Cybercrime and Aggravated Fraud Lawyer in Antalya, Turkey

Cybercrime and online fraud investigations often involve much more than the contents of a single computer or telephone. A criminal file may combine bank transactions, IP records, messaging applications, online accounts, digital devices, payment systems and statements from several suspects or complainants.

For that reason, I do not treat every offence committed through the internet as the same type of cybercrime. Under Turkish criminal law, unauthorised access to a computer system, interference with data, misuse of bank or credit cards and aggravated fraud committed through information systems are legally distinct offences.

When I review a cybercrime or fraud file, I first identify exactly what conduct is attributed to the client. I then examine whether the digital and financial evidence actually connects that person with the account, device, transaction or communication relied upon by the prosecution.

For broader information about criminal investigations, statements, evidence and defense strategy, see the Antalya Criminal Defense Lawyer page.

Attorney Cennet Kesici Çetinbaş - Antalya Lawyer

Attorney Cennet Kesici Çetinbaş
Antalya Bar Association
Last updated: 30 August 2026
Legal review: Attorney Cennet Kesici Çetinbaş

Cybercrime and Aggravated Fraud Cases in Antalya - Attorney Cennet Kesici Çetinbaş

Quick Answer: How Are Cybercrime and Online Fraud Cases Treated in Turkey?

Turkish criminal law contains several separate offences that may arise in cases involving computers, mobile devices, internet accounts, banking systems and digital communications.

Important provisions include:

  • Article 243: unauthorised access to an information system,
  • Article 244: disrupting systems or destroying, altering or transferring data,
  • Article 245: misuse of bank or credit cards,
  • Article 245/A: prohibited devices, programs, passwords or security codes, and
  • Article 158: aggravated fraud, including fraud committed through information systems or by using banks or credit institutions as instruments.

The fact that a telephone, computer or internet service was involved does not automatically determine the offence. The way the technology was used and the purpose of the conduct must be examined.

What Is Considered a Cybercrime Under Turkish Law?

The Turkish Criminal Code contains a specific chapter concerning offences in the field of information systems.

These provisions primarily protect the security and functioning of information systems, data and payment instruments.

However, technology can also be used as an instrument for offences regulated elsewhere in the Criminal Code. Aggravated fraud committed through information systems is one of the most important examples.

I therefore distinguish between a crime committed against an information system and an offence committed through an information system. This distinction can determine the applicable article, potential sentence and evidence that must be proved.

Unauthorised Access to an Information System – Article 243

Article 243 regulates unlawful entry into all or part of an information system or unlawfully remaining in that system.

The basic form is punishable by imprisonment of up to one year or a judicial fine.

If data contained in the system is destroyed or altered as a result of the act, the statute provides a separate imprisonment range of six months to two years.

Article 243 also regulates unlawfully monitoring data transmissions occurring within or between information systems through technical means without entering the system. That conduct is punishable by imprisonment from one to three years.

Does Knowing a Password Prove Lawful Access?

Not necessarily.

The legal issue is not merely whether a password or login information was technically available. The scope of any permission, who provided access, whether permission had been withdrawn and which parts of the system were accessed may all become relevant.

In workplace, relationship or shared-device disputes, this distinction can be particularly important.

Blocking a System, Altering Data or Making Data Inaccessible – Article 244

Article 244 regulates several forms of interference with information systems and data.

A person who prevents or disrupts the functioning of an information system may be sentenced to imprisonment from one to five years.

Destroying, altering or making data inaccessible, placing data into a system or sending existing data elsewhere is subject to a separate imprisonment range of six months to three years.

Where these acts are committed against an information system belonging to a bank, credit institution or public institution, the sentence is increased under the statutory rule.

If unlawful benefit is obtained through the conduct described in Article 244 and the act does not constitute another offence requiring punishment, Article 244 also contains a separate provision concerning unlawful benefit.

Misuse of Bank or Credit Cards – Article 245

Article 245 regulates several distinct offences involving bank and credit cards.

Using another person's bank or credit card without consent to obtain a benefit for oneself or another person is punishable by imprisonment from three to six years together with a judicial fine.

The provision also separately regulates:

  • producing, selling, transferring, purchasing or accepting counterfeit bank or credit cards linked to other persons' accounts, and
  • obtaining a benefit by using a counterfeit or falsified bank or credit card.

These forms carry different statutory punishment ranges and should therefore be distinguished carefully from ordinary fraud and aggravated fraud.

