Criminal Defense
Cyber Crime & Digital Fraud in Turkey 2026: Legal Defense Guide
How does Turkish law punish cyber crime & digital fraud? Complete 2026 guide on TCK 243-245 penalties, victim remedies & cross-border defense — by Istanbul lawyers.
Cyber crime in Turkey is a significant criminal exposure for foreign investors, multinational corporation executives, and high-net-worth individuals with digital assets or business operations within Turkish jurisdiction. The Turkish Penal Code (TCK) Articles 243 through 245 establish a comprehensive criminal framework targeting unauthorized system access, data manipulation, and bank card fraud — with prison ranges reaching eight years for using a counterfeit bank card (TCK 245(3)) and judicial fines of up to 10,000 days for producing or trading counterfeit cards (TCK 245(2)).
For C-level executives overseeing Turkish subsidiaries, investors managing cross-border digital platforms, and HNWIs with significant financial exposure in Turkey, the intersection of cyber crime law and corporate liability creates a risk landscape that demands strategic legal architecture. Whether you face prosecution as an accused, seek redress as a victim, or need to structure compliance protocols to shield your enterprise, understanding TCK 243-245 is a prerequisite for operating in the Turkish digital economy. Istanbul Attorneys' criminal defense practice advises international clients on cyber crime matters, both as suspects and as victims.

Key Takeaways
TCK Article 243 criminalizes unlawfully entering or remaining in an information system, with up to one year's imprisonment or a judicial fine; the penalty is reduced by up to one-half for systems used for a fee, rises to six months to two years if data is destroyed or altered, and unlawfully monitoring data transfers with technical means carries one to three years.
TCK Article 244 covers hindering or disrupting a system (1-5 years) and destroying, altering or inserting data (6 months-3 years); both are increased by half for systems of banks, credit institutions or public bodies, and where the acts secure an unjust benefit that is not another offence, the range is 2-6 years and a judicial fine of up to 5,000 days.
TCK Article 245 addresses bank and credit card fraud: using another person's card without consent to obtain a benefit carries 3-6 years, producing or trading counterfeit cards linked to others' accounts 3-7 years, and using a counterfeit card 4-8 years.
Foreign nationals are subject to the same rules: under TCK 8(1), Turkish law applies to offences committed in Turkey, and an offence is deemed committed in Turkey where the act is committed wholly or partly there or its result occurs there, regardless of the offender's citizenship.
Account suspension: since Law No. 7571 of 24 December 2025, banks, payment service providers and crypto-asset service providers can suspend an account used in bank-card misuse, theft committed through information systems, or qualified fraud under TCK 158(1)(f) or (l) for up to 48 hours, and the proceeds can be seized within that period (CMK 128/A).
Understanding Turkish Cyber Crime Law: TCK Articles 243-245
Article 243: Unauthorized Access to Information Systems
TCK Article 243 establishes criminal liability for any person who unlawfully accesses part or all of an information processing system, or who remains within such a system without authorization. The baseline penalty is imprisonment of up to one year or a judicial fine. The provision then contains one reduction and two heavier forms.
When the system is one that can be used for a fee — for example a subscription service — the penalty is reduced by up to one-half (TCK 243(2)). If, because of the unlawful access, data in the system is destroyed or altered, the sentence becomes six months to two years imprisonment (TCK 243(3)). Furthermore, any person who unlawfully monitors data transfers within or between systems with technical means, without entering the system, faces one to three years imprisonment (TCK 243(4)).
Article 244: System Disruption, Data Manipulation, and Sabotage
Article 244 targets acts that hinder, destroy, or disrupt the operation of information processing systems — commonly known as denial-of-service (DDoS) attacks, ransomware deployment, and database sabotage. The penalty range is one to five years imprisonment for hindering or disrupting the operation of a system (TCK 244(1)), and six months to three years for corrupting, destroying, altering or making inaccessible the data in a system, inserting data into it, or sending existing data elsewhere (TCK 244(2)). Under TCK 244(3), these penalties are increased by half where the acts are committed against an information system belonging to a bank or credit institution or to a public institution or body.
