

A foreign company suffers a ransomware attack in Turkey. Learn how to preserve digital evidence, file a criminal complaint, protect logs and servers, document cryptocurrency demands and manage the investigation.
A ransomware attack against a foreign-owned company operating in Turkey can stop production, encrypt servers, disable accounting systems, expose customer information and create substantial financial losses within hours. The first reaction is often purely technical: isolate affected systems, restore backups and restart operations. However, ransomware is also potentially a criminal investigation, digital-evidence and corporate-risk matter. Actions taken during the first hours can determine whether the attacker can later be identified and whether critical evidence remains usable.
A foreign company should therefore coordinate cybersecurity containment with legal evidence preservation. Systems should not be unnecessarily wiped or reformatted before relevant forensic evidence is secured, ransom communications should be preserved, cryptocurrency-payment instructions should be recorded and a structured chronology of the incident should be created.
The company should activate its incident-response procedure and isolate compromised systems where technically appropriate. At the same time, it should preserve evidence concerning how the attack occurred and what the attacker did.
The objective is to contain the incident without unnecessarily destroying evidence.
Rapid restoration may be commercially necessary, but indiscriminately wiping affected systems can destroy logs, malware artifacts, access records and other forensic evidence.
Before rebuilding critical devices, determine whether forensic imaging or another preservation method is appropriate.
Keep the original ransom message and record where it appeared.
Preserve screenshots and available metadata as well as any files containing payment instructions, deadlines, threats or contact information.
If attackers communicate by email, preserve the messages in their original electronic form where possible rather than relying only on screenshots.
Technical information contained in email records may become relevant to forensic analysis.
Ransomware groups frequently demand payment through cryptocurrency.
Record every wallet address, amount demanded, cryptocurrency type, transaction instruction and communication concerning payment.
If negotiations take place through a website, messaging platform or attacker-controlled portal, preserve the complete conversation.
Screenshots can help, but technical exports or other original records may provide stronger evidence where available.
Record when suspicious activity was first detected, when systems became inaccessible, when the ransom note appeared, which systems were affected, what containment actions were taken and when management became aware of the incident.
Update the timeline as new facts emerge.
Potentially relevant records can include authentication logs, firewall logs, VPN records, endpoint security alerts, server logs, cloud-access records and other security information.
Retention periods should be checked immediately because some systems automatically overwrite older records.
Determine which user accounts were accessed before and during the attack.
Suspicious login locations, times, devices and authentication events may help reconstruct the intrusion.
If remote access may have been used, VPN records can be particularly important.
The company should identify successful and failed connections, source addresses and the accounts involved.
Network logs may help identify communication between compromised systems and external infrastructure.
The company’s cybersecurity team should preserve relevant records before routine retention systems delete them.
If the business uses cloud infrastructure, preserve relevant audit and authentication records promptly.
Ransomware investigations should not focus solely on physical computers located in the Turkish office.
Possible attack vectors include compromised credentials, phishing, vulnerable remote-access services, exposed servers, compromised suppliers or exploitation of software vulnerabilities.
The company should avoid publicly attributing the attack until the technical evidence is sufficiently developed.
Modern ransomware incidents may involve both encryption and data exfiltration.
Investigate whether attackers copied customer information, employee records, commercial secrets, contracts, financial data or other sensitive information before encryption.
If information may have left the network, preserve traffic records, security alerts and forensic findings supporting the conclusion.
Avoid assuming that a ransom message claiming “we stole all your data” is automatically accurate.
For important servers or endpoints, forensic preservation may be useful before remediation.
The process should be properly documented so that investigators can later understand how the evidence was obtained and preserved.
Record who collected each device or digital record, when it was collected, where it was stored and who subsequently accessed it.
This becomes particularly important if digital evidence is later submitted in criminal proceedings.
Work from forensic copies where technically appropriate rather than repeatedly examining the original evidence.
Any unavoidable changes should be documented.
Potentially, yes. Where conduct affecting the company falls within Turkish criminal jurisdiction, the company may report the incident to the competent Turkish authorities and provide the available evidence.
The appropriate procedural strategy depends on the facts of the attack and the company’s connection with Turkey.
The complaint should provide a clear factual chronology rather than simply state that “the company was hacked.”
It should identify the affected company and systems, date and time of discovery, nature of the unauthorized access, encryption, ransom demand, suspected data theft, known financial losses and evidence already preserved.
Large quantities of raw logs should be accompanied by an explanation of what they show.
A structured evidence index can identify each server, device, log source, communication and forensic report.
Original records should be preserved separately. Investigative summaries or converted files can be prepared, but the underlying original data should remain available.
Depending on the investigation and applicable criminal-procedure requirements, digital systems or copies of data may become relevant to investigative measures.
Companies should coordinate with counsel and technical personnel so that legitimate investigative needs can be addressed while unnecessary business disruption is minimized where legally possible.
A company does not have to ignore operational recovery simply because an investigation may follow.
The goal is to preserve legally and technically significant evidence before systems are rebuilt or restored.
Record which backups were used, which systems were restored, which devices were replaced and what remediation measures were implemented.
This helps distinguish post-attack changes from the condition of the network at the time of the incident.
Backups can show the historical state of files and systems.
Do not automatically overwrite all previous backups during recovery.
Attackers may attempt to delete or encrypt backup systems before launching ransomware.
Preserve evidence showing whether backup infrastructure was accessed.
This decision creates significant legal, sanctions, financial, operational and cybersecurity risks. Payment does not guarantee restoration or deletion of stolen information.
Before any payment, the company should evaluate the recipient, applicable sanctions risks, insurance position, payment mechanics and law-enforcement implications.
A ransomware payment can create additional legal concerns where the recipient or associated infrastructure is connected with a sanctioned person or organization.
The company should therefore avoid treating payment as a purely technical decision.
If management considers payment, preserve communications with negotiators, insurers, cybersecurity advisers and other relevant participants.
If a payment is ultimately made, retain complete transaction records.
Keep wallet addresses, transaction identifiers, timestamps, amounts and exchange-related records.
These may later assist financial tracing.
If the company has cyber insurance, review notification requirements immediately.
Policies may contain requirements concerning forensic vendors, legal advisers, ransomware negotiations and consent before incurring certain expenses.
Keep records of production shutdown, lost sales, emergency IT expenses, forensic fees, recovery costs and other direct financial consequences.
Do not wait until months later to reconstruct the financial impact.
Identify employees who first noticed suspicious activity, received phishing messages or interacted with compromised accounts.
Their recollections should be documented while events remain fresh.
If phishing is suspected, preserve the original email and available technical information.
Do not merely forward the message repeatedly, as this may make later technical analysis more difficult.
Cloud providers, hosting companies, managed service providers and other technology vendors may hold logs that the company itself does not possess.
Request preservation promptly where appropriate.
If the ransomware entered through a vendor or shared software platform, preserve contracts, security correspondence and technical records concerning the third party.
Potential contractual responsibility may need separate analysis.
For multinational groups, the Turkish company and foreign headquarters should establish a unified incident-response structure.
Evidence may exist across several jurisdictions and corporate entities.
Cybersecurity, legal, management and public-relations teams should work from a verified factual chronology.
Unconfirmed technical assumptions should not be presented internally or externally as established facts.
Companies should distinguish operational incident reports, forensic findings, legal assessments and communications prepared for different purposes.
Sensitive material should be handled through an appropriate legal structure.
If the attackers accessed information relating to identifiable individuals, the company should separately evaluate its obligations under the applicable Turkish personal-data framework.
The criminal complaint and data-protection response are related but distinct workstreams.
Ransomware attackers may obtain source code, pricing information, technical designs, customer lists or strategic documents.
Identify sensitive commercial information that may have been exfiltrated and preserve evidence of its confidentiality and economic importance.
Some attackers threaten to publish information if payment is refused.
Any monitoring should be performed safely and lawfully. Preserve evidence if company data later appears online.
Employees should not independently communicate with attackers from personal accounts or devices.
Communications should be centrally controlled and documented.
IP addresses, usernames or cryptocurrency wallets do not necessarily establish the identity of an individual attacker.
Attribution should be based on sufficient technical and investigative evidence.
Foreign forensic reports can potentially provide valuable evidence. The company should preserve the underlying methodology, source data and records demonstrating how the conclusions were reached.
Attack infrastructure, hosting providers, cryptocurrency exchanges and suspects may be located outside Turkey.
The investigation may therefore require international evidence-gathering mechanisms depending on the circumstances.
A criminal complaint may still be important even where the perpetrator is initially unknown.
Preserved technical evidence may later connect the attack with other investigations or identified infrastructure.
The company does not need to complete its own attribution investigation before approaching the authorities.
Known facts can be presented while additional evidence is preserved and developed.
Investigators may seek statements from managers, IT employees or other personnel who can explain the incident.
Relevant witnesses should review the factual chronology and distinguish personal knowledge from information learned from others.
A foreign company representative who does not sufficiently understand Turkish should ensure that they understand the procedural documents and statements attributed to them. Interpretation issues should be addressed before signing records.
Company representatives should read investigative records carefully and ensure that technical descriptions and factual statements accurately reflect what they said.
Errors should be raised before signature where possible.
Operational recovery does not end the legal process.
Maintain a secure evidence archive containing forensic images, logs, communications, reports, screenshots, ransom notes, wallet information and investigation correspondence.
A well-organized file should include the incident chronology, affected-system inventory, forensic preservation records, ransom communications, cryptocurrency information, security logs, backup records, employee statements, financial-loss evidence and correspondence with relevant third parties.
Potentially, yes. Where the conduct falls within Turkish criminal jurisdiction, the company can evaluate filing a criminal complaint and submitting preserved digital evidence.
Not before considering whether relevant forensic evidence should first be preserved. Operational recovery and evidence preservation should be coordinated.
Screenshots are useful, but original electronic files, communications, metadata and associated technical evidence should also be preserved where available.
Yes. Wallet addresses, transaction instructions and related communications can become important investigative evidence.
Yes, but critical evidence should be preserved before restoration destroys or changes it.
Payment requires careful assessment of legal, sanctions, insurance, cybersecurity and commercial risks. It does not guarantee successful recovery or deletion of stolen data.
Potentially. Their evidentiary value will be stronger where methodology and underlying technical records are properly preserved.
The company should separately evaluate applicable personal-data obligations in addition to the criminal investigation.
Cross-border investigative and evidence-gathering mechanisms may become necessary.
Contain the attack without destroying the evidence. Preserve logs, compromised-system evidence, ransom communications, cryptocurrency information and the incident chronology before routine restoration or deletion makes reconstruction of the attack substantially more difficult.
Ransomware incidents involving foreign companies can require simultaneous management of criminal complaints, digital evidence preservation, forensic investigations, cryptocurrency tracing, business interruption, cyber insurance, personal-data exposure and cross-border evidence.
Fırat Fesih Kaya Law Office assists foreign companies and international investors affected by cybercrime and ransomware incidents in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in preparing criminal complaints, organizing digital evidence, coordinating forensic documentation, protecting company representatives during criminal proceedings and evaluating related financial and contractual claims.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower, Office No:148, 06520 Balgat, Çankaya, Ankara, Turkey