What are Cybercrimes? A Guide to Cybercrimes under the Turkish Penal Code
What are Cybercrimes? A Guide to Cybercrimes under the Turkish Penal Code
With the widespread use of the internet, mobile banking, social media platforms, cloud systems, and e-commerce, the ways in which crimes are committed have changed significantly. Today, hacking a person's bank account, unauthorized access to a social media account, deleting data from a company system, rendering a website inoperable, or using a counterfeit bank card can have serious consequences under criminal law.
These types of acts are generally referred to as cybercrimes , or internet crimes . However, legally , not all crimes committed over the internet fall into the same category
The Turkish Penal Code primarily regulates crimes directly related to information systems Articles 243 to 245/A . However, many classic crimes such as fraud, theft, unlawful acquisition of personal data, violation of privacy, defamation, and similar offenses can also be committed using information systems.
Therefore, the fact that an event was "carried out online" does not, by itself, mean that one of the cybercrimes under Article 243 and subsequent articles of the Turkish Penal Code has occurred. In the specific case, what the perpetrator did, which system they interfered with, whether they altered data, whether they gained economic benefit, and which legal value of the victim was violated must be evaluated separately.
What is cybercrime?
In its broadest sense, cybercrime refers to unlawful acts committed on or through computers, telephones, servers, websites, social media accounts, banking systems, electronic databases, or similar information systems.
From a criminal law perspective, cybercrimes can be divided into two main groups.
The first group consists of crimes that directly target the information system or the data contained within the system.
For example;
unauthorized access to someone's email account,
Attacking a company's computer system,
delete data,
to render the website inoperable,
installing malware on the system
It can join this group.
The second group consists of crimes where the information system is not the target of the crime, but is used as a tool in committing the crime.
For example, collecting money by posting fake advertisements online is not a classic cyberattack in the traditional sense. Here, the cyberattack is merely a tool that facilitates the commission of the fraud.
This distinction is extremely important in terms of the legal classification of the crime and the punishment to be applied.
What are cybercrimes under the Turkish Penal Code?
The section of the Turkish Penal Code No. 5237 titled "Crimes in the Field of Information Technology" primarily contains the following regulations:
Turkish Penal Code Article 243: Unauthorized access to an information system;
Turkish Penal Code Article 244: Obstructing, disrupting, destroying or altering data in a system;
Penal Code Misuse of bank or credit cards;
Turkish Penal Code Article 245/A: Prohibited devices or programs;
Turkish Penal Code Article 246: Security measures concerning legal entities.
According to Article 243 of the Turkish Penal Code, unlawfully accessing all or part of an information system, or remaining in a system unlawfully, is a crime. Furthermore, unlawfully monitoring data transfers using technical means without accessing the system is also a crime.
1. Crime of Unauthorized Access to an Information System – Turkish Penal Code Article 243
The crime of unauthorized access to an information system is regulated in Article 243 of the Turkish Penal Code.
Unlawfully accessing or remaining in all or part of an information system may constitute a crime.
For a crime to occur, it is not necessary to actually damage the system.
In other words, the perpetrator;
He didn't delete the file
He hasn't transferred any money
No posts have been made from the account
no changes have been made to the system
Even so, unauthorized access to the system can, under certain circumstances, lead to criminal liability on its own.
What does the concept of an information system encompass?
An information system doesn't just mean a classic desktop computer.
Depending on the specifics of the case;
computer,
presenter,
smartphone,
email account
corporate information system,
website administration panel,
cloud account,
social media account,
database
mobile app account
It can be considered as part of an information system.
Is it a crime to access someone else's Instagram account?
Accessing an account using a password or other method without the account holder's consent may be considered under Article 243 of the Turkish Penal Code.
For example, it doesn't automatically become legal for an ex-partner, spouse, employee, or business partner to access an account using a password they already know.
What matters here is whether there was valid authorization or consent at the time of access.
The fact that the password has been previously provided by the user does not mean that this access is permanent.
