

A foreign company’s business email is compromised and payment is diverted to a fraudulent bank account in Turkey. Learn about criminal complaints, bank account freezes, digital evidence, fund recovery and urgent legal remedies.
Business Email Compromise (BEC) and payment diversion fraud can cause substantial losses to foreign companies doing business with customers, suppliers or distributors in Turkey. A typical case begins when criminals gain access to a corporate email account, imitate an employee or supplier, alter payment instructions and persuade the victim to transfer money to a fraudulent bank account. The money may then be rapidly transferred through several accounts, withdrawn in cash, converted into crypto-assets or sent abroad. When Turkey is connected to the payment, recipient account, suspect or transaction chain, speed is critical. A foreign company should immediately preserve digital evidence, notify the relevant banks, determine the Turkish connection to the transaction and evaluate a criminal complaint seeking investigation of the individuals and accounts involved.
BEC is generally a fraud method in which criminals exploit or imitate legitimate business communications to redirect payments. The criminal may compromise a genuine corporate email account or create an address visually similar to the real address.
The victim believes that it is communicating with a legitimate business partner when the payment instructions have actually been changed by the fraudster.
A foreign company may receive an apparently genuine email stating that the supplier has changed its bank account. Alternatively, the Turkish customer may receive instructions supposedly sent by the foreign supplier requesting payment to a different account.
Because the criminals may have monitored genuine correspondence beforehand, fraudulent messages can contain correct invoice numbers, employee names, transaction values and contract details.
Fraudsters frequently register domains that closely resemble genuine corporate domains. A changed letter, added character or different domain ending may be difficult to notice.
Preserve both the genuine and fraudulent email addresses exactly as they appeared.
Not every case involves a fake domain. Criminals may obtain access to an actual company mailbox and send fraudulent instructions from the genuine account.
This makes email-header information, access logs and authentication records particularly important.
Money transferred into a fraudulent account can move quickly through multiple accounts. Businesses should therefore avoid spending days conducting only an internal investigation before contacting the relevant bank and obtaining legal assistance.
Fund-tracing and preservation efforts should begin immediately.
The company that made the transfer should contact its bank immediately, explain that the transaction resulted from suspected fraud and request available recall, fraud-reporting or interbank procedures.
Provide the transaction reference, amount, currency, beneficiary details and transfer date.
If the fraudulent beneficiary account is located in Turkey, information concerning the account and transfer should be included in the criminal complaint so that the competent authorities can investigate the account and transaction history.
Private parties may not themselves be entitled to obtain all confidential banking information directly.
Not necessarily. Once funds have been credited or transferred onward, recovery can involve banking procedures, criminal investigation, judicial measures and potentially separate civil remedies.
The existence of a fraudulent transfer does not mean that a bank can automatically reverse every transaction on demand.
Where the conduct has a sufficient connection with Turkey, the foreign company should evaluate filing a criminal complaint with the competent Turkish authorities.
The complaint should explain the fraud chronologically and identify the relevant Turkish bank account, transaction and available suspect information.
The legal characterization depends on the facts. Payment diversion schemes may potentially raise issues involving fraud, information-system misuse, unauthorized access, banking-related conduct, forgery or other criminal offenses.
The investigation should be based on the actual method used rather than forcing every BEC incident into one predetermined offense.
A useful complaint should identify the genuine commercial relationship, original invoice, legitimate payment instructions, fraudulent communication, altered bank details, transfer and discovery of the fraud.
Attaching organized evidence can significantly improve the clarity of the investigation.
Do not preserve only screenshots. Where technically possible, retain the original electronic messages and associated metadata.
The technical origin and routing of communications may become relevant to forensic examination.
Full email headers can contain information relevant to servers, routing and authentication. The company’s IT team should preserve them before messages are deleted or systems are changed.
After securing the account, preserve forensic evidence. Immediately wiping a device or deleting the mailbox may destroy information needed to reconstruct the intrusion.
Security containment and evidence preservation should be coordinated.
