Legal Procedures and Complaint Routes in Ransomware Attacks
Entrance
Ransomware attacks are one of the most severe types of cyberattacks faced by companies, government agencies, healthcare organizations, e-commerce businesses, law firms, accounting offices, manufacturing facilities, and individual users today. Known as "ransomware" in English, it is malicious software that encrypts files on a system, rendering them inaccessible, often halting company operations, and demands a ransom in exchange for the decryption key.
These attacks are not merely a technical problem. A ransomware attack can result in the theft of a company's customer data, employee files, financial records, trade secrets, patient or client information, order records, email archives, and contracts. Encrypting files alone can halt a company's operations; however, nowadays attackers often go beyond just encryption and threaten to publish the data if payment isn't made. This makes ransomware attacks a multifaceted issue from the perspectives of criminal law, GDPR, commercial law, and compensation law.
A company's first reflex after a ransomware attack often focuses on the question of "how do we recover the data?" However, legally, the real issue is not limited to this. The company needs to protect evidence, determine whether a personal data breach has occurred, assess whether notification to the Personal Data Protection Board is required, inform relevant individuals, file a criminal complaint with the Public Prosecutor's Office, review insurance and supplier contracts, record management decisions, and manage potential administrative fines/compensation risks.
The Personal Data Protection Authority explicitly states that the data controller is obligated to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data, to ensure the preservation of data, and to provide an appropriate level of security. The data controller may also be jointly responsible with other persons for taking the necessary measures when personal data is processed on their behalf by those persons.
What is a Ransomware Attack?
Ransomware attacks occur when an attacker encrypts and renders inaccessible files, databases, servers, backups, or network resources within a computer system. The attacker often leaves a ransom note on the screen or in folders. This note demands payment to a specific cryptocurrency wallet; failure to pay will result in the data being deleted, published, or the decryption key being withheld.
Ransomware attacks typically occur through phishing emails, malicious attachments, weak remote desktop protocol connections, outdated servers, compromised VPN accounts, weak passwords, vendor systems, vulnerable software, or employee errors. The Personal Data Protection Authority's announcement regarding user security also emphasizes that using the same username/password across different platforms, failing to change passwords at regular intervals, and not using methods such as two-factor authentication can lead to data breaches.
A ransomware attack can have three different consequences. First, the system stops working, and the company suffers operational losses. Second, data is encrypted, and the company loses data integrity. Third, if the data is leaked, it poses a threat of personal data breach, breach of trade secrets, and disclosure. This third possibility is particularly critical in terms of the Turkish Personal Data Protection Law (KVKK) and criminal law.
Is a Ransomware Attack a Crime?
Ransomware attacks are, in most cases, a crime under the Turkish Penal Code. If the attacker illegally gains access to the company's system, this could constitute the crime of unauthorized access to an information system under Article 243 of the Turkish Penal Code. According to this article, anyone who unlawfully accesses or remains in all or part of an information system is punishable.
The true severity of ransomware attacks often falls under Article 244 of the Turkish Penal Code (TCK). This includes encrypting systems, rendering data inaccessible, corrupting, deleting, altering, or sending files; and disrupting or impairing the functioning of an information system, destroying data, or rendering data inaccessible. Article 244 of the TCK specifically regulates the acts of disrupting or impairing the functioning of an information system, as well as the corruption, destruction, alteration, rendering inaccessible, inserting data into the system, or sending data elsewhere.
In addition, if the aggressor demands payment, crimes such as blackmail, threats, aggravated fraud, unlawful acquisition or dissemination of personal data, and disclosure of trade secrets may also be considered in the specific case. In particular, the threat of "we will publish your customer data if you don't pay" is not only a technical cyberattack but also a tool of legal and criminal pressure.
First Legal Step: Evidence Must Be Preserved
The most common mistake companies make in the aftermath of a ransomware attack is panicking and formatting systems or trying to erase traces of the attack. Of course, restoring the system to working order is important; however, interventions made without preserving evidence can weaken the prosecution process, the GDPR assessment, and insurance and compensation processes.
