

A foreign business is impersonated through fake social media accounts, websites or messaging profiles in Turkey. Learn how to preserve digital evidence, file a criminal complaint, identify suspects and seek removal of fraudulent content.
A foreign company operating in or doing business with Turkey may discover that criminals have created a fake social media account, messaging profile, website or online advertisement using the company’s name, logo, executives, photographs, products or contact information. Fake accounts may then be used to collect payments, obtain customer information, distribute fraudulent invoices or redirect customers to bank accounts controlled by third parties. The company should react quickly because an online impersonation case can involve both criminal investigation and urgent protection of digital evidence. Removing the fake account is important, but identifying the perpetrators and preserving evidence before it disappears can be equally critical.
Online impersonation can take many forms. Criminals may create a fake social media account using the company’s trade name, copy the company’s website, impersonate a manager, contact customers through messaging applications, send fake payment instructions or advertise products that the company never offered.
More sophisticated schemes may combine several techniques simultaneously.
Businesses sometimes treat impersonation exclusively as an intellectual-property issue. However, depending on the conduct, the facts may also raise questions concerning fraud, unlawful use of personal or corporate information, unauthorized access, document-related offenses or other criminal conduct.
The precise criminal characterization depends on how the fake account is actually being used.
This is one of the most important practical steps.
Before the fraudulent account disappears, preserve screenshots, profile information, usernames, account identifiers, URLs where available, advertisements, messages, payment instructions and customer complaints.
Evidence should demonstrate not only that the account existed but also how it was being used.
Screenshots are useful, but the company should preserve as much contextual information as possible.
Record the date, time, platform, username, profile identifier and relevant conversations. Where financial fraud occurred, preserve banking and transaction records separately.
Prepare evidence showing the company’s legitimate identity. Relevant materials can include corporate registration documents, genuine branding, authorized websites or social-media accounts, trademark information and evidence concerning authorized representatives.
This helps distinguish the genuine business from the impersonating account.
If customers received fraudulent messages, ask them to preserve the original communications rather than merely forwarding screenshots.
The original messages may contain account information, telephone numbers, payment details or other evidence useful to investigators.
A common impersonation scheme involves sending customers false bank-account details.
If money has already been transferred, obtain the recipient account information, transfer time, amount, payment description and banking records immediately.
Delay can make recovery significantly more difficult.
Where fraudulent transfers occurred, the affected business or customer should contact the relevant bank without delay and determine what protective measures may still be available.
Bank notification does not replace a criminal complaint.
Potentially, where the conduct falls within Turkish criminal jurisdiction and the company or its representatives have the necessary legal standing.
The complaint should explain the impersonation scheme clearly and attach the available digital and financial evidence.
Depending on the circumstances, the matter may be reported to the competent public prosecutor’s office or law-enforcement authorities.
The appropriate jurisdiction should be evaluated according to the conduct, victims, suspects and digital or financial connections with Turkey.
The company does not necessarily need to know the real identity of the person behind the fake account before making a complaint.
A criminal investigation may begin against unidentified suspects where sufficient factual information concerning the alleged offense is provided.
Investigators may examine available platform information, telecommunications data, banking records, IP-related evidence and other digital traces within the limits of applicable criminal-procedure rules.
The precise evidence available depends heavily on the platform and facts.
Digital records may be retained only for limited periods under the relevant provider’s systems and legal obligations.
This is one reason why companies should not wait months before considering formal investigative measures.
A fraudulent profile may use the company’s logo, photographs and corporate description while communicating with customers as though it were genuine.
Preserve the complete profile and examples of fraudulent communication before submitting a removal request.
Criminals may impersonate a company’s CEO, director, sales manager or finance officer.
This is particularly dangerous where the fake executive sends urgent payment instructions to employees or customers.
A fraudster may use the photograph and name of a company representative while communicating from a different telephone number.
The number itself, profile details and complete conversation history should be preserved.
Some schemes copy the genuine company’s website almost completely but change contact details or payment instructions.
Preserve screenshots of the pages, domain information available to the company, payment instructions and communications directing victims to the fake site.
Fraudsters may register a domain differing from the genuine company domain by only one letter or character.
Employees and customers can easily overlook the difference.
The suspicious domain should be recorded exactly.
A fraudulent account may send invoices carrying the company’s logo and genuine customer information but substitute another bank account.
Preserve both the fraudulent invoice and authentic invoices for comparison.
Some impersonation cases involve compromised or deceptively similar email accounts.
Determine whether the genuine corporate email account was actually accessed or whether criminals simply created a look-alike address.
These scenarios require different technical investigations.
If criminals know confidential customer names, invoice amounts or payment schedules, investigate whether internal email or information systems may have been compromised.
Online impersonation can sometimes be only the visible part of a larger cyber incident.
Where internal compromise is suspected, preserve access logs, security alerts, unusual login information and relevant email records.
Do not destroy potential evidence while resetting systems.
Where impersonation is used to deceive victims into transferring money or providing economic benefit, fraud-related criminal provisions may become relevant depending on the facts.
The use of digital systems can also affect the legal characterization of the conduct.
A criminal complaint should not necessarily be abandoned merely because an alert employee or customer discovered the deception before sending money.
The attempted conduct should be documented carefully.