Is it necessary to crack the password?
No.
The crime of unauthorized access to an information system does not necessarily require bypassing a firewall, using hacking software, or cracking passwords.
Perpetrator;
the password he had learned beforehand,
an open session,
the login information it obtained,
a user account that remains active despite its authorization having expired
They can also gain illegal access by using this method.
Therefore, in cybercrime cases, the defense that "the technical method wasn't very complex" alone does not prevent the crime from being committed.
What is the penalty under Article 243 of the Turkish Penal Code?
According to Article 243/1 of the Turkish Penal Code, a person who unlawfully accesses or remains in all or part of an information system imprisonment for up to one year or a judicial fine .
If the crime is committed against systems that can be accessed in exchange for a fee, a reduction in the sentence may be considered.
If data in the system is lost or altered due to unauthorized access, more severe penalties are foreseen.
Furthermore, monitoring data transfers between information systems illegally using technical means, without accessing the system itself, constitutes a separate crime under Article 243/4 of the Turkish Penal Code and imprisonment for one to three years .
2. Crime of Obstructing or Disrupting the System – Turkish Penal Code Article 244/1
If an unauthorized access to an information system is not sufficient, but its operation is also interfered with, then Article 244 of the Turkish Penal Code may come into play.
According to Article 244/1 of the Turkish Penal Code;
It is a crime to obstruct or disrupt the functioning of an information system.
The law prescribes a prison sentence of one to five years for this crime .
For example;
to make a website inaccessible,
to disable the company server,
to carry out an attack that will disrupt the normal functioning of the system,
prevent the use of the server or network system
Depending on the specifics of the case, it can be evaluated within the scope of Article 244/1 of the Turkish Penal Code.
Is a DDoS attack a crime?
In distributed denial-of-service attacks, a large amount of traffic is sent from numerous devices to the target server, thereby preventing the system from providing service.
If such an attack prevents or disrupts the functioning of an information system, Article 244/1 of the Turkish Penal Code may be applied.
3. The Crime of Destroying or Altering Data in an Information System
Article 244/2 of the Turkish Penal Code regulates interventions directly targeting data, rather than interventions targeting the system itself
According to the law;
to corrupt data in an information system,
destroying data,
modifying the data,
making the data inaccessible,
inserting data into the system
sending existing data elsewhere
is being punished.
These offenses are punishable by imprisonment ranging from six months to three years .
For example, a dismissed employee remotely connecting to a company computer to delete a customer list or transfer company data to another server could be considered within this scope.
Similarly;
Modifying records in the database,
encrypting files,
transferring customer records to another location,
Adding unauthorized content to the website,
deletion of company records
This is important in terms of Article 244 of the Turkish Penal Code.
4. Attacking a Bank or Public Institution's System Carries a Harsher Penalty
Article 244/3 of the Turkish Penal Code provides for a special aggravating circumstance.
The acts falling within the scope of Articles 244/1 and 244/2 of the Turkish Penal Code;
If the offense is committed on an information system belonging to a bank or credit institution, or a public institution or organization, the penalty is increased by half.
For example;
preventing the bank's system from functioning,
deletion of records from the municipal database,
Modifying data in a public institution's information system
It can be punished more severely depending on the type of basic crime.
5. Obtaining Unjustifiable Advantage from an Information System – Turkish Penal Code Article 244/4
Attacks on information systems are sometimes not carried out solely with the aim of disrupting the system.
The perpetrator can interfere with the system and obtain an economic or other unfair advantage for themselves or another person.
According to Article 244/4 of the Turkish Penal Code, obtaining an unfair advantageis punishable separately, provided that the act does not constitute another crime.
In this case, the penalty ranges from two to six years imprisonment and a fine of up to five thousand days' worth of daily wages
One of the most important points here is that the ruling of a secondary nature .
The law explicitly uses the phrase "provided it does not constitute another crime.".
Therefore, if the same incident constitutes, for example, aggravated fraud or misuse of bank cards, the nature of the crime must be assessed separately.
