CyberCode.ph · Philippines

CICC Philippines: What the Cybercrime Investigation and Coordinating Center Handles

Last updated October 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

What is CICC in the Philippines?

Direct answer: The Cybercrime Investigation and Coordinating Center (CICC) coordinates the Philippine government’s response to cybercrime. For a scam report and agency referral, call Hotline 1326, the 24/7 Inter-Agency Response Center (I-ARC) channel described by DICT Caraga. For a formal criminal investigation, file with the NBI Cybercrime Division or PNP Anti-Cybercrime Group. If money has moved, contact your bank or e-wallet immediately.

Where it sits: RA 10175 created the CICC and originally placed it under the Office of the President. The later RA 10844 Section 15(b) attached it to the DICT, made the DICT Secretary its chair and transferred specified cybersecurity powers to the department. A hotline report is a useful first contact, but it does not itself open an NBI or PNP criminal case.

Quick contacts (checked 29 September 2026)

  • Scam or phishing report: call 1326 for I-ARC routing and ask for a reference number.
  • Criminal complaint: NBI Cybercrime Division or PNP Anti-Cybercrime Group. Bring preserved messages, account identifiers, timestamps and transaction records.
  • Money at risk: contact your bank or e-wallet provider immediately to secure or dispute the transaction.
  • Official CICC site: cicc.gov.ph for current agency notices.

Key Takeaways

  • Report fast: call 1326 for a scam report or agency referral; file a criminal complaint with the NBI Cybercrime Division or PNP Anti-Cybercrime Group. Contact your bank or e-wallet immediately if money is at risk.
  • Current placement: RA 10175 originally put CICC under the Office of the President. RA 10844 Section 15(b) later attached it to the DICT and made the DICT Secretary its chair.
  • Distinct jobs: CICC coordinates prevention and monitors cases. NBI and PNP investigate; DOJ handles prosecution and international cooperation; NPC handles personal-data complaints.
  • The national plan: RA 10175 listed plan formulation under CICC, but RA 10844 transferred cybersecurity functions, including the plan and national CERT, to DICT. EO 58, s. 2024 adopted the NCSP 2023–2028.
  • Preserve evidence: keep original messages, full-context screenshots, payment records and a dated timeline. Ask the receiving agency for a reference number.

Jump to a Section

Decision Snapshot: Who Should You Actually Contact?

Your situation Practical route
Scam, phishing or suspicious online contact; unsure where to start Call 1326 for I-ARC reporting and referral. Save the reference number.
You want a criminal investigation File with the NBI Cybercrime Division or PNP Anti-Cybercrime Group under RA 10175 Sec. 10; bring original evidence.
Money was taken from a bank or e-wallet Contact the provider at once, then use 1326 and NBI/PNP as appropriate.
A company mishandled your personal data Use the NPC complaint route; report any separate crime to NBI or PNP.
You need national cybercrime coordination CICC is relevant. DICT holds the transferred national cybersecurity plan and CERT functions under RA 10844.
You need a warrant or prosecution Investigators, prosecutors and courts handle these legal processes; a CICC hotline call is not a substitute.

The CICC at a Glance

Question Answer
What is it? An inter-agency cybercrime coordination body created by RA 10175 Section 24.
Where is it today? Attached to the DICT for policy and program coordination under RA 10844 Section 15(b); chaired by the DICT Secretary.
Who investigates? NBI and PNP specialized cybercrime units under RA 10175 Section 10.
Can the public report to a CICC-linked channel? Yes, I-ARC Hotline 1326 accepts scam and cybercrime reports for coordination and referral. It does not replace a formal criminal complaint.
Who owns the national cybersecurity plan function now? RA 10844 transfers that cybersecurity function to the DICT; the CICC remains a coordinating attached body.
Official website cicc.gov.ph; confirm live contact details there.

Section 24: How the CICC Was Created

Section 24 of RA 10175 does three things in a single sentence, and each one matters for understanding what the CICC is.

First, it creates a body rather than an agency. The section creates an inter-agency body called the Cybercrime Investigation and Coordinating Center. An inter-agency body draws its members from existing departments and offices; it is a table those agencies sit around rather than a separate bureau with its own investigators.

Second, it set a deadline. The CICC was to be created within thirty (30) days from the effectivity of the Act. RA 10175 was approved on 12 September 2012, and its effectivity clause provides that it takes effect fifteen days after publication in the Official Gazette or in at least two newspapers of general circulation.

Third, it states why the CICC exists. The stated purpose is policy coordination among concerned agencies and the formulation and enforcement of the national cybersecurity plan. The later DICT Act transferred cybersecurity plan and CERT functions to the DICT, while the CICC remains a coordinating body. Read the original Section 26 list with that later change.

Section 24 originally placed the CICC under the administrative supervision of the Office of the President. RA 10844 Section 15(b) later attached it to the DICT and changed the chair; the current placement is explained below.

