CyberCode.ph · Philippines

Cyber Incident Response in the Philippines: Ransomware, Phishing and Hacked Accounts Compared

Last updated September 28, 2026 · Practical privacy, cybersecurity and technology-law guidance

Direct answer: Ransomware, phishing and a hacked account are three different incidents with three different first moves — isolate the affected systems, rotate the exposed credentials, or regain control of the account — and three different offence mappings under Republic Act No. 10175. What they share is the clock. If personal data was exposed, notification to the National Privacy Commission runs for 72 hours from knowledge or reasonable belief, and a BSP-supervised institution has two hours.

Key Takeaways

  • The first action is the main thing that differs. Ransomware is contained by isolating. Phishing is contained by rotating credentials. A hacked account is contained by recovering it and ending every other session.
  • No Philippine statute uses the word phishing, but the conduct is squarely penalised. Where it gives access to a bank or e-wallet account, it is a social engineering scheme under Section 4(b) of RA 12010, the Anti-Financial Account Scamming Act. Otherwise it is reached through computer-related forgery, computer-related fraud, computer-related identity theft, and estafa carrying a penalty one degree higher under Section 6 of RA 10175.
  • Ransomware sits inside two offences whose enrolled text expressly covers the introduction or transmission of viruses — data interference and system interference.
  • The 72-hour clock is not triggered by the attack. It is triggered by a three-part test about personal data, and any of the three scenarios can pass or fail it.
  • A BSP-supervised institution answers to a two-hour clock that has nothing to do with privacy law, for all three scenarios.
  • Evidence decays on a statutory timer. Section 13 of RA 10175 sets six months for traffic data and subscriber information, running from the transaction — not from the day you decide to report.
  • This page compares the law, not other people’s guides. Every row below is built from a statute, an implementing rule or a regulator issuance, with the Cybercode guide that goes deeper named alongside it.

Jump to a Section

Decision Snapshot

Question Practical answer
Is there one incident-response procedure that covers all three? No. The containment step differs. The reporting and evidence steps largely do not.
Does Philippine law define a separate offence called phishing? Not by that name. RA 10175 contains no offence named phishing, but RA 12010 Sec. 4(b) penalises a social engineering scheme: obtaining another person’s sensitive identifying information by deception, resulting in unauthorised access to and control of a financial account.
Does it define one called ransomware? No. Ransomware is charged through data interference, system interference and illegal access.
Does every cyberattack start a 72-hour National Privacy Commission clock? No. Only a personal data breach meeting the three-part test in NPC Circular 16-03 does.
Does a hacked personal account create an NPC duty for the individual? Generally no. The duty falls on personal information controllers and processors, not on a private individual whose own account was taken over.
Is there a shorter clock than 72 hours anywhere? Yes. Two hours, for BSP-supervised institutions, under Section 148 of the Manual of Regulations for Banks.
Do you report all three to the same agency? Broadly yes — the NBI Cybercrime Division or the PNP Anti-Cybercrime Group. The privacy regulator is a separate, parallel report.
Does the CICC take complaints? It takes reports, not criminal complaints. The CICC and DICT run the Inter-Agency Response Center hotline 1326 for scam and phishing reports, with PNP and NBI support. RA 10175 gives the CICC no investigative or prosecution power, so a sworn complaint still goes to the NBI or PNP-ACG.
Should you wipe and rebuild immediately? Not before preserving evidence. A rebuild destroys the material an investigation needs.
Is paying a ransomware demand a separate legal question? Yes, and it is dealt with in its own guide rather than here.

The Master Comparison Table

Eight incidents, read across. The first column is what happened, the last is the Cybercode guide that goes deeper. Everything between is drawn from the statute, the implementing rules or the regulator issuance named in the verification log.

Incident First action, before anything else Primary RA 10175 offence Does a 72-hour NPC clock start? Where to report first
Ransomware Isolate affected machines from the network. Do not power them down. Sec. 4(a)(3) data interference and Sec. 4(a)(4) system interference; Sec. 4(a)(1) illegal access for the entry point Only if personal data was accessed, exfiltrated or rendered unavailable in a way that meets the three-part test NBI Cybercrime Division or PNP Anti-Cybercrime Group. NPC in parallel if the test is met
Phishing that harvested credentials Rotate the exposed password everywhere it was reused, then end all active sessions. Sec. 4(b)(1) computer-related forgery for the fake page; Sec. 4(b)(3) identity theft for the credentials taken Only if the credentials unlocked personal data of others NBI or PNP-ACG. The impersonated brand should also be told
Phishing that moved money (business email compromise) Call the bank and request recall of the transfer, then preserve the full email headers. Sec. 4(b)(2) computer-related fraud; estafa under Art. 315 of the Revised Penal Code, one degree higher via Sec. 6 Only if personal data was also exposed; a pure funds-transfer loss is not automatically a personal data breach The bank first, because recall is time-critical. Then NBI or PNP-ACG
Hacked personal social account Use the platform recovery flow, then remove unknown logged-in devices and reset the linked email. Sec. 4(a)(1) illegal access; Sec. 4(b)(3) identity theft if the account is used to impersonate Generally no. The duty sits on personal information controllers, not on a private individual whose own account was taken The platform, then NBI or PNP-ACG
Hacked company account or admin takeover Revoke the session and the API tokens, not just the password. Then audit what the account could reach. Sec. 4(a)(1) illegal access; Sec. 4(a)(3) or 4(a)(4) if data or systems were altered Very often yes, because a company account usually reaches customer or employee data NPC assessment immediately, in parallel with NBI or PNP-ACG
Website defaced or compromised Take the site to maintenance mode and preserve the server logs before restoring. Sec. 4(a)(3) data interference; Sec. 4(a)(4) system interference Only if the site held personal data — a form database, an order table, an account system The host first, to stop the bleeding. Then NBI or PNP-ACG
Malware without a ransom demand Isolate, then determine whether it was an information stealer before assuming it was noise. Sec. 4(a)(3) data interference; Sec. 4(a)(5) misuse of devices as against whoever supplied the tool Only if personal data was exfiltrated or corrupted NBI or PNP-ACG
SIM swap into an account takeover Contact the mobile network to reclaim the number, because every one-time password follows the SIM. Sec. 4(b)(3) identity theft; Sec. 4(b)(2) fraud where funds moved Only if personal data of others was reached The network operator and the bank first. Then NBI or PNP-ACG

