Direct answer: Ransomware, phishing and a hacked account are three different incidents with three different first moves — isolate the affected systems, rotate the exposed credentials, or regain control of the account — and three different offence mappings under Republic Act No. 10175. What they share is the clock. If personal data was exposed, notification to the National Privacy Commission runs for 72 hours from knowledge or reasonable belief, and a BSP-supervised institution has two hours.
Key Takeaways
- The first action is the main thing that differs. Ransomware is contained by isolating. Phishing is contained by rotating credentials. A hacked account is contained by recovering it and ending every other session.
- No Philippine statute uses the word phishing, but the conduct is squarely penalised. Where it gives access to a bank or e-wallet account, it is a social engineering scheme under Section 4(b) of RA 12010, the Anti-Financial Account Scamming Act. Otherwise it is reached through computer-related forgery, computer-related fraud, computer-related identity theft, and estafa carrying a penalty one degree higher under Section 6 of RA 10175.
- Ransomware sits inside two offences whose enrolled text expressly covers the introduction or transmission of viruses — data interference and system interference.
- The 72-hour clock is not triggered by the attack. It is triggered by a three-part test about personal data, and any of the three scenarios can pass or fail it.
- A BSP-supervised institution answers to a two-hour clock that has nothing to do with privacy law, for all three scenarios.
- Evidence decays on a statutory timer. Section 13 of RA 10175 sets six months for traffic data and subscriber information, running from the transaction — not from the day you decide to report.
- This page compares the law, not other people’s guides. Every row below is built from a statute, an implementing rule or a regulator issuance, with the Cybercode guide that goes deeper named alongside it.
Jump to a Section
- Decision snapshot
- The master comparison table
- Why the response differs at all
- Ransomware: what changes
- Phishing: what changes
- Hacked accounts: what changes
- What is identical in all three
- The clocks, side by side
- Is it a personal data breach?
- Evidence to preserve, by scenario
- Where to report, by scenario
- What not to do
- Six worked scenarios
- Common mistakes
- FAQs
- Verification log
- Official sources
Decision Snapshot
| Question | Practical answer |
|---|---|
| Is there one incident-response procedure that covers all three? | No. The containment step differs. The reporting and evidence steps largely do not. |
| Does Philippine law define a separate offence called phishing? | Not by that name. RA 10175 contains no offence named phishing, but RA 12010 Sec. 4(b) penalises a social engineering scheme: obtaining another person’s sensitive identifying information by deception, resulting in unauthorised access to and control of a financial account. |
| Does it define one called ransomware? | No. Ransomware is charged through data interference, system interference and illegal access. |
| Does every cyberattack start a 72-hour National Privacy Commission clock? | No. Only a personal data breach meeting the three-part test in NPC Circular 16-03 does. |
| Does a hacked personal account create an NPC duty for the individual? | Generally no. The duty falls on personal information controllers and processors, not on a private individual whose own account was taken over. |
| Is there a shorter clock than 72 hours anywhere? | Yes. Two hours, for BSP-supervised institutions, under Section 148 of the Manual of Regulations for Banks. |
| Do you report all three to the same agency? | Broadly yes — the NBI Cybercrime Division or the PNP Anti-Cybercrime Group. The privacy regulator is a separate, parallel report. |
| Does the CICC take complaints? | It takes reports, not criminal complaints. The CICC and DICT run the Inter-Agency Response Center hotline 1326 for scam and phishing reports, with PNP and NBI support. RA 10175 gives the CICC no investigative or prosecution power, so a sworn complaint still goes to the NBI or PNP-ACG. |
| Should you wipe and rebuild immediately? | Not before preserving evidence. A rebuild destroys the material an investigation needs. |
| Is paying a ransomware demand a separate legal question? | Yes, and it is dealt with in its own guide rather than here. |
The Master Comparison Table
Eight incidents, read across. The first column is what happened, the last is the Cybercode guide that goes deeper. Everything between is drawn from the statute, the implementing rules or the regulator issuance named in the verification log.
| Incident | First action, before anything else | Primary RA 10175 offence | Does a 72-hour NPC clock start? | Where to report first |
|---|---|---|---|---|
| Ransomware | Isolate affected machines from the network. Do not power them down. | Sec. 4(a)(3) data interference and Sec. 4(a)(4) system interference; Sec. 4(a)(1) illegal access for the entry point | Only if personal data was accessed, exfiltrated or rendered unavailable in a way that meets the three-part test | NBI Cybercrime Division or PNP Anti-Cybercrime Group. NPC in parallel if the test is met |
| Phishing that harvested credentials | Rotate the exposed password everywhere it was reused, then end all active sessions. | Sec. 4(b)(1) computer-related forgery for the fake page; Sec. 4(b)(3) identity theft for the credentials taken | Only if the credentials unlocked personal data of others | NBI or PNP-ACG. The impersonated brand should also be told |
| Phishing that moved money (business email compromise) | Call the bank and request recall of the transfer, then preserve the full email headers. | Sec. 4(b)(2) computer-related fraud; estafa under Art. 315 of the Revised Penal Code, one degree higher via Sec. 6 | Only if personal data was also exposed; a pure funds-transfer loss is not automatically a personal data breach | The bank first, because recall is time-critical. Then NBI or PNP-ACG |
| Hacked personal social account | Use the platform recovery flow, then remove unknown logged-in devices and reset the linked email. | Sec. 4(a)(1) illegal access; Sec. 4(b)(3) identity theft if the account is used to impersonate | Generally no. The duty sits on personal information controllers, not on a private individual whose own account was taken | The platform, then NBI or PNP-ACG |
| Hacked company account or admin takeover | Revoke the session and the API tokens, not just the password. Then audit what the account could reach. | Sec. 4(a)(1) illegal access; Sec. 4(a)(3) or 4(a)(4) if data or systems were altered | Very often yes, because a company account usually reaches customer or employee data | NPC assessment immediately, in parallel with NBI or PNP-ACG |
| Website defaced or compromised | Take the site to maintenance mode and preserve the server logs before restoring. | Sec. 4(a)(3) data interference; Sec. 4(a)(4) system interference | Only if the site held personal data — a form database, an order table, an account system | The host first, to stop the bleeding. Then NBI or PNP-ACG |
| Malware without a ransom demand | Isolate, then determine whether it was an information stealer before assuming it was noise. | Sec. 4(a)(3) data interference; Sec. 4(a)(5) misuse of devices as against whoever supplied the tool | Only if personal data was exfiltrated or corrupted | NBI or PNP-ACG |
| SIM swap into an account takeover | Contact the mobile network to reclaim the number, because every one-time password follows the SIM. | Sec. 4(b)(3) identity theft; Sec. 4(b)(2) fraud where funds moved | Only if personal data of others was reached | The network operator and the bank first. Then NBI or PNP-ACG |
Which Cybercode guide answers which question
This is a routing table for our own material. It lists no other publisher.