Prohibited Devices and Programs – Article 245/A

Article 245/A concerns devices, computer programs, passwords or security codes created exclusively for committing specified cyber offences or other offences capable of being committed through information systems.

The provision can apply to conduct such as manufacturing, importing, transporting, storing, selling, purchasing, providing or possessing qualifying tools where the statutory elements are established.

The statutory punishment is imprisonment from one to three years together with a judicial fine.

Aggravated Fraud Through Information Systems – Article 158

Many cases described in everyday language as “cyber fraud” are legally prosecuted as aggravated fraud rather than as a pure information-system offence.

Article 158 includes fraud committed through the use of information systems, banks or credit institutions as instruments.

The general punishment for aggravated fraud is imprisonment from three to ten years together with a judicial fine.

For certain forms of aggravated fraud, including the use of information systems, banks or credit institutions as instruments, the Criminal Code provides a higher minimum imprisonment threshold and additional rules concerning the judicial fine.

Examples of Allegations That May Require Article 158 Analysis

Depending on the precise facts, investigations may involve allegations concerning:

  • online marketplace fraud,
  • fake product or service listings,
  • social-media account fraud,
  • fake investment schemes,
  • phishing-related payment transactions,
  • online banking fraud,
  • fraud involving bank transfers or payment accounts,
  • impersonation of bank or institutional personnel,
  • cryptocurrency-related fraud allegations, or
  • other deceptive conduct carried out through digital systems.

This list does not mean that every allegation automatically constitutes aggravated fraud. The deception, intent, benefit, loss and role of the information system must be established from the individual case.

What Is the Difference Between Cybercrime and Aggravated Fraud?

This distinction is one of the most important issues in these files.

For example, unlawfully accessing another person's account may raise Article 243 issues. Altering or deleting data may bring Article 244 into consideration. Using another person's bank card may fall under Article 245.

By contrast, deceiving another person and obtaining a financial benefit by using an information system as the instrument of the fraud may require assessment under Article 158.

A single factual sequence can sometimes lead prosecutors to consider more than one offence. The question then becomes whether the statutory elements of each alleged offence are independently established and how the rules concerning concurrence of offences apply.

The correct legal classification should follow the conduct and evidence. I would not treat the police description “cybercrime” or “online fraud” as a final legal conclusion without examining the specific acts attributed to each suspect.

Bank Account, IBAN and Payment Account Fraud Cases

A common issue in current fraud investigations is the use of a bank account, payment account, card or cryptocurrency account belonging to someone other than the principal person alleged to have communicated with the complainant.

An account appearing in a money transfer does not, by itself, answer every question concerning criminal responsibility.

Depending on the file, I examine:

  • who opened and controlled the account,
  • who had access to internet or mobile banking,
  • where transferred funds were subsequently sent or withdrawn,
  • whether the account holder received a financial benefit,
  • messages between the account holder and other suspects,
  • device and login information where available,
  • ATM or transaction records,
  • whether the account holder knew the alleged purpose of the transaction, and
  • the exact extent of that person's alleged participation.

Important 2026 Amendment: TCK Article 158(4)

A significant amendment entered into force on 31 July 2026.

Article 158(4) now provides a specific sentence reduction where participation in fraud under Articles 157 or 158 is limited to giving another person a bank or credit card, another qualifying payment instrument, or the information or tools necessary to use an account held with a bank, intermediary institution, payment service provider or crypto-asset service provider for the purpose specified by the statute.

Where all statutory conditions are met, the sentence is reduced by one half.

This provision should not be read as an automatic reduction for every person whose IBAN, card or account appears in a fraud investigation. The person's participation must be limited to the conduct described by Article 158(4), and the exact evidence concerning their role remains decisive.

How Is Digital Evidence Examined in a Cybercrime Case?

Digital evidence can be central to these investigations, but a technical record should not automatically be treated as proof of who performed a particular act.

Depending on the case, evidence may include:

  • mobile phones and computers,
  • IP and connection records,
  • account login records,
  • WhatsApp or other messaging data,
  • email records,
  • social-media accounts,
  • bank and payment transaction records,
  • ATM records,
  • cryptocurrency transaction information,
  • digital forensic reports,
  • cloud or platform records where lawfully obtained, and
  • other electronic material connected with the alleged transaction.

Does an IP Address Prove Who Committed the Offence?

