Single Blog Title

This is a single blog caption

IP Address Tracing and Evidence Gathering in Crimes Committed Through Fake Accounts

Entrance

With the proliferation of social media platforms, methods of committing crimes have also changed. On platforms like Instagram, X, TikTok, Facebook, YouTube, WhatsApp, Telegram, and similar sites, it is common to see crimes such as insult, threat, blackmail, fraud, violation of privacy, unlawful dissemination of personal data, defamation, sexual harassment, stalking, and attacks on brand/commercial reputation, all perpetrated through fake accounts. The perpetrator often does not use their real name, instead operating through fake profile pictures, temporary email addresses, fake phone numbers, VPNs, shared internet connections, or compromised accounts.

In these types of cases, the most common question asked by the victim is: "Can the person who created the fake account be identified from their IP address?" The answer varies from case to case. IP identification is an important piece of evidence; however, it does not always definitively identify the perpetrator. This is because an IP address can indicate an internet connection, device, or network exit, but it doesn't always directly show who was actually sharing the content at that moment. Especially with CGNAT, public Wi-Fi, VPNs, Tor, mobile internet, compromised accounts, and multi-user networks, the IP address needs to be supported by other evidence.

Nevertheless, IP log records are one of the most important technical elements in investigating social media crimes. When the creation date of the fake account, the IP addresses used for login, device information, associated email or phone numbers, user activity, posting dates, messaging times, money transfers, GSM records, and the examination of the suspect's device are evaluated together, it may be possible to identify the perpetrator. Therefore, in fake account cases, the legal process should not be limited to simply taking screenshots; the proper collection of digital evidence and requests for investigation from the prosecutor's office are necessary.

What crimes can be committed through fake accounts?

Fake social media accounts can be used as tools in the commission of many different crimes. One of the most common crimes defamation . The perpetrator may directly insult the victim, use derogatory language in public, or make serious accusations by tagging the victim. According to Article 125 of the Turkish Penal Code, any concrete act or fact that offends a person's honor, reputation, and dignity, or any expression of a derogatory nature, constitutes the crime of defamation.

Another common crime threats and blackmail. Messages such as "I will humiliate you," "I will share your photos," "I will send them to your family," or "I will expose you if you don't send money" may be sent through fake accounts. In this case, the crimes of threat, blackmail, violation of privacy, and unlawful dissemination of personal data may all come up simultaneously.

Fraud through fake accounts is also common. The perpetrator opens a fake boutique account, takes payments as if there are products available, makes investment promises, shows cryptocurrency earnings, or uses a compromised account to solicit money from the victim's relatives. As stated in the General Directorate of Security's fraud information, deceiving a person through fraudulent behavior to gain benefit for oneself or another is a crime; using information systems and banks/credit institutions as tools can be considered aggravated fraud.

Furthermore, if the victim's photograph, phone number, address, private correspondence, identity information, or health information are shared on fake accounts, unlawful dissemination of personal data and violation of privacy may arise. IP address can also be considered personal data as it is one of the data that can identify an individual; in the GDPR disclosure examples of public institutions, IP address is listed among the categories of personal data along with information such as email and phone.

What is an IP address and why is it important from a legal perspective?

An IP address is a technical address that digitally identifies a device or network connected to the internet. When a social media account is logged in, a message is sent, a post is made, or the platform is accessed, most systems may keep log records of the IP address, date and time information, device information, browser, session, and so on. These logs can show which connection the fake account was used through.

However, an IP address doesn't necessarily mean "this is definitely the perpetrator." An IP address often indicates an internet subscription or access point. For example, a home internet connection can be used by many people. Different employees can connect via a shared Wi-Fi network in a workplace. Dozens of people can access the internet from a wireless network in a cafe. With mobile operators, the same IP address can be shared among different users. When using a VPN or proxy, the displayed IP address may indicate the intermediary server, not the perpetrator's actual connection.

Therefore, IP address identification can be a strong initial piece of evidence in criminal proceedings; however, ideally, the IP address should be supported by other evidence. For example, the fact that the same IP address belongs to the suspect's home internet, the presence of login traces on the suspect's device to the relevant account at the same times, the account being linked to the suspect's phone number or email address, money transfers going to accounts associated with the suspect, message language consistent with the suspect's, and the existence of a previous dispute between the victim and the suspect all strengthen the integrity of the evidence.

How to Detect an IP Address?

IP address tracing in fake accounts is not something a victim can do directly on their own. Victims can often only see the account's username, URL, messages, and shared content. The account's login IP addresses, creation information, associated email/phone records, and session history are usually stored in the platform's own database. Access to this information requires a formal request from the Public Prosecutor's Office or a court.

The prosecutor's office may send a request to the relevant social media platform for the account's creation date, login IP addresses, date and time records, email and phone information associated with the account, user activity, message sending dates, and device/session information if available. The IP records received from the platform are then requested from the internet service provider or GSM operator. The service provider can provide information on which subscriber the relevant IP address was assigned to at the specified date and time, along with port information if available.

The scope of access and hosting provider traffic information is important in Law No. 5651 and related regulations. Access provider traffic information includes records such as the subscriber's connection date and time, system logout information, the IP address assigned for the connection, and ports; hosting provider traffic information includes data such as source IP, destination IP, connection date and time, and transaction information.

Time information is extremely important here. When identifying an IP address, not only the IP address but also the date, hour, minute, second, and time zone must be accurately recorded. The same IP address may be assigned to different subscribers at different times. In mobile internet and CGNAT systems, it can be difficult to reach the correct subscriber without port information. Therefore, the date and time of the shared or message should be provided as clearly as possible in the criminal complaint petition.

Is an IP address alone sufficient grounds for conviction?

In criminal proceedings, conviction requires conclusive and convincing evidence beyond any reasonable doubt. While an IP address is important technical data, it should not always be considered sufficient on its own. Even if the IP address belongs to the suspect, whether the suspect actually shared the data must be evaluated separately.

For example, home internet may have been used by family members, guests, or neighbors. At work, many employees may have accessed the internet through a shared IP address. In cafes, dormitories, schools, hotels, or public Wi-Fi networks, numerous users may be using the same connection. The suspect's modem may have been compromised, their account hacked, or malware may have been installed on their device. These possibilities are particularly important from a defense perspective.

Therefore, an IP address is only one link in the digital chain of evidence. For sound proof, IP records should be evaluated together with device analysis, account connections, email/phone verification information, GSM call records or base station records, payment records, camera footage, witness statements, message content, the language used by the perpetrator, previous conflicts, the suspect's location at the time of the incident, and other technical data.

The First Step in Proving a Fake Account: Is a Screenshot Sufficient?

In fake account files, victims often only take screenshots. Screenshots are important; however, they may not always be sufficient on their own. This is because screenshots can be altered, cropped, taken out of context, or may not show the account link. Therefore, it is important to take screenshots correctly.

The screenshot must clearly show the account's username, profile picture, profile URL, the full content of the post, the date and time, comments, messages, tags, and if possible, the link in the browser's address bar. Screen recording is safer for short-lived content like Instagram stories. For X posts, the post link should be saved; for TikTok videos, the video link; and for Facebook posts, the post URL.

In WhatsApp or Telegram conversations, not just a screenshot of a single message should be preserved, but the entire conversation and its context. The perpetrator's payment demands, threats, phone number, IBAN, or link should be shown together. In group chats, the group name, number of participants, and message dates are important.

If the shared content constitutes a serious crime, involves the disclosure of private information, damages commercial reputation, or carries a high risk of damages, a notarized statement of fact, evidence gathering, or a forensic IT expert report may be considered. However, since the perpetrator can quickly close the account, the victim should immediately take screenshots and screen recordings as a first step.

Notary Public Verification, Evidence Gathering, and Forensic Computing Report

In fraudulent account cases, the reliability of the evidence is crucial. Screenshots are easy to take; however, the other party may claim that the screenshot is fabricated, that the account does not belong to them, or that the post was taken out of context. Therefore, in some cases, a notarized statement or a forensic IT report strengthens the evidentiary value.