| If you want | Read |
|---|---|
| First steps for an individual who has just been hacked | Hacked in the Philippines: first 15 minutes and recovery |
| The generic first-hour sequence for a business | What to do after a business cyberattack |
| A written plan to have in place before an incident | Building a cybersecurity incident response plan |
| A tick-box list to work through during one | The cyber incident response checklist |
| The ransomware sequence in detail | Ransomware attack: what to do immediately |
| Whether to pay, and what reporting follows | Ransomware payment and reporting |
| What to do after clicking a phishing link | Clicked a phishing link: next steps |
| The payment-fraud variant | Business email compromise |
| An account you no longer control | Unauthorised account access |
| A social account specifically | Hacked Facebook account |
| A compromised website | Website hacked: recovery |
| Malware without extortion | Malware attacks in the Philippines |
| Whether you have actually been compromised | How to tell if your phone or account is hacked |
| The breach-reporting procedure end to end | Data breach Philippines: how to report one |
| A number that was ported away from you | SIM swap fraud and liability |
Why the Response Differs at All
Three variables decide almost everything about how a Philippine incident is handled. Once you know where an incident sits on each of them, the rest of the response follows.
| Variable | What it decides | How it differs across the three |
|---|---|---|
| Is the attacker still inside? | Whether containment means isolation, credential rotation or account recovery | Ransomware: usually yes, and the encryption is the last stage of a longer intrusion. Phishing: often no — the credential has been taken and used elsewhere. Hacked account: yes, and they hold the keys |
| Was personal data reached? | Whether a 72-hour National Privacy Commission clock starts at all | Ransomware and company-account takeovers usually reach it. A hacked personal account of an individual usually does not create a duty for that individual |
| Is the organisation BSP-supervised? | Whether a two-hour clock applies on top of everything else | Identical across all three. The clock attaches to the institution, not to the attack type |
That last row is the one most commonly missed. A bank, an e-money issuer or another institution supervised by the Bangko Sentral ng Pilipinas is working to a two-hour reporting window for a major cyber-related incident, whatever the attack was called. For everyone else, that clock does not exist. Our cybersecurity duties overview sets out which obligations attach to which kind of organisation.
Ransomware: What Changes
The short version: ransomware is the scenario where the wrong first move causes the most permanent damage, because powering a machine down can destroy volatile evidence and, in some cases, the only copy of a decryption key held in memory. Isolate from the network; do not shut down.
Which offences it maps to
RA 10175 contains no offence called ransomware. Two provisions do the work, and both were written broadly enough to cover it expressly.
Section 4(a)(3), Data Interference, covers “the intentional or reckless alteration, damaging, deletion or deterioration of computer data, electronic document, or electronic data message, without right, including the introduction or transmission of viruses.” Encryption that renders a company’s own files unusable is deterioration of computer data without right, and the closing clause about the introduction or transmission of viruses puts the delivery of the payload inside the same subsection.
Section 4(a)(4), System Interference, covers “the intentional alteration or reckless hindering or interference with the functioning of a computer or computer network” by, among other things, “inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing computer data or program,” again “including the introduction or transmission of viruses.” Where the ransomware stopped operations rather than merely locking files, this is the closer fit.
Section 4(a)(1), Illegal Access — “the access to the whole or any part of a computer system without right” — covers how the attacker got in, which is usually a separate act from the encryption itself.
Section 4(a)(5), Misuse of Devices, reaches the supply side: making available, without right, a device or computer program “designed or adapted primarily for the purpose of committing any of the offenses under this Act.” Its second limb matters for anyone who finds tooling on a compromised machine, because it criminalises “the possession of an item referred to in paragraphs 5(i)(aa) or (bb) above with intent to use said devices” for those offences. Possession with intent is enough.
What is distinctive in the response
- Do not power off. Disconnect the network cable or disable the wireless adapter instead. Memory contents can matter to both forensics and recovery.
- Check the backups before you negotiate anything. Whether a clean restore exists changes every subsequent decision. Our backup and recovery guide covers what a restorable backup actually requires.
- Assume exfiltration until you can rule it out. Double-extortion is now routine, and if data left the building the privacy analysis changes even though the files are back.
