

Foreigners who lose money through SIM swap, stolen banking credentials or unauthorized online banking transactions in Turkey may have legal remedies. Learn when banks may be responsible, what evidence matters and what victims should do immediately.
Yes. A foreign individual, property owner, investor or company that loses money through SIM swap fraud, unauthorized mobile banking access, stolen passwords, fraudulent money transfers or other online banking fraud in Turkey may be able to recover the stolen funds. However, reimbursement is not automatic, and the outcome depends heavily on how the fraud occurred, whether the customer authorized the transactions, what security controls the bank applied and how quickly the customer reacted.
SIM swap cases deserve particular attention because Turkish banking regulations impose specific security requirements concerning customers who replace their SIM cards or change mobile operators through number portability. Banks must identify these changes through integration with mobile operators before using SMS-based authentication. Unless the change has been confirmed, a SIM-based factor cannot be used for electronic banking authentication for 90 days following the change.
This can become highly relevant where a criminal obtains control of a foreign customer’s telephone number, resets mobile banking access and transfers substantial funds without the customer’s knowledge.
Foreign victims in Ankara, Istanbul, Izmir, Mersin, Bursa and throughout Turkey should act immediately. Delays can make tracing funds, preserving technical evidence and establishing the sequence of unauthorized transactions significantly more difficult.
SIM swap fraud occurs when a criminal obtains control over a victim’s mobile telephone number.
The fraudster may use stolen identity information, social engineering, forged documentation or compromised telecommunications credentials to activate the victim’s number on another SIM card or device.
Once the fraudster controls the number, they may attempt to intercept verification messages, reset banking credentials, activate mobile banking and authorize transfers.
The victim may first realize something is wrong when their telephone unexpectedly loses network service.
Minutes later, money may begin leaving the bank account.
Turkish electronic banking regulations contain a specific safeguard addressing SIM replacement and mobile-number portability.
Banks must establish integration with mobile operators so that SIM-card replacement and operator changes can be detected before SMS-based authentication is used. Unless the relevant change is confirmed, the SIM-based factor cannot be used as an authentication factor for 90 days following the change.
The regulation also addresses the burden of proving that certain transactions following confirmation of such changes were actually performed by the customer.
Therefore, the technical history of the SIM change can become central evidence in a banking fraud dispute.
Not necessarily.
A successful technical login does not always establish genuine customer authorization.
Modern banking fraud frequently involves criminals who have obtained passwords, device access, verification codes or control of a victim’s telephone number.
The relevant question is not merely whether a technically correct password or verification code appeared in the bank’s system.
The investigation may need to determine who actually initiated the transaction and whether the bank’s authentication and security systems operated in accordance with applicable requirements.
The Banking Regulation and Supervision Agency’s Regulation on Information Systems and Electronic Banking Services requires banks to operate authentication mechanisms and security controls for electronic banking.
Among other things, the regulation requires additional security measures after repeated unsuccessful authentication attempts and ultimately requires access to be prevented where such attempts continue.
The regulation also restricts the use of SMS verification for customers who have activated mobile banking applications. For ordinary login and transaction verification during active mobile banking use, banks may not simply rely on an SMS one-time password as the authentication factor, subject to specific exceptions such as initial installation, activation or reactivation.
These technical requirements can be important when determining whether a disputed transfer resulted from an unavoidable criminal attack or a failure in the security process.
The bank should be contacted immediately through an official emergency or fraud-reporting channel.
The customer should request blocking of mobile and internet banking, payment cards and any compromised accounts where appropriate.
The customer should clearly identify every unauthorized transaction.
The customer should also contact the mobile operator immediately if SIM swap is suspected.
Evidence that the victim’s original SIM suddenly stopped functioning can be extremely important.
A criminal complaint should also be considered promptly so that available transaction, telecommunications and digital evidence can be preserved and investigated.
No.
The victim can cooperate with the bank’s investigation while simultaneously preserving evidence and considering other legal remedies.
Time matters because fraud proceeds may be transferred through several accounts within a short period.
The victim should preserve bank notifications, emails, text messages, screenshots, account statements, telephone records and communications with the mobile operator.
The exact time when the victim’s telephone lost service should also be recorded.
Potentially, particularly if the fraud is discovered quickly.
The bank should immediately be asked whether the payment can be stopped, recalled or traced.
If the money has already reached another Turkish bank, identifying the recipient account quickly can be important.
However, a recall request does not guarantee recovery.
Fraudsters frequently move stolen funds through several accounts or withdraw them quickly.
Potentially, yes.
Bank transfers normally generate transaction records identifying the accounts involved.
Where a criminal investigation is opened, competent authorities may seek banking and other evidence necessary to identify the destination and subsequent movement of the funds.
The victim should therefore preserve the exact transaction amount, date, time, recipient information displayed on the account statement and transaction reference.
Potentially.
The answer depends on the facts.
A bank dispute may focus on whether the transaction was genuinely authorized, whether required authentication measures were properly applied, whether unusual transaction activity should have triggered additional controls and whether a SIM replacement or device change was properly detected.
In a SIM swap case, compliance with the specific 90-day security mechanism can become particularly significant.
A bank’s assertion that “the transaction was completed through mobile banking” does not necessarily resolve these questions.
The customer should request the technical basis for that conclusion through the appropriate legal process.
Relevant evidence can potentially include login records, authentication method, device information, transaction timestamps, failed login attempts, mobile application activation records, SIM-change information and other security logs.
The objective is to reconstruct the attack.
For example, if the foreign customer was physically abroad while a new mobile banking activation occurred immediately after an unauthorized SIM replacement in Turkey, that sequence may be highly relevant.
The electronic banking regulation contains an important rule concerning SIM changes.
Where a customer has replaced a SIM card or changed operator through number portability, banks must detect that change before sending an SMS authentication code. Unless confirmed, the SIM-based factor cannot be used for 90 days. For the specified transactions performed without two-factor authentication in connection with confirmation of those changes, the regulation places the burden on the bank to demonstrate that the relevant transactions were carried out by the customer.
This makes the precise authentication sequence particularly important in SIM swap litigation.
That does not automatically end the analysis.
The question becomes how the criminal obtained access and whether additional security mechanisms should have prevented unauthorized transactions.
A compromised password can be only one stage of an account takeover.
The bank’s records may need to show how a new device was activated, how identity was verified, whether the SIM had recently changed and how the disputed transaction was confirmed.
This can make recovery more difficult, but it does not necessarily justify deciding the case without examining all surrounding circumstances.
Social-engineering fraud may involve criminals impersonating bank employees, public officials, police officers, investment companies or other trusted persons.
The Banking Regulation and Supervision Agency specifically warns customers about fraudsters impersonating regulatory personnel and requesting passwords, personal information or installation of applications.
Customer conduct, bank security measures, warnings, authentication records and the precise fraud method may all require examination.
Remote-access fraud has become another important online banking scenario.
A fraudster may persuade the victim to install software that allows the criminal to view or control the victim’s telephone.
The customer may then unknowingly expose banking credentials or permit transactions.
These cases can be more complicated because the bank may argue that authentication occurred through the customer’s registered device.
Technical evidence becomes especially important.
The victim should immediately contact both the bank and mobile operator.
If the device contains active mobile banking, the customer should request suspension of banking access.
The precise circumstances matter: whether the device was locked, whether biometric authentication was enabled, whether the criminal knew the device password and whether new banking credentials were established.
The fact that the physical phone was stolen does not automatically establish either bank liability or customer liability.
Credit-card rules have additional protections.
The Banking Regulation and Supervision Agency states that when a card is lost, stolen or an unauthorized transaction is discovered, the customer should immediately notify the bank. Its current guidance explains that timely notification is particularly important for determining the customer’s liability for unauthorized use.
Unauthorized card transactions should therefore be reported immediately rather than waiting for the monthly statement cycle.
The customer should obtain the rejection in writing where possible.
The response should then be compared with the technical and factual evidence.