Evidence that needs to be preserved includes the ransom note, the attacker's contact addresses, crypto wallet information, email headers, log records, firewall logs, VPN/RDP access logs, EDR/antivirus alerts, samples of encrypted files, malware files, server images, network traffic logs, backup logs, and correspondence with the attacker. These records can help determine when the attack began, which systems were accessed, whether data was compromised, and the methods used by the attacker.
Evidence preservation should be carried out with the support of a forensic IT expert. Technical analysis is particularly necessary so that the company can later claim that "personal data was not leaked" or "only the system was encrypted." Without log records, proving whether a data breach occurred becomes difficult. Therefore, the first step after an attack should not be technical cleanup, but controlled isolation and evidence preservation.
Crisis Team and Legal Response Plan
An emergency crisis team should be formed within the company in the event of a ransomware attack. This team should include the IT department, a cybersecurity expert, a legal advisor, a GDPR officer, senior management, human resources, finance, customer relations, and, if necessary, an external digital forensics expert.
The crisis team's first task is to determine the scope of the attack. Which servers were affected? Are the backups intact? Is the attack ongoing? Has personal data been compromised? Is there any sensitive personal data? Does the attacker claim to have compromised data? In which sector does the company operate? Is there a sectoral reporting obligation? Is there an insurance policy? Is there a possibility of a supplier-related breach?
Paying ransom, making public statements, or making definitive claims such as "there was no data breach" without answering these questions is risky. Every step the company takes should be documented in writing. The board of directors or authorized body should make decisions on matters such as appointing external experts, GDPR notifications, complaints to the prosecutor's office, and customer notifications. These records are important for demonstrating the company's diligent actions in the future.
Data Breach Assessment from the Perspective of the Personal Data Protection Law (KVKK)
The most critical question in ransomware attacks is: Were personal data merely encrypted, or was it obtained by the attacker? According to Article 12 of the Personal Data Protection Law (KVKK), if personal data processed is obtained by others through unlawful means, the data controller is obligated to notify the data subject and the Board. The Board also states that the data controller must take appropriate technical and administrative measures to fulfill its data security obligations.
In ransomware incidents, data breaches occur when the attacker has copied the database, exported files, stolen customer lists, leaked employee data, compromised patient or sensitive data, released sample data, or when system logs show data leakage. Furthermore, the attacker claiming to have obtained the data is not conclusive proof on its own, but it is a serious risk indicator that should be taken seriously.
The company must conduct this assessment with a technical report. Which categories of personal data have been affected? Is there any information including name, surname, Turkish ID number, phone number, email address, address, IP address, order history, financial information, health data, employee payroll, client/patient information, password, or identification document? What is the number of affected individuals? Was the data encrypted? Have backups been affected? This information is necessary for the GDPR notification and for explanations to be provided to relevant individuals.
Notification under the Personal Data Protection Law within 72 Hours
If a personal data breach is detected or the likelihood of a breach reasonably exists, the notification period to the Personal Data Protection Board immediately comes into effect. The Board's recent announcement clearly states that, in accordance with the Board's decision dated January 24, 2019, and numbered 2019/10, data controllers are obligated to notify the Board without delay and within a maximum of 72 hours from the date they become aware of the breach.
This timeframe does not include waiting for the company to fully resolve the attack in all its details. All technical investigations may not be completed within the first 72 hours. In such a case, the company should make an initial notification with the available information and provide additional information as the investigation progresses. If notification is delayed, the reason for the delay must be explained. The notification should include the date of the breach, the date of detection, affected systems, data categories, groups of people, potential consequences, measures taken, and contact information.
If the 72-hour deadline is missed, the company may face an investigation by the Board regarding both data security measures and notification obligations. The Board also states that an investigation decision can be made after the notification obligation has been fulfilled. Therefore, making a notification does not automatically relieve the company of responsibility; however, failure to notify on time and accurately creates additional risks.
