Detection of Cybercrime Proceeds in Banking Money Transfers: A Comparative Analysis from the Perspective of Turkish, EU and U.S. Law
Keywords:
Cybercrime Proceeds, Banking Money Tranfers, Turkish Law, EU Law, U.S. LawAbstract
This article examines the detection of cybercrime proceeds in banking money transfers from a comparative legal perspective, focusing on Turkish,European Union and United States law. It argues that cybercrime proceeds no longer move through simple linear banking channels but are increasingly routed through crypto-asset anonymisation services, OTC intermediaries,money mule networks and multi-layered transfer chains. In this context,traditional rule-based compliance systems are insufficient, making anomaly detection, risk scoring and machine-learning-based monitoring an expected institutional capacity for banks. The article first explains the structural link between cybercrime proceeds and banking transfers through ransomware,business email compromise and SWIFT manipulation cases. It then analyses the technical and legal status of statistical detection tools, including clustering, network analysis, ARIMA, Isolation Forest, Random Forest,XGBoost and LightGBM. The central legal question is whether algorithmic outputs should be treated as evidence, presumptions, risk indicators or mere grounds for initiating investigations. The article compares Turkish centralised administrative compliance, the EU’s multilayered rights-sensitive regulatory model and the U.S. risk-based and innovation-oriented approach.It further evaluates the implications of algorithmic detection for legality,equality of arms, the right of defence, explainability, the presumption of innocence and property rights. The article concludes that the most defensible
model is a hybrid framework combining Turkish institutional clarity, EU transparency and human oversight safeguards, and U.S. model risk management. Algorithmic detection should therefore be accountable,auditable, contestable, human-reviewed and compatible with cross-border cooperation within modern digital criminal procedure and financial regulatory governance systems today.
References
Anti-Money Laundering Act of 2020. (2021). 134, 116-283.
Arrieta AB and others, ‘Explainable Artificial Intelligence (XAI): Concepts, Taxonomies,
Opportunities and Challenges toward Responsible AI’ (2020) 58 Information Fusion 82.
Box GEP and Jenkins GM, Time Series Analysis: Forecasting and Control . (2015). Wiley.
(2021). c. United States Department of Justice.
Chainalysis. (2024). The 2024 Crypto Crime Report.
Clarifying Lawful Overseas Use of Data Act. (2018). (132), 115-141.
Correa Bahnsen A, A. D. (2016). Feature Engineering Strategies for Credit Card Fraud Detection. (51), 134.
Council of Europe. (2001, November 23). Convention on Cybercrime. (European Treaty Series, 185.
Council of Europe. (2022). Explanatory Report to the Second Additional Protocol to the Convention on Cybercrime on Enhanced Co-operation and Disclosure of Electronic Evidence.
(2018). Criminal Complaint: United States of America v Park Jin Hyok No 18-MJ-1479. United States Department of Justice.
Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. (2021, July 4). Kaseya VSA Supply-Chain Ransomware Attack.
Daubert v Merrell Dow Pharmaceuticals Inc 509 US 579. (1993).
Dal Pozzolo A and others, ‘Learned Lessons in Credit Card Fraud Detection from a Practitioner Perspective’ (2014) 41(10) Expert Systems with Applications 4915.
Türkiye Cumhuriyet Merkez Bankası, Dijital Türk Lirası Birinci Faz Değerlendirme Raporu (2023).
Europol. (2020). Retrieved from Money Muling: European Money Mule Action Awareness Report.
Europol. (2023). Retrieved from Internet Organised Crime Threat Assessment (IOCTA).
Gazette, O. (2005). Retrieved from Bankacılık Kanunu,Kanun No 5411.
Gazette, O. (2020). Retrieved from Bankacılık Düzenleme ve Denetleme Kurumu, Bankaların Bilgi Sistemleri ve Elektronik Bankacılık Hizmetleri Hakkında Yönetmelik.
H, C. N. (2023). Ceza Muhakemesi Hukuku . Beta Yayınları.
J, D. (2018). Microsoft Ireland, the CLOUD Act, and International Lawmaking 2.0. Stanford Law Review Online 9, 71.
Kaspersky Lab. (2017). Lazarus under the Hood .
Liu FT, T. K. (2008). Isolation Forest’ in Eighth IEEE International Conference on Data Mining. (p. 413). IEEE.
M, D. J. (2006). The Relationship between Precision-Recall and ROC Curves’ in Proceedings of the 23rd International Conference on Machine Learning . ACM , 233.
Mali Suçları Araştırma Kurulu. (2014). Suç Gelirlerinin Aklanmasının ve Terörün Finansmanının Önlenmesine Dair Tedbirler Hakkında Yönetmelik Uygulanmasına İlişkin MASAK Genel Tebliği Sıra No 13. Retrieved from Official Gazette.
Network, F. C. (2020). Retrieved from Section 314(b) .
Network, F. C. (2024). Retrieved from Bank Secrecy Act/Anti-Money Laundering Examination Manual .
Network, F. C. (223, September 8). Retrieved from Alert on Prevalent Virtual Currency Investment Scam Commonly Known as “Pig Butchering.
Ke G and others, ‘LightGBM: A Highly Efficient Gradient Boosting Decision Tree’ (2017) 30
Advances in Neural Information Processing Systems 3146.
Öztürk B and others, Ceza Muhakemesi Hukuku: Nazari ve Uygulamalı (18th edn, Seçkin
Yayıncılık 2024).
Öztürk B and others, Dijital Ceza Muhakemesi Hukuku (3rd edn, Seçkin Yayıncılık 2024).
(2006). Suç Gelirlerinin Aklanmasının Önlenmesi Hakkında Kanun, Kanun No 5549. Official Gazette.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Cüneyt Şamil Oğurlu

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.