- The payment question is separate. Whether to pay, and what reporting follows a payment, is dealt with in ransomware payment and reporting, not here.
Phishing: What Changes
The short version: phishing is the scenario where the incident you can see is rarely the incident that matters. The click is not the damage. The damage is whatever the harvested credential unlocked, and that is usually somewhere else entirely.
Which offences it maps to — and the gap
No provision of RA 10175 is named phishing. This is a real gap in the vocabulary of the statute, and it is worth stating plainly because it is the single most common misconception about Philippine cybercrime law. The conduct is reached, but it is reached obliquely, through four different routes depending on what the attacker actually did.
| What the attacker did | Provision | Why it fits |
|---|---|---|
| Built a fake login page or spoofed a real one | Sec. 4(b)(1), computer-related forgery | “The input, alteration, or deletion of any computer data without right resulting in inauthentic data,” done “with the intent that it be considered or acted upon for legal purposes as if it were authentic” |
| Used the harvested data to deceive | Sec. 4(b)(1), second limb | “The act of knowingly using computer data which is the product of computer-related forgery” and doing so “for the purpose of perpetuating a fraudulent or dishonest design” |
| Moved money or caused loss | Sec. 4(b)(2), computer-related fraud | “The unauthorized input, alteration, or deletion of computer data or program or interference in the functioning of a computer system, causing damage thereby with fraudulent intent” |
| Took or used someone’s identifying information | Sec. 4(b)(3), computer-related identity theft | “The intentional acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another, whether natural or juridical, without right” |
| Used deception or electronic messages to get someone’s banking or e-wallet credentials and took control of the account | RA 12010 Sec. 4(b), social engineering scheme | Committed by a person who “obtains sensitive identifying information of another person, through deception or fraud, resulting in unauthorized access and control over the person’s Financial Account,” including by misrepresenting oneself as acting for an institution or “using electronic communications to obtain another person’s sensitive identifying information” |
| Committed estafa by means of the deception | Revised Penal Code Art. 315, with RA 10175 Sec. 6 | Where a Revised Penal Code offence is committed through information and communications technology, Sec. 6 provides that “the penalty to be imposed shall be one (1) degree higher than that provided for” |
Sec. 6 is the provision that does the heavy lifting in most phishing prosecutions, and it is why our online estafa guide works through the Art. 315 penalty scale rather than stopping at RA 10175. The identity-theft limb is covered separately in computer-related identity theft, and the fraud limb in computer-related fraud.
What is distinctive in the response
- Rotate before you investigate. Unlike ransomware, there is no evidence cost to changing a password immediately, and every minute of delay is a minute the credential is live.
- Password reuse is the whole problem. Change the credential everywhere it was used, not only on the site that was imitated.
- End the sessions, not just the password. A password change does not always invalidate a session token an attacker already holds.
- Check for a mail forwarding rule. A silent inbox rule is the standard way a mailbox compromise is kept alive after the password changes, and it survives a reset.
- Turn on multi-factor authentication now, not later. See the MFA guide. Where staff are involved, phishing awareness is the durable control.
- An e-wallet is its own route. Where the phishing targeted a wallet, the provider’s own dispute channel runs in parallel — see our GCash scam and phishing reporting guide.
Hacked Accounts: What Changes
The short version: a hacked account is the only one of the three where the attacker holds the controls you would normally use to fix the problem. Recovery is a race, and whether the account is personal or corporate changes the legal consequences completely.
Which offences it maps to
Section 4(a)(1), illegal access, is the core fit: “the access to the whole or any part of a computer system without right.” Note what it does not require. There is no threshold of harm, no requirement that anything was taken, and no requirement that a security measure was defeated. Access without right is the offence.
Where the account is then used to pose as its owner, Section 4(b)(3), computer-related identity theft, applies on top: the acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another, whether natural or juridical, without right. Where the attacker altered or deleted content, Sections 4(a)(3) and 4(a)(4) come into play as well.
The personal-versus-corporate split
This is the single biggest divergence inside the third scenario, and most guidance treats the two as one thing.
| Question | Personal account | Company account |
|---|---|---|
| Is it a crime under RA 10175? | Yes — illegal access | Yes — illegal access |
| Does the account holder owe a National Privacy Commission notification? | Generally no. The duty in the Data Privacy Act attaches to personal information controllers and processors | Frequently yes, because the account usually reaches personal data the organisation holds about others |
| Who must be told? | The platform, and contacts who may be targeted next | The Data Protection Officer immediately, then potentially the NPC and the affected data subjects |
| What is the deadline? | None set by statute | 72 hours to the NPC and 72 hours to affected data subjects once the three-part test is met |
| Who investigates? | NBI Cybercrime Division or PNP Anti-Cybercrime Group | The same, plus an internal assessment the organisation must document |
What is distinctive in the response
- Recover the account before anything else, because every other step depends on control.
- Reset the recovery email and phone number first. Changing only the password leaves the attacker’s recovery path intact, and they will simply reset it back.
- End all other sessions and revoke connected apps and API tokens. For a corporate account this is the step that is most often skipped and most often the reason the compromise returns.
- Warn the contact list. A taken-over account is usually monetised by messaging the people who trust it.
- If a mobile number was the entry point, the network operator is part of the response — see SIM swap fraud and liability.
- If you are not sure you were compromised, start with how to tell if your phone or account is hacked rather than assuming.
What Is Identical in All Three
The comparison above is about divergence. This section is the opposite, and it is the more useful half for anyone writing a procedure: five things do not change at all with the attack type.
- Preserve before you remediate. Screenshots, logs, headers and timestamps first; cleanup second. This holds for every incident.
- The privacy question is asked the same way. The three-part test in NPC Circular 16-03 does not care how the data was reached.
- The reporting route is the same. The National Bureau of Investigation and the PNP Anti-Cybercrime Group are the two law-enforcement bodies given enforcement responsibility by Section 10 of RA 10175.
- The BSP clock is the same. Two hours for a supervised institution, whatever happened.
- The evidence timer is the same. Section 13 of RA 10175 runs from the transaction, not from the incident being noticed.
A useful way to hold this: the containment step is scenario-specific, and almost everything after it is not. That is why a single incident response checklist works across incident types once the first hour is past, and why the incident response plan is written once rather than per attack.
The neutral technical backbone
Where an organisation wants a vendor-neutral structure to hang its procedure on, the National Institute of Standards and Technology Cybersecurity Framework 2.0 divides the work into six Functions, two of which cover this ground. RESPOND (RS) is described as “Actions regarding a detected cybersecurity incident are taken” and breaks into four Categories: Incident Management (RS.MA), Incident Analysis (RS.AN), Incident Response Reporting and Communication (RS.CO) and Incident Mitigation (RS.MI). RECOVER (RC) is “Assets and operations affected by a cybersecurity incident are restored” and breaks into two: Incident Recovery Plan Execution (RC.RP) and Incident Recovery Communication (RC.CO).
RS.CO is the Category that maps onto Philippine law, because NIST describes it as response activities being “coordinated with internal and external stakeholders as required by laws, regulations, or policies.” NIST CSF 2.0 is a voluntary United States framework and is not Philippine law. It is useful as an organising structure; it imposes nothing, and no Philippine regulator requires it.
The Clocks, Side by Side
Five separate clocks can run in a Philippine incident. They come from different instruments, they start at different moments, and only one of them is the well-known 72 hours.
| Clock | Length | Runs from | Source | Who it binds |
|---|---|---|---|---|
| Initial incident report to the Bangko Sentral | 2 hours | Discovery of a reportable major cyber-related incident | Manual of Regulations for Banks, Sec. 148 | BSP-supervised institutions only |
| Follow-up report to the Bangko Sentral | 24 hours | The same discovery | Manual of Regulations for Banks, Sec. 148 | BSP-supervised institutions only |
| Notification to the National Privacy Commission | 72 hours | Knowledge of, or reasonable belief in, a personal data breach | NPC Circular 16-03, Sec. 17(A); IRR Rule IX Sec. 38 | Personal information controllers and processors |
| Notification to affected data subjects | 72 hours | The same moment — these two run in parallel, not in sequence | NPC Circular 16-03, Sec. 18(A) | Personal information controllers and processors |
| Full breach report to the NPC | 5 days | The date of discovery | NPC Circular 16-03, Sec. 17(C); Advisory 2026-02, Sec. 2(C) | Personal information controllers |
| Compliance with a disclosure order | 72 hours | Service of a court-warranted law-enforcement order | RA 10175, Sec. 14 | Any person or service provider served |
The two-hour clock is the one that catches people out. If you are a BSP-supervised institution, treating 72 hours as the Philippine incident deadline is wrong by a factor of thirty-six. If you are not, the two-hour clock does not apply to you at all and you should not build a procedure around it.
Two further points on the 72-hour clocks. First, delay is permitted under Sec. 17(B) only to determine the scope of the breach, prevent further disclosures or restore integrity — and there is no delay at all where the breach involves at least one hundred data subjects or the disclosure of sensitive personal information. Second, a request to the NPC for exemption, postponement or alternative means does not pause anything: Advisory 2026-02 Sec. 2(D) provides that the Commission’s inaction “shall not be construed as an approval, implied consent, or automatic grant.” Silence is not approval. The full procedure is in our data breach reporting guide and the system itself in DBNMS breach notification.
Is It a Personal Data Breach? The Test Applied to Each Scenario
An attack is not automatically a personal data breach, and the distinction decides whether any regulator deadline exists. Section 11 of NPC Circular 16-03 sets three conditions, and all three must be met.
- (A) The breach involves sensitive personal information, or any other information that may be used to enable identity fraud.
- (B) There is reason to believe the information may have been acquired by an unauthorised person.
- (C) The unauthorised acquisition is likely to give rise to a real risk of serious harm to any affected data subject.
Circular 16-03 Sec. 3(F) defines the breach itself as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.” Note that destruction and loss count, not only disclosure — which is why encryption-only ransomware can qualify even where nothing left the network.
| Scenario | Limb (A) — the data | Limb (B) — acquisition | Limb (C) — risk of serious harm | Typical outcome |
|---|---|---|---|---|
| Ransomware, encryption only, backups clean | Often met if customer or employee records were on the encrypted systems | Contestable — encryption is destruction and loss under Sec. 3(F), but acquisition is a separate question | Depends on what was rendered unavailable and for how long | Assess and document; do not assume it is out of scope |
| Ransomware with exfiltration | Met | Met | Usually met | Notifiable |
| Phishing, one staff credential, no further access | Depends on what that credential reached | Met as to the credential itself | Often not met if nothing further was accessed | Frequently not notifiable, but document the assessment |
| Phishing into a mailbox holding client files | Met | Met | Usually met | Notifiable |
| Business email compromise, funds moved, no personal data touched | Often not met | — | — | A crime and a loss, but not automatically a personal data breach |
| Hacked personal social account of an individual | — | — | — | No controller duty arises for the individual |
| Hacked company admin account | Usually met | Met | Usually met | Notifiable |
A word on documenting a negative. Deciding an incident is not notifiable is itself a decision that should be written down, with the reasoning and the date. Section 22 of Circular 16-03 requires that all security incidents and personal data breaches be documented through written reports, and that a summary of all reports be submitted to the Commission annually. An undocumented decision that something was not a breach is indistinguishable, later, from not having looked.
