

What can a foreign company do when an employee steals money, inventory or company assets in Turkey? Learn about criminal complaints, breach of trust, employee fraud, bank transfers, evidence preservation and recovery of company losses.
A foreign company operating in Turkey may discover that an employee has transferred company money to a personal account, diverted customer payments, stolen inventory, manipulated expense records, used a corporate credit card for private purchases, created fictitious suppliers or transferred company property to themselves or another person. These situations are commonly described in international business language as employee theft, employee embezzlement or misappropriation of company assets, but the precise criminal classification under Turkish law depends on how the employee obtained possession or control of the property and what they subsequently did with it. Turkish criminal law distinguishes, among other offenses, theft under Articles 141–147 of the Turkish Penal Code and breach of trust under Article 155. (Adli Sicil) For private companies, it is particularly important not to automatically translate every employee misappropriation case into the Turkish offense of “zimmet,” because the applicable offense must be determined from the employee’s position, the manner in which the property was obtained, the authority granted to the employee and the conduct involved. A foreign parent company discovering missing funds at its Turkish subsidiary should therefore act quickly but methodically: preserve evidence, prevent further unauthorized access, calculate the loss, reconstruct the transactions, identify the persons involved and determine the appropriate criminal and civil remedies.
The basic form of theft under Article 141 of the Turkish Penal Code concerns taking movable property belonging to another person from its location without the possessor’s consent for the purpose of obtaining a benefit for oneself or another person. Depending on the circumstances, qualified forms and other provisions may also become relevant. (Mevzuat) Whether employee misconduct constitutes theft therefore depends on the way the property was taken.
Assume an employee enters a company warehouse and secretly removes laptops, electronic equipment or inventory that they were not authorized to possess or dispose of. The circumstances may require analysis under the theft provisions.
The legal analysis can change where the company voluntarily entrusted the property to the employee because of their position.
Suppose a finance employee is legitimately authorized to manage payments from a company account but transfers TRY 3 million into a personal account.
This differs conceptually from secretly taking property over which the employee never had entrusted control.
Article 155 regulates breach of trust. This provision can become particularly important where property is delivered to a person for safekeeping or use for a particular purpose and that person subsequently disposes of the property contrary to the purpose for which possession was transferred.
Where the property was entrusted because of a service, professional, commercial or asset-management relationship, the aggravated form of breach of trust may potentially require examination.
A company should not file a criminal complaint using a random offense label simply because money is missing. The facts should be described accurately and the legal classification should be based on how the employee obtained control of the property.
International companies frequently instruct Turkish counsel that an employee has committed “embezzlement.” In ordinary English, this usually means that a person entrusted with company assets misappropriated them.
The offense called zimmet in Turkish criminal law concerns a specific legal framework associated with public officials. Private-sector employee misappropriation should therefore not automatically be described as zimmet.
The important questions are: What property disappeared? Who owned it? Who possessed it? Why did the employee have access? What authority did the employee have? What did they do with the property? Who ultimately benefited?
This is one of the most common internal fraud scenarios.
The company should reconstruct:
Company Account → Employee Personal Account → Subsequent Withdrawal/Transfer → Ultimate Destination.
If the employee subsequently transferred the money to a spouse, relative, another company or cryptocurrency platform, the subsequent financial trail can become important for both criminal investigation and asset recovery.
A finance manager may have legitimate access to corporate internet banking but use that access to make unauthorized payments.
Determine precisely which employees could initiate transfers.
Some employees may initiate payments but require approval from a director.
Determine who controlled the relevant mobile phone, security token, electronic signature or authentication application.
Where available, technical information concerning transaction execution can help identify who actually performed the transfer.
A sophisticated internal fraud may involve manipulation of supplier payment information.
A genuine supplier invoices the company for EUR 200,000. An employee changes the supplier’s IBAN in the accounting system and causes the payment to be sent to an account controlled by the employee or an accomplice.
The original invoice, supplier correspondence and previous payment history can demonstrate the legitimate bank account.
Accounting and enterprise software may show which user changed the bank details.
An employee may create a fake supplier and approve invoices for goods or services that were never provided.
System logs and approval records can become critical.
Determine who owns the recipient business.
Common addresses, telephone numbers, family relationships, bank movements or other evidence may reveal connections.
An employee may arrange payments to a supposed consultant who performed no genuine services.
Investigators should examine whether any service was actually provided.
Reports, correspondence, meetings, project files and other work product can help establish whether the consultancy relationship was genuine.
Another common scheme involves an employee instructing customers to pay into a personal bank account rather than the company’s official account.
Emails, WhatsApp messages and payment instructions can demonstrate what the employee told customers.
A legitimate company invoice may contain the corporate IBAN while the employee separately sends different bank details.
Customer evidence can help establish who provided the fraudulent instructions.
Cash businesses can present greater evidentiary difficulties.
Compare invoices, point-of-sale information and accounting records with actual bank deposits.
Patterns may reveal that particular employees or shifts correspond with missing revenue.
Employees may use corporate credit cards for private shopping, holidays, restaurants or online purchases.
A hotel, flight or restaurant payment may have a genuine business purpose.
Identify the business justification, expense report, receipt and approving manager.
A pattern of clearly personal expenditure without authorization can create a substantially stronger case.
An employee may submit fabricated taxi receipts, hotel bills, travel expenses or other reimbursement claims.
Check whether the same receipt was submitted more than once.
Compare reimbursement claims with actual payment records.
Where authenticity is disputed, obtain records directly from the relevant business where legally possible.
Employees responsible for payroll may create fictitious workers, manipulate salary amounts or redirect payments.
Every payroll recipient should correspond with an actual employee.
Several fictitious employees receiving payments into the same account can be a major warning sign.
An employee with payroll access may increase their own bonus or salary without approval.
Determine who had authority to authorize compensation changes.
Foreign manufacturers, distributors and retailers in Turkey may discover substantial stock shortages.
Compare opening stock, purchases, sales, returns, damaged stock and closing inventory.
Identify when shortages occurred and who had access.
Preserve relevant footage immediately because systems may automatically overwrite older recordings.
Badge and entry records may help identify who entered restricted areas.
Compare warehouse exits with authorized shipments.
Factories may experience theft of metals, chemicals, components or production materials.
Some theft schemes disguise valuable material as waste or scrap.
Unusual discrepancies between production volume and material consumption can reveal systematic diversion.
An employee may sell, transfer or conceal a company vehicle entrusted for work purposes.
Unauthorized personal use and deliberate disposal of company property may require different legal analysis.
Employees may also misuse company fuel cards for personal vehicles or third parties.
Mileage, vehicle location and fuel capacity can reveal anomalies.
An employee may operate a parallel business using the employer’s inventory, equipment, employees or customer database.
The criminal complaint should not merely state that company resources were “misused.”
Determine which equipment, stock, labor or funds were diverted.
Employees with financial authority may convert company money into cryptocurrency.
Company Bank Account → Crypto Platform → Cryptocurrency Purchase → Wallet → Subsequent Wallets.
Account records, transaction histories and withdrawal information can become important.
Blockchain evidence can assist with tracing digital assets.
The technical and legal possibilities depend on where the assets ultimately moved and whether identifiable intermediaries were involved.
Retail and e-commerce businesses may experience fraudulent refund schemes.
An employee creates fake customer returns and directs refunds to cards or bank accounts they control.
Was the product physically returned?
Determine whether multiple refunds went to the same account.
An employee may cooperate with a supplier to inflate prices and receive a secret payment.
The company should compare market prices, competing quotations and communications between the employee and supplier.
Where an employee receives money from a supplier in exchange for directing company business, the investigation may extend beyond simple misappropriation.
Emails, messaging records and bidding documents can become important.
International corporate structures create additional challenges.
Local accounting systems, bank records and employee communications may contain critical evidence unavailable to the foreign parent.
Preserve local servers, computers, corporate email and accounting systems.
Determine who could approve payments and contracts.
Reports sent from the Turkish subsidiary to foreign headquarters can show whether local employees concealed the misconduct.
The investigation should determine whether the misconduct was limited to one employee or involved directors, accountants or other managers.
Where appropriate, access to sensitive systems should be secured immediately through lawful corporate procedures.
System access should be documented before accounts are disabled.
A properly organized internal investigation can be extremely important before filing a criminal complaint.
Determine when the misconduct began and ended.
Use actual transaction evidence rather than estimates where possible.
Separate primary suspects from witnesses.
Do not edit original files.
Analysis can be performed on copies while original evidence remains preserved.
Digital evidence should be collected in a manner that allows its origin and authenticity to be explained later.
Preserve complete email threads rather than isolated screenshots.
Relevant communications can become important evidence, but their authenticity and method of acquisition should be considered carefully.
Preserve original recordings and document where and when they were obtained.
Obtain complete statements rather than selected screenshots.
Preserve exports and, where possible, relevant system logs.
Where evidence indicates employee theft or misappropriation, a criminal complaint can be submitted to the competent authorities.
The complaint should explain who the employee was, what authority they possessed, what property was affected, how the misconduct was discovered, which transactions are disputed and what evidence supports the allegations.
Instead of writing “Employee X stole EUR 1 million,” explain the transaction sequence and supporting documents.
15 March – Customer pays EUR 250,000 → Company account receives funds → 16 March – Employee creates fictitious supplier → 17 March – EUR 230,000 transferred to supplier → Supplier controlled by employee’s relative → No goods delivered.
This gives investigators a concrete transaction to examine.
Complex foreign-company complaints can contain hundreds of documents. Organizing them chronologically can make the investigation significantly easier to understand.
Depending on the allegations and applicable procedural requirements, investigators may examine statements, banking movements, digital communications, accounting records and other relevant evidence.
Directors, employees, customers and suppliers may be heard.
The movement of suspected funds can be reconstructed.
Company computers and relevant devices may become significant where the alleged scheme involved electronic transactions.
Complex accounting losses may require technical or financial analysis.
Depending on the alleged offense, evidence and applicable criminal-procedure requirements, measures concerning assets may potentially become relevant.
Where money has already been transferred through multiple accounts, delay can make tracing and recovery more difficult.
Obtaining a criminal conviction and recovering the company’s money are related but distinct objectives.
A criminal complaint should not be the company’s only recovery strategy where civil or commercial remedies may also be available.
Depending on the circumstances, the company may pursue compensation for losses caused by the employee.
Employee theft or serious misuse of company assets can also have significant employment-law consequences, including questions concerning termination.
Criminal, civil and employment steps should be planned consistently so that statements made in one proceeding do not unnecessarily undermine another.
Resignation does not automatically eliminate potential criminal responsibility or the company’s ability to seek recovery.
The procedural options depend on the criminal allegation, available evidence, location of the suspect and subsequent decisions of Turkish judicial authorities.
An employer’s desire to find evidence does not provide unlimited authority to access every aspect of an employee’s private life.
Evidence collection should be conducted with attention to applicable privacy, employment and criminal-procedure rules.
A company should not attempt to obtain evidence through unlawful access to an employee’s personal email, social-media or banking accounts.
Company-owned systems, properly obtained records and evidence secured through judicial procedures should form the basis of the case.
Authorization becomes a central factual issue.
Was there an email, board decision, purchase order or manager approval?
A document produced only after the investigation begins should be examined carefully.
Check payroll records and remuneration approvals.
Request the underlying expense documents.
Determine whether a genuine loan agreement existed before the dispute.
An alleged employment or commercial receivable does not automatically authorize unilateral removal of company property. The precise circumstances and claimed legal basis should be examined.
An employee may return part or all of the money after being confronted.
Record the amount, date and source.
Its legal effect depends on the applicable offense and circumstances.
The company may still need records for criminal, civil, employment, insurance, audit or regulatory purposes.
Foreign companies should also review whether employee dishonesty, crime, fidelity or another relevant insurance policy may cover some of the loss.
Policy notification periods and documentation requirements should be reviewed promptly.
Criminal and insurance processes can proceed on different timelines.
Preserve bank statements, accounting records, CCTV and digital communications; secure unauthorized access to corporate financial systems; identify the suspected transactions and prevent additional loss.
Determine who had access to the affected assets, reconstruct money movements, identify recipient accounts and preserve evidence connecting the suspected employee with the transactions.
Calculate the preliminary loss, interview key internal witnesses where appropriate, organize documentary evidence, assess criminal and employment measures and identify possible assets or recipients relevant to recovery.
Use Employee → Position → Bank Access → Accounting Access → Approval Authority → Asset Access → Relevant Period.
Use Date → Amount → Company Account → Recipient → Stated Purpose → Actual Evidence → Person Initiating → Person Approving → Ultimate Destination.
Use Misconduct Type → Amount/Asset → Recovery Made → Outstanding Loss → Supporting Evidence.
Use Allegation → Supporting Document → Witness → Digital Evidence → Banking Evidence → Additional Evidence Required.
