Jump to

Phishing

What is phishing?

Phishing is a social engineering attack in which a message impersonates a trusted party — a bank, a supplier, a colleague — to trick the recipient into revealing credentials, transferring money, or opening malicious content. The vulnerability being exploited is not a server but a person, which is why technical defences alone never close it. For companies, a successful phishing email is the most common first step towards a data breach or a ransomware incident.

Common variants

  • Bulk phishing. Mass emails imitating banks, cargo firms or tax authorities, harvesting whoever clicks.
  • Spear phishing. A tailored message aimed at a specific person, built from public and leaked information about them.
  • Business email compromise (BEC). The attacker impersonates or hijacks an executive’s or supplier’s mailbox and redirects payments with a convincing invoice or IBAN change.
  • Smishing and vishing. The same play over SMS and voice calls, often quoting real order or account details.

The legal dimension

When phishing yields personal data, the incident becomes a regulatory matter. Article 12 of the KVKK obliges the data controller to take appropriate security measures, and Turkish Board practice requires breaches to be notified without delay and at the latest within 72 hours of learning of them; the GDPR’s Articles 32 and 33 impose the same measures-plus-72-hours pattern. The recurring enforcement question is not whether the attacker was clever but whether the controller’s defences were reasonable: was multi-factor authentication in place, were staff trained, was the mailbox monitored?

Turkish context

The Turkish Board’s decisions on compromised accounts keep returning to authentication expectations — our review of the authentication and e-mail access decisions shows fines turning on missing two-step verification and weak internal access rules rather than on the attack itself. Payment redirection through BEC also raises private-law disputes over who bears the loss between defrauded contract parties, an issue Turkish courts resolve on the facts of each transfer.

Do: enforce multi-factor authentication, verify every bank detail change by a second channel, and rehearse the 72-hour notification workflow. Don’t: treat phishing as an IT-only problem or delay notification while the investigation continues — the clock runs from awareness, not from full clarity.

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call