Where a vendor rather than your own systems were breached, responsibility splits differently — see vendor and SaaS data breach responsibility. The underlying statute is covered in our Data Privacy Act guide, and the regulator in our National Privacy Commission page.
Evidence to Preserve, by Scenario
The general rule is identical across all three: do not alter, crop, overwrite or clean up the original material. What differs is which material matters most, and how fast it disappears.
| Evidence | Ransomware | Phishing | Hacked account | Why it matters |
|---|---|---|---|---|
| Full email headers, not a forwarded copy | Where the entry was an email | Critical | Where the entry was an email | Headers carry the routing and originating data a forward strips out |
| The ransom note file itself | Critical | — | — | Identifies the variant and the contact channel |
| A sample encrypted file with its extension | Critical | — | — | Some variants have public decryptors; identification depends on this |
| Login and access logs with timestamps and IP addresses | Yes | Yes | Critical | Establishes when control was lost and from where |
| The phishing page URL, captured before it is taken down | — | Critical | — | Phishing infrastructure has a short life; it is usually gone within days |
| Screenshots of the account as the attacker left it | — | Where relevant | Critical | Platform recovery often wipes the evidence of misuse |
| Mail forwarding and filter rules as found | — | Critical | Yes | The persistence mechanism, and proof of intent |
| Transaction references and recipient account details | Where a ransom was paid | Where funds moved | Where funds moved | The bank cannot act on a recall without them |
| A written incident timeline kept contemporaneously | Yes | Yes | Yes | Establishes the moment of knowledge, which is when every clock starts |
| Device and system images taken before rebuild | Critical | Where a device was compromised | Where a device was compromised | A rebuild is irreversible |
The six-month timer nobody plans around
Section 13 of RA 10175 requires service providers to preserve the integrity of traffic data and subscriber information for six months from the date of the transaction. Content data is preserved for six months from receipt of a law-enforcement order, with a one-time extension of six months.
Read those two sentences together and the practical consequence is uncomfortable. The traffic-data clock is already running from the day of the attack, while the content-data clock does not begin at all until law enforcement issues an order. An organisation that decides to handle an incident quietly for four months, then changes its mind, may find that the records it needs have lawfully ceased to exist. Reporting early is not only a compliance posture; it is evidence preservation.
On what a Philippine court will accept, and in what form, see electronic evidence in the Philippines. We say plainly there and here that the Rules on Electronic Evidence and the Rule on Cybercrime Warrants are Supreme Court issuances that could not be read from a reachable government source for this page, so nothing on this page states their contents.
Where to Report, by Scenario
Section 10 of RA 10175 makes the National Bureau of Investigation and the Philippine National Police responsible for enforcement, and requires each to organise a cybercrime unit staffed by special investigators handling Act violations exclusively. Section 11 requires those units to submit pre-operation, post-operation and investigation reports to the Department of Justice. That allocation is the same for all three scenarios.
| Body | What it does | Relevant to | What we can and cannot publish |
|---|---|---|---|
| NBI Cybercrime Division | Takes complaints and investigates. Its published service entry lists no checklist of requirements, no fee, and a total processing time of 1 hour and 10 minutes, with staff assisting the complainant to complete a sworn complaint sheet | All three | Published procedure confirmed. Note the location discrepancy below |
| PNP Anti-Cybercrime Group | Investigates cybercrime; designated by RA 11313 Sec. 13 to receive gender-based online sexual harassment complaints | All three | No hotline, email or address is published on a government page we could read. We do not print one |
| The bank or e-money issuer | Recall and dispute handling | Phishing with funds moved; any incident with a payment leg | Time-critical — this is the only step where minutes change the outcome |
| The platform or host | Account recovery, takedown, restoration | Hacked accounts and compromised websites | Not a substitute for a law-enforcement report |
| National Privacy Commission | Breach notification through the Data Breach Notification Management System | Any incident meeting the three-part test | Submissions outside the DBNMS are not valid |
| Bangko Sentral ng Pilipinas | Incident reporting by supervised institutions | All three, if you are supervised | Two hours, then 24 hours |
| DOJ Office of Cybercrime | Created by RA 10175 Sec. 23 as central authority for mutual assistance and extradition, and describes itself as the “focal agency in formulating and implementing law enforcement investigation and prosecution strategies” | Prosecution stage | It publishes no contact details and no reporting procedure on the pages we could read |
| CICC | Policy coordination and the national cybersecurity plan; with the DICT, runs the Inter-Agency Response Center hotline 1326 for scam, phishing and account-recovery reports, supported by the PNP and NBI | Phishing and scams, for a fast report and referral | RA 10175 Secs. 24 to 26 give it no investigative, arrest, warrant or prosecution power. A 1326 report is not a sworn criminal complaint; file that with the NBI or PNP-ACG |
An unresolved detail we report rather than settle. The NBI homepage gives a Filinvest Cyberzone Bay, Diosdado Macapagal Boulevard, Pasay City address for the Bureau, while its Citizen’s Charter entry refers to complaints filed outside “NBI Taft headquarters” going to Regional Cybercrime Centers. We report both and assert neither. Confirm the office before travelling.
The full agency-by-agency routing is in where and how to report cybercrime, with contact-level detail in the cybercrime reporting directory and the government cybersecurity agencies directory. What the CICC does and does not do is set out in our CICC guide.
What the prosecutor will need
If the matter proceeds to a complaint for preliminary investigation, the Department of Justice publishes what must be filed: a duly accomplished and certified Investigation Data Form (NPS INV Form No. 1) in two copies; the complaint-affidavit or sworn statement of the complainant in five copies plus the number of respondents; an affidavit for each witness on the same copy rule; and supporting documents across thirteen offence-specific categories, again five copies plus the number of respondents. Office hours are Monday to Friday, 8:00 a.m. to 4:30 p.m., with no noon break. The DOJ page publishes no procedural timeline and no step sequence, and we do not supply one.
What Not to Do
| Do not | Ransomware | Phishing | Hacked account | Why |
|---|---|---|---|---|
| Power the machine down | Especially not | — | — | Destroys volatile memory and sometimes recovery material. Isolate instead |
| Wipe and rebuild before imaging | No | — | — | Irreversible destruction of the evidence an investigation needs |
| Delete the phishing email | — | No | — | The headers are the most useful single artefact |
| Forward the phishing email as evidence | — | No | — | Forwarding strips the original headers. Export or save the message instead |
| Reply to the attacker to find out what they want | No | No | No | Confirms the channel is live and, in a business email compromise, is often exactly what the attacker is waiting for |
| Change only the password | — | Insufficient | Insufficient | Leaves sessions, tokens, recovery routes and forwarding rules intact |
| Announce it publicly before assessing | No | No | No | A public statement that later proves wrong is harder to correct than a delayed one |
| Wait for certainty before starting the clock | No | No | No | The 72-hour clock runs from reasonable belief, not from proof |
| Treat the platform report as the legal report | — | — | No | A platform ticket is not a complaint to law enforcement and is not an NPC notification |
| Assume the incident is over because it stopped | No | No | No | Quiet is a common stage of an intrusion, not the end of one |
One provision worth knowing before an investigation begins. Section 15 of RA 10175 allows law enforcement, under a warrant, to require persons who have knowledge of the functioning of a computer system and of the measures protecting the data in it to give reasonable assistance. Companies rarely expect that their own administrators can be compelled to help. Separately, Section 20 makes failure to comply with a Chapter IV order a violation of Presidential Decree No. 1829, punished by imprisonment or a fine of ₱100,000, or both, for each and every noncompliance.
Six Worked Scenarios
1. A Makati logistics firm finds its file server encrypted on a Monday morning
The ransom note names a leak site. Isolate the server and any machine showing the same extension; do not power them off. Preserve the note, a sample encrypted file, and the server logs. Because a leak site is named, treat exfiltration as likely and assess the three-part test now rather than after recovery — customer contact details and employee records were on that server, so limbs (A) and (B) are in view and the 72-hour clock should be treated as running from this morning. Report to the NBI Cybercrime Division. If the firm is not BSP-supervised, there is no two-hour clock. Restoration comes after imaging, and only from a backup verified clean.
2. An accounts clerk enters her password on a page that looked like the company webmail
Nothing else appears to have happened. Rotate the password immediately, everywhere it was reused, and end all sessions. Check the mailbox for a forwarding rule — this is the step most often skipped. Capture the phishing URL before it disappears and export the original email with headers intact. On the privacy test: if the credential reached only the clerk’s own mailbox and that mailbox holds no personal data of others, limb (A) is likely not met and this is probably not a notifiable breach. Document that conclusion and the reasoning. An unrecorded assessment looks identical, a year later, to no assessment.
3. A supplier’s bank details change by email and ₱1.8 million goes to the wrong account
This is business email compromise. Call the bank first — recall depends on speed, not on paperwork. Preserve the full headers of the instruction email and of the genuine correspondence it imitated, because the difference between them is the case. The offence route runs through Sec. 4(b)(2) computer-related fraud and estafa under Art. 315 with the Sec. 6 uplift. On the privacy side: if no personal data was exposed, this is a serious crime and a serious loss but not automatically a personal data breach, and no NPC clock starts. Report to the NBI or the PNP Anti-Cybercrime Group.
4. A shop owner loses control of the business Facebook page
The attacker is posting fake promotions to the followers. Recover through the platform flow, then reset the linked email and phone, end all sessions, and remove connected apps. Screenshot the posts before they are deleted, because platform recovery often erases them. This is illegal access under Sec. 4(a)(1), and identity theft under Sec. 4(b)(3) once the page is used to pose as the business. Warn the followers. Whether an NPC duty arises depends on what customer data the page and its message inbox held.
5. A rural bank discovers unauthorised administrative access to its core system at 9:40 a.m.
The two-hour clock under Section 148 of the Manual of Regulations for Banks is the binding one, and it is running from discovery. An initial report to the Bangko Sentral is due by 11:40 a.m., with a follow-up within 24 hours. The 72-hour privacy assessment runs separately and in parallel — it does not replace the two-hour obligation, and the two-hour obligation does not satisfy the privacy one. Both, not either.
6. An individual’s mobile number is ported away and her e-wallet is drained
Contact the network operator first to reclaim the number, because every one-time password follows the SIM. Then the wallet provider’s dispute channel. The offence route is Sec. 4(b)(3) identity theft and Sec. 4(b)(2) fraud. As an individual she owes no NPC notification — that duty belongs to controllers and processors. Whether the telco or the wallet provider has its own breach to report is their question, not hers, and she is entitled to ask them.
