What are theft and aggravated fraud committed through information systems?
Crimes of Theft and Aggravated Fraud Committed Through Information Systems:
In the digitalized world, the internet, smartphones, mobile banking applications, and e-commerce platforms, which permeate every aspect of our lives, have brought with them a brand new typology of crime. While traditional crime remained confined within the boundaries of physical space, modern crime is committed via fiber optic cables by invisible perpetrators behind screens. Within the Turkish Penal Code (TCK) system, theft and aggravated fraud committed using information systems as tools are among the most dangerous, fastest-growing, and most victimizing crimes against property.
As a Turkish citizen, in the hustle and bustle of daily life, you may become a target of cyber fraudsters through an SMS notification, a fake website, or unauthorized access to your account. In this comprehensive guide, we will delve into the legal boundaries of theft via information technology (Turkish Penal Code 142/2-e) and aggravated fraud (Turkish Penal Code 158/1-f), the fine line between the two crimes, judicial decisions, the legal avenues you should follow when you lose your money or assets, and the functioning of judicial processes.
1. Legal Framework: The Place and Meaning of Cybercrimes in the Turkish Penal Code
In the Turkish Penal Code, the concept of an information system is not regulated as a separate crime in itself, but rather as an aggravating circumstance that increases the severity of existing crimes .
An information system can be defined as a collection of systems that collect and store data, then transfer it to hardware (computers, servers, smartphones, POS devices, etc.) capable of performing automated processes. Using these systems as tools in committing a crime significantly increases the scope of the crime, the number of victims, and the amount of damage; therefore, the legislator has punished such acts with severe prison sentences.
2. Theft Crime Committed Through an Information System (Turkish Penal Code Article 142/2-e)
A. Definition and Elements of the Crime
The crime of theft, according to Article 141 of the Turkish Penal Code, is the act of taking movable property belonging to another person from its location without the owner's consent, with the intention of obtaining benefit for oneself or another. The commission of this crime using information systems as a tool is regulated in Article 142/2-e and constitutes an aggravated form.
The most fundamental element in this type of crime is the circumvention of the victim's will or the unlawful acquisition of benefit by exploiting the technical aspects of an information system.
-
Example Scenario: The perpetrator obtains someone else's online banking password (via malware, keylogger, or social engineering). Without the victim's knowledge or consent, they log into the system and transfer the money from the account to their own. The victim did not give any approval to the system; their will was not impaired; the perpetrator directly manipulated the system to withdraw the money.
B. Criminal Sanctions
The penalty for theft committed through information systems is imprisonment for 3 to 7 years. While not a high-security criminal court involving arrest warrants and lengthy trials, this is a serious offense heard in lower criminal courts.
3. Qualified Fraud by Using Information Systems as a Tool (Turkish Penal Code Article 158/1-f)
A. Definition and Elements of the Crime
Fraud (Turkish Penal Code Article 157) is the act of deceiving someone through fraudulent conduct in order to gain a benefit for oneself or another person, to the detriment of that person or another. When this crime is committed using information systems, banks, or credit institutions as tools, it falls under Article 158/1-f of the Turkish Penal Code and is classified as aggravated fraud.
In this type of crime, the impairment of legal will (deception/fraud) is fundamental. The victim voluntarily enters data into the system, sends the money themselves, or tells the fraudster the verification code (SMS OTP) because they have believed the other party's lies.
-
Example Scenario: A citizen sees an advertisement online for a used car or household goods at a very low price and contacts the seller. The scammer, posing as the seller, says, "There's high demand, send a deposit." The citizen voluntarily sends the money to the IBAN number. This action is a form of sophisticated fraud via information technology.
B. Criminal Sanctions and Severe Consequences
The penalty for aggravated fraud is imprisonment for 3 to 10 years and a very heavy fine, not less than twice the amount of the benefit obtained from the crime .
The use of information systems (social media, fake websites, phishing emails, fake investment applications) as tools in this crime is considered by the legislator as an action with a high societal risk; therefore, while judicial fines and imprisonment sentences are applied at the minimum level, they are quite deterrent.
4. The Fine Line Between Theft and Qualified Fraud, and Its Significance
In practice and in the jurisprudence of the Court of Cassation (especially the Criminal General Assembly and the relevant criminal chambers), it is frequently debated whether an act constitutes cyber theft or aggravated fraud. Why is this distinction important? Because a change in the nature of the crime affects the competent court, the complaint periods, and the legal provisions that are favorable or unfavorable to the accused.
-
In theft: The perpetrator directly infiltrates the system, the victim is unaware, and the victim's will is not compromised (e.g., copying someone else's card into an ATM and entering the PIN to withdraw money).
