E-mail Fraud

Emails, a common medium for daily communication, are susceptible to interception by malicious actors through various methods. Cyber attackers may gather information through social engineering or access your data through other means to send harmful emails designed to obtain credentials and financial information, as well as to introduce malware to your devices. To safeguard against email fraud, it is strongly advised that you adhere to, at a minimum, the following measures:

In this context;

  • Exercise utmost caution with respect to suspicious, unexpected, or unsolicited emails from unknown sources, and refrain from opening such emails whenever possible.
  • Never open links or attachments included in emails if their source is untrusted or deemed suspicious.
  • Avoid accessing your email account on untrusted or shared devices. If it becomes necessary to log in on an untrusted device, ensure that you do not save your password, and that you securely terminate the session by selecting the secure sign-out option.
  • Regularly update the password associated with your email account, and avoid reusing the same password across different platforms.

     

We strongly urge you to refrain from responding to fraudulent emails that impersonate the Development and Investment Bank of Türkiye under any circumstances, and to avoid accessing the official web properties of the Development and Investment Bank of Türkiye by clicking on unofficial links that may be included in such communications.

 

Malware Fraud

Numerous malicious applications found in official mobile app stores (such as the Google Play Store, Apple Store, and Windows Store) installed on your smart mobile device are specifically designed to function as conduits, redirecting users to download actual malware rather than containing the payload directly.

Malicious applications available for download from app stores are frequently in Turkish and imitate financial categories or religious themes, using names such as Number Inquiry, Currency Exchange/Conversion, Revenue Administration, Land Registry Inquiry, Vehicle Buying/Selling, Accounting/Bookkeeping, Digital Wallets, Toll Collection (HGS/OGS) inquiry/recharge, and transit pass (Akbil) inquiry.

Malicious software is frequently propagated via malicious SMS messages and emails.

In this context;

  • Alternative or unofficial app stores and unknown sources typically lack adequate security measures and verification controls. Therefore, always use only official app stores to download mobile applications. Strictly refrain from downloading mobile applications from any sources other than these official platforms. 
  • Do not click on embedded links in messages received via SMS, WhatsApp, email, or similar channels, particularly if they originate from unknown sources or appear suspicious, even if received from acquaintances.
  • Never store personal data, passwords, or other sensitive information in plain text on your computer or smart mobile devices. Your identity is an invaluable and personal asset; thus, do not store scanned images of personal identity documents—such as national ID cards, driver's licenses, or passports—on your computer.
  • Ensure that all personal or professional smart mobile devices, desktop computers, and laptops used for banking operations are equipped with up-to-date antivirus software, installed and active.