Critically for foreign investors and corporate executives, Article 244 includes an economic enrichment aggravator: where the acts secure an unjust benefit for the perpetrator or a third party, and that benefit does not constitute another offence, the penalty is two to six years imprisonment plus a judicial fine of up to 5,000 days (TCK 244(4)). Depending on the facts, it can be relevant to insider data manipulation or competitor sabotage.
Article 245: Bank and Credit Card Fraud
Article 245 addresses the misuse, cloning, and fraudulent use of bank and credit cards. A person who obtains or holds another person's bank or credit card and uses it, or has it used, without the consent of the cardholder to obtain a benefit faces three to six years imprisonment and a judicial fine of up to 5,000 days (TCK 245(1)). Producing, selling, transferring, buying or accepting counterfeit cards linked to other people's bank accounts carries three to seven years and up to 10,000 days (TCK 245(2)), and using a counterfeit or falsified card to obtain a benefit carries four to eight years and up to 5,000 days, unless the act is a more serious offence (TCK 245(3)). For the offence in the first paragraph, the effective remorse rules for property offences apply (TCK 245(5)), and no penalty is imposed on the relative where it is committed against a spouse not subject to a separation decision, a direct ascendant or descendant, an in-law of the same degree, an adoptive parent or child, or a sibling living in the same home (TCK 245(4)).
For foreign investors, the practical exposure under Article 245 can arise in two scenarios: being victimized by card fraud while conducting business in Turkey, or facing allegations connected to corporate payment systems that process transactions through Turkish banking infrastructure.
Cyber Crime Exposure for Foreign Investors and MNCs in Turkey
Jurisdictional Reach and Cross-Border Prosecution
Under TCK 8(1), Turkish law applies to offences committed in Turkey, and an offence is deemed committed in Turkey where the act is committed wholly or partly there or its result occurs there. Offences committed entirely abroad are covered only under the conditions in TCK 11 (Turkish citizens) and TCK 12 (foreign nationals), which include minimum penalty thresholds and the person's presence in Turkey. For multinational corporations operating Turkish subsidiaries, an attack launched from a foreign server whose result occurs in Turkey can therefore fall within Turkish jurisdiction.
Requests to foreign states for evidence, transfer of proceedings and extradition are handled under Law No. 6706 on International Judicial Cooperation in Criminal Matters, without prejudice to the treaties Turkey is party to (Article 1(3)). As discussed in our guide on MASAK compliance and money laundering obligations, where proceeds move through Turkish banks or other obliged parties, the suspicious-transaction reporting regime of Law No. 5549 can also be engaged.
Corporate Criminal Liability and Executive Exposure
Criminal liability in Turkish law is personal: no one is held responsible for another's act, and criminal penalties cannot be imposed on legal entities, only the security measures provided by law (TCK 20). For cyber offences, TCK 246 provides for such measures against a legal entity that obtained an unjust benefit from the offence; under TCK 60, they include cancellation of an operating licence where its organs or representatives abused it, and confiscation. An executive is criminally liable under Articles 243-245 only for their own intentional acts: these are intentional offences, and negligent acts are punishable only where the law expressly says so (TCK 22(1)). A failure to implement adequate security is therefore not in itself a cyber crime; it is primarily a data-protection compliance issue.
Data protection law adds a parallel regulatory layer. Under Law No. 6698 (KVKK), the data controller must take all necessary technical and administrative measures to prevent unlawful processing of and access to personal data (Article 12(1)), and if personal data is obtained by others unlawfully, it must notify the data subject and the Personal Data Protection Board as soon as possible (Article 12(5)). Failure to meet these data-security obligations is subject to an administrative fine imposed by the Board under Article 18(1)(b), and unlawfully giving, disseminating or obtaining personal data is separately a crime under TCK 136 (two to four years). This dual-track enforcement model makes pre-incident compliance work important for any foreign company operating in Turkey.
Account suspension and seizure of proceeds (CMK 128/A)
Law No. 7571 of 24 December 2025 added Article 128/A to the Code of Criminal Procedure. Where there is a reasonable suspicion of qualified theft committed by using information systems (TCK 142(2)(e)), qualified fraud under TCK 158(1)(f) or (l), or bank or credit card misuse (TCK 245), the bank, payment service provider or crypto-asset service provider can itself suspend any account used in the offence for up to 48 hours. The suspension and the account movements are reported immediately to the Chief Public Prosecutor's Office and to the account holder, who can apply to the prosecutor to lift it; the prosecutor decides within 24 hours. Within the suspension period, the proceeds can be seized by a judge's decision or, where delay would be harmful, by the prosecutor's written order, which must be submitted to a judge within 24 hours; if the judge does not decide within 48 hours of the seizure, it lapses. Proceeds found to belong to the victim are returned to them during the investigation or prosecution.
Common questions about criminal defence in Turkey
What are the penalties for cyber crime in Turkey?
Under TCK Articles 243-245, penalties range from up to one year's imprisonment or a judicial fine for unlawfully entering an information system (TCK 243(1)) to four to eight years for using a counterfeit bank card (TCK 245(3)). Disrupting a system carries one to five years, and the penalties under TCK 244 are increased by half where the system belongs to a bank, credit institution or public body. Judicial fines of up to 5,000 days apply under TCK 244(4) and 245(1) and (3), and up to 10,000 days under TCK 245(2).
Can foreign nationals be prosecuted for cyber crime in Turkey?
Yes. Under TCK 8(1), Turkish law applies to offences committed in Turkey regardless of nationality, including where only the result of the act occurs in Turkey. Where evidence or a suspect is abroad, requests to the foreign state are made under Law No. 6706.
What is the role of MASAK in cyber fraud investigations?
MASAK (Financial Crimes Investigation Board) operates under Law No. 5549. Banks and other obliged parties must report to MASAK any transaction where there is information or suspicion that the assets were obtained illegally (Article 4), and where there is a suspicion of laundering or terrorist financing the Minister may suspend a transaction for seven business days (Article 19/A). Seizure of a suspect's accounts in a criminal case is a separate step: it is ordered by a judge under CMK 128, or under the faster CMK 128/A procedure for card fraud and IT-based fraud.
How does Turkey handle cryptocurrency fraud cases?
Cryptocurrency fraud in Turkey is prosecuted under TCK Article 157 (fraud: one to five years and up to 5,000 days' fine) and, where information systems, banks or credit institutions are used as the means, TCK 158(1)(f) (qualified fraud: three to ten years, with a minimum of four years and a judicial fine of not less than twice the benefit obtained). Since Law No. 7589 of 16 July 2026, a participant whose role was limited to handing over their own or another's payment card, or the information or tools needed to use an account at a bank, payment service provider or crypto-asset service provider, receives a sentence reduced by half (TCK 158(4)). Crypto-asset service providers are among the institutions that can suspend accounts under CMK 128/A.
What should a foreign investor do if they are a victim of cyber crime in Turkey?
Foreign victims can file a criminal complaint with a Chief Public Prosecutor's Office or the police (CMK 158(1)); for offences committed abroad that must be prosecuted in Turkey, a complaint can also be lodged with a Turkish embassy or consulate (CMK 158(3)). Where the loss involves card fraud, or fraud or theft committed through information systems, the bank, payment service provider or crypto-asset service provider can suspend the account used for up to 48 hours, the proceeds can be seized within that period, and proceeds found to belong to the victim are returned to them (CMK 128/A), so reporting the loss to the bank and to the prosecutor without delay matters.
Does Turkey have an extradition framework for cyber criminals?
Yes. Extradition to and from Turkey follows Law No. 6706 together with any extradition treaty in force with the other state. Under Article 11(1)(a) of that Law, Turkey does not extradite its own citizens, except for obligations arising from being party to the International Criminal Court, and a request is also refused where, among other grounds, the offence falls within Turkish jurisdiction (Article 11(1)(c)(4)).
This guide is general information on Turkish law, not legal advice on your own matter. Rules and practice change; check the position before you act.