Phishing is a method by which a person's bank account, credit card, or identity information is obtained through a fraudulent SMS message, email, or website impersonating a bank, courier company, or official institution. Withdrawing funds from, or making purchases with, the victim's account using information obtained in this manner is assessed under the Turkish Penal Code.
Fraud committed through the use of information systems, banks, or credit institutions as a tool constitutes aggravated fraud under Article 158/1-f of the Turkish Penal Code and carries a more severe penalty than simple fraud. Acts such as creating a fake banking website, sending fraudulent links via SMS, and carrying out transactions with information obtained in this way fall within this scope.
It is important for the victim to first notify the relevant bank of the situation and have their card/account blocked, then file a complaint with the nearest police station or the Chief Public Prosecutor's Office, and preserve any SMS/email content and screenshots as evidence. Bank records and digital evidence play a decisive role during the investigation process.
In phishing cases, it may also be necessary to pursue legal remedies against the bank in order to obtain compensation for the loss; this depends on the circumstances of the specific case. It is advisable to conduct the process with the assistance of an attorney, both with respect to the criminal complaint and any potential compensation claim.