Which Cybercode guide answers which question

This is a routing table for our own material. It lists no other publisher.

If you want Read
First steps for an individual who has just been hacked Hacked in the Philippines: first 15 minutes and recovery
The generic first-hour sequence for a business What to do after a business cyberattack
A written plan to have in place before an incident Building a cybersecurity incident response plan
A tick-box list to work through during one The cyber incident response checklist
The ransomware sequence in detail Ransomware attack: what to do immediately
Whether to pay, and what reporting follows Ransomware payment and reporting
What to do after clicking a phishing link Clicked a phishing link: next steps
The payment-fraud variant Business email compromise
An account you no longer control Unauthorised account access
A social account specifically Hacked Facebook account
A compromised website Website hacked: recovery
Malware without extortion Malware attacks in the Philippines
Whether you have actually been compromised How to tell if your phone or account is hacked
The breach-reporting procedure end to end Data breach Philippines: how to report one
A number that was ported away from you SIM swap fraud and liability

Why the Response Differs at All

Three variables decide almost everything about how a Philippine incident is handled. Once you know where an incident sits on each of them, the rest of the response follows.

Variable What it decides How it differs across the three
Is the attacker still inside? Whether containment means isolation, credential rotation or account recovery Ransomware: usually yes, and the encryption is the last stage of a longer intrusion. Phishing: often no — the credential has been taken and used elsewhere. Hacked account: yes, and they hold the keys
Was personal data reached? Whether a 72-hour National Privacy Commission clock starts at all Ransomware and company-account takeovers usually reach it. A hacked personal account of an individual usually does not create a duty for that individual
Is the organisation BSP-supervised? Whether a two-hour clock applies on top of everything else Identical across all three. The clock attaches to the institution, not to the attack type

That last row is the one most commonly missed. A bank, an e-money issuer or another institution supervised by the Bangko Sentral ng Pilipinas is working to a two-hour reporting window for a major cyber-related incident, whatever the attack was called. For everyone else, that clock does not exist. Our cybersecurity duties overview sets out which obligations attach to which kind of organisation.

Ransomware: What Changes

The short version: ransomware is the scenario where the wrong first move causes the most permanent damage, because powering a machine down can destroy volatile evidence and, in some cases, the only copy of a decryption key held in memory. Isolate from the network; do not shut down.

Which offences it maps to

RA 10175 contains no offence called ransomware. Two provisions do the work, and both were written broadly enough to cover it expressly.

Section 4(a)(3), Data Interference, covers “the intentional or reckless alteration, damaging, deletion or deterioration of computer data, electronic document, or electronic data message, without right, including the introduction or transmission of viruses.” Encryption that renders a company’s own files unusable is deterioration of computer data without right, and the closing clause about the introduction or transmission of viruses puts the delivery of the payload inside the same subsection.

Section 4(a)(4), System Interference, covers “the intentional alteration or reckless hindering or interference with the functioning of a computer or computer network” by, among other things, “inputting, transmitting, damaging, deleting, deteriorating, altering or suppressing computer data or program,” again “including the introduction or transmission of viruses.” Where the ransomware stopped operations rather than merely locking files, this is the closer fit.

Section 4(a)(1), Illegal Access — “the access to the whole or any part of a computer system without right” — covers how the attacker got in, which is usually a separate act from the encryption itself.

Section 4(a)(5), Misuse of Devices, reaches the supply side: making available, without right, a device or computer program “designed or adapted primarily for the purpose of committing any of the offenses under this Act.” Its second limb matters for anyone who finds tooling on a compromised machine, because it criminalises “the possession of an item referred to in paragraphs 5(i)(aa) or (bb) above with intent to use said devices” for those offences. Possession with intent is enough.

What is distinctive in the response

  • Do not power off. Disconnect the network cable or disable the wireless adapter instead. Memory contents can matter to both forensics and recovery.
  • Check the backups before you negotiate anything. Whether a clean restore exists changes every subsequent decision. Our backup and recovery guide covers what a restorable backup actually requires.
  • Assume exfiltration until you can rule it out. Double-extortion is now routine, and if data left the building the privacy analysis changes even though the files are back.
  • The payment question is separate. Whether to pay, and what reporting follows a payment, is dealt with in ransomware payment and reporting, not here.

Phishing: What Changes

The short version: phishing is the scenario where the incident you can see is rarely the incident that matters. The click is not the damage. The damage is whatever the harvested credential unlocked, and that is usually somewhere else entirely.

Which offences it maps to — and the gap

No provision of RA 10175 is named phishing. This is a real gap in the vocabulary of the statute, and it is worth stating plainly because it is the single most common misconception about Philippine cybercrime law. The conduct is reached, but it is reached obliquely, through four different routes depending on what the attacker actually did.

What the attacker did Provision Why it fits
Built a fake login page or spoofed a real one Sec. 4(b)(1), computer-related forgery “The input, alteration, or deletion of any computer data without right resulting in inauthentic data,” done “with the intent that it be considered or acted upon for legal purposes as if it were authentic”
Used the harvested data to deceive Sec. 4(b)(1), second limb “The act of knowingly using computer data which is the product of computer-related forgery” and doing so “for the purpose of perpetuating a fraudulent or dishonest design”
Moved money or caused loss Sec. 4(b)(2), computer-related fraud “The unauthorized input, alteration, or deletion of computer data or program or interference in the functioning of a computer system, causing damage thereby with fraudulent intent”
Took or used someone’s identifying information Sec. 4(b)(3), computer-related identity theft “The intentional acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another, whether natural or juridical, without right”
Used deception or electronic messages to get someone’s banking or e-wallet credentials and took control of the account RA 12010 Sec. 4(b), social engineering scheme Committed by a person who “obtains sensitive identifying information of another person, through deception or fraud, resulting in unauthorized access and control over the person’s Financial Account,” including by misrepresenting oneself as acting for an institution or “using electronic communications to obtain another person’s sensitive identifying information”
Committed estafa by means of the deception Revised Penal Code Art. 315, with RA 10175 Sec. 6 Where a Revised Penal Code offence is committed through information and communications technology, Sec. 6 provides that “the penalty to be imposed shall be one (1) degree higher than that provided for”

Sec. 6 is the provision that does the heavy lifting in most phishing prosecutions, and it is why our online estafa guide works through the Art. 315 penalty scale rather than stopping at RA 10175. The identity-theft limb is covered separately in computer-related identity theft, and the fraud limb in computer-related fraud.

What is distinctive in the response

  • Rotate before you investigate. Unlike ransomware, there is no evidence cost to changing a password immediately, and every minute of delay is a minute the credential is live.
  • Password reuse is the whole problem. Change the credential everywhere it was used, not only on the site that was imitated.
  • End the sessions, not just the password. A password change does not always invalidate a session token an attacker already holds.
  • Check for a mail forwarding rule. A silent inbox rule is the standard way a mailbox compromise is kept alive after the password changes, and it survives a reset.
  • Turn on multi-factor authentication now, not later. See the MFA guide. Where staff are involved, phishing awareness is the durable control.
  • An e-wallet is its own route. Where the phishing targeted a wallet, the provider’s own dispute channel runs in parallel — see our GCash scam and phishing reporting guide.

Hacked Accounts: What Changes

The short version: a hacked account is the only one of the three where the attacker holds the controls you would normally use to fix the problem. Recovery is a race, and whether the account is personal or corporate changes the legal consequences completely.

Which offences it maps to

Section 4(a)(1), illegal access, is the core fit: “the access to the whole or any part of a computer system without right.” Note what it does not require. There is no threshold of harm, no requirement that anything was taken, and no requirement that a security measure was defeated. Access without right is the offence.

Where the account is then used to pose as its owner, Section 4(b)(3), computer-related identity theft, applies on top: the acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another, whether natural or juridical, without right. Where the attacker altered or deleted content, Sections 4(a)(3) and 4(a)(4) come into play as well.

The personal-versus-corporate split

This is the single biggest divergence inside the third scenario, and most guidance treats the two as one thing.

Question Personal account Company account
Is it a crime under RA 10175? Yes — illegal access Yes — illegal access
Does the account holder owe a National Privacy Commission notification? Generally no. The duty in the Data Privacy Act attaches to personal information controllers and processors Frequently yes, because the account usually reaches personal data the organisation holds about others
Who must be told? The platform, and contacts who may be targeted next The Data Protection Officer immediately, then potentially the NPC and the affected data subjects
What is the deadline? None set by statute 72 hours to the NPC and 72 hours to affected data subjects once the three-part test is met
Who investigates? NBI Cybercrime Division or PNP Anti-Cybercrime Group The same, plus an internal assessment the organisation must document

What is distinctive in the response

  • Recover the account before anything else, because every other step depends on control.
  • Reset the recovery email and phone number first. Changing only the password leaves the attacker’s recovery path intact, and they will simply reset it back.
  • End all other sessions and revoke connected apps and API tokens. For a corporate account this is the step that is most often skipped and most often the reason the compromise returns.
  • Warn the contact list. A taken-over account is usually monetised by messaging the people who trust it.
  • If a mobile number was the entry point, the network operator is part of the response — see SIM swap fraud and liability.
  • If you are not sure you were compromised, start with how to tell if your phone or account is hacked rather than assuming.

What Is Identical in All Three

The comparison above is about divergence. This section is the opposite, and it is the more useful half for anyone writing a procedure: five things do not change at all with the attack type.

  1. Preserve before you remediate. Screenshots, logs, headers and timestamps first; cleanup second. This holds for every incident.
  2. The privacy question is asked the same way. The three-part test in NPC Circular 16-03 does not care how the data was reached.
  3. The reporting route is the same. The National Bureau of Investigation and the PNP Anti-Cybercrime Group are the two law-enforcement bodies given enforcement responsibility by Section 10 of RA 10175.
  4. The BSP clock is the same. Two hours for a supervised institution, whatever happened.
  5. The evidence timer is the same. Section 13 of RA 10175 runs from the transaction, not from the incident being noticed.

A useful way to hold this: the containment step is scenario-specific, and almost everything after it is not. That is why a single incident response checklist works across incident types once the first hour is past, and why the incident response plan is written once rather than per attack.

The neutral technical backbone

Where an organisation wants a vendor-neutral structure to hang its procedure on, the National Institute of Standards and Technology Cybersecurity Framework 2.0 divides the work into six Functions, two of which cover this ground. RESPOND (RS) is described as “Actions regarding a detected cybersecurity incident are taken” and breaks into four Categories: Incident Management (RS.MA), Incident Analysis (RS.AN), Incident Response Reporting and Communication (RS.CO) and Incident Mitigation (RS.MI). RECOVER (RC) is “Assets and operations affected by a cybersecurity incident are restored” and breaks into two: Incident Recovery Plan Execution (RC.RP) and Incident Recovery Communication (RC.CO).

RS.CO is the Category that maps onto Philippine law, because NIST describes it as response activities being “coordinated with internal and external stakeholders as required by laws, regulations, or policies.” NIST CSF 2.0 is a voluntary United States framework and is not Philippine law. It is useful as an organising structure; it imposes nothing, and no Philippine regulator requires it.

The Clocks, Side by Side

Five separate clocks can run in a Philippine incident. They come from different instruments, they start at different moments, and only one of them is the well-known 72 hours.

Clock Length Runs from Source Who it binds
Initial incident report to the Bangko Sentral 2 hours Discovery of a reportable major cyber-related incident Manual of Regulations for Banks, Sec. 148 BSP-supervised institutions only
Follow-up report to the Bangko Sentral 24 hours The same discovery Manual of Regulations for Banks, Sec. 148 BSP-supervised institutions only
Notification to the National Privacy Commission 72 hours Knowledge of, or reasonable belief in, a personal data breach NPC Circular 16-03, Sec. 17(A); IRR Rule IX Sec. 38 Personal information controllers and processors
Notification to affected data subjects 72 hours The same moment — these two run in parallel, not in sequence NPC Circular 16-03, Sec. 18(A) Personal information controllers and processors
Full breach report to the NPC 5 days The date of discovery NPC Circular 16-03, Sec. 17(C); Advisory 2026-02, Sec. 2(C) Personal information controllers
Compliance with a disclosure order 72 hours Service of a court-warranted law-enforcement order RA 10175, Sec. 14 Any person or service provider served

The two-hour clock is the one that catches people out. If you are a BSP-supervised institution, treating 72 hours as the Philippine incident deadline is wrong by a factor of thirty-six. If you are not, the two-hour clock does not apply to you at all and you should not build a procedure around it.

Two further points on the 72-hour clocks. First, delay is permitted under Sec. 17(B) only to determine the scope of the breach, prevent further disclosures or restore integrity — and there is no delay at all where the breach involves at least one hundred data subjects or the disclosure of sensitive personal information. Second, a request to the NPC for exemption, postponement or alternative means does not pause anything: Advisory 2026-02 Sec. 2(D) provides that the Commission’s inaction “shall not be construed as an approval, implied consent, or automatic grant.” Silence is not approval. The full procedure is in our data breach reporting guide and the system itself in DBNMS breach notification.

Is It a Personal Data Breach? The Test Applied to Each Scenario

An attack is not automatically a personal data breach, and the distinction decides whether any regulator deadline exists. Section 11 of NPC Circular 16-03 sets three conditions, and all three must be met.

  1. (A) The breach involves sensitive personal information, or any other information that may be used to enable identity fraud.
  2. (B) There is reason to believe the information may have been acquired by an unauthorised person.
  3. (C) The unauthorised acquisition is likely to give rise to a real risk of serious harm to any affected data subject.

Circular 16-03 Sec. 3(F) defines the breach itself as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.” Note that destruction and loss count, not only disclosure — which is why encryption-only ransomware can qualify even where nothing left the network.

Scenario Limb (A) — the data Limb (B) — acquisition Limb (C) — risk of serious harm Typical outcome
Ransomware, encryption only, backups clean Often met if customer or employee records were on the encrypted systems Contestable — encryption is destruction and loss under Sec. 3(F), but acquisition is a separate question Depends on what was rendered unavailable and for how long Assess and document; do not assume it is out of scope
Ransomware with exfiltration Met Met Usually met Notifiable
Phishing, one staff credential, no further access Depends on what that credential reached Met as to the credential itself Often not met if nothing further was accessed Frequently not notifiable, but document the assessment
Phishing into a mailbox holding client files Met Met Usually met Notifiable
Business email compromise, funds moved, no personal data touched Often not met — — A crime and a loss, but not automatically a personal data breach
Hacked personal social account of an individual — — — No controller duty arises for the individual
Hacked company admin account Usually met Met Usually met Notifiable

A word on documenting a negative. Deciding an incident is not notifiable is itself a decision that should be written down, with the reasoning and the date. Section 22 of Circular 16-03 requires that all security incidents and personal data breaches be documented through written reports, and that a summary of all reports be submitted to the Commission annually. An undocumented decision that something was not a breach is indistinguishable, later, from not having looked.

Where a vendor rather than your own systems were breached, responsibility splits differently — see vendor and SaaS data breach responsibility. The underlying statute is covered in our Data Privacy Act guide, and the regulator in our National Privacy Commission page.

Evidence to Preserve, by Scenario

The general rule is identical across all three: do not alter, crop, overwrite or clean up the original material. What differs is which material matters most, and how fast it disappears.

Evidence Ransomware Phishing Hacked account Why it matters
Full email headers, not a forwarded copy Where the entry was an email Critical Where the entry was an email Headers carry the routing and originating data a forward strips out
The ransom note file itself Critical — — Identifies the variant and the contact channel
A sample encrypted file with its extension Critical — — Some variants have public decryptors; identification depends on this
Login and access logs with timestamps and IP addresses Yes Yes Critical Establishes when control was lost and from where
The phishing page URL, captured before it is taken down — Critical — Phishing infrastructure has a short life; it is usually gone within days
Screenshots of the account as the attacker left it — Where relevant Critical Platform recovery often wipes the evidence of misuse
Mail forwarding and filter rules as found — Critical Yes The persistence mechanism, and proof of intent
Transaction references and recipient account details Where a ransom was paid Where funds moved Where funds moved The bank cannot act on a recall without them
A written incident timeline kept contemporaneously Yes Yes Yes Establishes the moment of knowledge, which is when every clock starts
Device and system images taken before rebuild Critical Where a device was compromised Where a device was compromised A rebuild is irreversible

The six-month timer nobody plans around

Section 13 of RA 10175 requires service providers to preserve the integrity of traffic data and subscriber information for six months from the date of the transaction. Content data is preserved for six months from receipt of a law-enforcement order, with a one-time extension of six months.

Read those two sentences together and the practical consequence is uncomfortable. The traffic-data clock is already running from the day of the attack, while the content-data clock does not begin at all until law enforcement issues an order. An organisation that decides to handle an incident quietly for four months, then changes its mind, may find that the records it needs have lawfully ceased to exist. Reporting early is not only a compliance posture; it is evidence preservation.

On what a Philippine court will accept, and in what form, see electronic evidence in the Philippines. We say plainly there and here that the Rules on Electronic Evidence and the Rule on Cybercrime Warrants are Supreme Court issuances that could not be read from a reachable government source for this page, so nothing on this page states their contents.

Where to Report, by Scenario

Section 10 of RA 10175 makes the National Bureau of Investigation and the Philippine National Police responsible for enforcement, and requires each to organise a cybercrime unit staffed by special investigators handling Act violations exclusively. Section 11 requires those units to submit pre-operation, post-operation and investigation reports to the Department of Justice. That allocation is the same for all three scenarios.

Body What it does Relevant to What we can and cannot publish
NBI Cybercrime Division Takes complaints and investigates. Its published service entry lists no checklist of requirements, no fee, and a total processing time of 1 hour and 10 minutes, with staff assisting the complainant to complete a sworn complaint sheet All three Published procedure confirmed. Note the location discrepancy below
PNP Anti-Cybercrime Group Investigates cybercrime; designated by RA 11313 Sec. 13 to receive gender-based online sexual harassment complaints All three No hotline, email or address is published on a government page we could read. We do not print one
The bank or e-money issuer Recall and dispute handling Phishing with funds moved; any incident with a payment leg Time-critical — this is the only step where minutes change the outcome
The platform or host Account recovery, takedown, restoration Hacked accounts and compromised websites Not a substitute for a law-enforcement report
National Privacy Commission Breach notification through the Data Breach Notification Management System Any incident meeting the three-part test Submissions outside the DBNMS are not valid
Bangko Sentral ng Pilipinas Incident reporting by supervised institutions All three, if you are supervised Two hours, then 24 hours
DOJ Office of Cybercrime Created by RA 10175 Sec. 23 as central authority for mutual assistance and extradition, and describes itself as the “focal agency in formulating and implementing law enforcement investigation and prosecution strategies” Prosecution stage It publishes no contact details and no reporting procedure on the pages we could read
CICC Policy coordination and the national cybersecurity plan; with the DICT, runs the Inter-Agency Response Center hotline 1326 for scam, phishing and account-recovery reports, supported by the PNP and NBI Phishing and scams, for a fast report and referral RA 10175 Secs. 24 to 26 give it no investigative, arrest, warrant or prosecution power. A 1326 report is not a sworn criminal complaint; file that with the NBI or PNP-ACG