6. Misuse of Bank or Credit Cards – Turkish Penal Code Article 245
One of the most frequently encountered regulations in practice regarding cybercrimes is Article 245 of the Turkish Penal Code.
There are several different types of offenses covered under this article.
Using someone else's bank or credit card
It is a crime for a person to obtain or possess another person's bank or credit card and use it to benefit themselves or another person without the cardholder's consent.
The penalty prescribed for this crime is:
The penalty is imprisonment for 3 to 6 years and a fine of up to 5,000 days' worth of daily wages.
How the card was obtained is not the sole determining factor here.
Card;
found,
borrowed,
stolen,
given for prior use,
otherwise acquired
it could be.
The important thing is that the card was used without consent to gain an advantage.
Is it a crime to shop online using someone else's credit card?
Yes.
Inserting a physical card into the POS device is not mandatory.
Making online payments using a card number, expiration date, and security code may also be evaluated under Article 245 of the Turkish Penal Code, depending on the specific circumstances of the case.
For example, using another person's credit card information;
receiving the phone,
purchasing plane tickets
purchasing games or digital products,
online shopping,
transferring economic value to another account
This could lead to criminal liability.
7. The Crime of Producing Counterfeit Bank or Credit Cards
Article 245/2 of the Turkish Penal Code regulates a separate type of crime.
Counterfeit bank or credit cards linked to bank accounts belonging to others;
producing,
satin,
from the circuit,
buyer or
accepting
for the individual from three to seven years of imprisonment and a fine of up to ten thousand days' worth of daily wages .
The counterfeit card doesn't necessarily have to have been used in this case.
The law also defines the acts of producing, selling, transferring, buying, and accepting as crimes.
8. Using a Counterfeit Bank or Credit Card
It is also a crime to gain benefit for oneself or another person by using a counterfeit or forged bank or credit card.
This crime a penalty of four to eight years imprisonment and a fine of up to five thousand days' worth of daily wages .
Therefore, the counterfeit card;
production,
selling,
purchase
The act of using a counterfeit card and the actual use of the card should be considered legally distinct actions.
Using the Bank Card Among Family Members
One of the special provisions to be considered under Article 245 of the Turkish Penal Code is the personal ground for immunity from punishment.
The crime defined in Article 245/1 of the Turkish Penal Code;
one of the spouses who have not yet been granted a separation decree,
ancestor or descendant,
equally related by marriage,
adoptive parent or adopted child,
one of the siblings living together in the same house
If the offense is committed to the detriment of the relative, it is possible for that relative not to be sentenced. This provision is only significant in relation to Article 245/1 of the Turkish Penal Code.
Furthermore, it is possible to apply the provisions on effective repentance regarding crimes against property within the scope of Article 245/1 of the Turkish Penal Code.
9. Offence of Using Prohibited Devices or Programs – Turkish Penal Code Article 245/A
The law also criminalizes the circulation of certain specialized devices, software, and security codes used in the commission of cybercrimes.
Article 245/A of the Turkish Penal Code was added to the Turkish Penal Code in 2016.
One;
device,
computer program,
password or
another security code
If they are created exclusively for the purpose of committing cybercrimes or other crimes that can be committed through information systems;
manufacturing,
importation
shipping or transportation,
storage,
acceptance,
selling,
offered for sale,
purchase,
to be given to someone else or
keeping
It could constitute a crime.
This offense is punishable by imprisonment for one to three years and a fine of up to five thousand days' worth of daily wages .
This regulation essentially makes it possible to punish even preparatory acts for certain cybercrimes. In legal doctrine, it is also stated that Article 245/A of the Turkish Penal Code is a special regulation that criminalizes preparatory acts for cybercrimes.
However, possessing every cybersecurity or network analytics program is not a crime.
Especially in software with dual-use capabilities, the technical nature of the program, its intended use, and the perpetrator's intent should be thoroughly investigated.
10. Security Measures Regarding Legal Entities – Turkish Penal Code Article 246
When cybercrimes are committed for the benefit of a company or other legal entity, it may not only be the individuals who face criminal liability.
According to Article 246 of the Turkish Penal Code, legal entities that have benefited unfairly through the commission of cybercrimes to security measures specific to legal entities .
Therefore, especially in cybercrime investigations conducted within the scope of company activities, it is necessary to examine not only the perpetrator but also the benefit the company has gained.
Is every crime committed online considered a cybercrime?
No.
This distinction is very important in practice.
The crimes listed in Articles 243-245/A of the Turkish Penal Code are directly regulated in the "Crimes in the Field of Information Technology" section.
However, there are numerous other crimes committed using information systems.
The most important of these are explained below.
11. Qualified Fraud Committed Through the Use of Information Systems
It is incorrect to classify all cases of online fraud as falling under Article 243 or Article 244 of the Turkish Penal Code.
For example;
fake rental house advertisement,
fake car sales advertisement,
selling counterfeit products,
Investment promises via social media,
fake bank or institution message,
Receiving money through a phishing link
Such actions aggravated fraud .
Here, the information system becomes a tool used to deceive the victim, rather than being the target of the attack.
The fundamental issue in fraud is that the victim is misled by deceptive behavior, resulting in financial loss.
In cybercrime, there is often a direct intervention against the system or data.
These two types of crimes should not be confused with each other in specific cases.
12. Fraud through Phishing Methods
Phishing can be carried out by sending a fake website or link to a victim, impersonating a legitimate bank, shipping company, government agency, or other organization.
For example, to the victim;
"Your shipment could not be delivered."
"Your account has been blocked."
"Update your banking information"
"An enforcement file has been opened in your name."
Messages like these can be sent to encourage users to click the link.
If the victim enters their username, bank password, or card information on the fake site, the information may fall into the perpetrator's hands.
In these cases, depending on the characteristics of the file;
Qualified fraud,
accessing the information system
misuse of bank or credit cards,
unlawful acquisition of personal data
Several types of crimes can be discussed, such as these.
Which crime has been committed is determined by the sequence of actions and the specific acts performed by the perpetrator.
13. Theft Using Information Systems
In the Turkish Penal Code, theft committed using information systems is also regulated as an aggravated offense.
For example, if the perpetrator transfers the victim's money to their own account by directly interfering with the victim's information system without deceiving them, the provisions for theft using an information system may apply instead of fraud.
One of the key differences between fraud and theft is the victim's will.
In fraud, the victim gains control over their assets as a result of the deception.
In theft, the property is taken by the perpetrator without the victim's consent.
This distinction is especially important in online banking transactions.
14. What crime is it to hack a social media account?
Hacking an Instagram, Facebook, X, TikTok, or any other social media account may not be a single crime.
For example, the perpetrator;
If someone accesses an account without authorization, according to Article 243 of the Turkish Penal Code
If someone deletes or alters the data in the account, they will be punished under Article 244 of the Turkish Penal Code
If they seize private correspondence, they may commit other crimes
If the account holder's personal information is published, it constitutes a crime related to personal data and privacy
If someone uses the account to ask for money from others, that's fraud
If the victim is threatened, it is a crime of threat
It may come up on the agenda.
Therefore, in cases of social media account hacking, simply classifying it as "the account was stolen" is not sufficient as a legal statement.
Each transaction made by the perpetrator on the account must be examined individually.
15. Hacking a WhatsApp Account
Obtaining a WhatsApp account verification code and activating the account on another device can also be considered an unlawful access to an information system.
If the perpetrator later sends messages to people in the victim's contact list demanding money, fraud charges may also arise.
In files of this type;
IP logs,
phone number records,
operator information,
bank accounts,
money transfers,
device records
They should be evaluated together.
16. Is Obtaining Personal Data Also a Cybercrime?
The unlawful recording or acquisition of personal data is not technically regulated in the "Crimes in the Field of Information Technology" section of the Turkish Penal Code.
However, in practice, it is very frequently associated with cybercrimes.
Articles 135 and subsequent articles of the Turkish Penal Code;
unlawful recording of personal data,
unlawful disclosure or acquisition of data,
data should not be deleted even though its expiration date has passed
They are regulated as separate crimes.
For example, if someone illegally accesses a company's customer database and transfers the customer list to their own computer, both crimes related to information systems and crimes related to personal data can be discussed.
Therefore, cybercrime cases should not be evaluated independently of the Personal Data Protection Law (KVKK) and other personal data protection legislation.
17. Is Unauthorized Access to an Email Account a Crime?
Accessing another person's email account without their consent may constitute a crime under Article 243 of the Turkish Penal Code.
Failed emails;
deletes,
changes,
It redirects to another address
download or
If he sends it to third parties,
Article 244 of the Turkish Penal Code and other relevant provisions regarding crimes may also come into play.
In cases of "business email compromise," where email accounts of commercial businesses are compromised and fake bank account numbers are sent to redirect company payments to other accounts, it may be necessary to consider multiple types of crimes together.
18. Company Employee Accessing the System After Leaving the Job
Cybercrimes are not limited to hacker attacks carried out from outside.
Cybercrimes can also be committed by current or former company employees.
For example, if a former employee's user account has not been closed and they use that account to access the company system, having prior access rights does not automatically make the new access legally valid.
It should be investigated whether the authorization has expired.
The employee;
downloading the customer list,
deleting files,
changing company data,
sending data to a competitor company
In this case, in addition to Articles 243 and 244 of the Turkish Penal Code, provisions regarding trade secrets, personal data, and unfair competition may also come into play.
19. Is Installing a Virus or Malware on a Computer a Crime?
If a person installs malicious software on their computer or system, resulting in the system malfunctioning, data being altered, or becoming inaccessible, they may be liable for crimes under Article 244 of the Turkish Penal Code.
For example;
Trojan,
ransomware,
keylogger,
remote access software
Its use should not be evaluated in isolation, but rather in conjunction with its purpose and the resulting consequences.
In ransomware attacks in particular, the encryption of data, rendering it inaccessible, is significant under Article 244/2 of the Turkish Penal Code.
If the perpetrator also demands money in exchange for making the data accessible again, other crimes may be involved depending on the circumstances of the incident.
20. Digital Evidence in Cybercrimes
One of the most important aspects in investigating cybercrimes is digital evidence.
Because, unlike in classic crimes, there may not always be a physical crime scene or eyewitnesses.
In cybercrimes, especially;
IP addresses,
log records,
CGNAT records,
HTS and communication records,
MAC address,
IMEI information,
server logs,
account login history,
Email header information,
bank transfer records,
cryptocurrency transfers,
computer and phone images,
hash values,
screenshots,
platform records
It could be important.
However, the mere presence of digital evidence in a file does not definitively prove that the person is the perpetrator.
For example, simply identifying the IP address is not always sufficient.
The question of who was assigned an IP address and who actually committed the crime are two separate issues.
This distinction is especially important in homes, workplaces, hotels, cafes, or wireless networks where shared internet access is used.
21. Is an IP address alone sufficient grounds for conviction?
One of the fundamental principles of criminal procedure is that the crime must be proven beyond any reasonable doubt, with conclusive and convincing evidence.
Therefore, in cybercrime cases, instead of relying solely on IP address matching;
Date and time the IP address was used,
subscription information,
CGNAT port records,
device information,
account login records,
phone and computer reviews,
money movements,
connections between the perpetrator and the account
They should be investigated together.
Accurate date, time, and port information is critical, especially for connections using dynamic IP addresses.
22. Can a screenshot be considered evidence?
Screenshots can be important initial evidence in cybercrime cases.
However, because the screenshot can be easily changed, it cannot always be considered sufficient on its own.
As much as possible;
URL information,
date and time,
account username,
message history,
payment receipt
email records,
platform records
They should be stored together.
Preserving the integrity of digital evidence is of paramount importance, especially in serious disputes.
23. What Should a Victim of Cybercrime Do?
Victims of cybercrime need to act as quickly as possible.
This is because some log records may be kept for specific periods, and money transactions can be transferred to different accounts within a short time frame.
The victim must first ensure that all existing digital evidence is not lost.
It is important to keep records of messages, links, usernames, phone numbers, bank accounts, and transaction information.
Then, depending on the nature of the event;
To the Public Prosecutor's Office,
to law enforcement agencies or
To the Cyber Crime Units
Applications can be submitted.
If the money transfer has been completed, the relevant bank should be notified immediately.
24. Is there a time limit for filing a complaint in cybercrime cases?
Under Articles 243 and 244 of the Turkish Penal Code, and for a significant portion of cybercrimes, investigations are generally not dependent on a complaint.
When the prosecutor's office learns of suspicion of a crime, it can initiate an investigation ex officio if the necessary conditions are met.
However, if the specific case involves both cybercrime and offenses such as defamation, threat, violation of privacy, or other crimes, the conditions for filing a complaint for these offenses must be examined separately.
Therefore, it is not advisable for the victim to wait a long time thinking that "the prosecutor's office will investigate it on its own anyway.".
Early application is crucial to prevent the loss of digital evidence.
25. Court Responsible for Cybercrimes
A significant portion of the crimes covered under Articles 243, 244, 245, and 245/A of the Turkish Penal Code in district criminal courts .
However, if the case includes another crime that carries a more serious penalty in addition to the cybercrime, the competent court may be changed accordingly.
For example, different rules of jurisdiction may apply to cases involving organized crime, robbery, or other serious offenses.
26. How is the competent court determined in cybercrime cases?
Cybercrimes are often acts that can occur in more than one city or country.
The perpetrator might be in Istanbul, the server in Ankara, the victim in Izmir, and the bank account in another city.
Therefore, the assessment of jurisdiction can be more complex than in classic crimes.
Within the framework of the general jurisdiction provisions of the Code of Criminal Procedure;
the place where the crime was committed
the place where the result occurred,
the place where the perpetrator's actions took place
It is evaluated according to the specific case.
Jurisdiction disputes are particularly important to address at the outset in cybercrime cases involving multiple cities.
27. Intent in Cybercrimes
Most cybercrimes regulated in the Turkish Penal Code are crimes that can only be committed intentionally.
The perpetrator must have knowingly and willingly carried out the actions on the system.
For example, the legal situation of someone who is accidentally redirected to another account is not the same as the legal situation of someone who gains access to the system by hacking into a password.
Similarly, in penetration tests conducted by cybersecurity experts, the system owner's consent and the scope of the authorization granted are of great importance.
Conducting an authorized safety test within legally permissible limits does not constitute a crime.
However, a different assessment may be made if the granted authority is exceeded.
28. Is Ethical Hacking a Crime?
Security tests conducted with the explicit and valid consent of a system owner are, as a rule, not unlawful.
However, merely stating that one acted "to expose a security vulnerability" does not, in itself, guarantee legality.
For example, accessing a company's system without authorization and later claiming "I just wanted to expose a vulnerability" does not automatically absolve one of criminal liability.
In penetration tests;
The scope of authorization,
IPs and systems to be tested,
test period,
applicable methods,
data access restrictions
It must be clearly defined beforehand.
29. The Difference Between Cybercrime and Cybersecurity Law
Cybercrimes, within the scope of criminal law, regulate individual acts that constitute a crime.
Cybersecurity law, however, is much broader than that.
Organizational cybersecurity responsibilities, critical infrastructure, incident reporting, information security obligations, and cybersecurity policies are also part of this field.
In Turkey, a new legal framework has been established in the field of cybersecurity with the Cybersecurity Law No. 7545, which was adopted in 2025
Therefore, as of 2026, the legal assessment of cyberattacks will not be limited solely to Articles 243-245/A of the Turkish Penal Code. Depending on the specifics of the case, it may be necessary to examine the provisions of the Cyber Security Law, the Personal Data Protection Law, Law No. 5651, and other special legislation.
30. Can Multiple Crimes Occur Simultaneously in Cybercrimes?
Yes.
One of the most important characteristics of cybercrime cases is that multiple crimes can be revealed in a single incident.
For example, the perpetrator;
It logs into the victim's account,
reads private messages in the account,
downloads personal data,
changes the password,
shares posts on behalf of the victim
then if the victim asks for money from their friends
depending on the nature of the event;
accessing the information system
modifying data,
obtaining personal data,
violation of privacy
fraud,
insult or threat
Their crimes may come to light together.
In this case, real concurrence of offenses, ideal concurrence of offenses, compound offenses, and the relationship between specific and general norms should be evaluated separately.
Frequently Asked Questions
Is it a crime to access someone else's Instagram account?
Accessing an account without the account holder's consent may constitute the crime of unauthorized access to an information system under Article 243 of the Turkish Penal Code. Knowing the password beforehand does not, by itself, prevent the crime from occurring.
I know my ex-boyfriend's password. Would it be a crime if I accessed his account?
A crime may be committed if there is no current and valid consent for access. Sharing a password during a relationship does not mean that access is unlimited.
Is it a crime to shop online using someone else's credit card?
Using a card to obtain a benefit without the cardholder's consent may constitute a crime under Article 245/1 of the Turkish Penal Code.
What crime is it to delete a company's data?
The destruction or rendering inaccessible of data in an information system may be evaluated under Article 244/2 of the Turkish Penal Code.
Is crashing a website a crime?
If the system's operation is obstructed or disrupted, Article 244/1 of the Turkish Penal Code may be applied.
Is hacking someone else's WhatsApp account a crime?
Unauthorized access to an account may constitute the crime of unauthorized access to an information system. If fraud is committed through the account, other crimes may also arise.
Is it possible to definitively identify the perpetrator from their IP address?
IP addresses are important pieces of evidence, but they do not definitively identify the perpetrator in every case. Subscriptions, CGNAT, devices, accounts, and other digital records must be considered together.
Where should I report a cybercrime?
You can contact the Public Prosecutor's Office or law enforcement agencies. Depending on the nature of the incident, a technical investigation may be conducted by the Cyber Crime Unit.
Conclusion
Cybercrime has become one of the fastest-changing and most technically demanding areas of criminal law, driven by technological advancements.
Crimes directly related to information systems are primarily regulated in Articles 243, 244, 245, and 245/A of the Turkish Penal Code. Actions such as unauthorized access to a system, disrupting its operation, deleting or altering data, unlawful use of bank and credit cards, and possessing devices or programs created for criminal purposes can lead to serious imprisonment and fines under these provisions.
However, not every crime committed online is directly a "cybercrime." Crimes such as theft, aggravated fraud, unlawful acquisition of personal data, violation of privacy, threats, and defamation, which are carried out using information systems, also need to be evaluated separately.
In particular, in incidents such as social media account hacking, money transfers via online banking, or phishing attacks, a single action can result in the commission of multiple types of crimes.
Therefore, in cybercrime investigations, it is necessary to evaluate not only the apparent outcome of the incident, but how the system was accessed, what data was obtained or altered, how financial transactions occurred, who the IP and log records point to, and whether a definitive technical link between the perpetrator and the digital accounts can be established .
Given the technical nature of digital evidence in criminal proceedings, a thorough examination of the case from the perspective of cybercrime law at an early stage is crucial for preventing loss of rights, both for the victim and the suspect or defendant.
Legal Basis: Turkish Penal Code No. 5237, Articles 243, 244, 245, 245/A and 246. The Turkish Penal Code No. 5237 was adopted on September 26, 2004 and published in the Official Gazette on October 12, 2004.