An IP record may be important evidence, but I would not treat it in isolation as automatic proof of the identity of the person who performed an act.

The device, subscriber information, network environment, date and time, account control, other users and supporting evidence may all require examination.

Does a Bank Account Prove Participation in Fraud?

Likewise, the fact that money entered an account is important but does not answer every issue concerning criminal intent or the person's role.

The prosecution evidence should be examined to determine whether the account holder participated knowingly in the alleged fraud, what they did with the funds and what communication or relationship existed with other persons in the file.

Computer Searches and CMK Article 134

Article 134 of the Turkish Code of Criminal Procedure regulates searches, copying and seizure concerning computers, computer programs and computer records under specified conditions.

The Constitutional Court issued a decision in 2026 annulling significant parts of Article 134. However, the annulment was given a delayed effective date.

As of 30 August 2026, the annulment has not yet entered into force. Its stated effective date is 25 February 2027 unless the legal framework is changed before then.

For current files, the applicable version of the law and the exact date on which a digital search or seizure was carried out should therefore be checked carefully.

How Does a Cybercrime or Online Fraud Investigation Develop?

A file may begin after a complainant reports an unauthorised transaction, fraudulent communication, account intrusion or online payment.

Depending on the allegation, the investigation may then expand through requests for:

  • banking records,
  • payment account information,
  • subscriber and connection information,
  • digital device examinations,
  • messages and communication records,
  • ATM or security-camera footage,
  • account ownership records,
  • financial transfers between suspects,
  • expert or forensic reports, and
  • statements from complainants, suspects and witnesses.

In multi-suspect files, I consider it particularly important to separate the evidence against each person. The presence of several names in the same banking or communication chain does not eliminate the need to individualise criminal responsibility.

Which Court Hears Cybercrime and Aggravated Fraud Cases in Turkey?

The competent court must be determined from the offence charged and the current jurisdiction rules.

A particularly important change occurred on 25 December 2025. Newly filed aggravated fraud cases under Article 158 are now generally heard by the Criminal Courts of First Instance rather than the High Criminal Courts under the previous jurisdiction structure.

The High Council of Judges and Prosecutors subsequently changed the specialisation arrangement concerning cybercrime cases as well. From 15 January 2026, the previous separate cybercrime specialisation arrangement for Criminal Courts of First Instance was removed and the relevant files became subject to general distribution under the Council's decision.

For the current first-instance court structure, see our Criminal Court of First Instance Lawyer in Antalya page.

Older aggravated fraud files require additional care. Transitional provisions can affect cases that were already pending before a High Criminal Court or were already at the appeal or cassation stage when the jurisdiction rules changed.

Where an older file remains before the High Criminal Court under transitional rules, information about that court is available on our High Criminal Court Lawyer in Antalya page.

Cybercrime and Fraud Cases Involving Foreign Nationals in Antalya

Foreign nationals may become involved in these files as complainants, account holders, suspects or defendants.

Additional issues can include:

  • foreign-language messages and contracts,
  • international bank transfers,
  • foreign telephone numbers or online accounts,
  • cryptocurrency transfers,
  • persons located outside Turkey,
  • interpreter assistance,
  • travel restrictions or judicial control, and
  • separate immigration consequences where relevant.

The digital nature of the allegation does not remove the ordinary guarantees of criminal procedure. The person must still understand the accusation and have an opportunity to respond to the evidence relied upon.

If detention or a travel restriction has also been imposed, see our page concerning police custody, pre-trial detention and judicial control objections in Antalya .

Cybercrime Lawyer in Antalya: How I Review a Digital Evidence File

When reviewing a cybercrime or aggravated fraud file, I do not begin with the assumption that the owner of a telephone, IP address or bank account must necessarily be the person who committed every alleged act.

I generally examine:

  • the exact offence attributed to the client,
  • the alleged act and its chronology,
  • the account, device or payment instrument involved,
  • who actually controlled that account or device,
  • banking and financial records,
  • IP, login and connection information where available,
  • messages and other communications,
  • digital forensic reports,
  • money transfers and withdrawals,
  • the client's relationship with other suspects,
  • whether the evidence establishes knowledge and intent,
  • how digital evidence was obtained,
  • whether the alleged conduct falls under Article 158(4), where relevant,
  • the competent court under the current jurisdiction rules, and
  • the procedural stage and available legal remedies.

The legal classification should follow the evidence concerning the individual's actual conduct. This is especially important in files containing many bank accounts or suspects, where the prosecution file may initially present several different roles together.

