Single Blog Title

This is a single blog caption

Bank/Credit Card Information Theft

1. Introduction: Increased Risks and Legal Liability in Card Payment Systems

With digitalization, online shopping, and the development of contactless payment options, bank and credit cards have become an indispensable part of daily life. However, the widespread use of cards has also led to a significant increase in disputes arising from the theft of card information and unauthorized transactions.

The fundamental questions in such disputes are:

  • Who will be held responsible for transactions made using stolen card information ?

  • the cardholder's negligenceincrease liability or reduce the amount of compensation?

  • a bankheld liable within the scope of the banking services and security infrastructure it provides?

  • As a lawyer, how should you position your client (cardholder) vis-a-vis the bank ?

This article will examine in detail the positions of the cardholder and the bank in cases of card information breach under Turkish law, the concept of cardholder negligence, and its impact on liability. The legal provisions, the established approach of the Supreme Court, and practical problems in application will be considered together.


2. Legal Framework: Which Legislation Applies?

In disputes involving theft of card information and unauthorized transactions, multiple norms apply together:

2.1. Law No. 5464 on Bank Cards and Credit Cards

Law No. 5464 regulates the rights and obligations of card-issuing institutions and cardholders. In particular:

  • Protecting your card and password,

  • Reporting lost and stolen items,

  • Liability for unauthorized actions,

  • Limitation of liability based on the fault of the bank and the cardholder

Key topics such as these fall under the umbrella of this Law.

The law provides provisions that limit the cardholder's liability in cases of loss/theft or unauthorized access to card information ; however, it is accepted that this limitation may be eliminated in cases of gross negligence or intent on the part of the cardholder. This point is central to discussions about cardholder negligence.

2.2. Turkish Code of Obligations (TBK)

The relationship between the bank and the cardholder is fundamentally a contractual relationship and is subject to the provisions of the Turkish Code of Obligations. Within this scope;

  • Turkish Code of Obligations, Article 112 (breach of obligation and compensation),

  • Turkish Code of Obligations, Articles 49 et seq. (Tort liability – against fraudulent third parties),

  • Turkish Code of Obligations, Article 52 (the effect of the injured party's fault in causing the damage – contributory negligence),

  • Turkish Code of Obligations, Articles 115, 116 (Liability for the actions of auxiliary persons)

It finds application.

The bank's duty of care is heightened due to its status as a "trusted institution." Conversely, the cardholder also has an obligation to carefully protect their card and password information. Within the framework of the Turkish Code of Obligations, the court evaluates the degree of fault of the parties and determines the amount of compensation accordingly.

2.3. Law No. 6502 on Consumer Protection (TKHK)

In most cases, the cardholder consumer . Bank card or credit card services are also legally considered a service provided . In this case:

  • Defective service,

  • Unfair terms (general terms and conditions),

  • The principle of interpretation in favor of the consumer,

  • Obligation to inform and enlighten

This comes to the forefront. Clauses included in the bank's contracts that are detrimental to the consumer, impose heavy liabilities, or attempt to circumvent legal limitations invalid .

In consumer disputes, Consumer Arbitration Boards and Consumer Courts are authorized/competent, and the process is conducted through these bodies within monetary limits.

2.4. Turkish Penal Code (TCK) – Criminal Law Aspect

Theft of credit card information is often a crime , especially:

  • Turkish Penal Code Article 245: Misuse of bank or credit cards,

  • Fraud committed through information systems (aggravated fraud)

A criminal investigation is conducted within this scope. Log records, IP information, camera footage, and expert reports obtained in the criminal case are also considered important evidence in the civil lawsuit.

This article will focus primarily on private law/civil liability and the positioning of the bank-client relationship, rather than criminal liability.


3. Methods of Card Information Acquisition and Legal Consequences

Card information theft is not limited to the physical theft of the card. For a sound analysis of the dispute, it is necessary to concretely determine the method by which the information was obtained; this is crucial in assessing the culpability of both the bank and the cardholder.

3.1. Physical Loss or Theft

  • Theft or loss of the wallet,

  • Leaving the card clearly visible in the middle,

  • Keep the card in an easily accessible place at work or at home.