The Banking Regulation and Supervision Agency states that individual banking applications seeking monetary reimbursement can be directed to the relevant customer arbitration mechanisms, while complaints concerning supervised institutions that do not involve reimbursement can be submitted through the regulator’s electronic complaint system.
Depending on the nature and amount of the claim, judicial proceedings may also need to be considered.
Not always.
An individual consumer who loses personal savings and a foreign-owned company that loses corporate funds may fall under different procedural frameworks.
The account agreement, commercial nature of the banking relationship and identity of the account holder should therefore be examined before choosing the dispute-resolution route.
Technical banking records can become critical evidence in litigation.
A dispute may require examination of device registration, login history, authentication events, IP-related information where available, mobile banking activation, transaction authorization and other system records.
The Banking Regulation and Supervision Agency’s electronic banking rules impose detailed authentication and security obligations precisely because electronic transactions require reliable identification and protection against unauthorized access.
Where necessary, expert examination may be required to interpret these records.
Potentially, depending on how the SIM swap occurred.
If a criminal obtained a replacement SIM through a telecommunications process, the circumstances of that replacement should be investigated.
The relevant questions can include how identity was verified, when the replacement occurred and whether the victim actually requested it.
A SIM swap case should therefore not automatically be investigated only as a dispute between the customer and the bank.
Account takeover can sometimes extend beyond theft of an existing balance.
A fraudster may attempt to obtain consumer credit, use an overdraft facility, transfer credit-card funds or create additional liabilities.
The customer should therefore examine the entire banking relationship, not only the first unauthorized transfer discovered.
All disputed transactions and newly created liabilities should be identified immediately.
Recovery may become more difficult but should not automatically be considered impossible.
The transaction trail should be reconstructed from the bank account to the recipient and onward where evidence permits.
Speed is especially important because digital assets can be moved rapidly.
The victim should preserve all available transaction references and report the fraud without delay.
This can create two separate legal problems.
Suppose a foreign buyer has EUR 400,000 in a Turkish account for an apartment in Istanbul. Criminals obtain control of the customer’s telephone number and transfer the money shortly before the property completion date.
The buyer must address both the banking fraud and the property contract.
The seller should be informed promptly, and any payment deadline or termination risk should be reviewed.
A foreign property owner may maintain a Turkish account solely for rent and property expenses.
If the account is compromised, historical statements should be preserved to distinguish legitimate rental payments from fraudulent transfers.
The landlord should also provide tenants with secure new payment instructions if the compromised account can no longer safely receive rent.
A foreign-owned company may suffer significant operational damage where fraudsters empty an operating account.
Payroll, taxes, suppliers and commercial obligations may immediately become affected.
The company should document not only the stolen amount but also consequential financial effects.
Corporate fraud cases may require a different litigation and dispute-resolution analysis from an individual consumer claim.
Potentially, depending on the legal basis of the claim and evidence.
Where the stolen money is not reimbursed promptly, disputes can arise concerning interest and additional losses caused by the inability to use the funds.
For example, a property buyer may claim that an unauthorized transfer caused loss of a transaction or contractual penalties.
Such consequential claims require careful proof of causation and amount.
Not necessarily.
Criminal investigation and civil recovery serve different purposes.
A criminal investigation may identify perpetrators, recipient accounts and evidence of the attack.
A separate claim against a bank or another responsible party may still require its own legal basis and procedure.
Victims should therefore avoid assuming that filing a criminal complaint automatically results in reimbursement.
A foreign investor in Ankara suddenly loses mobile network service.
Within an hour, a new mobile banking activation occurs and EUR 250,000 is transferred from the investor’s account.
The investigation should establish when the SIM was replaced, whether the investor authorized that replacement, how the bank detected the SIM change, how the banking application was activated and what authentication was used.
The specific SIM-change protections in the electronic banking regulation may be highly relevant.
A foreign property owner is in London when several online transfers are made from a Turkish account in Izmir.
The customer immediately informs the bank that the transactions were unauthorized.
Travel records alone may not prove the case, because electronic banking can be used internationally, but they can form part of a broader evidentiary picture when combined with device, SIM and authentication records.