Collect available information concerning unusual login times, IP information, geographic indicators, authentication events, password resets and mailbox rules.
This evidence may help determine whether the real account was compromised.
Attackers sometimes create mailbox rules that automatically forward, hide or delete communications.
The IT investigation should therefore examine forwarding rules, filters and account settings.
If the criminals altered an invoice, keep both the genuine and fraudulent versions.
Compare the bank account, beneficiary, company information, invoice number, amount and formatting.
Record the beneficiary’s full name, bank, branch or account information where available, IBAN, transfer reference, date, currency and amount.
Do not rely on an employee’s handwritten summary if the original banking record is available.
The initial recipient may not be the person who ultimately controls the fraud. Funds may pass through several intermediary accounts.
The criminal investigation may therefore need to trace subsequent transfers rather than focusing exclusively on the first beneficiary.
Fraudulent funds may be received by individuals who allow their bank accounts to be used by others. Their criminal responsibility depends on the evidence concerning their knowledge and participation.
A foreign company should therefore avoid assuming that the account holder necessarily organized the entire scheme.
Depending on the evidence and applicable criminal procedure, judicial measures concerning suspected criminal proceeds may potentially become relevant.
The complaint should emphasize urgency where there is a continuing risk that identifiable funds will be dissipated.
Potentially. Banking transaction records may reveal subsequent transfers.
The practical possibility of recovery, however, becomes more difficult when funds are rapidly dispersed, withdrawn or transferred internationally.
The investigation may need to examine transfers involving crypto-asset platforms and relevant transaction records.
Preserve every wallet address, transaction identifier and platform communication known to the company.
Cross-border transfers can make recovery more complicated and may require international cooperation. The Turkish portion of the transaction chain should nevertheless be documented carefully.
A foreign corporate victim may be able to act in Turkey through properly authorized legal representation, depending on the procedural step involved.
Corporate authorization documents should therefore be prepared carefully.
The company may need to establish its legal existence and the authority of the person acting on its behalf.
For foreign companies, legalization, certification and translation requirements should be planned before they cause unnecessary procedural delay.
A foreign company seeking Turkish legal representation should ensure that its power of attorney satisfies the requirements applicable to the intended proceedings.
Corporate signatory authority should also be verified.
Prepare a clear calculation showing the amount transferred, amount recovered, bank charges and remaining loss.
If several payments were diverted, create a transaction-by-transaction table.
The investigation may need to understand why the payment was made and why the fraudulent instructions appeared credible.
Keep the supply agreement, purchase order, invoice and genuine correspondence.
A central factual issue is whether the foreign company’s system, Turkish customer’s system, supplier’s system or another intermediary was compromised.
This can also affect later contractual and civil disputes concerning who should bear the loss.
A separate contractual dispute can arise where the buyer transferred money to a fraudulent account believing it was paying the supplier.
Whether the buyer’s genuine payment obligation was discharged depends on the contractual and factual circumstances and should be analyzed separately from the criminal investigation.
The foreign supplier may never receive its invoice payment, while the buyer may have already lost the same amount to the fraudster.
Both businesses therefore have an incentive to preserve evidence rather than immediately blaming each other.
Check whether the agreement specifies approved bank accounts, procedures for changing payment details, verification requirements and responsibility for compromised communications.
These clauses can become important in a subsequent civil dispute.
Companies should investigate whether employees followed internal procedures when the payment details changed.
The purpose is not only to allocate responsibility but also to understand exactly how the fraud succeeded.
Even where an employee failed to verify changed payment instructions, the conduct of the fraudsters can still require criminal investigation.
Internal-control failures and offender liability are separate questions.
Cyber, crime, fidelity or other insurance policies may potentially provide relevant coverage depending on their wording.
Notification periods and cooperation requirements should be reviewed promptly.
If insurance may apply, timely notice should be considered even while the criminal investigation is continuing.
Recovery may potentially occur if funds or assets connected with the offense can be identified and legally returned. However, a criminal complaint should not be treated as a guaranteed recovery mechanism.