-
In fraud: The perpetrator deceives the victim, impairing their free will, and the victim carries out the transaction themselves (e.g., a person posing as a banker saying, "Your account has been blocked, tell us this password so we can unblock it," and the victim providing the password to withdraw the money). The Supreme Court considers any situation where the victim's consent is obtained through deception as fraud.
5. The Most Common Cybercrime Scenarios in Türkiye
The main cybercrime scenarios that Turkish citizens are most frequently exposed to and that are brought to the attention of judicial authorities are as follows:
-
Phishing and Fake Bank Websites: Scammers create exact replicas of official bank websites and place advertisements on search engines to steal citizens' passwords and empty their accounts.
-
Social Media Account Hacking and Investment Promise Scam: A friend's social media account is hacked, and messages are sent saying, "I made this much profit from this forex/crypto investment, you should join too," prompting relatives to send money based on this lie.
-
E-commerce and Deposit Fraud: Fraud involves posting attractive advertisements on platforms like Sahibinden, Letgo, or similar sites at prices far below market value, and then collecting a deposit or upfront payment for the product.
-
Fake Call Center Scam: Citizens are contacted via phone and intimidated with statements such as "You have a credit card fee refund," "You have an insurance debt," or "There is an enforcement file opened in your name," and their accounts are then compromised through remote access programs (AnyDesk, etc.).
6. Step-by-Step Guide to Follow When You Are a Victim of Cybercrime
As a Turkish citizen, you must remember that the moment you realize you've been scammed through cybercrime or your account has been emptied, it's a race against time . Taking the right steps within seconds can ensure your money is recovered or the perpetrator is caught.
Step 1: Immediately Contact Your Bank or Financial Institution (Report Fraud)
-
Call your bank's 24/7 customer service as soon as you notice the problem.
-
your account, credit cards, and online banking be blocked immediately .
-
formal "Fraud" report, . This report is one of the most important pieces of evidence in future legal proceedings.
Step 2: Record and Preserve All Digital Evidence
In our legal system, the burden of proof rests with the claimant. Therefore, do not delete or alter any evidence
-
Telephone call records and call times with the scammers.
-
Screenshots of WhatsApp, Telegram, or SMS conversations (with the date and time clearly visible).
-
IBAN numbers to which the money was sent, names, receipts, and EFT/wire transfer descriptions.
-
Links (URLs) to fake websites used by scammers.
Step 3: Contact the nearest police station or the Cyber Crime Unit
Without delay, go to the nearest Cyber Crime Unit of the Police Departmentor police station in your area of residence.
-
Present all the evidence and receipts you have in a single file.
-
Provide a detailed statement to an Incident Report and Document Registration Number .
Step 4: File a Criminal Complaint with the Public Prosecutor's Office
Following the police report, submit a comprehensive criminal complaint to the relevant Public Prosecutor's Office, either through a criminal defense lawyer or in person . In your complaint, request that the act be punished under Article 158/1-f (Aggravated Fraud) or Article 142/2-e (Cybertheft) of the Turkish Penal Code.
Step 5: Securing Account Blocking Through the Prosecutor's Office (Crucial Step)
The petition submitted to the prosecutor's office should request that the recipient bank accounts (recipient accounts) and the associated intermediary/electronic money institutions (Papara, Payfix, Moka, etc.) be identified and immediately blocked . If the money has not yet been withdrawn from the recipient account, it can be secured by blocking the account with a prosecutor's order, and its return can then be secured through legal action.
7. Challenges Encountered in Practice and Practical Information
-
“I Sent the Money, But the Account Holder May Not Be Guilty” (Mule/Courier Accounts): Scammers often “mule” (courier) accounts . The account holder may defend themselves by saying, “I didn’t know, I lost my card.” This requires a thorough investigation during the legal process; however, if the account holder withdrew the money or transferred it elsewhere at that moment, they cannot escape responsibility.
-
Statute of Limitations: The statute of limitations for these crimes is generally 8 years (this varies depending on the maximum penalty). However, initiating legal proceedings immediately from the moment the victimization is understood is essential to prevent the loss of evidence.
-
Compensation for Damages and Effective Repentance: If suspects are apprehended during the investigation or prosecution phase and fully compensate the victim for the damages, effective repentance may be applied, resulting in a reduction in sentences. Therefore, encouraging defendants to compensate for damages is a frequently employed method through lawyers.
Conclusion
Crimes such as theft and sophisticated fraud committed through information systems are among the leading digital traps threatening individuals' assets in today's society. The most important rule in combating these crimes is to be aware and not to trust suspicious links and promises.
However, if you have somehow fallen into this trap, it is vital to contact your banks immediately without panicking, to preserve all digital evidence completely, and to file a criminal complaint with the police and the prosecutor's office. The legal system is working with all its mechanisms to protect the rights of victims and to punish cybercriminals with deterrent penalties; obtaining professional legal support during this process will prevent loss of rights.