A foreigner with an account in Mersin receives a telephone call from someone claiming to work for the bank.
The caller persuades the customer to install an application and money is transferred.
The dispute may require examination of customer conduct, authentication records, bank security controls and the technical method used to gain access.
A foreign-owned company in Bursa discovers multiple transfers to newly added beneficiaries.
The company should immediately suspend compromised access, notify the bank, preserve transaction and user-access records and investigate whether employee credentials, mobile devices or banking authorizations were compromised.
Potentially, yes. Recovery depends on the fraud method, customer conduct, authentication process, bank security measures and available evidence.
Potentially. Turkish electronic banking rules impose specific security requirements following SIM replacement or operator changes, making compliance with those requirements important in determining responsibility.
Immediately notify the bank, block compromised banking access, contact the mobile operator if SIM fraud is suspected, preserve evidence and consider promptly reporting the criminal conduct.
Not necessarily. A fraudster may obtain passwords or control of authentication mechanisms. The complete authorization process should be examined.
Banks must detect SIM replacement or operator changes before using SMS authentication. Unless the change is confirmed, the SIM-based factor cannot be used for electronic banking authentication for 90 days.
Such records can become important evidence in a dispute and may be sought through the appropriate legal procedure.
That can complicate the claim, but responsibility should still be assessed according to the complete circumstances rather than one fact in isolation.
Yes. The Banking Regulation and Supervision Agency identifies customer arbitration mechanisms for qualifying individual banking claims involving reimbursement and provides a regulatory complaint channel for other supervised banking issues.
Where money has been stolen through unauthorized access, a prompt criminal complaint may be important for identifying perpetrators, recipient accounts and technical evidence.
Potentially, yes. Foreign victims can appoint appropriately authorized legal representation in Turkey for relevant banking disputes and legal proceedings.
The strongest cases are usually built through a precise technical chronology.
The victim should establish the last legitimate banking activity, time the telephone lost network access, time of any SIM replacement, mobile banking activation or reactivation, first unauthorized login, each fraudulent transfer, time the fraud was discovered and time the bank and mobile operator were notified.
Bank statements, text messages, emails, screenshots, telephone-operator records and banking notifications should be preserved.
The bank’s authentication records can then be compared with the victim’s evidence.
In SIM swap cases, particular attention should be given to the regulatory requirement that banks detect SIM replacement or number portability and restrict use of the SIM-based authentication factor unless the change has been confirmed.
The central legal issue is therefore rarely limited to the question “Was the correct password entered?” A proper analysis should determine whether the customer genuinely authorized the disputed transactions and whether the required electronic banking security mechanisms functioned correctly.
Firat Fesih Kaya Law Office provides legal assistance to foreign individuals, investors, property owners and foreign-owned companies affected by SIM swap fraud, unauthorized mobile banking transactions, stolen banking credentials and online account takeover in Ankara, Istanbul, Izmir, Mersin, Bursa and throughout Turkey.
Legal assistance may include reviewing fraudulent transfers, preparing objections to banks, examining authentication and SIM-change records, assessing potential bank responsibility, preserving technical evidence, pursuing appropriate reimbursement procedures, coordinating claims involving telecommunications issues and representing victims in related civil or criminal proceedings.
Foreign victims should seek legal assessment particularly quickly where substantial funds have been transferred, the fraud followed an unauthorized SIM replacement, the bank rejects responsibility merely because a password or verification mechanism was used, the stolen money was intended for a property or investment transaction or the fraud has affected a company operating account.
Phone: +90 312 434 22 22
Mobile / WhatsApp: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Office: Mevlana Boulevard No:221, Yildirim Tower, Balgat, Cankaya, Ankara, Turkey
The key 2026 principle is clear: foreigners who lose money through SIM swap or online banking fraud should not assume that successful electronic authentication automatically proves that they authorized the transaction. Turkish banking rules impose detailed security requirements, including specific protections following SIM replacement and number portability. Recovery depends on reconstructing the attack, preserving technical evidence, reporting the fraud immediately and determining whether the bank, customer, telecommunications process or another party bears legal responsibility for the loss.