

A foreign national’s email account is hacked in Turkey and money is stolen. Learn how to file a criminal complaint, preserve digital evidence, trace bank transfers and seek recovery of stolen funds.
Email-account hacking can quickly turn into a serious financial crime. A foreign national or foreign company may discover that an email account has been accessed without authorization, correspondence has been monitored, payment instructions have been changed and money has been transferred to a bank account controlled by fraudsters. In other cases, criminals may take control of the victim’s email account and impersonate the victim when communicating with customers, suppliers, employees or banks. Foreign victims facing this situation in Turkey should act quickly because digital logs, bank records, IP information, account-opening records, camera footage and transaction data may become essential to identifying the perpetrators and tracing the stolen funds.
A common scenario involves criminals gaining access to an email account used for commercial correspondence. They may secretly monitor communications between a company and its customers or suppliers.
When a legitimate payment becomes due, the attacker may send altered bank-account details and instruct the payer to transfer the money to another account.
The victim may not discover the fraud until the legitimate supplier reports that payment was never received.
Foreign companies doing business with Turkish companies can become victims of business email compromise schemes.
Criminals may imitate executives, suppliers, accountants or commercial partners and issue fraudulent payment instructions.
These cases can involve substantial international transfers and multiple bank accounts.
The victim should simultaneously protect the compromised account, preserve evidence, contact the relevant banks and begin the criminal complaint process.
Waiting several days can substantially reduce the possibility of stopping onward transfers.
Preserve the original emails.
Screenshots can be useful, but they should not be the only evidence retained. Original messages may contain technical information that becomes relevant during the investigation.
Email headers may contain technical routing information useful for investigating the origin and transmission of messages.
Foreign victims should preserve the original electronic records rather than forwarding everything into a new format that removes technical information.
If the email provider displays login history, IP addresses, device information or security alerts, preserve those records immediately.
Access information may later help investigators understand when and how the account was compromised.
The victim should change the compromised password and review account-recovery methods, connected devices and active sessions.
Multi-factor authentication should be activated where available.
Security measures should be implemented without destroying evidence of the unauthorized access.
Attackers sometimes create automatic forwarding or filtering rules so that messages continue being copied to another account.
Review forwarding addresses, inbox rules, filters and delegated account access.
Fraudsters may delete correspondence showing that bank details were changed.
Review deleted, archived and sent folders and preserve recovered messages.
If money has already been transferred, notify the sending bank immediately that the transaction is suspected to be fraudulent.
Provide the transaction date, amount, beneficiary information and reference number.
Speed can be critical where funds have not yet been transferred onward or withdrawn.
The recipient bank may also become relevant to efforts to trace or preserve the funds.
The criminal investigation can subsequently seek formal banking records and other information concerning the recipient account.
A foreign victim may file a criminal complaint concerning suspected criminal conduct in Turkey with the competent authorities.
The complaint should explain the sequence of events clearly rather than merely stating that the email was hacked.
The complaint should identify the victim, compromised email address, relevant commercial relationship, date the unauthorized activity was discovered, fraudulent messages, payment instructions, bank transfers and known beneficiary information.
Supporting evidence should be organized chronologically.
Relevant materials may include email correspondence, original electronic messages, screenshots, bank transfer records, invoices, contracts, payment instructions, security alerts and login records.
Documents issued abroad may require appropriate procedural handling depending on how they will be used.
Where the fraud occurred during a real business transaction, provide the genuine contract, invoice and previous correspondence.
This helps distinguish the legitimate transaction from the fraudulent payment instruction inserted by the attacker.
A particularly useful comparison can show:
the original beneficiary;
the fraudulent beneficiary;
the date the account details changed;
the email address used;
and the transfer ultimately made.
This can make the fraudulent sequence easier for investigators to understand.
Some fraud cases do not involve actual hacking. Instead, criminals register an email address that differs from the legitimate address by only one character.
The victim should therefore determine whether the genuine account was compromised or merely impersonated.
Where a fake domain or similar email address was used, preserve the exact domain name and relevant registration or technical information available at the time.
Fraudulent infrastructure can disappear quickly.
If stolen funds were transferred to a Turkish bank account, investigators may seek information concerning the account holder, transaction history and movement of funds.
The person whose name appears on the account is not necessarily the organizer of the fraud, but the account can provide an important investigative starting point.
Fraud proceeds may move rapidly from the first recipient account into other accounts.
The investigation may therefore need to trace the transaction chain rather than examining only the first beneficiary.
In some cases, stolen money is transferred to cryptocurrency platforms or converted into digital assets.
Relevant bank and platform records may become important to tracing the funds.
A recipient may argue that another person obtained access to the account or that the account was provided to a third party.
Investigators may therefore examine device records, withdrawals, ATM footage, transfers and communications in addition to formal account ownership.
IP information may assist investigators in identifying access patterns, although an IP address alone does not necessarily establish who personally committed an offense.
VPNs, shared networks and compromised devices can complicate attribution.
If a suspect is identified, computers and mobile phones may contain emails, banking applications, passwords, messages or other evidence connected with the fraud.
Any search, seizure and forensic examination must follow the applicable criminal procedure.
Yes. Language barriers should not prevent a foreign victim from seeking criminal-law protection.