Representation of Persons Reporting Cyber Fraud

A person or business claiming to have suffered financial loss through an online transaction may also require legal representation.

Depending on the circumstances, this may involve reviewing available records, identifying legally relevant evidence, submitting criminal complaints and supporting documents, monitoring the investigation and exercising procedural rights during prosecution.

Defense of Suspects and Defendants

For a suspect or defendant, the defense should focus on the precise offence alleged and the evidence said to connect that individual with the digital or financial conduct.

In my view, one of the most important questions is whether the prosecution evidence proves actual control, knowledge and intent rather than merely showing that a person's name, account, telephone or device appears somewhere in the investigative chain.

If you or a family member is involved in a cybercrime, online fraud, bank-account or aggravated fraud investigation in Antalya, you may contact Attorney Cennet Kesici Çetinbaş for a legal assessment based on the available digital, financial and procedural records.

CONTACT FOR LEGAL CONSULTATION

Phone: +90 543 620 68 36   |   Email: av.cennetkesicicetinbas@gmail.com

For broader explanations of Turkish criminal procedure and other legal topics, you can also review the Legal Guide for Turkey .

Attorney Cennet Kesici Çetinbaş - Antalya Bar Association

Attorney Cennet Kesici Çetinbaş
Antalya Bar Association
Muratpaşa, Antalya, Turkey

Frequently Asked Questions

What is considered a cybercrime in Turkey?

The Turkish Criminal Code regulates offences including unauthorised access to information systems, interference with systems or data, misuse of bank or credit cards and prohibited devices or programs. Technology may also be used as an instrument for other offences such as aggravated fraud.

What is the punishment for unauthorised access to a computer system in Turkey?

Under Article 243, the basic offence of unlawfully entering or remaining in all or part of an information system is punishable by imprisonment of up to one year or a judicial fine. Different penalties apply where data is destroyed or altered or where data transmissions are unlawfully monitored.

What is the punishment for aggravated online fraud in Turkey?

Article 158 generally provides imprisonment from three to ten years together with a judicial fine for aggravated fraud. Certain forms, including fraud committed by using information systems, banks or credit institutions as instruments, are subject to additional statutory minimum rules.

Does receiving money into my bank account prove that I committed fraud?

Not automatically. The transaction is relevant evidence, but criminal responsibility requires examination of the person's knowledge, intent, control of the account, communications, movement of the funds and relationship with other persons involved in the file.

What changed for IBAN and bank-account fraud cases in 2026?

Article 158(4), effective from 31 July 2026, provides a one-half sentence reduction where participation in fraud is limited to providing specified payment instruments or account-access information under the statutory conditions. The rule does not automatically apply to every account holder involved in a fraud investigation.

Can an IP address prove who committed a cybercrime?

An IP record may be important evidence but should be assessed together with device information, subscriber records, timestamps, account control and other evidence. It does not necessarily identify the individual user in every case.

Can WhatsApp messages and social-media records be used as evidence?

Digital communications may be relevant where lawfully obtained. Their authenticity, completeness, account or device ownership, context and consistency with other evidence should be examined in the individual case.

Which court hears aggravated fraud cases in Turkey?

Following the jurisdictional change effective from 25 December 2025, newly filed aggravated fraud cases under Article 158 are generally heard by the Criminal Courts of First Instance. Transitional rules may affect older files already pending before a High Criminal Court or in appellate review.

Is CMK Article 134 still in force for computer searches in 2026?

As of 30 August 2026, the Constitutional Court's annulment concerning significant parts of Article 134 has not yet entered into force. The stated effective date of the annulment is 25 February 2027, unless the legal framework is changed before then.

Can an English-speaking lawyer assist with a cybercrime case in Antalya?

Yes. Legal assistance may include reviewing investigation documents, banking records and digital evidence, attending relevant criminal-procedure stages, preparing defense submissions and explaining the Turkish criminal process in English where needed.

Official Legal Sources

Legal Information Notice: This page provides general information about cybercrime, digital evidence, bank-account cases and aggravated fraud under Turkish criminal law. It does not constitute legal advice for an individual case. The relevant offence, alleged conduct, ownership and control of accounts or devices, financial transactions, digital records, intent, role of other suspects, applicable court, date of the alleged offence and subsequent legislative amendments can materially change the legal assessment. Current procedural and substantive law should always be checked against the specific case file.