On January 19, 2026, four consecutive transactions were made through iyzico/Godaddy.com.tr on my personal İş Bank credit card without my knowledge or consent. The charges were $4 at 1:39 p.m., $1 at 1:44 p.m., $46 at 1:58 p.m., and $36 at 2:15 p.m., meaning funds were withdrawn from my account without my authorization.
Even though my credit card security settings are enabled and I normally receive both a mobile notification and an SMS verification code for every transaction, I did not receive any approval SMS during these transactions. Although these charges do not belong to me, I cannot understand how they were processed without a password, and I consider this a serious security breach. I have no membership, purchase history, or connection with these websites.
As soon as I noticed the transactions, I called İş Bank customer service and immediately blocked my card. However, only the card cancellation was processed; I was not informed about placing a block on the transactions, receiving a provisional refund, completing a charge dispute form, or receiving any refund guarantee. This situation has caused me hardship in terms of both the bank’s and iyzico’s security and notification processes.
I do not accept any responsibility for these transactions made without my knowledge or consent. I believe my credit card information may have been misused by malicious third parties through iyzico. I request that iyzico and İş Bank fully carry out all necessary security and investigation procedures, cancel these transactions, and issue a full refund of all amounts charged to me.
Comments