Single Blog Title

This is a single blog caption

Corporate Email Account Hacking and Fraud Crimes

Entrance

Corporate email account hijacking is one of the most dangerous cyberfraud methods companies face today. Email accounts of company employees, managers, accounting departments, purchasing units, or personnel handling supplier relations are targeted; fraudulent payment instructions are sent, IBAN information is altered, supplier invoices are manipulated, customer payments are redirected to fraudsters, or confidential internal company correspondence is intercepted.

These types of incidents are often referred to as Business Email Compromise ( BEC) in international literature . The FBI defines BEC fraud as one of the most financially damaging online crimes, exploiting the reliance many individuals and companies place on email in their daily business, and carried out through fraudulent payment or transaction requests that appear to come from a known source. Examples given by the FBI include a regularly used supplier appearing to have changed their billing address or an urgent payment order being sent in the name of a company executive.

In Turkey, these incidents should not be viewed as simple technical problems such as "email hacking." The hijacking of corporate email accounts should be considered in conjunction with other including: Article 243 (unauthorized access to an information system), Article 244 (obstructing, disrupting, destroying, or altering data), Article 158 (aggravated fraud), unlawful acquisition or dissemination of personal data, data breach under the Personal Data Protection Law (KVKK), violation of trade secrets, labor law liability, and bank and payment refund processes , as well as compensation claims .

What does it mean to have a corporate email account compromised?

Corporate email account compromise is the unauthorized access of an email account belonging to a company employee, manager, accounting department, or authorized person. This access can occur directly through password theft, or through phishing links, fake Microsoft 365/Google Workspace login screens, malicious attachments, weak passwords, using the same password on different platforms, lack of multi-factor authentication, leaving an old employee account open, or compromising a supplier system.

An attacker who gains access to an email account often doesn't immediately commit fraud. First, they examine the correspondence. They learn which customers have been contacted for payment, which suppliers have been paid, which invoices are open, who has approval authority, the company's payment schedule, bank accounts, and the language used in communication among employees. Then, waiting for the right moment, they insert a fake IBAN or a fake payment instruction into the legitimate correspondence.

Therefore, corporate email hijacking is more dangerous than classic "spam email" incidents. The scammer uses the company's real correspondence history, tone, invoice numbers, customer names, and payment processes. This increases the persuasive power of the attack. The accounting employee or customer may transfer money believing the email is genuine.

What is Business Email Compromise and CEO Fraud?

Business Email Compromise (BEC) is a type of fraud that involves using company email addresses or fake email addresses that appear to belong to a company. In BEC attacks, fraudsters typically use the following methods:

They pose as company executives and send urgent payment instructions to the accounting department. This method is known as "CEO fraud." They hijack a supplier's email account and send messages resembling legitimate correspondence, such as "Our IBAN details have changed." They send fake invoices to customers in the company's name and change the payment account. They hijack the account of an employee in the purchasing or finance department and manipulate legitimate payment correspondence. Sometimes they create a fake domain name that closely resembles the real email address; for example, they change a letter in the company's domain name to create a difficult-to-detect email address.

FBI statements indicate that in BEC (Business Email Compromise) fraud, attackers can mimic real accounts, deceive victims with minor domain name variations, and gain access to company accounts, calendars, and data through spear phishing emails.

In Türkiye, such incidents are frequently seen, particularly in import-export companies, construction and subcontractor payments, law firm-client payment correspondence, supplier invoices, foreign currency commercial transactions, real estate down payments and sales prices, and logistics and customs procedures. Even though the victim company appears to have sent the money voluntarily, this voluntary sending has been compromised by fraudulent behavior.

What crimes are involved in email hijacking incidents?

If a corporate email account is compromised, multiple types of crimes may arise simultaneously. Firstly, if the perpetrator has unlawfully accessed the company's email account or information system, the crime of unauthorized access to an information system under Article 243 of the Turkish Penal Code (TCK) comes into question. Article 243 of the TCK punishes the act of unlawfully accessing or remaining in all or part of an information system.

If the perpetrator has altered, deleted, rendered inaccessible, transferred, or disrupted the operation of the email account, Article 244 of the Turkish Penal Code comes into play. According to Article 244, a person who obstructs or disrupts the operation of an information system is punishable; a person who corrupts, destroys, alters, renders inaccessible, inserts data into, or transfers existing data within the system also incurs criminal liability.

Fraud occurs when a fraudulent payment instruction is given via email, the IBAN is changed, or the victim company/individual is persuaded to send money. Article 158 of the Turkish Penal Code stipulates that fraud committed using information systems, banks, or credit institutions as tools constitutes an aggravated offense. Under the same article, the penalty is increased for fraud committed using banks or credit institutions as tools.

