

Foreigners Accused Because of an IP Address in Turkey: How to Challenge IP Evidence in 2026
Accused of a crime in Turkey because of an IP address? Learn how foreign suspects can challenge dynamic IP, CGNAT, shared Wi-Fi, VPN, timestamps, subscriber attribution and digital forensic evidence in 2026.
A foreign national may become a suspect in a Turkish criminal investigation because investigators trace an online transaction, social-media post, email, fraudulent payment, unauthorized account access or other internet activity to an IP address associated with the foreigner’s internet subscription.
This can sound conclusive:
“The IP address belongs to you, so you committed the offence.”
From a digital-evidence perspective, however, the issue is considerably more complicated.
An IP address can be an important investigative lead, but identifying an internet subscription is not necessarily the same as identifying the person who actually used the device or performed the alleged act.
Official Ministry of Justice cybercrime materials expressly recognize this distinction. They explain that when an IP address leads to a residence, an investigation may need to examine other occupants, guests and possible third-party Wi-Fi use. Most importantly, those materials state that even where the internet subscriber is the only person living at the address, an IP address by itself should not support a conviction unless the allegation is admitted or the IP evidence is supported by other evidence.
For foreigners accused because of IP evidence in Turkey, the defense should therefore focus on a chain of attribution:
IP address → subscriber → network → device → account → actual user → alleged criminal act.
A weakness at any stage of this chain can materially affect the prosecution’s case.
An IP address is a technical identifier used in internet communications.
It can help investigators determine which internet connection was involved in an online event at a particular time.
Examples include:
But an IP address does not contain the name of the person sitting behind the device.
Investigators generally need additional information to connect the IP address to a subscriber and then to an actual user.
This should never be assumed merely because a police report says so.
Defense counsel should examine:
A technical attribution error at this stage can affect the entire investigation.
Many internet connections use dynamically assigned IP addresses.
This means an address can be assigned to one subscriber during one period and another subscriber later.
Therefore, an IP address without a precise timestamp may have limited attribution value.
The relevant question is not simply:
“Who used this IP address?”
It is:
“Which subscriber was allocated this IP address at the exact date and time of the alleged online activity?”
Even relatively small timing errors can become important where addresses are reassigned.
Time-zone errors are particularly important in investigations involving foreign platforms.
An international service may record an event in Coordinated Universal Time while Turkish authorities or another system records local time.
For example:
Server record: 19:15 UTC
and
Subscriber inquiry: 19:15 local time
may refer to different moments.
The defense should determine:
An incorrectly converted timestamp can potentially result in incorrect subscriber attribution.
Carrier-grade network address translation is particularly important in modern IP investigations.
CGNAT can allow multiple subscribers to share the same public IP address.
This means a public IP address alone may not uniquely identify one internet subscriber.
Additional technical information may be necessary, potentially including:
Constitutional Court case materials demonstrate the importance of obtaining and comparing CGNAT records, telecommunications information and device identifiers where internet-use attribution is disputed.
A foreign suspect should therefore ask whether the prosecution has genuinely identified the individual connection or merely identified a shared public IP.
Where multiple subscribers share a public IP through network-address translation, the source port can become an important technical identifier.
A prosecution file that contains:
IP address + timestamp
may therefore require closer examination if CGNAT was used.
The defense should ask whether the original service provider preserved the technical information necessary to distinguish users sharing that public address.
If critical technical information is missing, attribution may become more difficult.
Suppose investigators correctly establish that an internet subscription registered to a foreign national used the relevant IP address.
The next question remains:
Who actually performed the online activity?
The subscriber could live with:
Other persons may know the Wi-Fi password.
The internet subscriber is not necessarily the only user of the connection.
Official Ministry of Justice cybercrime guidance specifically recognizes that third-party Wi-Fi access and guests can complicate proof and require deeper investigation.
This can be especially important for foreign tourists and business travelers.
A hotel may provide one internet connection to hundreds of guests.
Identifying the hotel’s public IP address therefore does not automatically identify the guest responsible for a particular online event.
Ministry of Justice cybercrime materials specifically identify hotels, internet cafés and shopping centers as environments in which determining the actual user from an IP address may be particularly difficult.
Additional evidence may be necessary, such as:
The same problem exists in company networks.
A foreign employee or executive may become a suspect because an online event originated from the company’s public IP address.
But that IP address may be shared by dozens or hundreds of users.
Relevant evidence could include:
The prosecution should establish the connection between the public IP and the particular employee rather than simply assuming that the foreign employee used it.
This distinction is particularly important for foreign executives.
A foreign director should not automatically be considered the user of every digital system operated by the company.
The same corporate internet connection may be used by:
Corporate authority and technical authorship are different issues.
Potentially, but it should be supported with facts.
Simply stating:
“Someone else could have used my Wi-Fi”
may have limited persuasive value without further evidence.
A stronger defense may identify:
Official guidance recognizes third-party Wi-Fi use as an issue capable of requiring additional investigation.
An unsecured or publicly accessible network can create significant attribution problems.
The defense should investigate:
An open network does not automatically prove that another person committed the offence, but it can be highly relevant to the reliability of individual attribution.
This possibility should be investigated objectively.
The Constitutional Court has discussed case-law principles requiring adequate investigation of claims that internet-access credentials were unlawfully obtained. Relevant inquiries may include CGNAT information, telecommunications records and device data.
Potential supporting evidence includes:
The defense becomes stronger when an alternative-access theory is supported by objective technical evidence.
A virtual private network routes internet traffic through another server.
The website or online service may therefore record the VPN server’s IP address rather than the user’s ordinary public internet address.
VPN use itself does not establish criminal intent.
Foreign executives, companies, journalists, travelers and remote employees may use VPNs for ordinary security and privacy purposes.
Where VPN technology is involved, the defense should determine which IP address represents which stage of the connection.
Proxy servers, cloud systems and corporate gateways can also cause a service to record an intermediary IP address.
Accordingly, defense counsel should determine whether the IP in the investigation belongs to:
The answer can fundamentally change the evidentiary analysis.
Yes, and this possibility should be investigated where supported by circumstances.
A compromised account may produce activity from:
Evidence may include:
A foreigner who suspects account compromise should preserve these records immediately.
Potentially.
Remote-access software and malware can create cases in which activity originates from a device without necessarily being manually performed by the device owner.
Technical examination may investigate:
This is a technical defense and should ordinarily be supported by forensic evidence rather than speculation.
Even after the prosecution identifies the correct internet connection, it may still need to establish which device generated the activity.
Was it:
Device identifiers and forensic examination can therefore be critical.
Depending on the system and investigation, relevant information might include:
The stronger the device attribution, the harder it may be to argue that the activity came from an unrelated user.
But even device attribution does not necessarily establish who physically controlled the device at the relevant time.
Suppose forensic evidence establishes that the relevant activity originated from a foreigner’s laptop.
The next question can still be:
Who was using the laptop?
Possible considerations include:
A technically rigorous defense separates each evidentiary stage.
The defense should not focus only on the internet provider’s subscriber response.
The first question is where the IP address originally came from.
Was it recorded by:
The underlying log should be examined where legally available.
Important questions include:
A screenshot may show information, but it can omit important technical context.
For example, it may not show:
Where the prosecution relies heavily on a screenshot, defense counsel may seek the underlying records or technical examination where procedurally available.
International technology platforms may store data outside Turkey.
This can introduce issues involving:
The chain from foreign platform log to Turkish subscriber identification should therefore be reconstructed carefully.
Yes.
Suppose the prosecution alleges that a foreigner used a home internet connection to commit an online offence at 21:00.
The foreigner may have objective evidence showing they were elsewhere.
Potential evidence includes:
This does not automatically establish who used the internet connection, but it can significantly undermine the allegation that the foreigner personally performed the act.
Imagine the allegedly criminal online activity occurred from an apartment internet connection at 18:30.
Airport CCTV shows the foreigner passing through security at that time.
This can create an important attribution issue.
The defense should preserve CCTV quickly because recordings may be automatically deleted after the operator’s retention period.
Foreign suspects frequently travel.
Relevant hotel evidence can include:
When combined with other evidence, these records can help reconstruct where the foreigner actually was when the disputed internet activity occurred.
A payment at a geographically distant location shortly before or after the alleged online event may provide corroborating evidence.
Other useful records may include:
No single record should necessarily be viewed in isolation.
Telecommunications records may help reconstruct a foreign suspect’s movements and communications.
The Constitutional Court has emphasized, in cases involving disputed digital attribution, the importance of examining technical information such as CGNAT records alongside other telecommunications and device evidence.
This supports a broader defense approach:
Do not challenge one technical record with speculation. Challenge it with other objective records.
If CGNAT is involved, counsel should examine whether the technical correlation actually identifies the suspect’s connection.
Questions may include:
Constitutional Court case law demonstrates that where digital attribution is disputed, meaningful examination of CGNAT and related technical records may be important.
Technical disputes should sometimes be resolved through expert analysis rather than assumption.
The Constitutional Court has found a fair-trial violation in a case where the conviction relied on technical records including CGNAT material while the defendant’s request for expert examination of the reliability and accuracy of those records was rejected without sufficient assessment.
Although every case depends on its circumstances, the decision illustrates an important principle:
Where technical evidence is decisive and genuinely disputed, the defense should clearly explain why the requested technical examination matters.
Depending on the case, an expert may examine:
The objective is not simply to obtain another opinion.
It is to test whether the prosecution’s technical attribution can actually be reproduced and verified.
Yes.
One of the strongest defenses may be that authorities stopped the investigation too early.
For example:
IP address identified → subscriber identified → subscriber charged.
But authorities did not examine:
Ministry of Justice guidance expressly recognizes the need to deepen an investigation where an IP address identifies a residence but personal authorship remains unresolved.
Potentially.
There are two separate defense questions:
Is the evidence reliable?
and
Was the evidence lawfully obtained?
