Combating Cybercrime and Legal Processes in Türkiye
Entrance
While digitalization has made daily life easier, it has also brought about new types of crime and new areas of victimization. The use of mobile banking applications, the central role of social media accounts in personal and business reputation, the proliferation of e-commerce platforms, the storage of company data in cloud systems, and the processing of personal information in digital environments have made combating cybercrime extremely important for individuals, companies, and public authorities alike.
Today, an individual can be defrauded online, have their bank account emptied, their social media account hacked, their personal photos shared without permission, a company's customer data compromised, a fraudulent payment instruction sent via email, or a business's website rendered inoperable by a cyberattack. Such incidents are not merely technical security problems; they are also serious legal disputes involving criminal law, data protection law, compensation law, commercial law, and forensic computing processes.
In Türkiye, the fight against cybercrime is conducted through a multi-faceted system. One aspect of this system consists of cybercrimes regulated in the Turkish Penal Code, while the other aspect comprises prosecutor investigations, law enforcement actions, digital evidence collection, content removal, access restrictions, data breach reporting, corporate cybersecurity obligations, and forensic IT investigations.
What is cybercrime?
Cybercrime, in its broadest sense, is a crime committed against or using information systems. Computers, mobile phones, tablets, servers, websites, social media accounts, email accounts, banking applications, digital wallets, databases, cloud storage, and electronic payment systems can all be considered within this scope.
There are two main types of cybercrime. In the first group, the crime is directly directed at the information system. For example, unauthorized access to a person's email account, crashing a company server, deleting data, installing malware on a system, or disrupting the operation of a website fall within this scope.
In the second group, information systems are used as tools for committing crimes. For example, deceiving victims with fake bank messages, obtaining money through promises of online investments, committing fraud with fake e-commerce websites, sending insulting or threatening messages via social media, and causing financial harm to individuals through promises of cryptocurrency fall into this category.
Therefore, the concept of "cybercrime" does not only mean hacking. Sometimes the perpetrator infiltrates the system using technical knowledge; sometimes they deceive the victim through social engineering, fake links, fake call centers, phishing messages, or psychological manipulation. From a legal standpoint, it is crucial to correctly determine which type of crime the incident falls under and to collect evidence before it is lost.
Legal Basis for Combating Cybercrime in Türkiye
In Türkiye, the fundamental penal norms for combating cybercrime are found in the Turkish Penal Code No. 5237. The provisions of the Turkish Penal Code concerning crimes in the field of information technology are particularly concentrated in Articles 243, 244, 245, and 245/A. These articles penalize acts such as unauthorized access to information systems, obstruction or disruption of systems, destruction or alteration of data, misuse of bank or credit cards, and the use of prohibited devices or programs.
The Turkish Penal Code alone is insufficient in combating cybercrime. The Code of Criminal Procedure is crucial in terms of collecting digital evidence. Article 134 of the Code of Criminal Procedure is one of the fundamental provisions regulating the processes of searching, copying, and seizing computers, computer programs, and files. This article is critically important in practice in terms of procedural safeguards such as judge's orders, prosecutor's orders, copying, analysis, and preservation of evidence when obtaining digital evidence.
Law No. 5651 comes into play regarding publications on the internet, content removal, access blocking, violation of personal rights, and the protection of privacy. Specifically, legal avenues under this law may arise in cases involving social media posts, unlawful news, fake accounts, content that constitutes an attack on personal rights, and the sharing of private images.
In cases of the seizure or dissemination of personal data, the Law No. 6698 on the Protection of Personal Data is also important. If personal data is obtained by others through unlawful means, the data controller has an obligation to notify the data subject and the Personal Data Protection Board. According to the KVKK's decision No. 2019/10, notification to the Board must be made without delay and within a maximum of 72 hours from the time the data breach is learned.
The Cyber Security Law No. 7545, which came into force in 2025, is also an important regulation in the field of cyber security and cyber incident response in Türkiye. The purpose of the law is to detect and eliminate threats directed at Türkiye's national power in cyberspace, to mitigate the effects of cyber incidents, to protect relevant structures, including public institutions and the private sector, against cyber attacks, and to determine cyber security policies.
Cyber Security Directorate, USOM and Corporate Struggle Mechanism
Combating cybercrime is not only carried out through prosecutors and courts. In Türkiye, there are also administrative and technical coordination mechanisms in the field of cybersecurity. In this context, USOM, the National Cyber Incident Response Center, has long been operating with the aim of responding to cyber incidents, identifying threats, mitigating the effects of attacks, and coordinating with relevant actors. According to the Information and Communication Technologies Authority (BTK), USOM was established on May 27, 2013, and conducts national and international coordination efforts regarding cyber incident response on a 24/7 basis.
Established in 2025, the Cyber Security Directorate holds a significant position as the central administrative authority in the field of cyber security. Its official website states that Law No. 7545 on Cyber Security was published on March 19, 2025, and that the Directorate operates as the authorized body for protecting critical infrastructure and mitigating digital risks.
This institutional structure is particularly important in the face of large-scale cyberattacks, threats to critical infrastructure, intrusions into public institutions' systems, attacks on financial systems, data breaches, and cyber incidents with national security implications. However, in cases of individual victimization, the primary recourse is usually the Public Prosecutor's Office and law enforcement agencies. The existence of technical institutions does not replace the judicial process; rather, it supports the judicial process and strengthens cybersecurity capacity.
Most Common Types of Cybercrime
One of the most common cybercrimes in Türkiye is internet fraud. Examples include fake bank links, fake shipping messages, fake e-government or bank screens, investment scams, cryptocurrency traps, fraud via second-hand shopping platforms, the sale of counterfeit products through social media, and fake call center methods.
Another common type of crime is the hijacking of social media accounts. Stealing an account on platforms like Instagram, Facebook, X, TikTok, or similar platforms, using the account for blackmail or fraud, sending messages demanding money to people in the victim's contact list, and threatening to disclose private messages can have serious criminal consequences.
The theft of bank and credit card information is also common in cybercrime cases. The perpetrator may send a fake link to the victim, obtain card information, trick them into giving the 3D Secure code, or use the card information for online shopping. In such cases, depending on the nature of the incident, the crime of misuse of bank or credit cards, aggravated fraud, and crimes against personal data, as defined in Article 245 of the Turkish Penal Code, may all come into play.
One of the most serious cybercrimes against companies is ransomware attacks. In these attacks, company files are encrypted, access to systems is blocked, and money is demanded for the return of data or for the company to remain anonymous. Technical intervention alone is insufficient in such cases. It is necessary to protect log records, prepare incident reports, conduct data breach assessments, file GDPR notifications if necessary, apply to the prosecutor's office, and manage insurance/contract processes.
What should a victim of cybercrime do?
The first thing a victim of cybercrime should do is to preserve evidence without panicking. The victim should save incoming messages, links, phone numbers, usernames, social media accounts, IBAN information, bank statements, screenshots, email subject lines, URLs, and date and time information. Deleting evidence or closing accounts can make identifying the perpetrator more difficult.
The second step is to prevent the damage from escalating. If bank account or card information has been compromised, contact the bank immediately, cancel the card, file a dispute report for suspicious transactions, and, if possible, request that the suspicious account be blocked. If a social media account has been compromised, use the platform's account recovery and security channels, activate two-factor authentication, and warn those close to you if fraudulent messages are being sent from the account.
The third step is to file a criminal complaint with the Public Prosecutor's Office. The complaint should clearly describe the chronology of the events and, if the perpetrator is known, their identity information should be included; if unknown, the accounts used, phone numbers, email addresses, IBANs, cryptocurrency wallet addresses, URL links, and all digital traces should be listed.
The fourth step is to make requests to prevent the loss of technical evidence. These may include requesting bank records from the prosecutor's office, investigating phone line information and HTS records from GSM operators, requesting IP records from internet service providers, sending requests to social media platforms, requesting transaction details from payment institutions, and obtaining device examinations and expert reports.
How does a prosecutor's investigation work?
In cybercrime investigations, investigations usually begin with a complaint or criminal report from the victim. Depending on the nature of the incident, the public prosecutor's office may instruct the Cyber Crimes Department or the relevant law enforcement unit. Law enforcement units take the victim's statement, examine digital materials, investigate bank and communication records, and present the obtained information to the prosecutor's office.
The most important issue at the prosecution stage is identifying the perpetrator. In cybercrimes, the perpetrator often uses fake accounts, temporary phone numbers, foreign IPs, VPNs, bank accounts belonging to others, or intermediaries. Therefore, the investigation should not focus solely on the apparent account holder; the endpoint of the money flow, device connections, IP records, account access information, and communication traffic should be evaluated together.
If the prosecutor finds sufficient suspicion, they can initiate a public trial by preparing an indictment. If they conclude that there is insufficient suspicion, they can issue a decision of no grounds for prosecution. However, since decisions based on insufficient investigation are sometimes encountered in cybercrime cases, the appeal process against a decision of no grounds for prosecution is important for the victim's representative. In particular, decisions made without requesting bank records, conducting IP address investigations, writing to social media platforms, or sending digital materials to an expert witness may be questioned in terms of insufficient investigation, depending on the specifics of the case.
The Importance of Digital Evidence
In cybercrime cases, classic witness statements are often insufficient. The real deciding factor is digital evidence. IP records, log records, email headers, message contents, screenshots, bank statements, cryptocurrency transfer records, device images, server logs, camera recordings, and platform responses form the backbone of the case.
However, digital evidence must be obtained legally. Correspondence obtained by unauthorized access to someone else's account may raise questions about whether it constitutes illegally obtained evidence. Conversely, the party concerned may present messages received, their own account transactions, payment receipts, publicly available content, or records obtained legally.
Under Article 134 of the Code of Criminal Procedure (CMK), searching, copying, and seizing computers and digital materials are subject to special procedures. Therefore, in criminal cases, the method of obtaining digital evidence, the chain of evidence, the image acquisition process, hash values, expert examination, and the preservation of copied data must be carefully examined. The Constitutional Court's decision dated February 12, 2026 (Case No. 2023/128 E., 2026/36 K.), which annulled Article 134 of the CMK and was published in the Official Gazette, demonstrates the need to keep up-to-date with procedural safeguards in this area.
Content Removal and Access Blocking
In some cybercrimes, the victimization is not limited to economic loss. Sometimes, a person's name, photograph, private life, business reputation, or personal rights are targeted in the digital environment. The creation of fake accounts, disclosures, defamatory content, false news, private images, or the publication of personal data all necessitate content removal and access blocking processes.
In such cases, the victim can both initiate a criminal investigation and apply for the removal of the relevant content. Especially in cases of violation of personal rights, it is possible to apply to the magistrates' court under Law No. 5651. In cases involving violations of privacy, publication of private images, or sharing of personal data, swift action is necessary. Because the longer the content remains online, the more damage the victim's reputation and privacy may suffer.
The key point here is to gather evidence before removing content. The URL address, screenshots, posting date, account name, user profile, comments, and interactions should be recorded. Otherwise, proving the violation after the content is deleted may become difficult.
Cyber Attack and Data Breach Process from a Corporate Perspective
For companies, combating cybercrime can be more complex than dealing with individual victims. This is because a cyberattack doesn't just damage company systems; it can also affect customers' personal data, trade secrets, financial records, contracts, employee data, and corporate reputation.
When a company is subjected to a cyberattack, the first step should be a technical response, but evidence should not be destroyed. Log records should be preserved, system images should be taken, the origin and scope of the attack should be determined, which data was affected should be identified, and an incident response report should be prepared.
If personal data has been obtained unlawfully, or if there is a risk of such an acquisition, a data breach assessment must be conducted under the Personal Data Protection Law (KVKK). It is accepted that the data controller must notify the Board within 72 hours of becoming aware of the breach. Furthermore, individuals affected by the breach must also be notified as soon as reasonably possible using appropriate methods.
Companies should also evaluate their contractual obligations. Contracts with customers, suppliers, payment institutions, insurance companies, or foreign business partners may include provisions regarding data security, privacy, incident reporting, and liability. Therefore, the post-cyberattack process is a crisis management process that must be carried out jointly by legal, compliance, management, and communications teams, not just the technical team.
Compensation and Legal Liability in Cybercrimes
A victim of cybercrime can seek compensation for material and moral damages in addition to a criminal investigation. A person who loses money as a result of online fraud can claim compensation for their financial losses if the perpetrator is identified. A person whose personal rights have been violated through social media can file a lawsuit for moral damages. If a company's commercial reputation, customer relations, or business continuity have been damaged, compensation for commercial losses may also be considered.
Data breaches can result in both administrative sanctions and liability under private law. Individuals whose personal data has been processed unlawfully or has fallen into the hands of third parties may claim compensation if concrete damages have occurred. Whether the data controller company has taken the necessary technical and administrative measures is a determining factor in this regard.
The Role of Lawyers in Combating Cybercrime
Cybercrime cases require both technical and legal expertise. Therefore, establishing the correct legal strategy at the outset is crucial. The victim's lawyer must determine which types of crimes the incident falls under, quickly prepare requests to prevent the loss of evidence, request the necessary warrants from the prosecutor's office, follow up with the bank and platform processes, and file content removal requests when necessary.
For the defense attorney of the suspect or defendant, the following should be examined: whether the digital evidence was obtained lawfully, whether the IP address alone is sufficient to identify the perpetrator, who used the device, the likelihood of the account being compromised, whether there was intent, and the technical adequacy of the expert report.
For companies, the role of a lawyer is broader. Processes such as GDPR notification, cyber incident reporting, contractual liability, employee-related breaches, supplier negligence, insurance notification, correspondence with public authorities, criminal complaints, and reputation management require legal coordination.
Conclusion
Combating cybercrime in Türkiye is a comprehensive field requiring the combined application of criminal law, criminal procedure law, personal data protection law, internet law, and cybersecurity legislation. Incidents such as unauthorized access to and disruption of information systems, data deletion, misuse of bank card information, internet fraud, hijacking of social media accounts, dissemination of personal data, and ransomware attacks can seriously affect both individuals and companies.
In such cases, the most important element is to act quickly and accurately. Evidence must be preserved before it is lost, applications must be made to the bank and platform, a detailed criminal complaint must be filed with the prosecutor's office, an investigation of digital traces must be requested, and if necessary, measures such as content removal and access blocking must be taken.
For companies, combating cybercrime is not a process that begins only after an attack. Data security policies, employee training, access authorizations, log management, backups, incident response plans, GDPR compliance, and contractual protection mechanisms should be established in advance.
In conclusion, combating cybercrime requires a combination of technical security measures and legal processes. To avoid loss of rights in the digital world, protect evidence, identify perpetrators, and claim compensation for damages, professional follow-up of the process is crucial.