Therefore, in corporate email fraud cases, not only "unauthorized access to an information system" but also, depending on the outcome of the incident, of aggravated fraud, the use of an information system as a tool, the use of banking institutions as a tool, personal data crimes, theft of trade secrets , and forgery of official/private documents should be considered together.

Fake IBAN and Invoice Fraud

The most common form of corporate email hijacking is fake IBAN fraud. The perpetrator gains access to the supplier or creditor company's email account or uses a fake address that closely resembles the company's domain name. They then send messages such as "Our bank details have changed," "Please make the payment to the following account," or "The account from the previous invoice has been closed." Because the message often appears within a real invoice, real product, real delivery, and real correspondence chain, the victim remains unsuspecting.

There are three important elements in terms of legal classification in such cases. First, fraudulent conduct. The perpetrator deceives the victim by impersonating a natural person or company. Second, the element of harm. The victim sends the money to the wrong account. Third, unjust enrichment. The perpetrator or related parties receive the money into their own account or into the account of a third party.

If the transaction was made via bank transfer, EFT, SWIFT, or through a payment institution, it may be assessed as aggravated fraud under Article 158/1-f of the Turkish Penal Code, using information systems and banks/credit institutions as tools. The General Directorate of Security also states that the crime of fraud is regulated in Articles 157 and 158 of the Turkish Penal Code; and that using information systems, banks, or credit institutions as tools is among the aggravating circumstances.

What Should the Victimized Company Do Immediately?

When it is discovered that a corporate email account has been compromised or a payment has been made to a fraudulent IBAN, time is of the essence. The first step is to immediately contact the bank that sent the money. A written and recorded request should be submitted to the bank, explaining that the transfer was made due to fraud and demanding that the recipient account be blocked, the money refunded, and that the other bank be notified immediately. If the transaction was via SWIFT, a recall process must be initiated immediately with both the correspondent bank and the recipient bank.

The second step is to isolate the company's own email system and cut off access to the compromised account. Passwords should be changed, active sessions should be closed, multi-factor authentication should be enabled, routing rules and automated filters should be checked, and it should be investigated whether the attacker created rules to hide emails.

The third step is preserving the evidence. Emails should not be deleted, the correspondence chain should be exported, email header information should be preserved, IP log records should be obtained, and payment receipts, invoices, fake IBAN messages, domain information, DNS records, account login records, user activity, and security alerts should be kept.

The fourth step is to file a swift criminal complaint with the Public Prosecutor's Office, supported by technical evidence. This process shouldn't simply state "we were defrauded"; the complaint must include the perpetrator's email addresses, domain names, IP addresses, bank account information, money transfer receipts, correspondence dates, and other technical findings.

Why is evidence preservation vitally important?

In corporate email fraud cases, proof largely relies on digital evidence. This evidence reveals which server the email was actually sent from, who used the sender's account, when the domain name was registered, which IP addresses accessed the account, whether an email forwarding rule was created, which account the money went to, and who opened the recipient account.

A screenshot alone may not be sufficient. The raw email headers, server logs, Microsoft 365/Google Workspace audit records, IP address logs, MFA records, device information, payment receipts, bank correspondence, WHOIS information for the fake domain name, DNS records, and security reports (if available) should all be included in the evidence file.

Companies often try to clean up an account after an attack, erasing the attacker's traces in the process. This is a mistake. Suspicious rules, deleted folders, automated redirects, recent login logs, and unauthorized application permissions in an email account should not be removed without a forensic investigation. Evidence should be collected first, then the cleanup and security improvements should be carried out.

How should a complaint to the prosecutor's office be prepared?

The criminal complaint to be filed with the prosecutor's office must be prepared in detail from both a technical and legal perspective. The petition should clearly describe the chronology of the events. On what date was correspondence made with which company? What invoice or payment relationship existed? From which email address was the IBAN change reported? To which bank account was the payment made? When was the fraud discovered? When was the bank notified? From which IP addresses was the company account accessed? Which data may have been affected?

The criminal complaint should specifically include the following requests: blocking the recipient bank account, tracing financial transactions, identifying the account holder and those using the account, requesting ATM/camera recordings, obtaining account opening documents, requesting IP-log records from relevant email service providers, investigating domain registrations if a fraudulent domain name was used, applying to international service providers for legal assistance or through relevant procedures, and initiating legal proceedings against the suspects under Articles 158, 243, 244 of the Turkish Penal Code and other offenses depending on the specific circumstances.

If the money hasn't been withdrawn yet, speed is crucial for blocking and returning it. Therefore, the criminal complaint should not be delayed; the bank application, the complaint to the prosecutor's office, and the collection of technical evidence should all be carried out simultaneously.

Application to the Bank and Payment Institution

If a payment was made to a fraudulent IBAN, filing a bank complaint is a separate legal avenue. The victimized company should immediately submit a written request to the sending bank, stating that the transfer was made due to fraud, and requesting that the money be blocked at the receiving bank and the refund process be initiated. The receiving bank should also be informed, if possible.

The application must include the payment receipt, the fake email, an invoice demonstrating a genuine business transaction, the date the fraud was discovered, and information regarding the prosecutor's office application. If the transaction went to a foreign bank, the SWIFT recall process must be initiated immediately. In some cases, money is transferred to different accounts very quickly; therefore, the first few hours are critical.

Bank liability is assessed on a case-by-case basis. The bank may have merely followed customer instructions. However, if there were suspicious transactions at account opening, unusual cash movements, money laundering warnings, rapid cash withdrawals, or delays after notification, the bank's duty of care may be questioned. Therefore, bank correspondence should be recorded and kept on file.

Is there a data breach under the KVKK (Turkish Personal Data Protection Law)?

The hacking of a corporate email account often results in a personal data breach. This is because email accounts may contain customer names, phone numbers, email addresses, proposal files, contracts, employee information, payroll documents, identity photocopies, bank details, invoice details, business correspondence, and sometimes sensitive personal data.

According to the Personal Data Protection Law (KVKK), the data controller is obliged to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of personal data. The Authority also states that the data controller may be jointly responsible with the person or organization processing personal data on their behalf for taking the necessary measures.

If an unauthorized person gains access to an email account, there is a risk of access to personal data. In this case, the company must answer the following questions: Which mailbox was compromised? Did it contain personal data? Which groups of people might be affected? Was the data exported? Was an email forwarding rule created? Did the attacker access attachments? Is there any sensitive personal data? What is the estimated number of affected individuals?

If it is determined that personal data has been obtained by others through unlawful means, or if there is a serious risk of this happening, then there is an obligation to notify the Personal Data Protection Board.

GDPR 72-Hour Notification

In the event of a personal data breach, the data controller must notify the Board without delay and within a maximum of 72 hours from the date they become aware of the breach. The KVKK's recent public announcement also clearly states, in accordance with the Board's decision dated January 24, 2019, and numbered 2019/10, that there is an obligation to notify the Board within a maximum of 72 hours from the date the breach is learned.

The entire technical review does not need to be completed when this notification is made. The initial notification can be made with the information available; additional information and updates can be provided later. The notification should include when the breach occurred, when it was learned, the affected groups, the categories of data affected, the potential consequences of the breach, the measures taken, and the contact person information.

It may also be necessary to notify affected individuals in clear and simple language. In particular, customers should be warned against fraudulent payment emails, suppliers should verify IBAN change emails, employees should change their passwords, and they should be vigilant against phishing risks.

Company Notification to Customers and Suppliers

Individuals with whom a company has business relationships are also at risk if their email account is compromised. The scammer could use the compromised account to send fraudulent payment instructions to customers or request confidential information from suppliers. Therefore, it's not enough for the company to simply fix its internal systems; controlled notifications must also be sent to external stakeholders.

The notification should clearly explain the situation without creating unnecessary panic. For example: “Unauthorized access has been detected to a specific email account belonging to our company. We kindly request that you disregard emails sent in our name regarding IBAN changes, payment instructions, or urgent payments without first confirming them by phone.” A clear and informative text like this could be used.

However, the company should not present unverified information as definitive. If it is stated that "no data has been affected," this must be supported by a technical report. Otherwise, problems may arise in the future regarding GDPR, compensation, or trust relationships.

Employee Responsibility and Internal Investigation

Employee error is common in corporate email hijacking incidents. An employee may have clicked on a phishing email, entered their password on a fake login screen, shared their MFA code, used a weak password, or accessed their corporate account insecurely on a personal device. However, this does not automatically place all responsibility on the employee.

The company is examined to see if it provides information security training to employees, uses multi-factor authentication, has a password policy, has established a two-factor authentication mechanism for suspicious payment instructions, and requires phone verification for IBAN changes.

If the employee has acted maliciously, termination of employment for just cause, criminal charges, and claims for compensation/recourse may arise. However, if the incident is purely negligence, the employee's fault and the company's organizational shortcomings should be considered together. The lack of payment security procedures, particularly in accounting and finance departments, constitutes a serious weakness for the company.

Company's Liability for Damages

A corporate email account being compromised can cause harm to a customer or supplier. For example, a customer might make a payment to a fraudulent account due to a fake email they believe came from the company. In this case, the customer may argue whether the payment should be considered made to the company, whether the company is at fault, and who should bear the damages.

In such disputes, the following criteria are important: Was the email account truly a company account? Was there a security vulnerability on the part of the company that allowed the account to be compromised? Did the customer confirm the unusual IBAN change? What is the standard practice for changes to payment accounts in commercial transactions? Did the company warn the customer beforehand? Was notification delayed once the fraud was detected? Was there a secure payment procedure in place between the parties?

Liability for damages may be questioned if the company has not taken basic security measures, has not used MFA (Meaningless Failure), has not established internal controls against unusual payment instructions, or has warned the customer too late after the breach. Conversely, contributory negligence may arise if the customer made a high-amount payment without confirming the unusual IBAN change.

Trade Secret and Confidential Information Risk

Corporate email accounts can contain not only personal data but also trade secrets. Proposal files, price lists, client portfolios, contracts, tender information, strategic plans, technical drawings, source code, partnership negotiations, and financial reports can all fall into the hands of an attacker.

In this case, the company needs to further assess the situation in terms of competitor damage, unfair competition, protection of trade secrets, breaches of contractual confidentiality, and supplier/customer relationships. If the obtained information was leaked through an employee or former employee, a combination of labor law, unfair competition, and criminal law avenues can be pursued.

Technical and Legal Preventive Measures

The most effective defense against corporate email fraud is taking preventative measures before the incident occurs. Companies should primarily mandate multi-factor authentication for all corporate email accounts. The risk of attack increases significantly, especially for administrative, finance, accounting, sales, and purchasing accounts, if MFA is not implemented.

Secondly, a payment security procedure must be established. For IBAN changes, new supplier accounts, high-amount payments, urgent payment instructions, or international transfers, confirmation must be obtained via a previously registered phone number. Confirmation should be made using the number already on company records, not the number provided in the email or message.

Thirdly, email security techniques should be used. SPF, DKIM, and DMARC logs should be properly configured; emails from external sources should be flagged; suspicious domains should be monitored; mail forwarding rules should be reviewed; and Microsoft 365/Google Workspace audit logs should be active.

Fourth, employee training should be conducted. Employees should be aware of fake login screens, pressure to make urgent payments, IBAN change scams, CEO fraud scenarios, and the risks of sharing MFA codes. Training should be recorded and repeated periodically.

Fifth, an incident response plan must be prepared. It should be determined in advance who will reset the password, who will contact the bank, who will prepare the prosecutor's report, who will conduct the GDPR assessment, and who will inform the customers if the email account is compromised.

It is stated that USOM, within the BTK (Information and Communication Technologies Authority), conducts national and international coordination efforts in responding to cyber incidents 24/7. In large-scale, sectoral, or critical attacks, USOM and the relevant sectoral SOME (Security Operations Center) processes should also be evaluated according to the company's field of activity.

Conclusion

Corporate email account compromises represent much more than just a technical security vulnerability for companies. These incidents often have serious consequences, such as fraudulent payment instructions, IBAN changes, supplier invoice fraud, customer payment redirection, theft of confidential information, and personal data breaches. Therefore, companies should treat email security not just as the responsibility of the IT department, but as a matter of corporate risk management and legal compliance.

If an email account is compromised, the following crimes may be committed under the Turkish Penal Code (TCK): unauthorized access to an information system (Article 243), corrupting, altering, rendering inaccessible, or sending data (Article 244), and aggravated fraud through the use of information systems and banks/credit institutions as tools (Article 158).

The company's initial steps include: urgently notifying the bank and payment institution, requesting a block on the recipient account, preserving evidence, obtaining email logs, filing a criminal complaint with the prosecutor's office with technical evidence, conducting a GDPR data breach assessment, notifying the Board within 72 hours if necessary, and publicly informing the affected individuals. The GDPR explicitly states that in cases of personal data breaches, notification to the Board must be made within 72 hours of learning of the breach.

In conclusion, the most effective legal protection against corporate email fraud is not filing a lawsuit after the event, but establishing a strong internal control system beforehand. Multi-factor authentication, double verification of payment instructions, telephone verification of IBAN changes, SPF-DKIM-DMARC configuration, employee training, log keeping, data breach response plans, and security clauses in supplier contracts protect the company against both fraud and the subsequent risks of compensation and administrative sanctions.

Leave a Reply

Call Now Button