Even technically accurate information can raise legal issues concerning the procedure used to collect it.
Internet traffic information and subscriber data can implicate personal-data and privacy protections. The Constitutional Court has recognized IP addresses, service timing, service type, transferred-data information and subscriber identity information as personal data.
Defense counsel should therefore examine the legal basis and authorization through which relevant records entered the investigation.
Foreign nationality does not make an IP address more reliable.
A foreign suspect can face additional practical disadvantages because:
These factors make early legal and technical review particularly important.
A foreign suspect should understand exactly what the authorities mean.
“The IP is yours” might mean:
Those statements have very different evidentiary significance.
The suspect should avoid making speculative statements before understanding the evidence.
A foreigner who learns of an IP-based investigation should not attempt to “clean” devices.
Do not delete:
The same records that appear concerning at first may later provide exculpatory information.
Many online services allow users to review:
These records can disappear over time.
If they may show unauthorized access, they should be preserved promptly and carefully.
If the foreigner denies personally performing the online act, immediately identify objective location evidence.
Potential evidence includes:
Evidence preservation should begin before records are automatically deleted.
When a foreign national is accused because of an IP address in Turkey, defense counsel should consider:
The practical legal position in 2026 remains that IP evidence can be highly important, but its evidentiary meaning depends on proper technical attribution and the complete body of evidence.
Official Ministry of Justice cybercrime materials expressly caution against treating an IP subscriber as the offender automatically and state that an IP number alone should not support conviction where personal authorship has not otherwise been established.
Constitutional Court materials also show that disputed digital attribution may require examination of CGNAT records, telecommunications data, device identifiers and claims of unauthorized access.
The Constitutional Court has additionally emphasized the importance of giving a defendant a meaningful opportunity to challenge technical evidence where CGNAT records and similar digital material play a decisive role.
Accordingly, the correct defense analysis is not:
“The IP is registered to the foreigner; therefore the foreigner committed the crime.”
The analysis should instead examine:
IP → timestamp → subscriber → network → device → account → actual user → corroborating evidence.
An IP address should not automatically be treated as sufficient proof of personal authorship. Ministry of Justice cybercrime guidance expressly recognizes that an IP subscriber may not necessarily be the person who committed the online act and that supporting evidence may be necessary.
The defense can examine the timestamp, time zone, dynamic allocation, CGNAT records, port information, subscriber identification, shared Wi-Fi, device attribution, VPN use, account security and corroborating evidence.
That can materially affect attribution. Authorities may need to determine which device and individual actually performed the relevant activity rather than assuming the subscriber was responsible.
Hotel networks can be shared by many guests. Official Ministry of Justice guidance specifically recognizes the difficulty of identifying an individual user where the IP address leads to a hotel or another shared-access location.
The defense should examine the precise timestamp, public IP, relevant port information and subscriber correlation. A shared public IP by itself may not uniquely identify one subscriber.
Where technical attribution is genuinely disputed, expert examination may be important. Constitutional Court case law has addressed the fairness implications of rejecting a meaningful request to test decisive CGNAT-based technical evidence without sufficient assessment.
A VPN can change the IP visible to an online service. The defense should determine whether the IP in the file belongs to the user’s internet connection or an intermediary VPN server.
CCTV can provide important corroborating evidence, particularly where it objectively places the foreigner elsewhere at the relevant time. It should be preserved quickly before routine deletion.
No. Deleting potentially relevant digital evidence can damage the defense. Devices, account records and other digital material should be preserved while legal advice is obtained.
The foreigner should avoid speculative explanations, preserve devices and account records, identify evidence showing where they were, and have counsel examine the exact IP, timestamp, time zone, CGNAT information, subscriber attribution, device attribution and supporting evidence.
An IP address can begin a criminal investigation. It should not end the technical analysis.
The central issue is whether the prosecution can reliably connect the disputed online activity not merely to an internet subscription but to the particular foreign national accused of performing it.
Fırat Fesih Kaya Law Office provides criminal-law assistance to foreign nationals, tourists, employees, executives, investors, students and foreign-owned companies involved in digital-evidence and cybercrime investigations in Turkey.
Lawyer Fırat Fesih Kaya assists foreign clients with IP-address evidence, dynamic IP attribution, CGNAT records, shared Wi-Fi disputes, cybercrime investigations, online fraud allegations, social-media cases, device examinations, digital forensics, police and prosecutor statements and challenges to technical evidence.
Early intervention can be especially important because server logs, CCTV, account-security information, router records and other potentially exculpatory evidence may have limited retention periods.
Phone: +90 312 434 22 22
Mobile: +90 532 769 22 22
Email: info@firatfesihkaya.av.tr
Address: Mevlana Boulevard No:221, Yıldırım Tower No:148, 06520 Balgat, Çankaya, Ankara, Turkey
This publication is provided for general informational purposes and does not constitute legal advice. The evidentiary value of an IP address must be assessed according to the precise logs, timestamps, network architecture, CGNAT information, subscriber attribution, device attribution, collection procedure and complete circumstances of the individual investigation.