Where interpretation is required during procedural acts, the applicable criminal procedure concerning interpretation should be observed.
Where a foreign company suffered the financial loss, its authorized representative may need to establish corporate authority and representation.
The necessary corporate and authorization documents should be prepared carefully.
A foreign individual or company can appoint a Turkish lawyer to represent them in the criminal process subject to the applicable representation requirements.
This can be particularly useful where the victim is outside Turkey.
Being outside Turkey does not necessarily prevent the victim from pursuing the matter.
The procedural strategy can be organized according to the victim’s location, the suspected offense, the banks involved and the evidence available in Turkey.
Email providers, banks, domain registrars or other relevant service providers may be located outside Turkey.
Obtaining foreign evidence can therefore involve international cooperation or other applicable procedural mechanisms.
Certain technical information may be retained only for limited periods.
The complaint should identify potentially important records as early as possible so that appropriate investigative measures can be considered.
Depending on the facts, legal requirements and available evidence, measures affecting suspected criminal proceeds may potentially become relevant during the investigation.
Such measures are judicial or prosecutorial matters governed by the applicable criminal procedure; victims cannot simply freeze another person’s bank account themselves.
Potentially, but recovery depends heavily on whether the money can still be identified and traced.
If funds remain in identifiable accounts, the practical position may be different from a case where money has already been withdrawn, transferred internationally or dispersed through numerous accounts.
Conviction of an offender and actual recovery of the victim’s financial loss should not be treated as identical questions.
Depending on the circumstances, additional civil or enforcement remedies may also need to be evaluated.
Bank responsibility cannot be assumed merely because fraud proceeds passed through a bank account.
Any potential claim involving a bank requires separate examination of the transaction, authentication process, warnings, security measures, contractual obligations and the bank’s conduct.
If an employee ignored internal payment-verification procedures or changed bank details without confirmation, employment and internal responsibility issues may arise.
However, the existence of an internal mistake does not eliminate the criminal investigation into the fraudsters.
A company should determine which email account was compromised, how long unauthorized access continued and whether other accounts were affected.
A broader cybersecurity review may be necessary.
Once criminals control a commercial email account, they may target multiple customers.
Notify potentially affected counterparties through a trusted communication channel.
If the email account itself may be controlled by criminals, verification through that same account is unreliable.
Use a previously verified telephone number or another independent communication channel.
Create a chronology covering:
the legitimate invoice;
original payment instructions;
first suspicious login;
fraudulent email;
change of bank details;
payment date;
discovery of fraud;
bank notification;
and criminal complaint.
A clear timeline can significantly improve the presentation of a complex digital-fraud case.
Avoid relying solely on printed copies.
Electronic files, original emails, attachments, transaction records and other digital evidence should be preserved carefully.
Voluntarily clicking “send” does not necessarily mean that no crime occurred.
If the transfer was induced by fraudulent impersonation or manipulated communications, the circumstances should be investigated as potential criminal conduct.
International elements do not automatically prevent Turkish authorities from becoming involved.
Jurisdiction requires analysis of the location and effects of the alleged conduct and other connections with Turkey.
International transfers can make recovery more difficult but do not necessarily make investigation impossible.
The receiving bank, intermediary banks and foreign authorities may become relevant depending on the circumstances.
Victims of online fraud can become targets of secondary “recovery” scams.
Requests for additional payments in exchange for supposed access to police, prosecutors, banks or frozen cryptocurrency should be treated with extreme caution.
A foreign victim should preserve the original fraudulent emails, full email headers, login and security records, screenshots, legitimate correspondence, invoices, contracts, fraudulent payment instructions, bank transfer receipts, beneficiary account details, telephone or messaging communications and any notification made to the banks.
Potentially, yes, where the alleged conduct falls within the jurisdiction of Turkish criminal authorities.
Where money has just been transferred, the bank should normally be contacted immediately. Banking action and preparation of the criminal complaint can proceed urgently in parallel.
Screenshots can be useful, but original electronic emails, headers, account logs and banking records should also be preserved where available.
Banking information may be obtained through the criminal investigation in accordance with the applicable legal procedure.
Formal account ownership is only one part of the investigation. Transaction records, devices, communications, withdrawals and other evidence may also be relevant.
Depending on the evidence and applicable legal conditions, measures concerning suspected criminal proceeds may potentially be considered by the competent authorities.
Potentially, although tracing and recovery generally become more difficult as funds move through additional accounts or jurisdictions.
Not necessarily in every case. Representation and procedural requirements should be evaluated according to the particular investigation.
Yes. Business email compromise frequently targets companies involved in international commercial payments.
Preserve the digital evidence, secure the compromised account, notify the banks immediately and prepare a detailed criminal complaint showing exactly how the fraudulent communication resulted in the transfer of money.
Email hacking and payment fraud cases can involve unauthorized account access, fraudulent payment instructions, bank-account tracing, digital evidence, cryptocurrency transfers, international evidence and urgent measures concerning suspected criminal proceeds. Fırat Fesih Kaya Law Office assists foreign nationals, foreign investors and international companies affected by cybercrime and financial fraud in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preparing criminal complaints, organizing digital and banking evidence, following prosecutor investigations and coordinating legal measures concerning stolen funds and identified suspects.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey