CyberCode.ph · Philippines

Computer-Related Identity Theft Philippines: What Victims Should Do

Last updated September 4, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 3, 2026

Direct Answer

Computer-related identity theft is a specific cybercrime under Republic Act No. 10175. It covers the intentional acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another person or organization, without right. Victims should secure affected accounts, preserve evidence, document financial or reputational harm, and report the incident to the NBI, PNP Anti-Cybercrime Group or other appropriate cybercrime authority.

Primary authority: RA 10175, Section 4(b)(3) — Computer-Related Identity Theft.

Key Takeaways

  • Identity theft is expressly defined as a cybercrime under RA 10175.
  • The law covers identifying information belonging to a natural or juridical person.
  • Actual financial loss is not always required before the offense can exist, although the penalty may differ where no damage has yet been caused.
  • Victims should preserve account, transaction and impersonation evidence before deleting anything.
  • Compromised passwords, email accounts and financial accounts should be secured immediately.
  • A complaint is stronger when it shows both the unauthorized use and the identity information involved.

Decision Snapshot

Incident Immediate response
Fake account using your name/photos Capture the profile, URL, username, messages and platform report.
Account takeover Recover the account, change credentials and preserve login/security notices.
Fraud using your identity Contact the bank/platform, dispute transactions and preserve records.
SIM or email used to reset accounts Contact the provider immediately and document the compromise.

What Does RA 10175 Define as Identity Theft?

Section 4(b)(3) defines computer-related identity theft as the intentional acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another, whether natural or juridical, without right. See the statutory definition.

What Evidence Should You Preserve?

  • screenshots of fake profiles or messages;
  • profile URLs, usernames and account IDs;
  • password-reset and login alerts;
  • emails or SMS showing unauthorized changes;
  • bank, card or e-wallet records;
  • copies of identification misused by the offender;
  • platform complaint or takedown reference numbers; and
  • a timeline showing when the misuse started and what harm followed.

What Should You Do First?

  1. Secure the email account connected to other accounts.
  2. Change passwords and enable MFA.
  3. Revoke unknown sessions and devices.
  4. Call financial institutions if money or credit is involved.
  5. Preserve the evidence before removing or blocking the offender.
  6. Report the incident to the relevant platform and cybercrime authority.

For where to file, use Where and How to Report Cybercrime in the Philippines.

Can Identity Theft Involve a Company?

Yes. The statutory wording covers identifying information belonging to either a natural person or a juridical person, so business identities and corporate information can also be implicated.

What If No Money Was Lost?

RA 10175 expressly provides that if no damage has yet been caused, the penalty imposable for computer-related identity theft is one degree lower. The absence of financial loss does not automatically make the conduct lawful. See Section 4(b)(3).

Frequently Asked Questions

Is a fake Facebook account automatically identity theft?

Not every fake account automatically satisfies every element of the offense. The facts must show unauthorized acquisition or use of identifying information within the statutory definition.

Should I report the fake account to the platform first?

Yes, but preserve evidence before the account is removed. Platform reporting and law-enforcement reporting serve different purposes.

Can stolen identity information be personal data under the Data Privacy Act too?

Yes, depending on the information and circumstances. Cybercrime and privacy issues can overlap.

What if the offender is overseas?

Cross-border cases can be more complex, but RA 10175 and the DOJ Office of Cybercrime provide mechanisms for international cooperation.

Related Cybercrime Guides

Related Cybercode Guides

Official Sources

General educational information only.