Do not immediately delete the suspected employee’s account before preserving relevant corporate evidence, do not alter accounting entries to “correct” the loss, do not publicly accuse employees before establishing the facts, do not create missing corporate records retrospectively, do not obtain evidence through unlawful access to private accounts, do not wait months before preserving CCTV or digital logs, do not focus solely on dismissal while ignoring asset recovery and do not assume that filing a criminal complaint automatically guarantees repayment.
An effective strategy should begin by determining exactly what was taken, how the employee obtained access and where the property ultimately went. The company should distinguish property secretly taken without entrusted possession from assets lawfully entrusted to the employee but subsequently misused, because this distinction may affect whether theft, breach of trust or another criminal provision is relevant. The company’s internal investigation should preserve original banking, accounting and digital evidence before access rights or systems are changed. Each disputed transaction should then be reconstructed from the company account to the ultimate beneficiary. Where fictitious suppliers are involved, beneficial ownership and actual delivery of goods or services should be examined. Where customer payments were diverted, communications containing unauthorized payment instructions should be preserved. Where inventory disappeared, warehouse, CCTV, access and delivery records should be reconciled. Where cryptocurrency was used, the fiat-to-crypto and wallet transaction trail should be reconstructed. The foreign parent company should obtain local Turkish records rather than relying solely on headquarters reporting. Criminal, civil, employment and insurance strategies should then be coordinated. The practical roadmap is therefore: detect the loss → preserve evidence immediately → secure financial access → identify suspected employees → determine the relevant period → reconstruct every disputed transaction → identify ultimate beneficiaries → preserve banking records → preserve accounting systems → preserve emails and messages → secure CCTV before deletion → examine supplier and customer records → trace related-party payments → trace cryptocurrency where relevant → calculate the company’s loss → distinguish theft from entrusted-property misuse → prepare an organized criminal complaint → pursue appropriate recovery measures → coordinate employment termination strategy → evaluate civil compensation → notify relevant insurers where appropriate → continue tracing assets while the criminal investigation proceeds.
The answer depends on how the employee obtained the money. Theft provisions may apply in some circumstances, while breach of trust under TCK Article 155 may become relevant where company assets were entrusted to the employee and subsequently misused. (Adli Sicil)
Not necessarily. International companies often use “embezzlement” broadly for employee misappropriation, while the Turkish criminal-law concept of zimmet has a more specific scope. Private-sector employee cases should be legally classified according to their actual facts.
Yes, where the circumstances indicate potentially criminal conduct. The company should preserve bank records, authorization documents and evidence showing the purpose and destination of the transfer.
Banking authority does not necessarily authorize personal use of company money. However, entrusted control can affect the legal classification of the alleged offense.
The correct complainant and procedural structure depend on which legal entity owned the misappropriated assets and the corporate circumstances. The relationship between the foreign parent and Turkish subsidiary should therefore be examined first.
Potential recovery depends on the legal basis, evidence and circumstances of subsequent transfers. The company should identify the ultimate beneficiaries as early as possible.
Repayment can be legally relevant, but it does not automatically mean that every criminal, civil or employment consequence disappears.
Potentially, yes. Serious misconduct affecting the employer’s property and trust relationship may have significant employment-law consequences, but termination procedure and evidence should be handled carefully.
Bank statements, accounting data, internet-banking access information, corporate emails, relevant messages, CCTV, ERP logs, invoices, supplier records and documents identifying who authorized the disputed transactions should be preserved promptly.
Not necessarily. Where assets are continuing to disappear, evidence may be lost or money is rapidly moving through accounts, delay can materially affect the investigation and recovery prospects. The timing should be determined according to the circumstances.
Foreign companies discovering employee theft, internal fraud or misappropriation at a Turkish subsidiary may need to coordinate criminal complaints, evidence preservation, forensic financial review, asset tracing, employment measures, compensation claims and insurance notifications. Early reconstruction of the money trail can be particularly important where funds have moved through personal accounts, related companies or cryptocurrency platforms.
Fırat Fesih Kaya Law Office provides legal assistance to foreign companies, international investors and Turkish subsidiaries dealing with employee theft, internal fraud and misuse of company assets in Turkey.
Fırat Fesih Kaya can assist with criminal complaints before Turkish prosecutors, employee theft and breach-of-trust allegations, internal fraud investigations, banking and accounting evidence, fictitious supplier schemes, unauthorized company transfers, cryptocurrency tracing, company asset recovery and coordination of related civil and employment proceedings.
Phone: +90 312 434 22 22
Mobile Phone: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No: 221, Yildirim Tower, Balgat, Cankaya / Ankara, Turkey