An unresolved detail we report rather than settle. The NBI homepage gives a Filinvest Cyberzone Bay, Diosdado Macapagal Boulevard, Pasay City address for the Bureau, while its Citizen’s Charter entry refers to complaints filed outside “NBI Taft headquarters” going to Regional Cybercrime Centers. We report both and assert neither. Confirm the office before travelling.

The full agency-by-agency routing is in where and how to report cybercrime, with contact-level detail in the cybercrime reporting directory and the government cybersecurity agencies directory. What the CICC does and does not do is set out in our CICC guide.

What the prosecutor will need

If the matter proceeds to a complaint for preliminary investigation, the Department of Justice publishes what must be filed: a duly accomplished and certified Investigation Data Form (NPS INV Form No. 1) in two copies; the complaint-affidavit or sworn statement of the complainant in five copies plus the number of respondents; an affidavit for each witness on the same copy rule; and supporting documents across thirteen offence-specific categories, again five copies plus the number of respondents. Office hours are Monday to Friday, 8:00 a.m. to 4:30 p.m., with no noon break. The DOJ page publishes no procedural timeline and no step sequence, and we do not supply one.

What Not to Do

Do not Ransomware Phishing Hacked account Why
Power the machine down Especially not — — Destroys volatile memory and sometimes recovery material. Isolate instead
Wipe and rebuild before imaging No — — Irreversible destruction of the evidence an investigation needs
Delete the phishing email — No — The headers are the most useful single artefact
Forward the phishing email as evidence — No — Forwarding strips the original headers. Export or save the message instead
Reply to the attacker to find out what they want No No No Confirms the channel is live and, in a business email compromise, is often exactly what the attacker is waiting for
Change only the password — Insufficient Insufficient Leaves sessions, tokens, recovery routes and forwarding rules intact
Announce it publicly before assessing No No No A public statement that later proves wrong is harder to correct than a delayed one
Wait for certainty before starting the clock No No No The 72-hour clock runs from reasonable belief, not from proof
Treat the platform report as the legal report — — No A platform ticket is not a complaint to law enforcement and is not an NPC notification
Assume the incident is over because it stopped No No No Quiet is a common stage of an intrusion, not the end of one

One provision worth knowing before an investigation begins. Section 15 of RA 10175 allows law enforcement, under a warrant, to require persons who have knowledge of the functioning of a computer system and of the measures protecting the data in it to give reasonable assistance. Companies rarely expect that their own administrators can be compelled to help. Separately, Section 20 makes failure to comply with a Chapter IV order a violation of Presidential Decree No. 1829, punished by imprisonment or a fine of ₱100,000, or both, for each and every noncompliance.

Six Worked Scenarios

1. A Makati logistics firm finds its file server encrypted on a Monday morning

The ransom note names a leak site. Isolate the server and any machine showing the same extension; do not power them off. Preserve the note, a sample encrypted file, and the server logs. Because a leak site is named, treat exfiltration as likely and assess the three-part test now rather than after recovery — customer contact details and employee records were on that server, so limbs (A) and (B) are in view and the 72-hour clock should be treated as running from this morning. Report to the NBI Cybercrime Division. If the firm is not BSP-supervised, there is no two-hour clock. Restoration comes after imaging, and only from a backup verified clean.

2. An accounts clerk enters her password on a page that looked like the company webmail

Nothing else appears to have happened. Rotate the password immediately, everywhere it was reused, and end all sessions. Check the mailbox for a forwarding rule — this is the step most often skipped. Capture the phishing URL before it disappears and export the original email with headers intact. On the privacy test: if the credential reached only the clerk’s own mailbox and that mailbox holds no personal data of others, limb (A) is likely not met and this is probably not a notifiable breach. Document that conclusion and the reasoning. An unrecorded assessment looks identical, a year later, to no assessment.

3. A supplier’s bank details change by email and ₱1.8 million goes to the wrong account

This is business email compromise. Call the bank first — recall depends on speed, not on paperwork. Preserve the full headers of the instruction email and of the genuine correspondence it imitated, because the difference between them is the case. The offence route runs through Sec. 4(b)(2) computer-related fraud and estafa under Art. 315 with the Sec. 6 uplift. On the privacy side: if no personal data was exposed, this is a serious crime and a serious loss but not automatically a personal data breach, and no NPC clock starts. Report to the NBI or the PNP Anti-Cybercrime Group.

4. A shop owner loses control of the business Facebook page

The attacker is posting fake promotions to the followers. Recover through the platform flow, then reset the linked email and phone, end all sessions, and remove connected apps. Screenshot the posts before they are deleted, because platform recovery often erases them. This is illegal access under Sec. 4(a)(1), and identity theft under Sec. 4(b)(3) once the page is used to pose as the business. Warn the followers. Whether an NPC duty arises depends on what customer data the page and its message inbox held.

5. A rural bank discovers unauthorised administrative access to its core system at 9:40 a.m.

The two-hour clock under Section 148 of the Manual of Regulations for Banks is the binding one, and it is running from discovery. An initial report to the Bangko Sentral is due by 11:40 a.m., with a follow-up within 24 hours. The 72-hour privacy assessment runs separately and in parallel — it does not replace the two-hour obligation, and the two-hour obligation does not satisfy the privacy one. Both, not either.

6. An individual’s mobile number is ported away and her e-wallet is drained

Contact the network operator first to reclaim the number, because every one-time password follows the SIM. Then the wallet provider’s dispute channel. The offence route is Sec. 4(b)(3) identity theft and Sec. 4(b)(2) fraud. As an individual she owes no NPC notification — that duty belongs to controllers and processors. Whether the telco or the wallet provider has its own breach to report is their question, not hers, and she is entitled to ask them.

Common Mistakes

  1. Treating 72 hours as the Philippine incident deadline. For a BSP-supervised institution it is two hours. For a business that suffered no personal data breach, there is no NPC deadline at all.
  2. Waiting for certainty. The clock runs from reasonable belief, not from a completed forensic report.
  3. Powering down a ransomware-affected machine. The instinct is right and the action is wrong.
  4. Forwarding the phishing email instead of exporting it. The forward is worth far less than the original.
  5. Changing the password and stopping there. Sessions, tokens, recovery addresses and inbox rules all outlive a password change.
  6. Assuming a personal hacked account creates a regulatory duty. It generally does not, and treating it as if it does wastes the time that should go into recovery.
  7. Assuming a company hacked account does not. It usually does.
  8. Reporting to the CICC hotline and thinking the criminal complaint is filed. A 1326 report gets help and referral; the sworn complaint is filed with the NBI or PNP-ACG.
  9. Not documenting a decision that an incident was not notifiable. Section 22 of Circular 16-03 requires the documentation either way.
  10. Rebuilding before imaging. Recovery and evidence are in tension, and only one of them is reversible.
  11. Letting the six-month traffic-data window run out while deciding whether to report.
  12. Writing one procedure that assumes every incident is a data breach. Most are not; the ones that are need a different set of steps, on a shorter clock.

Frequently Asked Questions

Is there a single incident response procedure that covers ransomware, phishing and hacked accounts?

Not for the first hour. Containment differs: isolate for ransomware, rotate credentials for phishing, recover control for a hacked account. After containment the procedures converge almost completely — evidence preservation, the personal data assessment, reporting and recovery are the same work in all three.

Is phishing a crime in the Philippines?

Yes, but not under a provision called phishing. Where phishing gives the attacker access to and control of a bank or e-wallet account, it is a social engineering scheme under Section 4(b) of RA 12010. Otherwise phishing conduct is reached through computer-related forgery (Sec. 4(b)(1)), computer-related fraud (Sec. 4(b)(2)), computer-related identity theft (Sec. 4(b)(3)), and estafa under Article 315 of the Revised Penal Code with the penalty raised one degree by Sec. 6.

Is ransomware a crime in the Philippines?

Yes. There is no offence named ransomware either, but Sec. 4(a)(3) data interference and Sec. 4(a)(4) system interference both expressly cover conduct “including the introduction or transmission of viruses,” and Sec. 4(a)(1) illegal access covers the intrusion that preceded it.

Does every cyberattack have to be reported to the National Privacy Commission?

No. Only a personal data breach meeting all three conditions in Sec. 11 of NPC Circular 16-03 does. A business email compromise that moved money but exposed no personal data is a serious crime that creates no NPC notification duty.

How long do I have to report?

It depends who you are. A BSP-supervised institution has two hours for an initial report of a major cyber-related incident and 24 hours for a follow-up. A personal information controller has 72 hours to notify the NPC and 72 hours to notify affected data subjects, both running from knowledge or reasonable belief, and five days for the full breach report. Everyone else has no statutory reporting deadline, though evidence decay makes early reporting sensible.

My personal Facebook account was hacked. Do I have to notify the NPC?

Generally no. The notification duty in the Data Privacy Act attaches to personal information controllers and processors. An individual whose own account was taken over is a victim, not a controller. Report it to the platform and to the NBI or the PNP Anti-Cybercrime Group.

Should I power off a machine hit by ransomware?

No. Disconnect it from the network instead. Powering down destroys volatile memory that can matter to both the investigation and, occasionally, to recovery.

Can I report all three to the same agency?

Yes. Section 10 of RA 10175 gives enforcement responsibility to the National Bureau of Investigation and the Philippine National Police, and both maintain cybercrime units. The privacy notification to the NPC is a separate, parallel obligation, not an alternative.

Can I report a cybercrime to the CICC?

You can report a scam or phishing incident to the CICC’s Inter-Agency Response Center hotline 1326, which the CICC and DICT run with PNP and NBI support. That is a report, not a criminal complaint. Sections 24 to 26 of RA 10175 give the CICC coordination and national cybersecurity plan functions, not investigative or prosecution powers, so a sworn complaint is filed with the NBI or the PNP Anti-Cybercrime Group.

How long is evidence kept by service providers?

Section 13 of RA 10175 sets six months from the date of the transaction for traffic data and subscriber information. Content data is preserved for six months from receipt of a law-enforcement order, extendable once by six months. The content-data clock does not start until that order is issued, which is a reason not to delay reporting.

Does paying a ransom change my reporting obligations?

The payment question has its own legal and reporting considerations and is addressed in our ransomware payment and reporting guide. Paying does not remove a personal data breach notification duty that has already arisen.

What if the breach happened at my supplier rather than at my company?

Your obligations do not disappear. A personal information controller remains accountable for processing it has outsourced, and the assessment still has to be made. See vendor and SaaS data breach responsibility.

Is NIST CSF 2.0 required in the Philippines?

No. It is a voluntary United States framework published by the National Institute of Standards and Technology. It is useful as a neutral structure for an incident response procedure, but no Philippine statute or regulator issuance requires its adoption.

Verification Log

What was checked for this page, where, and what could not be established.

Claim Source Status
RA 10175 Sec. 4(a)(1) illegal access, wording Senate Legislative Digital Resource Read directly, 26 September 2026
RA 10175 Sec. 4(a)(3) data interference, including the viruses clause Senate Legislative Digital Resource Read directly, 26 September 2026
RA 10175 Sec. 4(a)(4) system interference, including the viruses clause Senate Legislative Digital Resource Read directly, 26 September 2026
RA 10175 Sec. 4(a)(5) misuse of devices, both limbs Senate Legislative Digital Resource Read directly, 26 September 2026
RA 10175 Sec. 4(b)(1) computer-related forgery, both limbs Senate Legislative Digital Resource Read directly, 26 September 2026
NIST CSF 2.0 RESPOND and RECOVER Categories and descriptions NIST CSWP 29 Read directly, 26 September 2026
RA 10175 Secs. 4(b)(2), 4(b)(3), 6, 10, 11, 13, 14, 15, 20, 23, 24–26 Senate Legislative Digital Resource Secs. 6, 10, 13, 14, 15, 20, 23 and 24–26 rechecked 28 September 2026; Secs. 4(b)(2), 4(b)(3) and 11 reused from earlier reads
NPC Circular 16-03 Secs. 3(F), 11, 17(A)–(C), 18(A), 22 National Privacy Commission Rechecked 28 September 2026
NPC Advisory 2026-02 Sec. 2(C) and 2(D) National Privacy Commission Rechecked 28 September 2026
DBNMS as the only valid channel for breach notification forms NPC breach reporting page Rechecked 28 September 2026
RA 12010 Sec. 4(b), social engineering scheme Bangko Sentral ng Pilipinas, AFASA booklet with IRR Read directly, 28 September 2026
CICC Inter-Agency Response Center hotline 1326 Philippine News Agency Read directly, 28 September 2026
IRR of RA 10173, Rule IX Sec. 38 National Privacy Commission Verified on earlier reads and reused, not re-fetched
MORB Sec. 148 two-hour and 24-hour clocks Bangko Sentral ng Pilipinas, Manual of Regulations for Banks Rechecked 28 September 2026
NBI Cybercrime Division intake: no fee, 1 hour 10 minutes NBI Citizen’s Charter Verified on an earlier read and reused, not re-fetched
DOJ preliminary-investigation filing requirements and copy rule Department of Justice Verified on an earlier read and reused, not re-fetched
PNP Anti-Cybercrime Group hotline, email or address — Not published on any government page we could read. No contact detail is printed here
CICC contact details and complaint procedure — The CICC site could not be read. No contact detail is printed here
Implementing Rules and Regulations of RA 10175 — Could not be read. Nothing on this page relies on them
Rules on Electronic Evidence; Rule on Cybercrime Warrants — Supreme Court issuances; not readable from a reachable government source. Their contents are not stated here
Case law on any provision cited — No jurisprudence is cited anywhere on this page. Provisions of RA 10175 were challenged before the Supreme Court after it took effect, and this page does not state which survived review
NBI office location Two NBI pages Discrepancy reported, not resolved. Confirm before travelling
Penalty figure for RA 10175 Sec. 5 offences — Not read from the primary text; no figure is stated
Prescriptive period for any offence discussed — Not asserted

Official Sources

Related Cybercode Guides

About This Guide

Author: Cybercode.ph Editorial Team. Last materially reviewed: 27 September 2026.

Reviewer: this page has not been reviewed by a named external legal reviewer. Cybercode does not attribute review to a person who has not carried it out. In place of a reviewer’s name, the verification log above records exactly which source was read for each claim, which claims were reused from an earlier verification, and which questions could not be answered from a reachable government source.

Corrections: if a figure, provision or procedure on this page does not match the official source cited beside it, the official source governs. Please tell us and we will correct the page.

Sources rechecked as of: 28 September 2026

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.