Civil or enforcement remedies may also need to be considered.
Depending on the circumstances, claims against recipients, contractual counterparties or other responsible parties may need separate evaluation.
The most effective strategy may involve criminal, banking and civil measures simultaneously.
Fraud victims are sometimes contacted by supposed investigators, recovery agents or intermediaries demanding further payments.
Any such request should be independently verified.
Where immediate preservation of funds or evidence is being considered, careless communication with suspected participants can allow assets to disappear.
External communications should be coordinated strategically.
Determine when the fraudulent access began, which accounts were affected, which messages were accessed and whether other payment instructions were manipulated.
One discovered fraudulent transfer may not be the only compromised transaction.
If a genuine company mailbox was compromised, other counterparties may have received fraudulent payment instructions.
Appropriate warnings can help prevent additional losses.
The compromised system should be secured immediately. Password changes, multi-factor authentication and access review may be necessary.
These cybersecurity measures should be performed while preserving relevant evidence.
A strong case file should show:
the genuine business relationship; the legitimate invoice; the original payment account; the compromised or fake communication; the changed payment instructions; the bank transfer; discovery of the fraud; communications with banks; and subsequent recovery efforts.
Important emails, contracts and banking records may need to be presented in a form usable in Turkish proceedings.
The original documents should always be preserved alongside translations.
For international companies, email and banking timestamps may appear in different time zones.
Normalize the chronology carefully to avoid apparent inconsistencies.
Investigators may need to examine the company, directors, account users and transaction history.
The existence of a corporate beneficiary does not automatically mean the company conducted a genuine commercial transaction.
That explanation should be investigated rather than accepted or rejected automatically.
The transaction history, communications, withdrawal pattern and relationship with other participants may help establish the recipient’s role.
Depending on the investigation, authorities may seek information from individuals with direct knowledge of the events.
Legal representation and preparation of corporate evidence can reduce unnecessary confusion.
The foreign company should immediately secure the compromised email system, preserve original messages and headers, notify the sending bank, identify the recipient account, preserve transaction records, determine whether a Turkish connection exists, prepare the corporate authorization documents required for representation, evaluate an urgent criminal complaint, request investigation of the money trail, notify any relevant insurer and consider parallel civil recovery options.
Potentially, where the fraud has a sufficient connection with Turkey, such as a Turkish recipient account, suspect or relevant conduct.
Bank notification should normally be treated as urgent because funds may move quickly. Banking and legal measures can proceed in parallel.
Potentially, subject to the applicable criminal-procedure requirements and the competent authorities’ assessment.
Screenshots can help, but original emails, headers, server information and other digital evidence should also be preserved where possible.
Potentially, depending on evidence of knowledge and participation. Receiving money alone does not establish every participant’s role in the overall scheme.
Preserve forensic evidence, secure the system and document unauthorized access. The technical compromise can become central evidence.
The criminal investigation and the contractual question of whether the customer’s debt was discharged are separate issues and should both be examined.
Potentially. Wallet addresses, transaction identifiers and exchange records should be preserved immediately.
Recovery depends heavily on how quickly the fraud is detected, whether funds remain identifiable and what assets or accounts can legally be reached. It is not guaranteed.
Act simultaneously on three fronts: preserve the digital evidence, notify the banking system immediately and begin the appropriate criminal process before the funds and electronic evidence become harder to trace.
Business email compromise cases involving Turkey can require urgent coordination of criminal complaints, banking records, account and asset measures, digital evidence, international transactions, corporate authorization documents and parallel recovery claims.
Fırat Fesih Kaya Law Office assists foreign companies, international suppliers, exporters and corporate victims facing payment diversion, cyber-enabled fraud and fraudulent bank transfers connected with Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preparing criminal complaints, preserving financial and digital evidence, following investigations involving Turkish bank accounts, coordinating foreign corporate documents and evaluating parallel civil and asset-recovery remedies.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey