International Cybercrime Cases in Turkey: Cross-Border Evidence and Jurisdiction Issues

Introduction

International cybercrime cases in Turkey are becoming increasingly complex because cyber incidents rarely remain within one country. A phishing message may be sent from abroad, the victim may live in Turkey, the receiving bank account may be Turkish, the domain may be registered through a foreign registrar, the server may be hosted in Europe, the cryptocurrency wallet may be controlled through another country and the suspect may be physically located outside Turkey. This cross-border structure creates difficult questions of jurisdiction, digital evidence, mutual legal assistance, extradition, data protection and criminal defence.

Turkish cybercrime law is mainly based on the Turkish Penal Code, the Criminal Procedure Code, Law No. 5651 on internet publications, Law No. 6706 on International Judicial Cooperation in Criminal Matters, the Personal Data Protection Law No. 6698 and, more recently, Cybersecurity Law No. 7545. Turkey is also a party to the Council of Europe Convention on Cybercrime, commonly known as the Budapest Convention, which supports preservation requests, mutual legal assistance and coordinated cross-border cybercrime investigations.

This article explains international cybercrime cases in Turkey from a practical legal perspective. It focuses on jurisdiction, cross-border evidence, mutual legal assistance, data preservation, digital forensics, foreign platforms, extradition, victim remedies and defence strategies.

1. Why Cybercrime Becomes International

Cybercrime becomes international when any element of the offence, evidence, victim, suspect, server, payment channel or digital service provider is located in more than one country. This is common in modern cases because cybercriminals deliberately use foreign infrastructure to hide identity and delay investigations.

Examples include:

A Turkish victim loses money through a phishing website hosted abroad.

A foreign suspect hacks a Turkish company’s database.

A ransomware group encrypts servers used by a Turkish hospital but communicates through foreign infrastructure.

A fake investment platform targets Turkish users while using offshore companies.

A Turkish bank account receives funds from victims in different countries.

A cryptocurrency scam involves wallets controlled from multiple jurisdictions.

A social media account is hacked through an IP address outside Turkey.

A Turkish company’s customer data is stored on foreign cloud servers.

These cases require both domestic criminal law analysis and international cooperation. A Turkish prosecutor may have authority to investigate the Turkish element of the crime, but crucial evidence may be held by foreign platforms, banks, hosting providers or telecom operators.

2. Jurisdiction in International Cybercrime Cases

Jurisdiction is the first legal issue in cross-border cybercrime. Turkish authorities must determine whether Turkey has a sufficient legal basis to investigate or prosecute the offence. In many cybercrime cases, jurisdiction may arise because the victim is in Turkey, the damage occurs in Turkey, the unlawful benefit is received in Turkey, the suspect is in Turkey, the affected system belongs to a Turkish person or company, or the offence targets Turkish public or private interests.

Turkish criminal law includes territorial jurisdiction and certain extraterritorial rules. Legal guidance on Turkish cybersecurity law notes that Turkish jurisdiction may apply where offences are committed in Turkey, where offences are committed abroad by Turkish citizens under certain conditions, where offences are committed abroad against Turkish citizens or Turkish private-law legal persons under specified circumstances, and in certain cases where offences are committed abroad to the detriment of Turkey.

In practice, jurisdiction must be assessed carefully. A cyber incident may have several connecting points, but not every foreign element gives Turkey unlimited power. The complaint should explain the Turkish connection clearly: who the Turkish victim is, where the damage occurred, which Turkish account received the money, which Turkish system was affected or how Turkish public order, companies or individuals were harmed.

3. Core Turkish Cybercrime Provisions

International cybercrime cases may involve several provisions of the Turkish Penal Code. The most important cybercrime offences are Articles 243, 244, 245 and 245/A. The Council of Europe identifies Article 243 as unlawful access to a computer network system, Article 244 as preventing system functioning and deletion, alteration or corruption of data, and Article 245 as misuse of bank or credit cards.

Article 243 may apply where a foreign or domestic suspect unlawfully accesses an e-mail account, server, social media account, corporate platform, cloud folder or banking system. Article 244 may apply where data is deleted, altered, transferred, made inaccessible or where a system is disrupted. Article 245 may apply where stolen bank or credit card data is used to obtain benefit. Article 245/A may be relevant where prohibited devices, programs, passwords or security codes are produced, possessed, transferred or used for cybercrime purposes.

Cross-border cases may also involve qualified fraud, personal data offences, violation of privacy, blackmail, threats, forgery, money laundering and criminal organization allegations. Therefore, a cybercrime complaint should not be drafted with a single label such as “hacking” or “online fraud.” It should identify each act and connect it to the correct legal provision.

4. Cross-Border Evidence: The Central Challenge

The most difficult part of international cybercrime cases is usually evidence. The victim may be in Turkey, but the evidence may be abroad. A social media platform may hold account login records. A foreign hosting provider may hold server logs. A foreign bank may hold recipient account records. A cryptocurrency exchange may hold KYC data. A cloud provider may hold deleted files. A registrar may hold domain ownership information.

Cross-border digital evidence may include:

IP logs.

Subscriber information.

Domain registration records.

Hosting data.

Cloud access records.

E-mail headers.

Server logs.

Social media account records.

Banking records.

Cryptocurrency exchange records.

Device identifiers.

Payment processor records.

Traffic data.

Content data.

Deleted account recovery records.

The legal strategy must separate locally available evidence from foreign-held evidence. Locally available evidence should be preserved immediately. Foreign-held evidence may require formal or informal international cooperation, depending on the type of data, urgency, platform policy and applicable treaty framework.

5. Mutual Legal Assistance in Cybercrime Cases

Mutual legal assistance is the formal method by which one state requests another state to collect evidence, serve documents, obtain records, search premises, examine witnesses or perform procedural actions. In Turkey, the Ministry of Justice, Directorate General of Foreign Relations and European Union Affairs is the designated central authority for mutual legal assistance in criminal matters.

Turkey’s international cooperation framework includes the Budapest Convention, European mutual assistance instruments, bilateral treaties and Law No. 6706 on International Legal Cooperation in Criminal Matters. The Council of Europe’s Turkey international cooperation guidelines state that Turkey cooperates on the basis of Law No. 6706 and that, where issues are not regulated by that law or other laws, the Turkish Criminal Procedure Code applies.

A mutual legal assistance request should be specific. It should identify the requesting authority, the reason for the request, the requested measure, the legal incident, the subject person’s information and the legal basis. Turkey’s cooperation guidelines state that the request should include the requesting authority, reason and request, an explanation of the legal incident, personal information of the subject and legal grounds; relevant court decrees and statutory basis should also be annexed.

6. Budapest Convention and 24/7 Contact Point

The Budapest Convention is particularly important for cybercrime because digital evidence can disappear quickly. Turkey has established a 24/7 point of contact under Article 35 of the Budapest Convention, based in the National Cybercrime Department of the Turkish National Police. The same structure is also used for G8 and INTERPOL network purposes.

The National Cybercrime Department has specific competence in urgent measures related to expedited preservation of traffic data, while criminal investigations are commenced and directed by the prosecution service with technical support from the police.

This structure is crucial in international cybercrime cases. If logs may be deleted soon, an urgent preservation request may be more realistic than waiting for a full evidentiary production process. Preservation does not necessarily mean immediate disclosure of all data; it means that the relevant data should be kept from deletion while formal legal channels are pursued.

7. Subscriber Data, Traffic Data and Content Data

Cross-border digital evidence should be categorized correctly. Subscriber data, traffic data and content data are not the same.

Subscriber data may identify the account holder, registered e-mail, phone number, billing information or user profile. Traffic data may show IP addresses, access times, connection duration, transferred data amount and service type. Content data may include messages, files, e-mails, images, documents or stored communications.

Turkey’s international cooperation guidelines define traffic data by reference to Law No. 5651 as including IP addresses of the parties, beginning and ending time of the service, type of service, transferred data amount and, if available, subscriber information. The same guidelines state that hosting providers must retain traffic data for a period not less than one year and not more than two years, while access providers must retain traffic data for a period not less than six months and not more than two years, as determined by regulations.

This distinction matters because different types of data may require different legal thresholds. Content data is usually more sensitive than subscriber or traffic data. Defence lawyers should examine whether the requested data type was properly authorized and whether the request exceeded what was necessary.

8. CMK Article 134 and Digital Evidence in Turkey

Where digital evidence is located in Turkey, Article 134 of the Turkish Criminal Procedure Code is central. Article 134 allows search, copying and seizure of computers, computer programs and computer logs where there are strong suspicions based on concrete evidence and no other way to obtain evidence. It also regulates copying, backing up, deciphering and converting records into readable form.

Article 134 is particularly relevant where Turkish authorities need to examine a suspect’s computer, phone, server, corporate device, external drive or local system. It is also important when foreign authorities request Turkey to search or seize computer data located in Turkey, because the domestic procedural safeguards still matter.

