Single Blog Title

This is a single blog caption

Counterfeit Tickets, Barcode Manipulation, and Cybercrimes

1. Introduction

In modern sporting events ticketing and electronic access systemsform the cornerstone of security.
However, in recent years, counterfeit tickets, QR/barcode manipulation , and electronic access system breaches, .

These acts constitute not only consumer deception but also forgery of official or private documents and cybercrimes under Articles 204 and 243 et al. of the Turkish Penal Code . Furthermore, Article 15 of Law No. 6222 defines these acts as aggravated offenses due to their commission in sports arenas.


2. Legal Framework: Article 15 of Law No. 6222

2.1. Article Text

“Persons who forge, use, or cause the use of forged tickets and accreditation documents for sporting events shall be sentenced to imprisonment for two to five years. If the crime is committed using an information system, the sentence shall be increased by half.”

This provision is a specific version of Article 204 of the Turkish Penal Code ; it applies when the act of forgery is committed in documents related to sports .

2.2. Protected Legal Value

  • Public trust,

  • Continuation of the sporting system,

  • Protecting the rights of fans and spectators.


3. Criminal Nature of Forgery Acts

3.1. Forgery of Official and Private Documents (Turkish Penal Code Article 204)

"A person who forges an official document or alters a genuine document in a way that deceives others shall be punished with imprisonment from two to five years."

E-tickets, electronic barcodes, and accreditation certificates are accepted as "documents" by the Supreme Court of Appeals due to their probative value and official nature

Supreme Court of Appeals, 7th Criminal Chamber, Case No. 2021/1124 E., Decision No. 2022/954 K.:

"Copying and duplicating an electronic ticket generated through the TFF (Turkish Football Federation) system constitutes the crime of forgery of an official document."

3.2. Connection with Cybercrimes (Turkish Penal Code Articles 243–245)

These acts are often accessing and modifying data via information systems .

  • Turkish Penal Code Article 243: Unlawfully accessing an information system.

  • Turkish Penal Code Article 244: Disrupting the system or altering data.

  • Turkish Penal Code Article 245: Misuse of bank or credit cards.

Therefore, a fan copying the stadium barcode is not only forgery but also data manipulation .


4. Barcode Manipulation and Derived Verbs

4.1. Methods

  1. QR Code Cloning:
    Enable multiple entries by sharing a screenshot of your mobile ticket.

  2. Exploiting System Vulnerabilities:
    Gaining unauthorized access by exploiting vulnerabilities in club or federation applications.

  3. Spoofing:
    Using someone else's photo on an accreditation card.

  4. Deep Fake Ticket:
    The creation of a visually exact copy of the original ticket.

4.2. Completion of the Verb

The crime is completed when the ticket is registered in the system or used at the entrance.
Cases that remain at the attempt stage are evaluated under Article 35 of the Turkish Penal Code.


5. Joint Liability and Groups of Perpetrators

Perpetrator Legal Status
The person who issues or prints the ticket Turkish Penal Code Article 204, Article 15 of Law No. 6222
The user or the person who causes it to be used Joint and several liability for the same offenses
The employee who exploited the system vulnerability Article 257 of the Turkish Penal Code (abuse of office)
Buying fan Negligence or aiding and abetting (depending on intent)

Supreme Court 19th Criminal Chamber, Case No. 2022/312, Decision No. 2023/485:

"A person who does not personally use the counterfeit ticket but sells it on social media is considered to have aided in the commission of the crime."


6. Nature of Evidence and Means of Proof

  • E-ticket system log records,

  • IP addresses and user sessions,

  • Payment records and transfer traces,

  • Camera footage (6222 m. 5).

According to Articles 217 and 134 of the Code of Criminal Procedure, a chain of custody protocol must exist for digital evidence.
Otherwise, the defense may object that "the integrity of the evidence has been compromised."


7. Examples from Supreme Court Decisions

7.1. Supreme Court of Appeals, 7th Criminal Chamber, Case No. 2020/1131, Decision No. 2021/745.

"Reusing a mobile ticket by altering its QR code constitutes the crimes of forgery and misuse of information systems."

7.2. Supreme Court 19th Criminal Chamber, Case No. 2021/834, Decision No. 2022/1243.

"The issuance of accreditation cards to unauthorized persons by the organizer constitutes the crimes of abuse of office and forgery."

7.3. Supreme Court of Appeals, 8th Criminal Chamber, Case No. 2022/273, Decision No. 2023/318.

"If a spectator enters a match with a fake ticket without malicious intent, they are liable for the crime of using a forged document through negligence."


8. Unauthorized Access to an Information System and Articles 243-244 of the Turkish Penal Code

These acts often occur through cyber access to club or federation applications. Unauthorized access to the system and modification of data are also crimes under Articles 243-244 of the Turkish Penal Code

Turkish Penal Code Article 243/1: “A person who unlawfully enters an information system…”
Turkish Penal Code Article 244/2: “A person who corrupts, alters, or renders data inaccessible…”

Supreme Court 15th Criminal Chamber, Case No. 2020/431, Decision No. 2021/842:

"The defendant's act of creating a barcode by accessing the e-ticket system's database without authorization constitutes the crime of data alteration within the meaning of Article 244/2 of the Turkish Penal Code."


9. Personal Data Breach and the Aspect of the GDPR

Personal data such as identification numbers, names, and seat numbers are often used when creating counterfeit tickets . According to Article 12 of the Turkish Personal Data Protection Law (KVKK), clubs, as data controllers, are obliged to ensure the confidentiality of this data.

Unauthorized access to personal data under Article 136 of the Turkish Penal Code (Unlawfully disclosing or obtaining data).


10. Penal Sanctions

Type of Crime Rest Punishment
Issuing fake tickets 6222 m. 15 2-5 years imprisonment
Forgery of official documents Turkish Penal Code Article 204/1 2-5 years imprisonment
Accessing the information system Article 243 of the Turkish Penal Code 1-3 years imprisonment
Modifying data Article 244 of the Turkish Penal Code 2-6 years imprisonment
Abuse of power Article 257 of the Turkish Penal Code 6 months – 2 years
Personal data breach Article 136 of the Turkish Penal Code 2-4 years

If these crimes are committed together, the penalties are increased according to the provisions for continuous offenses.


11. Responsibility from the Perspective of Clubs and Organizers

Clubs are required to operate their ticketing systems with a secure and encrypted infrastructure.
Otherwise, administrative and criminal liability will arise.
According to Article 19 of Law No. 6222, clubs that fail to fulfill their security and ticketing obligations will be subject to fines and penalties of playing matches behind closed doors.


12. Difficulties in Detection and Proof in Practice

  1. Digital Footprint Analysis: Shared use of IP addresses makes perpetrator identification more difficult.

  2. Ticket Cloning: Detecting the use of the same QR code multiple times takes time.

  3. Evidence integrity: A screenshot alone is not sufficient evidence.

  4. Cyber ​​attack originating from abroad: Requires legal cooperation.

Therefore, it is proposed that an "e-ticket evidence pool" be established between the Turkish Football Federation (TFF) and the prosecutor's offices.


13. Sanctions Policy and Judicial Trends

In recent years, the Supreme Court and other courts have adopted a stricter penal policy, particularly against crimes involving the "production of counterfeit tickets using information systems." This is because these crimes directly threaten the security of competitions and economic integrity

Courts also increase sentences if the perpetrator possesses professional technical knowledge.


14. Recommendations

  1. E-ticket blockchain infrastructure: Cloning and manipulation are prevented.

  2. Data audit certificate: Clubs should undergo annual IT audits.

  3. Instant notification system: Automatic blocking when the same QR code is scanned a second time.

  4. Penalty education: Fans and ticket vendors should be made aware of Law 6222.

  5. IT expert testimony should be mandatory in every case.


15. Conclusion

Counterfeit tickets and barcode manipulation are not just an economic fraud; they are also a criminal law issue that threatens the integrity of sports, fan safety, and the integrity of information systems.

The combined application of Law No. 6222, the Turkish Penal Code, and the Personal Data Protection Law provides multi-layered protection against these actions.
The Supreme Court's rulings also demonstrate that not every barcode change is an innocent technical act, but rather a crime that jeopardizes public security.

In sports, information security and legal transparency are essential complements to justice and fair play.

Leave a Reply

Call Now Button