Determine whether the same fake account contacted multiple customers, suppliers or employees.
A consolidated factual picture can demonstrate the scale and method of the scheme more clearly.
For each incident, record the date, victim, account used, communication method, requested payment, bank information and actual loss.
This can significantly improve the organization of a criminal complaint.
Platform reporting mechanisms may allow the company to request removal based on impersonation, fraud, trademark rights or other violations.
However, evidence should generally be preserved before removal.
Taking down the account may stop immediate harm but does not necessarily identify the perpetrator.
Where substantial fraud or repeated impersonation exists, the company should consider both immediate platform action and appropriate legal remedies.
Where there is an ongoing risk, a carefully drafted customer warning may help prevent further losses.
The communication should identify official contact channels without unnecessarily publishing investigative details that could alert suspects to law-enforcement strategy.
If customers cancel contracts or question the company’s legitimacy because of the fake account, preserve the relevant correspondence.
This may become relevant to separate civil or commercial claims.
Preserve the IBAN, account holder information available to the victim, transaction details and payment instructions.
Bank-account evidence can be important in tracing the movement of funds.
Fraud schemes can involve accounts obtained from third parties or individuals who allow others to use their accounts.
Investigators should therefore examine the broader transaction chain rather than assuming that the first account holder necessarily organized the entire scheme.
If victims were instructed to transfer cryptocurrency, preserve wallet addresses, transaction identifiers, exchange information and communications.
Blockchain transactions can leave evidence, but identifying the individuals controlling particular wallets may require additional investigation.
Where the social-media or technology provider is located abroad, obtaining subscriber or technical data may involve additional procedural and international issues.
This makes early evidence preservation especially important.
Direct confrontation may cause the fake account to disappear and evidence to be deleted.
Before contacting suspected perpetrators, consider whether preservation and investigative steps should occur first.
A company should not attempt to hack a fake account or unlawfully obtain private data in order to identify the offender.
Evidence should be gathered through lawful methods.
Where the foreign company’s representatives are abroad, Turkish legal representation may require properly prepared authorization documents.
The exact formalities depend on the documents and country involved.
A serious impersonation incident can involve criminal proceedings, banking disputes, cybersecurity response, trademark protection, platform removal and civil claims simultaneously.
The company should coordinate these processes so that one response does not undermine another.
Identify each transfer immediately and preserve bank records. The victims may have their own criminal and civil rights, while the impersonated company should document that it did not authorize the fraudulent payment instructions.
Potential claims depend on the company’s actual loss and the persons responsible.
The company should separately document investigation expenses, interrupted transactions, contractual losses and other measurable damage.
If new accounts repeatedly appear after earlier ones are removed, the company should investigate whether they share telephone numbers, payment accounts, content, domains or other identifying characteristics.
A pattern can be more informative than a single account.
Foreign businesses operating in Turkey should have an internal procedure requiring employees to preserve suspicious messages, payment instructions and account details immediately.
Employees should know whom to contact when impersonation is discovered.
Customers and employees should verify changes in bank details through an independent communication channel.
A payment instruction received only through email or messaging applications should not automatically be trusted.
Clearly identifying genuine corporate accounts and payment procedures can reduce the effectiveness of impersonation attempts.
This is particularly important for foreign companies conducting high-value transactions with Turkish customers.
When a foreign business is impersonated online in Turkey, the company should immediately preserve the fake profile and communications, document its genuine corporate identity, collect customer complaints, identify fraudulent bank accounts or payment information, preserve cybersecurity records, evaluate a criminal complaint, consider urgent platform-removal requests, warn customers where necessary, investigate whether internal systems were compromised and coordinate criminal, banking, cybersecurity and commercial remedies.
Potentially, where the alleged criminal conduct has the necessary connection with Turkish jurisdiction.
Yes, depending on the facts. The complaint can identify the known digital, financial and factual evidence even where the perpetrator’s identity has not yet been established.
Usually the immediate harm should be addressed quickly, but evidence should first be preserved where possible because removal can make later documentation more difficult.
They are useful but should ideally be accompanied by usernames, profile identifiers, dates, messages, transaction records and other contextual evidence.
Preserve the payment instructions and notify relevant banks promptly in addition to considering criminal remedies.
The victim should act immediately to preserve banking evidence and determine whether any protective banking or criminal-procedure measures remain available.
Yes. Fraudulent invoices, payment instructions and related communications can become important evidence depending on the alleged offense.
Cross-border elements can make investigation and evidence collection more complex, but they do not automatically eliminate potential Turkish legal remedies.
Yes, particularly where criminals possess confidential customer, invoice or payment information that should not otherwise be publicly available.
Preserve the digital and financial evidence before the fake account disappears. The company can pursue removal quickly, but identifying the perpetrator and tracing fraudulent payments may depend on evidence that is difficult or impossible to reconstruct later.
Foreign companies impersonated online may face fake social media accounts, fraudulent websites, false invoices, business email compromise, unauthorized payment instructions, customer fraud and significant reputational damage. Fırat Fesih Kaya Law Office assists foreign companies, international businesses and investors dealing with online impersonation and related criminal investigations in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preserving digital evidence, preparing criminal complaints, coordinating evidence concerning fraudulent accounts and payments, following criminal investigations and evaluating related civil and commercial remedies.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey