and recovery of corporate funds.
Fırat Fesih Kaya Law Office assists foreign companies, international investors and corporate victims facing fraud and cyber-enabled payment schemes connected with Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preparing criminal complaints, coordinating urgent evidence preservation, analyzing bank transfers and digital communications, pursuing available measures concerning suspected fraud proceeds and protecting related commercial claims.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey