

A foreign company director’s electronic signature is used without authorization in Turkey. Learn about unauthorized contracts, company liability, evidence preservation, commercial litigation, criminal complaints and urgent protective measures.
A foreign director or company manager may discover that their electronic signature has been used in Turkey without permission to execute a contract, approve a corporate transaction, submit a document or create an apparent financial obligation. The consequences can be substantial. Unauthorized use may result in disputed contracts, payment obligations, corporate filings, bank transactions, guarantees, invoices or other records apparently issued with the director’s approval. The dispute should be handled simultaneously as an electronic-signature, authority, evidence, corporate-liability and potentially criminal-law matter. Immediate preservation of digital evidence is particularly important because the company may later need to establish who actually used the electronic signature, from which device or system, at what time and for what transaction.
An electronic signature may be used to authenticate documents and transactions. If another person obtains access to the director’s signing credentials or signing mechanism, third parties may initially believe that the resulting transaction was genuinely authorized.
The director and company should therefore react immediately rather than simply informing colleagues that the signature was misused.
Obtain every document allegedly executed using the director’s electronic signature.
Determine the document date, signature timestamp, counterparty, transaction value and legal consequences.
One compromised signature event may also indicate additional unauthorized transactions.
Prepare a chronology identifying every suspicious document and transaction.
This may include commercial agreements, purchase orders, corporate resolutions, guarantees, acknowledgments of debt, banking instructions, electronic invoices, applications and other electronic records.
Do not rely solely on printed copies or screenshots.
The original electronic file may contain signature information, certificates, timestamps and other technical data relevant to determining how the document was created and signed.
Relevant evidence can include computer logs, email records, access logs, authentication records, IP information, device records, security alerts and internal correspondence.
Evidence should be preserved before systems are reformatted or user accounts are deleted.
If the unauthorized signature may have originated from a company computer or mobile device, avoid unnecessary changes before appropriate technical preservation is completed.
Routine deletion or resetting can destroy important evidence.
The director should immediately take the appropriate steps to prevent further unauthorized use.
Relevant certificate or service-provider procedures should be reviewed, and compromised credentials or devices should be secured.
Senior management, legal, compliance and information-security personnel should be informed promptly.
Access rights should be reviewed to determine whether another employee, former employee, accountant, consultant or third-party service provider could have used the signature.
Determine who had access to the device, smart card, token or other signing mechanism.
Physical custody can become an important factual issue in later proceedings.
Investigate whether the director disclosed credentials, stored them insecurely or whether another person obtained them without authorization.
This issue may become relevant to both technical attribution and disputes concerning responsibility.
Even where a document technically contains a valid electronic signature, a separate legal question can arise concerning whether the underlying transaction was actually authorized.
Technical authenticity and corporate authority should therefore be analyzed separately.
Determine the director’s actual representation powers at the date of the disputed transaction.
Review corporate records, signature authorities, internal limitations and the type of transaction allegedly approved.
Some companies require multiple authorized representatives for particular transactions.
If the disputed document was signed only with one director’s electronic signature despite a legally relevant joint-representation structure, this may become important.
Large transactions may require board, shareholder, finance or compliance approval.
The absence of required approvals can provide additional evidence that the transaction was not genuinely authorized.
Third-party rights can become a central commercial-law issue.
The company should examine what the counterparty knew or reasonably could have known concerning the director’s authority and the circumstances of the transaction.
Suspicious transaction terms, unusual communication channels or departure from established business practice may become relevant.
If the company disputes the transaction, formal notice should be considered immediately.
The notice should identify the disputed document and make clear that the company or director contests the alleged authorization.
Delay may complicate the evidentiary and commercial position.
After discovering the unauthorized transaction, company personnel should be careful not to act in a manner that could later be argued to constitute approval or acceptance.
Payments, deliveries and correspondence concerning the disputed agreement should be reviewed strategically.
Potentially. The available legal arguments depend on how the electronic signature was used, the authority of the person involved, the counterparty’s position and the nature of the transaction.
The validity and binding effect of the document should therefore be analyzed transaction by transaction.
Depending on the dispute, litigation may be considered to establish that the alleged obligation or transaction does not bind the company.
The appropriate claim depends on the underlying commercial relationship and procedural circumstances.
If the disputed electronic document is used to demand payment or initiate enforcement, the company should respond within the applicable procedural deadlines.
The unauthorized-signature defense should be supported by both corporate and technical evidence.
If the unauthorized transaction threatens immediate transfer of money, shares, assets or other rights, provisional judicial protection may need to be evaluated.
Speed becomes particularly important where the transaction could be completed before ordinary litigation produces a judgment.
If the electronic signature was connected with payment instructions or banking documentation, review company accounts immediately for suspicious transfers.
Banks should be notified through appropriate channels where unauthorized activity is identified.
Determine whether the electronic signature was used for corporate filings, applications or changes affecting the company.
Any unauthorized filing should be addressed through the legally appropriate correction or challenge mechanism.
Unauthorized use becomes particularly serious where documents concern share transfers, management appointments, representation authority or corporate restructuring.
The company should verify its current corporate records immediately.
An unauthorized electronic signature may have been used to create an apparent guarantee, acknowledgment of debt or other security obligation.
These documents can create substantial financial exposure and should receive priority review.
Unauthorized access to another person’s electronic-signature mechanism or use of it to create false transactions may potentially raise criminal-law issues depending on the conduct.
The facts should be assessed carefully before a criminal complaint is prepared.
A complaint should not consist only of an allegation that “someone used my electronic signature.”
Prepare the disputed documents, chronology, access evidence, relevant communications and information identifying potential users.
Digital forensic analysis may help determine which computer, user account or network environment was involved.
Where technically available, logs and electronic records can substantially strengthen the evidentiary file.
An IP address can be useful but does not necessarily identify the individual who physically performed the transaction.
It should be considered together with device, account, timing and access evidence.
Review communications immediately before and after the disputed transaction.
A person requesting documents, discussing the transaction or transmitting the signed file may leave an evidentiary trail.
Business communications through messaging platforms may help establish who initiated or approved a transaction.
Preserve original records where possible rather than relying exclusively on isolated screenshots.
If a former employee retained access to company systems or signing mechanisms, determine when their employment ended and when access privileges were revoked.
Weak offboarding procedures can create continuing security risks.
Companies frequently allow accountants, consultants and service providers to use internal systems.
Review exactly what access was granted and whether credentials were shared contrary to company policy.
The company should distinguish between evidence showing that a credential was used and evidence identifying the individual responsible.
Premature accusations can create additional disputes.
A director living outside Turkey may need to establish that they were physically elsewhere when the disputed transaction occurred.
Travel records, passport information, flight records, meeting calendars and other evidence can potentially support the factual chronology.
Electronic signatures can potentially be used remotely. Therefore, evidence that the director was abroad should be combined with technical and corporate evidence.
Determine whether electronic-signature devices and credentials were properly controlled.
After the incident, introduce stronger access restrictions and documented custody procedures.
Do not limit the investigation to the transaction first discovered.
Search for other documents signed during the suspected compromise period.
Multiple unauthorized documents may involve the same commercial party.
Compare dates, communications, payment flows and personnel involved.
Keep records of unauthorized payments, legal expenses, investigation costs, lost assets and other measurable consequences.
This evidence may become relevant to later compensation claims.
Potentially. The responsible person may face civil liability for losses caused by unauthorized use, depending on the circumstances and evidence.
Contractual liability of service providers or employees may also need to be considered separately.
If an employee used the signature without authorization, employment-law and commercial consequences may arise alongside possible criminal issues.
Preserve personnel records and internal authority documentation.
If a security failure involving an external technology or professional service provider contributed to the incident, review contractual security obligations and liability clauses.
Companies carrying cyber, crime or other potentially relevant insurance should review notification requirements promptly.
Late notice can create separate coverage disputes.
If the foreign director, manufacturer, parent company or electronic systems are outside Turkey, documents and technical evidence may need to be obtained from another jurisdiction.
Start preservation efforts before routine data-retention periods expire.
A director should not assume that an unauthorized electronic signature automatically creates personal liability.
The underlying document, capacity in which it was signed and surrounding corporate authority must be examined.
The same disputed signature may create different questions for the company and individual director.
A defense strategy should address both separately.
After discovering unauthorized electronic-signature use, the foreign director and company should immediately secure the signing mechanism, preserve original electronic documents, identify all suspicious transactions, protect system logs, review corporate authority, notify relevant counterparties where appropriate, examine bank and corporate records, evaluate interim judicial protection, preserve evidence for potential criminal proceedings and investigate whether other transactions were affected.
Companies should maintain strict individual control of electronic-signature credentials, prohibit credential sharing, document custody, restrict administrator access, revoke former personnel access immediately and maintain audit logs.
High-value transactions should also require independent internal verification.
Not necessarily. The technical signature, actual authorization, representation authority and circumstances surrounding the transaction should all be examined.
Secure the electronic-signature mechanism and preserve the disputed electronic documents and access evidence immediately.
Yes. The original electronic document can contain information that is lost when the document is merely printed.
Potentially. The available remedy depends on authority, evidence, counterparty circumstances and the nature of the transaction.
Depending on the conduct, unauthorized access and use may potentially raise criminal-law issues.
Where the company disputes the transaction, prompt formal notification can be important. The wording and timing should be considered strategically.
Technical records may be highly relevant in identifying how, when and through which systems the signature was used.
Evidence of physical location can support the chronology, but it should be combined with technical evidence because electronic transactions may occur remotely.
Potentially, depending on where the funds went, the legal basis of the transfer and how quickly protective measures are pursued.
Yes. Unauthorized use discovered in one document may indicate a broader compromise.
Unauthorized use of a foreign director’s electronic signature can create simultaneous commercial, corporate, enforcement, digital-evidence and criminal-law risks. Fırat Fesih Kaya Law Office assists foreign directors, international investors and foreign-owned companies facing disputed electronic transactions in Turkey. Lawyer Fırat Fesih Kaya provides legal assistance in challenging unauthorized contracts and corporate transactions, preserving electronic evidence, seeking urgent judicial measures, responding to enforcement claims and coordinating civil and criminal proceedings arising from unauthorized electronic-signature use.
Phone:
+90 312 434 22 22
Mobile:
+90 532 769 22 22
Email:
info@firatfesihkaya.av.tr
Address:
Mevlana Boulevard No:221, Yıldırım Tower, Office No:148
06520 Balgat, Çankaya, Ankara, Turkey