Notarized verification serves to prove that the relevant website or social media content was available on a specific date. However, because social media platforms are dynamic, the notarized verification must also be technically accurate. The URL, username, posting date, content, and access method must be clearly visible.

Evidence gathering can be done through legal means. This is especially relevant if the content will be deleted quickly or if documentation of the content is required before access is restricted. This approach becomes even more important in cases of reputational attacks, trademark infringements, high-follower accounts, and systematic smear campaigns.

A digital forensics report provides a technical examination of screenshots, device data, messaging records, metadata, file integrity values, log records, and digital materials. Specifically, when a suspect's device is seized, it can examine whether the fake account was accessed, as well as browser history, application logs, session data, deleted files, and connection traces.

CMK Article 134 and Collection of Digital Evidence

In crimes committed through fake accounts, it may be necessary to examine the suspect's phone, computer, tablet, or other digital devices. In this case, Article 134 of the Code of Criminal Procedure comes into play. This article regulates the searching, copying, and seizure of computers, computer programs, and files. Failure to collect digital evidence in accordance with proper procedure can create serious problems regarding the reliability and legality of the evidence.

The Constitutional Court, in its decision dated February 12, 2026, numbered E.2023/128, K.2026/36, annulled certain parts of Article 134 of the Code of Criminal Procedure. According to the Constitutional Court's announcement, the annulment concerns certain sections of the provisions regarding searching/copying/seizing computers and records, and it was decided that the annulment would enter into force nine months after its publication in the Official Gazette. Since the decision was published in the Official Gazette on May 25, 2026, this area is in a transition period within 2026, and current legislation regarding digital evidence collection procedures should be carefully monitored.

The Constitutional Court's decision highlighted the importance of safeguards such as evidence security, protection of personal data, and the storage and destruction of copied data in the examination of digital data. Therefore, simply stating "seize the phone" is insufficient in cases involving forged account files. It must be clearly defined which device is linked to which account, what evidence will be sought, which records will be copied, and how the integrity of the evidence will be protected.

What requests should be included in a complaint to the prosecutor's office?

In crimes committed through fake accounts, the criminal complaint must be technical and concrete. Simply stating "I was insulted from a fake account, find its IP address" is often insufficient. The complaint should describe the events chronologically and present each piece of evidence individually.

The petition should first describe the platform used by the fake account, its username, profile URL, profile picture, account description, the content of posts or messages, the date and time information, how the victim was targeted, and the nature of the crime. If the account uses the victim's photo, the source of the photo should be stated; if private information is being disseminated, which personal data was shared; if fraud is involved, the IBAN to which the payment was made; and if there are threats, the threatening statements should be clearly stated.

The following requests may be made to the prosecutor's office: the account creation date from the relevant platform, login IP log records, associated email and phone information, device/session information, and user activity records; IP allocation and port records from internet service providers; line subscription information from GSM operators; digital examination of the suspect's devices under Article 134 of the Code of Criminal Procedure; investigation of bank, payment, or cryptocurrency records; and the issuance of an urgent warrant to prevent the loss of evidence.

If the victim suspects the perpetrator, this suspicion must be supported by concrete facts. For example, prior animosity, threatening messages, the language used, the sharing of information only the suspect would know, the account monitoring the suspect's circle, or the request for money being directed to an account linked to the suspect should be included in the complaint.

Why can obtaining data from platforms be difficult?

Most platforms like Instagram, Facebook, WhatsApp, X, TikTok, Telegram, and similar platforms are based abroad. Therefore, it is not always easy for Turkish prosecutors to obtain information directly and quickly from these platforms. The platforms' own data retention policies, international judicial cooperation procedures, the nature of the crime, the urgency, and the technical accuracy of the request can all affect information provision.

Some platforms only provide information in specific crimes and at the request of official authorities. In some cases, IP logs are kept for a limited time. On platforms like Telegram, user identification can be more difficult. If a VPN or temporary email address is used, IP logs may not reveal the perpetrator's true connection. Therefore, local evidence in the victim's possession, such as money transfers, phone numbers, IBANs, camera footage, witness statements, and other evidence linking them to the suspect, is of great importance.

At this point, it is crucial that the complaint is technically correctly prepared, the content of the memorandum sent to the platform is clear, and that the date, time, and username information are provided completely. An incorrect username, incomplete URL, an unclear date range, or a request based solely on a screenshot can make it difficult to obtain a technical response.

Using VPN, Proxy, Tor, and Public Wi-Fi

Fake account perpetrators often use VPNs, proxies, Tor, or public Wi-Fi to conceal their identities. In this case, the IP address appearing in platform logs may indicate a VPN server or public network exit, rather than the perpetrator's actual subscription. This makes investigations more difficult, but not impossible.

VPN use alone can hinder perpetrator identification; however, other mistakes made by the perpetrator can constitute evidence. For example, they may have logged into the account once from their own home internet connection. The phone number associated with the account may be registered in their name. The money involved in the fraud may have gone to their own account or a linked account. The fake account may have used private information of the victim that only the perpetrator would know. Session logs, application records, or screenshots related to the account may be found on the suspect's device.

In shared Wi-Fi usage, the IP address may not always belong to the perpetrator. For example, if an abusive account is opened from a cafe's IP address, identifying the users present in the cafe at that time, camera recordings, payment receipts, device MAC addresses, hotspot authentication records, and witnesses become important. Therefore, IP identification should be evaluated together with the technical and physical evidence of the incident.

Account holder's "My account was hacked" defense

In cases involving fake accounts or social media crimes, suspects often defend themselves with statements such as "my account was hacked," "someone else used my phone," "I didn't write it," "someone else used my home internet," "my device had a virus," or "the account doesn't belong to me." These defenses are not automatically accepted; however, they must be seriously investigated in criminal proceedings.

If the suspect genuinely claims their account has been compromised, supporting evidence should be sought. Password change notifications, login records from different countries, two-factor authentication alerts, platform security notifications, account recovery process details, email notifications, and post-incident claims can all be examined.

Conversely, the defense may be weakened if the account has been used by the suspect for a long time, if the incriminating content is consistent with the suspect's language and relationships, if there are previous normal posts from the same account, if login records are found on the suspect's device, or if the email/phone linked to the account belongs to the suspect.

Should the victim try to find the IP address on their own?

Attempting to independently identify an IP address is often unsafe for the victim and can lead to legal risks. Unauthorized access to the perpetrator's account, sending phishing links, attempting to steal passwords, using malware, or accessing the other party's device can constitute a crime. The victim's justification does not grant them the right to collect evidence illegally.

The victim's responsibility is to gather legally available evidence. This includes messages sent to them, publicly available posts, account profile information, payment receipts, phone numbers, IBAN information, URLs, and screen recordings. Technical IP-log analysis, however, should be conducted through the prosecutor's office and other relevant authorities.

This distinction is important. Evidence obtained illegally may not be usable in court and could lead to further criminal proceedings against the victim. Therefore, obtaining legal support during the digital evidence gathering process is crucial, especially in cases involving fake accounts.

IP Address Tracing and Personal Data Protection

IP addresses and log records may constitute personal data. Therefore, when determining IP addresses, the protection of personal data and safeguards under criminal procedure must be considered together. It is not possible for everyone to have random access to IP information. This data should be requested by investigative and prosecutorial authorities within the scope of their legal powers and in a proportionate manner.

IP and log records should only be requested to the extent necessary for solving the relevant crime. Broad, vague, and all-user requests may raise proportionality issues. For example, login records for a specific fake account within a particular date range may be requested; however, collecting all data of unrelated individuals would be legally problematic.

In the process of collecting digital evidence, a balance must be struck between the protection of personal data, the right to privacy, and the right to a fair trial. The Constitutional Court's decision to annul Article 134 of the Code of Criminal Procedure also emphasized the importance of safeguards regarding the personal data and privacy aspects of digital evidence.

Practical Checklist for Victims of Fake Accounts

The first step for a victim of a fake account is to record the account's username and URL. Profile pictures, bio, follower/following list, posts, stories, comments, and messages should be documented with screenshots and screen recordings.

Secondly, the date and time of the post should be saved. This is especially important for stories, live streams, or temporary content; act quickly. For X posts, save the share link; for TikTok videos, save the video URL; and for Instagram, save the profile and content link.

Thirdly, if the perpetrator requested money, the IBAN, crypto wallet address, payment link, receipt, and recipient information must be protected. In fraud cases, bank and payment traces can be stronger evidence than IP addresses.

Fourthly, if the perpetrator used a phone number, the number, WhatsApp profile information, message times, and voice recordings should be saved. However, one should not attempt to illegally access the other party's device or account.

Fifthly, a detailed criminal complaint should be filed with the Public Prosecutor's Office. The complaint should explicitly request IP log records, platform information, service provider records, and an examination of the suspect's device.

Defense Strategy from the Perspective of the Suspect or Defendant

In fraudulent account cases, the defense of the suspect or defendant must be based on the accuracy of technical evidence. The fact that an IP address belongs to the suspect does not necessarily mean that the crime was committed by the suspect. Therefore, the environment in which the IP address was used, whether the connection was shared, whether other individuals had access at that time, device analysis, account connections, and the suspect's location at the time of the incident should be examined.

If the account does not belong to the suspect, the email address or phone number used to log in, whether there are any application records for the account on the suspect's device, browsing history, application sessions, screenshots, and notification logs should be investigated. If the suspect's account has been compromised, platform security logs, password change notifications, and unusual login alerts should be presented.

Instead of simply saying "I didn't do it," the defense must substantiate the technical possibilities. Claims such as shared Wi-Fi, family members' use, workplace network, VPN, device loss, account hacking, malware, or another person's access must be supported by evidence. In criminal proceedings, the principle that the defendant benefits from the doubt applies; however, this principle does not mean abstract denial, but rather is evaluated based on the level of certainty of the evidence in the case.

Conclusion

In crimes committed through fake accounts, IP address identification and evidence gathering is a technically demanding and meticulous process in terms of cyber law and criminal procedure. An IP address is important evidence as it shows which connection the fake account was used through; however, it may not always be sufficient to definitively identify the perpetrator. Especially due to the use of VPNs, proxies, CGNAT, public Wi-Fi, mobile internet, compromised accounts, and multi-user networks, the IP address must be supported by other evidence.

For a successful investigation of fraudulent account files, screenshots, screen recordings, URLs, usernames, profile information, messages, date and time records, payment information, phone numbers, IBANs, cryptocurrency wallet addresses, platform logs, internet service provider records, and examination of the suspicious device should be evaluated together. The fact that Law No. 5651 and related regulations require traffic information to include elements such as connection date and time, IP address, and port demonstrates why detailed IP identification is technically necessary.

The most important step for the victim is to protect the evidence quickly and legally. Before the fake account is closed, the username is changed, or the posts are deleted, a screen recording should be taken; then, a detailed criminal complaint, including technical requests, should be filed with the Public Prosecutor's Office. The prosecutor's office should be requested to provide platform records, IP-log information, service provider records, GSM subscription information, bank/payment records, and, if necessary, a digital device examination under Article 134 of the Code of Criminal Procedure.

For suspects or defendants, what the IP address indicates and what it does not indicate must be carefully analyzed. An IP connection may indicate a subscription; however, to determine who actually shared the data, the device, account, time, location, money flow, and other technical evidence must be examined together. The Constitutional Court's 2026 decision to annul Article 134 of the Code of Criminal Procedure has further highlighted the importance of evidence security and personal data protection in the collection of digital evidence.

In conclusion, IP address identification in crimes committed through fake accounts is a central piece of evidence, but it should not be considered sufficient on its own. Unlike classic criminal investigations, these cases require technical knowledge, swift intervention, accurate requests for warrants, digital evidence security, and legal strategy. Therefore, it is crucial for both the victim and the suspect/defendant to conduct the process with knowledge of cyber law and criminal law, ensuring that evidence is not lost and that the procedure is followed correctly.

Leave a Reply

Call Now Button