Notification to Relevant Persons
Individuals whose personal data has been affected by a ransomware attack should also be informed. These individuals may include customers, employees, former employees, members, patients, clients, students, supplier representatives, or platform users. The purpose of the notification is to enable individuals to take precautions to mitigate potential losses.
Notifications to relevant individuals should be simple, clear, and informative. They should specify which data may have been affected, when the breach occurred, potential risks, measures taken, and precautions individuals can take. For example, if password data has been compromised, a password change should be recommended; if email and phone information has been leaked, a warning against phishing attacks should be issued; and if financial data has been affected, monitoring bank accounts should be advised.
It is not correct for the company to be content with vague explanations such as "a system problem occurred." Conversely, making definitive statements about matters that have not yet been technically verified is also risky. The most appropriate approach is to honestly disclose what is known, what is unknown, the measures taken, and the communication channels used.
How should a criminal complaint be filed with the prosecutor's office?
In cases of ransomware attacks, a criminal complaint should be filed with the Public Prosecutor's Office. The complaint should not be a standard formal request, but rather a comprehensive cybercrime report supported by technical evidence. The perpetrator is often anonymous; therefore, the complaint should specifically mention technical data that will help identify the perpetrator.
The petition should include the date the attack was detected, the attack method, the affected systems, the ransom note, the email/messaging addresses used by the attacker, the cryptocurrency wallet address, IP log records, a sample of the malware, the data allegedly leaked, the damage suffered by the company, business interruption, customer impact, and a technical report. The petition should request the prosecutor's office to investigate the IP addresses used in the attack, examine the domain names, identify cryptocurrency wallet transactions, request records from relevant service providers, investigate suspicious accounts, and conduct an investigation against the perpetrator(s) under Articles 243 and 244 of the Turkish Penal Code, and other relevant offenses depending on the specific circumstances of the case.
Delaying a complaint in ransomware attacks can lead to the loss of evidence. Some log records are kept for a short time. The infrastructure used by the attacker can be shut down quickly. Cryptocurrency transactions can be transferred to other wallets in a short time. Therefore, a criminal complaint should be filed immediately after technical evidence is collected.
Should a ransom be paid?
In ransomware attacks, the most difficult decision is paying the ransom. While legally paying a ransom isn't always outright prohibited, it carries significant risks. Paying doesn't guarantee data recovery. The attacker may not provide the decryption key, the key they provide might not work, they may have already copied the data, or they may make new demands after payment.
Furthermore, making a payment does not absolve the company of its GDPR responsibilities. If personal data has been leaked or obtained by unauthorized persons, a data breach notification may still be issued even if payment has been made. The fact that the company paid to prevent the attacker from publishing the data does not automatically negate the Board's assessment of whether the company has taken the necessary technical and administrative measures.
Before deciding to pay the ransom, the possibility of technical recovery, the status of backups, insurance policies, sanctions lists, money laundering risk, internal company approval mechanisms, prosecution processes, and GDPR obligations should all be evaluated together. All correspondence and payment requests made with the attacker should be preserved as evidence.
Insurance Notification and Cyber Insurance
Some companies may have cyber insurance policies. Policy terms should be reviewed immediately in the event of a ransomware attack. Notification periods, coverage, exclusions, ransom payments, data recovery costs, business interruption damages, legal advice, digital forensics services, third-party claims, and administrative fines all vary according to the policy.
Late notification to the insurance company can lead to loss of coverage. Therefore, an insurance manager or financial advisor should also be included in the crisis team. In some cases, the insurer may require the use of specific digital forensics firms or request approval before payment. This process should be carried out in conjunction with legal advice.
Supplier-originated ransomware attacks
Ransomware attacks may originate not from the company's own systems, but from a supplier or external service provider. Cloud services, accounting software, CRM systems, email providers, call centers, payment infrastructure, hosting companies, or external IT service providers can be entry points for the attack.
Under the Turkish Personal Data Protection Law (KVKK), the data controller may be jointly liable with the data processor for taking necessary measures when personal data is processed by another person on their behalf. Therefore, a company cannot automatically absolve itself of responsibility by stating that "the breach occurred in the supplier's system." Supplier selection, contract terms, auditing, data processing protocol, breach notification period, and security standards are all important considerations.
The supplier contract should be reviewed after the attack. Did the supplier report the breach in a timely manner? Did they take the necessary security measures? Are they sharing the logs? Did they use subcontractors? Was the data transferred abroad? Does the contract contain provisions regarding compensation, recourse, confidentiality, and data security? These questions are important both for the company's defense and for any claims that may be made against the supplier.
Employee-Related Vulnerabilities and Their Implications for Labor Law
Some ransomware attacks stem from employee error. Clicking on a phishing email, opening a malicious attachment, using a weak password, lacking multi-factor authentication, failing to revoke access for a former employee, or installing unauthorized software can all pave the way for an attack.
If an employee intentionally leaks data or assists an attacker, termination of employment for just cause, criminal charges, and compensation claims may arise. However, if the error is solely employee fault, the company's responsibility for providing necessary training and technical measures will also be examined. The company's own negligence will be questioned if employees have not received information security training, if there is no password policy, if access rights are not limited to job descriptions, and if multi-factor authentication has not been used.
The organization's announcement regarding user security states that deficiencies such as password reuse, failure to change passwords, and two-factor authentication can lead to data breaches. Therefore, companies should view employee training, access management, and authentication measures not merely as technical preferences, but as legal obligations.
USOM and Sectoral Notifications
It cannot be said that all companies are equally obligated to report to USOM (National Security Center for Combating Organized Crime) in every ransomware attack. However, the nature of the attack, the company's sector, its critical infrastructure connections, and whether it involves electronic communications, finance, energy, healthcare, or public services should be considered separately for evaluation regarding USOM and sectoral SOME (Special Operations Center for Combating Organized Crime) processes.
According to BTK (Information and Communication Technologies Authority), USOM (National Cyber Security Center) was established to identify threats to Türkiye's cybersecurity, mitigate or eliminate the effects of potential cyberattacks and incidents, and to conduct national and international coordination in responding to cyber incidents on a 24/7 basis. USOM acts in coordination with judicial authorities and law enforcement agencies when encountering findings that constitute a crime.
Regarding the electronic communications sector, the BTK (Information and Communication Technologies Authority) states that operators have obligations such as taking precautions against cyberattacks, establishing Corporate Security Operations Centers (COCs), and working under the coordination of Sectoral COCs. Therefore, a company that has been subjected to a ransomware attack should evaluate not only the Personal Data Protection Law (KVKK) and the prosecutor's office, but also the sectoral regulatory body aspects, depending on its field of activity.
Indemnification and Contractual Liability
Ransomware attacks can cause harm to third parties. If customer data is leaked, claims for phishing, fraud, reputational damage, or moral damages may arise. If employee data is disclosed, claims for compensation due to privacy and personal data breaches may occur. Customers or business partners may claim contractual damages due to the company's inability to provide services.
When assessing a company's liability for damages, factors such as the foreseeability of the attack, the technical and administrative measures taken, data security policies, backup systems, incident response speed, notification to relevant parties, supplier audits, and the causal link between the breach and the damage are examined. The risk of damages increases if the company has not taken necessary precautions or has delayed fulfilling its obligations after the attack.
The risk of claiming compensation for non-pecuniary damages is higher, especially in cases involving sensitive personal data. The disclosure of health data, biometric data, criminal conviction information, data relating to children, financial information, or data classified as trade secrets can have more serious consequences.
Documents to Prepare After a Ransomware Attack
Following a ransomware attack, the company needs to create a comprehensive incident file. This file should include the following documents: incident report, crisis team decisions, preliminary technical investigation report, digital forensics report, log and image acquisition records, ransom note, correspondence with the attacker, cryptocurrency wallet information, GDPR assessment note, data breach notification to the Board, notification texts sent to relevant parties, criminal complaint to the prosecutor's office, insurance notification, supplier correspondence, customer communication texts, and a closing report.
The closing report is particularly important. This report should specify the root cause of the attack, the affected systems, the categories of data affected, the initial measures taken, permanent security improvements, efforts to prevent recurrence, and the responsible parties. Such a report helps demonstrate that the company acted diligently in any Board review, insurance process, customer litigation, or management liability discussion.
Legal and Technical Preventive Measures Against Ransomware Attacks
Ransomware attacks may not be completely preventable; however, companies can mitigate the risk. Technical measures include regular backups, offline backups, backup testing, multi-factor authentication, strong password policies, RDP/VPN security, EDR/antivirus, firewalls, email security, patch management, log management, penetration testing, vulnerability scanning, and network segmentation.
Administrative measures include information security policy, employee training, supplier contracts, data processing contracts, breach response plan, authorization matrix, data retention-destruction policy, crisis communication plan, cyber insurance analysis, and regular internal audits. The Personal Data Protection Authority states that data security measures should be determined in a way that is appropriate to the structure, activities, and risks of each data controller.
For companies, it's not enough to simply take preventative measures; documenting those measures is crucial. Training records, audit reports, penetration test results, backup tests, policy signatures, supplier audits, and security updates should all be on record. In the event of a breach, the company must be able to demonstrate, with concrete evidence, that it has taken the necessary precautions.
Complaint Procedures for Ransomware Victims
Companies or individuals targeted by ransomware attacks should first file a criminal complaint with the Public Prosecutor's Office. The complaint should be supported by technical evidence and request an assessment of the crime under Articles 243 and 244 of the Turkish Penal Code, as well as, depending on the specific circumstances, blackmail, threats, unlawful acquisition of personal data, and fraud.
In the event of a personal data breach, the data controller company is responsible for notifying the Personal Data Protection Authority (KVKK) and the data subject. Individuals affected by the data breach can contact the data controller to inquire about which of their data has been affected, what measures have been taken, and to request compensation for their losses. If necessary, they can also pursue legal action through the Authority, consumer law, compensation claims, or labor law.
If the company's customers have also suffered damages as a result of the attack, contractual liability and compensation claims may arise. For example, if the e-commerce site was unable to deliver orders due to the attack, customer data was disclosed, or service was interrupted for an extended period, the contract terms and consumer legislation should be examined separately.
Conclusion
In ransomware attacks, the legal process is not simply a matter of "whether or not to pay the ransom." From the outset, the company must protect evidence, establish a crisis team, conduct a personal data breach assessment, not miss the 72-hour notification period stipulated by the Turkish Personal Data Protection Law (KVKK), properly inform relevant individuals, file a criminal complaint with the prosecutor's office using technical evidence, investigate supplier and employee responsibilities, initiate the insurance process, and meticulously document all steps in writing.
Ransomware attacks may constitute crimes under Article 243 of the Turkish Penal Code (TCK) for unauthorized access to an information system, and under Article 244 for obstructing, disrupting, destroying, altering, rendering inaccessible, or sending data to another location. Therefore, the complaint should be supported by a technical report, log records, the ransom note, crypto wallet information, and correspondence with the attacker.
According to the KVKK (Law on the Protection of Personal Data), if personal data is obtained by others through unlawful means, the data controller may have an obligation to notify the Board and the data subjects. The Authority explicitly states that notification must be made to the Board without delay and within a maximum of 72 hours from the time the data breach is learned.
In conclusion, ransomware attacks require a combination of technical response and legal crisis management. Companies with a pre-prepared data breach response plan, a robust backup system, multi-factor authentication, employee training, supplier audits, digital forensics procedures, and a legal notification process can better manage both operational losses and legal liability risks when an attack occurs. Acting quickly is crucial in a ransomware attack; however, equally important is acting in an evidence-based, transparent, and legally compliant manner.