Common Mistakes
- Treating 72 hours as the Philippine incident deadline. For a BSP-supervised institution it is two hours. For a business that suffered no personal data breach, there is no NPC deadline at all.
- Waiting for certainty. The clock runs from reasonable belief, not from a completed forensic report.
- Powering down a ransomware-affected machine. The instinct is right and the action is wrong.
- Forwarding the phishing email instead of exporting it. The forward is worth far less than the original.
- Changing the password and stopping there. Sessions, tokens, recovery addresses and inbox rules all outlive a password change.
- Assuming a personal hacked account creates a regulatory duty. It generally does not, and treating it as if it does wastes the time that should go into recovery.
- Assuming a company hacked account does not. It usually does.
- Reporting to the CICC hotline and thinking the criminal complaint is filed. A 1326 report gets help and referral; the sworn complaint is filed with the NBI or PNP-ACG.
- Not documenting a decision that an incident was not notifiable. Section 22 of Circular 16-03 requires the documentation either way.
- Rebuilding before imaging. Recovery and evidence are in tension, and only one of them is reversible.
- Letting the six-month traffic-data window run out while deciding whether to report.
- Writing one procedure that assumes every incident is a data breach. Most are not; the ones that are need a different set of steps, on a shorter clock.
Frequently Asked Questions
Is there a single incident response procedure that covers ransomware, phishing and hacked accounts?
Not for the first hour. Containment differs: isolate for ransomware, rotate credentials for phishing, recover control for a hacked account. After containment the procedures converge almost completely — evidence preservation, the personal data assessment, reporting and recovery are the same work in all three.
Is phishing a crime in the Philippines?
Yes, but not under a provision called phishing. Where phishing gives the attacker access to and control of a bank or e-wallet account, it is a social engineering scheme under Section 4(b) of RA 12010. Otherwise phishing conduct is reached through computer-related forgery (Sec. 4(b)(1)), computer-related fraud (Sec. 4(b)(2)), computer-related identity theft (Sec. 4(b)(3)), and estafa under Article 315 of the Revised Penal Code with the penalty raised one degree by Sec. 6.
Is ransomware a crime in the Philippines?
Yes. There is no offence named ransomware either, but Sec. 4(a)(3) data interference and Sec. 4(a)(4) system interference both expressly cover conduct “including the introduction or transmission of viruses,” and Sec. 4(a)(1) illegal access covers the intrusion that preceded it.
Does every cyberattack have to be reported to the National Privacy Commission?
No. Only a personal data breach meeting all three conditions in Sec. 11 of NPC Circular 16-03 does. A business email compromise that moved money but exposed no personal data is a serious crime that creates no NPC notification duty.
How long do I have to report?
It depends who you are. A BSP-supervised institution has two hours for an initial report of a major cyber-related incident and 24 hours for a follow-up. A personal information controller has 72 hours to notify the NPC and 72 hours to notify affected data subjects, both running from knowledge or reasonable belief, and five days for the full breach report. Everyone else has no statutory reporting deadline, though evidence decay makes early reporting sensible.
My personal Facebook account was hacked. Do I have to notify the NPC?
Generally no. The notification duty in the Data Privacy Act attaches to personal information controllers and processors. An individual whose own account was taken over is a victim, not a controller. Report it to the platform and to the NBI or the PNP Anti-Cybercrime Group.
Should I power off a machine hit by ransomware?
No. Disconnect it from the network instead. Powering down destroys volatile memory that can matter to both the investigation and, occasionally, to recovery.
Can I report all three to the same agency?
Yes. Section 10 of RA 10175 gives enforcement responsibility to the National Bureau of Investigation and the Philippine National Police, and both maintain cybercrime units. The privacy notification to the NPC is a separate, parallel obligation, not an alternative.
Can I report a cybercrime to the CICC?
You can report a scam or phishing incident to the CICC’s Inter-Agency Response Center hotline 1326, which the CICC and DICT run with PNP and NBI support. That is a report, not a criminal complaint. Sections 24 to 26 of RA 10175 give the CICC coordination and national cybersecurity plan functions, not investigative or prosecution powers, so a sworn complaint is filed with the NBI or the PNP Anti-Cybercrime Group.
How long is evidence kept by service providers?
Section 13 of RA 10175 sets six months from the date of the transaction for traffic data and subscriber information. Content data is preserved for six months from receipt of a law-enforcement order, extendable once by six months. The content-data clock does not start until that order is issued, which is a reason not to delay reporting.
Does paying a ransom change my reporting obligations?
The payment question has its own legal and reporting considerations and is addressed in our ransomware payment and reporting guide. Paying does not remove a personal data breach notification duty that has already arisen.
What if the breach happened at my supplier rather than at my company?
Your obligations do not disappear. A personal information controller remains accountable for processing it has outsourced, and the assessment still has to be made. See vendor and SaaS data breach responsibility.
Is NIST CSF 2.0 required in the Philippines?
No. It is a voluntary United States framework published by the National Institute of Standards and Technology. It is useful as a neutral structure for an incident response procedure, but no Philippine statute or regulator issuance requires its adoption.