In these situations, the card may fall into the wrong hands. However, if the cardholder does not immediately notify the bank, the bank's claim of "late notification" will be strengthened, and the cardholder's liability will increase.

3.2. Skimming and Copying via POS

In some cases, the card is not physically lost; however, the information on the card's magnetic strip is copied using devices placed in POS terminals or ATMs. In such technical attacks:

  • The customer is often subjected to an attack that is not technically detectable,

  • The bank has the responsibility for ATM security and monitoring

This is taken into consideration. In this case, as a rule, the bank's security measures and supervisory obligations come to the forefront; the cardholder's fault is often assessed as being of lesser importance.

3.3. Phishing and Social Engineering

  • Requesting card information, CVV, or passwords through fake bank emails, SMS messages, or websites,

  • Calls from individuals posing as bank employees requesting information over the phone,

  • "You've won a prize, click the link," etc.

Factors to consider in such cases:

  • Whether the bank informed the customer about these types of fraud methods ,

  • Whether it constitutes a minor or a serious fault for the cardholder to share their information despite clearly suspicious warnings ,

  • The extent to which the fake website could be mistaken for a real bank is "avoidable".

3.4. SIM Swap, Phone Line Hijacking, and SMS Confirmation Codes

SMS verification systems , used for security purposes , can turn against the cardholder if the phone line is compromised. In this case:

  • The responsibility of the GSM operator,

  • The bank's alternative security mechanisms (in-app approval, biometric authentication, etc.),

  • The cardholder has an obligation to notify both the operator and the bank when they realize their SIM card has been lost or has fallen into someone else's hands

is taken into consideration.


4. Bank's Responsibility: Trust Institution and Aggravated Duty of Care

Banks are legally considered "institutions of trust." In card payment systems , banks are in a much stronger position than cardholders in terms of risk management, cybersecurity, and transaction monitoring capabilities . Therefore, a bank's duty of care is considered more stringent than in an ordinary debt relationship.

4.1. Security Infrastructure and Authentication Obligation

To prevent card information from being stolen and used without authorization, the bank:

  • Secure card production,

  • 3D Secure or similar multi-factor authentication systems,

  • Limit and risk monitoring systems (unusual amount, different country/city, large number of transactions in a short period of time, etc.),

  • Security of ATM and POS devices,

  • Instant alert systems (SMS, push notifications, email)

It is expected to establish and maintain technical and administrative measures such as these.

Even if these measures have been taken, whether the system actually worked in the specific casemust be meticulously examined in lawsuits filed against the bank. For example:

  • If the client has made numerous overseas expenditures in a short period of time, even though they have never made any expenditures abroad before,

  • If the client made no transactions during the night, but consecutive transactions were carried out in the early morning hours,

The fact that the bank's fraud monitoring system failed to detect these unusual activities is strong evidence of a breach of duty of care

4.2. Obligation to Inform and Clarify

The bank cannot simply have the customer sign the card agreement; it cannot evade responsibility by assuming it did not read the lengthy, technically complex texts to the customer . Within the framework of the Consumer Protection Law:

  • The importance of card and password security,

  • Which situations will be considered gross negligence?

  • Procedure to follow in case of loss/theft and suspicious transactions,

  • Examples of fake calls, fake SMS messages, and fake websites

Clear information should be provided regarding this matter. If this is not done, it would not be legally correct to place all responsibility on the customer by asking "why did you do this?"

4.3. The Bank's Burden of Proof

The crucial point in practice is this:
If the bank claims that the cardholder was grossly at fault, it has the burden of proof. To do this:

  • The IP address where the transaction took place, device information,

  • Log records of 3D Secure or password verification steps,

  • Information regarding the physical location of the POS device,

  • Camera recordings

Technical evidence such as these must be presented. The approach of simply stating "the transaction was made with a card and password, therefore the customer is responsible" is no longer considered sufficient in current case law.


5. Cardholder Responsibilities and the Concept of Negligence

The cardholder is not passive in the debt relationship; they are obligated to carefully protect the card and its related information.

5.1. Protecting Your Card and Password

In summary, the cardholder's responsibilities are:

  • Do not share your card and password with third parties

  • Not writing the PIN on the card or in an easily accessible place,

  • Avoid choosing a password that is easy to guess (such as your date of birth, 1234, 0000, etc.)

  • If you lose your card or realize it has been stolen, must immediately notify the bank.

  • Be wary of potentially fraudulent SMS messages, emails, and calls sent by banks.

If the cardholder fails to take these precautions, which the bank reasonably anticipated, negligence will be present. However, the degree of negligence alters the scope of liability.

5.2. Distinction Between Simple Defect and Gross Defect

The distinction between " simple negligence " and " gross negligence " is important in terms of the impact of negligence on liability :

  • Simple fault: A reasonable breach of the diligence expected of the average careful person. For example, in a busy work environment, believing a phishing email to be legitimate and sharing information in a one-time transaction.

  • Gross negligence: Failure to exercise even the most basic care and attention; ignoring a risk that anyone could easily spot. For example, writing the PIN on the card itself, regularly sharing the PIN with a third party despite repeated warnings from the bank, or giving all card and SMS codes without hesitation to someone who calls and identifies themselves as a "bank employee."

The limited liability mechanism in the law may be voided in cases of gross negligence or intent on the part of the cardholder . Therefore, the court's decision will depend closely on which category it places the cardholder's conduct in the specific case


6. Impact of Cardholder Negligence on Liability and Distribution of Fault

6.1. Before and After Reporting Lost/Stolen Items

According to Law No. 5464, if a card is lost, stolen, or its information falls into the hands of third parties, the cardholder is required to immediately notify the bank. Notification:

  • Call center,

  • Mobile application,

  • Internet banking,

  • Branch

This can be done through this method. In practice, call center records usually serve as evidence.

  • The cardholder's legal liability for unauthorized transactions made prior to notification is limited (the amount has varied in law from time to time; the limit in effect as of the date applicable to the specific case will be taken into account).

  • Following notification , except in exceptional circumstances, the cardholder's liability ends; it is the bank's responsibility to quickly close the card and disable further transactions.

Therefore, the most critical point in favor of your cardholder client should be:
The bank was notified immediately as soon as the suspicious transactions were noticed.”

6.2. Contributory Negligence (Fault of the Injured Party) and Reduction in Compensation

According to Article 52 of the Turkish Code of Obligations, if the injured party also contributed to the damage, the judge may reduce or completely eliminate the compensation. In bank-customer disputes, this provision is one of the fundamental grounds for determining the distribution of fault.

For example:

  • The bank uses 3D Secure and monitors abnormal spending patterns; however, if the attack in a single incident is very sophisticated and happens quickly,

  • If the cardholder clicked on a suspicious link but was not adequately informed about phishing by the bank beforehand,

The court may conclude that both parties are to some degree at fault . In this case:

  • Part of the damage will be covered by the bank

  • in proportion to the cardholder's contributory negligence .

The aim in positioning the client is to minimize the cardholder's fault rate as much as possible, while highlighting the bank's fault through systemic deficiencies, insufficient information, and security vulnerabilities.

6.3. Allegation of Gross Negligence and the Bank's Burden of Proof

The bank argues that the cardholder was grossly at fault , requesting that the limited liability provision in the law not be applied, thus placing the entire burden of the damage on the customer. However:

  • Allegations of gross negligence should not remain abstract; they must be supported by concrete facts.

  • The bank has a responsibility to demonstrate, log records, audio recordings, and camera footage, that the cardholder's behavior is inconsistent with normal life experience.

For example;

  • Despite repeated warnings, the cardholder gave their PIN to third parties

  • He entered all his card and SMS codes into a site that was clearly fake

  • If no notification is given for days after the card is lost,

The court is more likely to consider the customer grossly at fault. Conversely, in cases involving a single instance of negligence where the bank also failed to provide the necessary information, it is more difficult to deem the customer grossly at fault.


7. Positioning the Bank and the Client: A Strategic Approach from the Lawyer's Perspective

In credit card theft cases, it is crucial to correctly position the client and establish a legal balance of responsibility between the client and the bank.

7.1. Client Positioning: The Weak Party and the Trust Relationship

In most cases, the client (cardholder):

  • Those who are not experts in banking systems and cybersecurity,

  • Those who conduct transactions relying on the bank's card and online banking services,

  • A consumer is a natural person with limited access to technical infrastructure.

Therefore, in lawsuits and applications:

  • The client of information asymmetry .

  • The bank is regulated in the legislation as a "trusted institution,"

  • The client has exhibited behavior that can be considered reasonable in the ordinary course of life,

  • The bank, however, has much more advanced risk management and monitoring capabilities

This should be particularly emphasized. The court should be made to understand that the primary responsibility lies with the bank, which holds significant technical and systemic power .

7.2. Bank Positioning: Strong Party, System Owner, and Professional

The bank's quantitative and qualitative superiority can be demonstrated by the following:

  • Advanced risk monitoring software,

  • A detailed data set regarding customer profile and spending habits,

  • The capacity to predict and prevent security vulnerabilities,

  • It is a professional organization that is strictly supervised by the Banking Regulation and Supervision Agency (BDDK) and other authorities.

In this context, it should be argued that the defense claiming "the bank fulfilled all its obligations completely" is unrealistic; and that placing all the blame on the customer would be neither legally nor equitable.

7.3. Methods of Redress: Arbitration Panel, Mediation, and Litigation

Depending on the amount involved in the specific case and the status of the parties:

  • Applying to the Consumer Arbitration Board: For consumer disputes below the monetary limit, this is both a quick and inexpensive option.

  • Consumer Court case: This comes into play in cases involving amounts exceeding the upper limit or in response to an appeal against an arbitration board decision.

  • Mandatory mediation: In consumer disputes, mediation may become mandatory under certain conditions; the process must be well-planned.

  • Courts of jurisdiction at the bank's headquarters or branch location: Since jurisdictional objections are expected, provisions regarding jurisdiction in favor of the consumer should be considered when filing a lawsuit.

In positioning the client in their favor, , starting with a written warning and internal application, followed by arbitration/mediation, and finally, litigation.

7.4. Claim Items and Scope of Compensation

In lawsuits filed against banks, typically:

  • Refund of the amount of the unauthorized transaction,

  • Interest accrued on this amount (especially interest charged to a credit card account),

  • Additional damages arising from account blocking or card being wrongfully disabled,

  • In appropriate cases, compensation for non-pecuniary damages (e.g., damages to reputation, etc., resulting from severe economic and psychological stress)

It is claimed. While moral damages are not accepted in every case, the court's discretion may be used in favor of the claim when the intense anxiety and insecurity caused to the cardholder are concretely evident


8. Fault Assessment with Case Studies

8.1. Scenario 1: Unauthorized Transactions Conducted Over the Internet

The client received an SMS message on their phone regarding a "bank security update." They clicked the link and entered their card information. Within a few hours, high-value purchases were made from abroad. As soon as the client saw the SMS messages, they called the bank and had the card canceled.

  • My client made a simple mistake clicking on a fake link; however, the scam methods were quite professional and not inconspicuous.

  • The bank, however, had not adequately informed the customer about phishing attacks beforehand and had not taken measures to immediately block unusual international transactions.

In this case, the distribution of faults is as follows:

  • The client's fault simple negligence .

  • The bank's fault significant .

A reduction in the amount of compensation due to contributory negligence is possible, but it is also possible for a significant portion of the damage to be borne by the bank.

8.2. Scenario 2: Writing a Password on the Card and Theft

The client had written their four-digit PIN on their card. Their wallet was stolen on public transport. Shortly afterward, several consecutive transactions were made via POS terminals in the same city. The client realized their wallet was missing a few hours later and reported it to the bank.

  • Writing a PIN on the card would be considered a gross oversight by everyone.

  • Even though the bank doesn't appear to have a general fault regarding insecure POS devices during transactions with a stolen card, there is also no unusual spending pattern (the customer has made purchases of similar amounts before).

In this case, the court may rule that the cardholder grossly at fault , and the possibility of the limited liability provision in the law not being applied may arise. Therefore, the majority of the damages may fall on the client.

As a lawyer, the strategy should be to mitigate gross negligence; however, the room for maneuver is narrow in cases like this.

8.3. Scenario 3: Skimming via ATM and Lack of Bank Oversight

The client used the bank's frequently used ATM. A device placed in the ATM copied the card's magnetic strip and the PIN was monitored via camera. Within a few days, physical POS transactions were made abroad. As soon as the client noticed, they called the bank.

In this case:

  • The client protected their card and password in the usual way; it is not expected that they would have noticed the technical attack.

  • The bank is responsible for ensuring the security of the area where the ATM is located, conducting regular checks, and providing camera security.

The fault lies primarily with the bank. The client's negligence is nonexistent or minimal. It can be strongly argued that the bank should compensate for the damages.

8.4. Scenario 4: SIM Swap and the Operator-Bank-Client Triangle

Scammers use the client's personal information to conduct transactions with the GSM operator using a fake identity and transfer the line to their own name (SIM swap). The bank continues to send SMS verification codes to this new line. When the client realizes their line has been disconnected, they contact the operator and the bank the same day; however, high-value transactions have already been made by that time.

In this situation:

  • The operator's fault in identity verification,

  • The bank's reliance on SMS as its sole security factor is insufficient

  • The client acted quickly when he realized the line was disconnected

They are evaluated together. While the client's fault is quite limited, systemic fault is concentrated on the operator and the bank. The lawyer must demonstrate with strong evidence that the liability cannot be attributed to the client.


9. Common Mistakes in Practice and Practical Tips for Lawyers

9.1. Relying Solely on Criminal Records

In many cases, the aggrieved customer merely a complaint with the criminal investigation and does not pursue legal action against the bank, or does so too late. However:

  • The bank may be legally liable for damages even before a criminal investigation is concluded.

  • Expert reports, IP records, and camera footage from the criminal case file are extremely valuable for the civil lawsuit; access to the criminal case file should be granted, and the evidence should be transferred to the civil lawsuit file.

9.2. Delay in Gathering Information and Documents

  • Bank transaction statement

  • ATM/POS device information,

  • Correspondence with the bank (complaint emails, call center records),

  • Correspondence with the GSM operator

The request should be made as soon as possible. The loss or weakening of evidence reduces the client's ability to prove their case.

9.3. Inadequately Justifying the Defect Assessment

In court petitions, the degree of fault is often glossed over with abstract statements such as "the bank is entirely at fault." However, in this specific case:

  • The time interval of the process,

  • Spending amounts,

  • Geographic location differences,

  • Client's previous habits

This should be analyzed in detail and presented to the court. The more justified the distribution of fault, the greater the likelihood of receiving compensation.

9.4. Accepting the Terms of the Agreement

The clauses in banks' standard contracts stating that "The customer is always responsible for the protection of the card and password, and the customer is responsible for all transactions" should not be considered automatically binding. This is in line with the Consumer Protection Law (TKHK)

  • Prohibition of unfair terms,

  • The principle of interpretation in favor of the consumer

Taking this into consideration, the invalidity or narrow interpretation should be requested.


10. Conclusion: The Delicate Balance Between Cardholder Negligence and Bank Liability

Determining responsibility when bank or credit card information is compromised is not simply a matter of "who is more at fault." In Turkish law;

  • Law No. 5464,

  • General liability provisions of the Turkish Code of Obligations,

  • Consumer protection mechanisms in the Consumer Protection Law,

  • The evidentiary framework provided by criminal law

It should be evaluated as a whole.

The cardholder's negligence certainly cannot be ignored; however, whether this negligence constitutes simple or gross negligence must be examined on a case-by-case basis. The bank, as an institution of trust, must demonstrate with concrete evidence that it fulfilled its aggravated duty of care. The dynamics of the burden of proof generally favor the cardholder.

From a lawyer's perspective, the goal is to help their client:

  • Technical knowledge and resources are limited

  • Acting on trust in the system,

  • Showing reasonable care,

  • Nevertheless, they suffered losses due to weaknesses in the banking system

The aim is to position the consumer as the party in question, while demonstrating on a legal basis that the bank is the professional and powerful party, and that its responsibility increases to the extent that it fails to effectively manage risk.

Leave a Reply

Call Now Button