The law requires attention to forensic integrity. During seizure of computers or computer logs, all data in the system is backed up; a copy from the backup is given to the suspect or counsel upon request, and the process is recorded.

For defence purposes, Article 134 should be examined carefully. Was there concrete evidence? Was there no other way to obtain the evidence? Was the judicial decision specific enough? Were copies properly made? Was the suspect or counsel given a copy where requested? Was unrelated private data included? These questions may affect admissibility and reliability.

9. Chain of Custody in Cross-Border Evidence

Chain of custody becomes more complicated when evidence crosses borders. A log may be preserved by a foreign provider, transmitted to a foreign authority, sent through mutual legal assistance, translated, added to a Turkish file and then examined by an expert. Each step must be reliable.

A defence lawyer should ask:

Who originally collected the data?

Was the data preserved before deletion?

Was the data complete?

Was a hash value or authenticity certification provided?

Which legal process was used?

Was the data translated accurately?

Was the time zone converted correctly?

Was the account identifier clearly linked to the suspect?

Was the evidence limited to the requested scope?

Was the defence given an opportunity to examine it?

Digital evidence may look objective, but cross-border handling can introduce errors. Time zones, daylight saving rules, UTC conversion, dynamic IP allocation, missing port information, VPN use and incomplete platform records may all affect interpretation.

10. Time Zone and Timestamp Problems

Timestamp errors are common in international cybercrime cases. A server may record UTC time, a platform may display local time, a bank may use Turkish time, an e-mail header may include multiple time zones and a phone may have its own device settings.

A one-hour or three-hour difference may change the entire case. For example, the suspect may have an alibi at the alleged time, but the time may be converted incorrectly. A bank transaction may appear to follow a login, but correct UTC conversion may show a different sequence. A foreign platform may provide logs in UTC, while the complaint uses Turkey time.

Every international cybercrime file should include a timeline. The timeline should specify the time zone for each record. Defence lawyers should not accept timestamps without checking their source and conversion.

11. Foreign Platforms and Data Disclosure

Many cybercrime cases depend on records held by foreign platforms such as social media companies, e-mail providers, cloud services, domain registrars, hosting companies, payment processors and cryptocurrency exchanges. These platforms may have different policies for emergency disclosure, preservation and formal legal requests.

In practice, Turkish victims should preserve all evidence they can access directly: screenshots, URLs, e-mails with headers, SMS messages, bank receipts, account notifications, platform warnings and domain information. The criminal complaint should then request the prosecutor to seek platform records through appropriate channels.

However, it should be understood that foreign platforms may not disclose content data directly to private persons or lawyers. They may require law enforcement or judicial requests. Therefore, a strong Turkish criminal complaint must clearly identify what data should be requested, why it is relevant and why urgency exists.

12. Cryptocurrency and Cross-Border Cybercrime

Cryptocurrency is frequently used in ransomware, investment scams, phishing, money laundering and cross-border cyber fraud. A Turkish victim may transfer funds to a wallet controlled abroad. The funds may then move through multiple wallets, exchanges, mixers or bridges.

Cryptocurrency evidence may include wallet addresses, transaction hashes, exchange accounts, KYC records, IP logs, withdrawal addresses and blockchain tracing reports. Blockchain data is public in many cases, but identifying the person behind a wallet often requires exchange cooperation.

A Turkish criminal complaint should include transaction hashes, wallet addresses, exchange names, screenshots, communication records and bank transfer records used to purchase crypto. If a Turkish or foreign exchange is involved, the prosecutor may request account records through domestic or international channels.

13. Extradition and International Suspects

If the suspect is abroad, prosecution may require international cooperation or extradition. Extradition depends on treaties, double criminality, nationality, seriousness of the offence, human rights considerations and domestic law of the requested state.

Law No. 6706 is the main national framework for international legal cooperation in criminal matters, and international cooperation may also rely on European conventions, bilateral treaties or reciprocity. Turkey’s cooperation guidelines identify European mutual assistance conventions, the Budapest Convention and Law No. 6706 as key legal bases.

In practice, extradition in cybercrime cases may be difficult if the suspect’s identity is uncertain, the offence is not sufficiently serious, evidence is incomplete or the requested country does not extradite its nationals. Therefore, victims and prosecutors should focus first on strong identification evidence, financial tracing and preservation of digital records.