Verification Log
What was checked for this page, where, and what could not be established.
| Claim | Source | Status |
|---|---|---|
| RA 10175 Sec. 4(a)(1) illegal access, wording | Senate Legislative Digital Resource | Read directly, 26 September 2026 |
| RA 10175 Sec. 4(a)(3) data interference, including the viruses clause | Senate Legislative Digital Resource | Read directly, 26 September 2026 |
| RA 10175 Sec. 4(a)(4) system interference, including the viruses clause | Senate Legislative Digital Resource | Read directly, 26 September 2026 |
| RA 10175 Sec. 4(a)(5) misuse of devices, both limbs | Senate Legislative Digital Resource | Read directly, 26 September 2026 |
| RA 10175 Sec. 4(b)(1) computer-related forgery, both limbs | Senate Legislative Digital Resource | Read directly, 26 September 2026 |
| NIST CSF 2.0 RESPOND and RECOVER Categories and descriptions | NIST CSWP 29 | Read directly, 26 September 2026 |
| RA 10175 Secs. 4(b)(2), 4(b)(3), 6, 10, 11, 13, 14, 15, 20, 23, 24–26 | Senate Legislative Digital Resource | Secs. 6, 10, 13, 14, 15, 20, 23 and 24–26 rechecked 28 September 2026; Secs. 4(b)(2), 4(b)(3) and 11 reused from earlier reads |
| NPC Circular 16-03 Secs. 3(F), 11, 17(A)–(C), 18(A), 22 | National Privacy Commission | Rechecked 28 September 2026 |
| NPC Advisory 2026-02 Sec. 2(C) and 2(D) | National Privacy Commission | Rechecked 28 September 2026 |
| DBNMS as the only valid channel for breach notification forms | NPC breach reporting page | Rechecked 28 September 2026 |
| RA 12010 Sec. 4(b), social engineering scheme | Bangko Sentral ng Pilipinas, AFASA booklet with IRR | Read directly, 28 September 2026 |
| CICC Inter-Agency Response Center hotline 1326 | Philippine News Agency | Read directly, 28 September 2026 |
| IRR of RA 10173, Rule IX Sec. 38 | National Privacy Commission | Verified on earlier reads and reused, not re-fetched |
| MORB Sec. 148 two-hour and 24-hour clocks | Bangko Sentral ng Pilipinas, Manual of Regulations for Banks | Rechecked 28 September 2026 |
| NBI Cybercrime Division intake: no fee, 1 hour 10 minutes | NBI Citizen’s Charter | Verified on an earlier read and reused, not re-fetched |
| DOJ preliminary-investigation filing requirements and copy rule | Department of Justice | Verified on an earlier read and reused, not re-fetched |
| PNP Anti-Cybercrime Group hotline, email or address | — | Not published on any government page we could read. No contact detail is printed here |
| CICC contact details and complaint procedure | — | The CICC site could not be read. No contact detail is printed here |
| Implementing Rules and Regulations of RA 10175 | — | Could not be read. Nothing on this page relies on them |
| Rules on Electronic Evidence; Rule on Cybercrime Warrants | — | Supreme Court issuances; not readable from a reachable government source. Their contents are not stated here |
| Case law on any provision cited | — | No jurisprudence is cited anywhere on this page. Provisions of RA 10175 were challenged before the Supreme Court after it took effect, and this page does not state which survived review |
| NBI office location | Two NBI pages | Discrepancy reported, not resolved. Confirm before travelling |
| Penalty figure for RA 10175 Sec. 5 offences | — | Not read from the primary text; no figure is stated |
| Prescriptive period for any offence discussed | — | Not asserted |
Official Sources
- Republic Act No. 10175, Cybercrime Prevention Act of 2012 — Senate Legislative Digital Resource
- Republic Act No. 10173, Data Privacy Act of 2012 — National Privacy Commission
- Implementing Rules and Regulations of the Data Privacy Act — National Privacy Commission
- NPC Circular 16-03, Personal Data Breach Management
- NPC Advisory No. 2026-02, submission of breach notification through the DBNMS
- NPC breach reporting page
- NPC, exercising breach reporting procedures (informational page dated 12 February 2022)
- Data Breach Notification Management System (DBNMS)
- Republic Act No. 12010, Anti-Financial Account Scamming Act, with IRR — Bangko Sentral ng Pilipinas
- Philippine News Agency, on the CICC’s Inter-Agency Response Center hotline 1326 (14 August 2023)
- Manual of Regulations for Banks, Section 148 — Information Technology Risk Management
- NIST Cybersecurity Framework 2.0 (NIST CSWP 29)
- National Bureau of Investigation
- PNP Anti-Cybercrime Group
- Department of Justice
- DOJ Office of Cybercrime
- Cybercrime Investigation and Coordinating Center
- Supreme Court of the Philippines
Related Cybercode Guides
- What to do after a business cyberattack in the Philippines
- Cybersecurity incident response plan Philippines
- Cyber incident response checklist Philippines
- Data breach Philippines: how to report one, step by step
- Data breach response checklist
- The Cybercrime Prevention Act (RA 10175), section by section
- Illegal interception under RA 10175
- Cybersecurity in the Philippines: legal duties and practical baseline
- Cybersecurity checklist for Philippine businesses
- Employee cybersecurity policy template
- Website security checklist
- Electronic evidence in the Philippines
About This Guide
Author: Cybercode.ph Editorial Team. Last materially reviewed: 27 September 2026.
Reviewer: this page has not been reviewed by a named external legal reviewer. Cybercode does not attribute review to a person who has not carried it out. In place of a reviewer’s name, the verification log above records exactly which source was read for each claim, which claims were reused from an earlier verification, and which questions could not be answered from a reachable government source.
Corrections: if a figure, provision or procedure on this page does not match the official source cited beside it, the official source governs. Please tell us and we will correct the page.
Sources rechecked as of: 28 September 2026
Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