14. International Cybercrime and Turkish Victims

Turkish victims of international cybercrime may include individuals, companies, banks, hospitals, e-commerce businesses, public institutions and professional service firms. Victims often feel helpless when the suspect appears to be abroad, but a Turkish criminal complaint can still be valuable.

A well-prepared complaint may lead to:

Collection of Turkish bank records.

Identification of Turkish mule accounts.

Preservation of local IP and telecom records.

Requests to foreign platforms.

Mutual legal assistance requests.

Freezing or seizure measures where legal conditions exist.

Digital forensic examination of victim devices.

Identification of local accomplices.

Content removal or access blocking.

KVKK breach assessment.

The complaint should not be limited to foreign suspects. Many international scams use local bank accounts, local SIM cards, local payment channels, local money mules or Turkish-language phishing pages. These local links may provide the most realistic route for investigation.

15. Corporate Cross-Border Cybercrime

Companies in Turkey face special risks in international cybercrime cases. A ransomware group may operate abroad, but the affected company must handle Turkish legal obligations immediately. A cloud provider may be foreign, but the data controller may be a Turkish company. A phishing e-mail may come from a foreign domain, but employee credentials may expose Turkish customer data.

Corporate response should include:

Incident containment.

Preservation of logs and evidence.

Legal assessment under Turkish criminal law.

KVKK data breach assessment.

Cybersecurity Law assessment where relevant.

Notification to insurers.

Review of foreign cloud or vendor contracts.

Preservation requests to foreign service providers.

Criminal complaint in Turkey.

International evidence request strategy.

The entry into force of Cybersecurity Law No. 7545 on 19 March 2025 is important because it creates a broader framework for cyber resilience, cyber incident governance and obligations for persons and entities operating in cyberspace. The law applies broadly to public institutions, professional organizations, individuals, legal entities and entities without legal personality operating or providing services in cyberspace.

16. Personal Data and Cross-Border Cyber Incidents

International cybercrime often involves personal data. If a Turkish company’s customer data is accessed through a foreign attack, the company may have obligations under the Personal Data Protection Law No. 6698. The Personal Data Protection Board’s Decision No. 2019/10 interprets the “shortest time” for breach notification as no later than 72 hours after the data controller becomes aware of the breach, and affected data subjects should be informed within the shortest reasonable period after identification.

This creates a difficult practical situation. A company may not know all details within 72 hours, especially in a cross-border incident. However, the Board’s decision allows information to be provided gradually without delay where all information cannot be provided at once.

Therefore, companies should not wait for perfect certainty. They should document what is known, what remains under investigation, what measures were taken, whether data was accessed or exfiltrated, which data categories are affected and whether notification is required.

17. Law No. 5651 and Cross-Border Online Content

International cybercrime may involve websites, fake pages, social media posts, phishing domains, illegal betting pages or leaked data hosted abroad. Law No. 5651 may become relevant for access blocking, content removal, provider records and traffic data.

Even if the content is hosted outside Turkey, access blocking in Turkey may be possible under the applicable legal route. For example, phishing pages, privacy-violating content, illegal betting content or catalogue crime content may require urgent action depending on the facts.

However, access blocking does not remove the content from the foreign server. Therefore, a complete strategy may require both Turkish access measures and foreign platform or hosting provider action.

18. Defence Strategies in International Cybercrime Cases

International cybercrime defence requires careful technical and procedural analysis. A suspect may be accused based on an IP address, bank account, phone number, device, platform username, cryptocurrency wallet or foreign record. None of these automatically proves guilt.

Common defence arguments include:

The IP address does not identify the accused personally.

The account was shared or compromised.

The device was infected or remotely controlled.

The bank account was used by another person.

The accused was deceived as a money mule.

Foreign platform records are incomplete.

Time zone conversion is wrong.

The foreign evidence lacks proper authentication.

The mutual legal assistance request exceeded its scope.

The evidence was collected unlawfully.

The alleged act occurred outside Turkish jurisdiction.

The accused had authorization.

There is no criminal intent.

The legal classification is excessive.

In cross-border cases, defence counsel should request the full chain of evidence. It is not enough to receive a summary saying that a foreign platform identified an IP address. The defence should examine the underlying records, timestamps, account identifiers, request scope and translation.

19. Victim Strategy in International Cybercrime Cases

Victims should act quickly and organize evidence before filing a complaint. The petition should be structured to help the prosecutor understand the cross-border chain.

A strong complaint should include:

A chronological summary.

Victim identity and Turkish connection.

Description of the cyber incident.

All known foreign and domestic elements.

URLs, domains, e-mails and account names.

Bank accounts, IBANs and transaction records.

Cryptocurrency wallet addresses and transaction hashes.

Screenshots and original messages.

E-mail headers.

IP or login alerts.

Platform notifications.

Suspected persons or accounts.

Explanation of damage in Turkey.

Request for preservation of Turkish records.

Request for international cooperation.

Request for digital forensic examination.

Legal qualification under Turkish law.

The complaint should also explain urgency. Logs may be deleted, domains may disappear, cryptocurrency may be moved, bank accounts may be emptied and social media accounts may change identifiers.

20. Practical Checklist for Cross-Border Evidence

A lawyer handling an international cybercrime file in Turkey should ask:

Where is the victim located?

Where did the damage occur?

Where is the suspect located?

Where are the servers located?

Which platform holds the key records?

Is subscriber, traffic or content data needed?

Is urgent preservation required?

Is mutual legal assistance required?

Is a Budapest Convention channel relevant?

Are Turkish bank accounts involved?

Are local accomplices or money mules involved?

Is cryptocurrency involved?

Are time zones clearly converted?

Is CMK Article 134 relevant?

Is KVKK notification required?

Is Law No. 5651 access blocking relevant?

Is extradition realistic?

Is the evidence admissible and authenticated?

Has chain of custody been preserved?

This checklist helps avoid a common mistake: focusing only on the foreign hacker while ignoring the local evidence that may be easier to obtain.

21. Practical Checklist for Companies

Turkish companies facing cross-border cybercrime should immediately:

Preserve server, firewall, VPN and cloud logs.

Identify affected systems.

Retain forensic experts where necessary.

Preserve phishing e-mails with headers.

Identify foreign service providers.

Send preservation requests where possible.

Assess personal data impact.

Review KVKK notification deadlines.

Notify cyber insurer if applicable.

Review cloud and vendor contracts.

Prepare a Turkish criminal complaint.

Document all response steps.

Identify local financial channels.

Monitor leaked data or fake domains.

Review Cybersecurity Law obligations.

Companies should avoid uncontrolled technical changes before evidence is preserved. Business recovery is important, but evidence destruction may weaken the criminal case and regulatory defence.

22. Why Legal Assistance Is Important

International cybercrime cases are legally and technically demanding. A victim may need a Turkish criminal complaint, foreign evidence request, bank action, cryptocurrency tracing, KVKK notification, content removal and civil compensation strategy at the same time. A suspect may need defence against complex foreign records, extradition risks, unlawful evidence and incorrect jurisdictional assumptions.

A Turkish cybercrime lawyer can assist with:

Jurisdiction analysis.

Criminal complaint drafting.

Mutual legal assistance strategy.

Digital evidence preservation.

Coordination with forensic experts.

KVKK breach notification assessment.

Law No. 5651 content removal or access blocking.

Banking and cryptocurrency evidence.

Defence against cybercrime allegations.

Extradition and international cooperation issues.

The most effective strategy is interdisciplinary. Criminal law, digital forensics, international cooperation, data protection, cybersecurity governance and civil liability must be evaluated together.

Conclusion

International cybercrime cases in Turkey require careful handling of jurisdiction, cross-border evidence and international cooperation. Turkey’s cybercrime framework includes the Turkish Penal Code, Criminal Procedure Code, Law No. 5651, Law No. 6706, KVKK, Cybersecurity Law No. 7545 and the Budapest Convention cooperation structure. The Ministry of Justice acts as the central authority for mutual legal assistance, while the prosecution service directs investigations with technical support from police authorities. Turkey also has a 24/7 Budapest Convention contact point based in the National Cybercrime Department.

For victims, speed is essential. Digital logs may disappear, cryptocurrency may move, domains may change and foreign platforms may require formal procedures. For companies, cross-border cyber incidents may also trigger KVKK breach notification, cybersecurity governance duties and contractual obligations. For suspects and defendants, the defence must challenge jurisdiction, attribution, intent, admissibility, time zone accuracy, chain of custody and the reliability of foreign-held evidence.

Cybercrime is borderless, but criminal procedure is not. Effective legal action in Turkey depends on connecting the international facts to Turkish jurisdiction, preserving local evidence, using the correct cooperation channels and presenting the case with technical precision. In cross-border cybercrime, the strongest legal strategy is fast, evidence-focused and internationally coordinated.

Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button