Section 25: Who Sits on It

RA 10175 Section 25 lists the original composition: the ICTO-DOST Executive Director as chair, the NBI Director as vice chair, the PNP Chief, the DOJ Office of Cybercrime head, and a representative from the private sector and academe. It also provides for a secretariat. This describes the 2012 text, not the current chair.

Role Original RA 10175 text Current-law clarification
Chair ICTO-DOST Executive Director DICT Secretary under RA 10844 Sec. 15(b)(3)(ii)
Vice chair NBI Director RA 10844 does not replace this named seat
Other members PNP Chief; DOJ Office of Cybercrime head; private sector and academe representative Read with later law and current government appointments

RA 10844 Section 15 abolished and transferred the ICTO’s functions to the DICT, attached the CICC to that department, and expressly made the DICT Secretary chair. The current organizational answer comes from the later statute, not an inference from a department website.

Section 26: The CICC’s Statutory Functions

RA 10175 Section 26 lists eight functions in its original text. Read its cybersecurity provisions with the later RA 10844 Section 15(b), which transferred cybersecurity powers, including formulation of the national plan, establishment of the national CERT and certain international intelligence cooperation, to the DICT. The CICC remains attached for policy and program coordination.

RA 10175 provision Function in the original statute Present-day reading
26(a) National cybersecurity plan and immediate CERT assistance Cybersecurity and national CERT functions transferred to DICT by RA 10844.
26(b)–(c) Coordinate prevention and suppression measures; monitor cases handled by participating agencies Coordination and monitoring do not grant police investigative power.
26(d) Facilitate international cooperation on intelligence, investigation, training and capacity building Read with RA 10844’s transfer of cybersecurity intelligence cooperation to DICT and DOJ’s central-authority role under RA 10175 Sec. 23.
26(e)–(h) Coordinate business, LGU and civil-society support; recommend laws and policies; call on agencies; perform related prevention and capacity-building tasks These explain the CICC’s cross-agency role; a recommendation is not a binding law.

Reporting versus investigation: the CICC-linked I-ARC can receive reports and refer victims through Hotline 1326. RA 10175 Section 10 assigns criminal enforcement and specialized investigators to the NBI and PNP. The CICC cannot itself arrest, prosecute or issue a court warrant merely because it receives a hotline report. See our RA 10175 guide for the wider statutory framework.

Who the CICC Answers To Today

Direct answer: The CICC is now attached to the DICT for policy and program coordination, and the DICT Secretary chairs it. Section 24 of RA 10175 originally put it under the Office of the President’s administrative supervision. The later RA 10844, Section 15(b) expressly attaches the CICC to the DICT, replaces the ICTO chair with the DICT Secretary and transfers cybersecurity functions, including the National Cybersecurity Plan and national CERT, to the department.

The CICC continues to operate under its creating law insofar as consistent with RA 10844. The old Office of the President wording is useful history, but it is incomplete as an answer to the present placement question. The DICT also lists CICC among its attached agencies. For the department’s broader responsibilities, see our DICT Act guide.

Attachment to the DICT does not make the CICC the police investigator or prosecutor for an individual case. The NBI and PNP retain the enforcement mandate in Section 10 of RA 10175; the reporting routes are below.

What the CICC Does Not Do

Direct answer: Receiving a scam report through the CICC-linked I-ARC is different from opening and investigating a criminal case. RA 10175 gives law-enforcement responsibility to the NBI and PNP. The CICC’s coordinating role does not confer arrest, prosecution or judicial warrant powers.

  • It does not replace NBI or PNP case filing. If you need an investigation, ask the receiving hotline for its referral and follow the investigating agency’s complaint process with your evidence.
  • It does not prosecute: prosecutors and courts handle charges and adjudication under their applicable procedures.
  • It does not decide data-subject complaints: the NPC is the regulator under RA 10173.
  • It cannot promise a refund or takedown: contact the financial provider or platform directly while pursuing the appropriate complaint route.

Where to Report a Cybercrime Instead

Direct answer: For a criminal investigation, file with the NBI Cybercrime Division or PNP Anti-Cybercrime Group. Section 10 of RA 10175 assigns enforcement to the NBI and PNP. For a quick scam report and referral, call the government’s 1326 Inter-Agency Response Center (I-ARC); that hotline report may help route the incident but is not by itself a sworn criminal complaint. For stolen money, contact your bank or e-wallet immediately as well.

Situation First action Formal route or next step
Online scam, phishing, hacked account or ransomware Secure account; use 1326 for rapid reporting or referral NBI Cybercrime Division or PNP-ACG with evidence; filing guide
Unauthorised bank or e-wallet transfer Contact the financial provider urgently to secure and dispute the transaction Preserve reference numbers; file with NBI or PNP-ACG if crime is suspected. See RA 12010 guide.
Company misuse or exposure of personal data Preserve breach notices and correspondence National Privacy Commission for a data-subject complaint; a related crime can also go to NBI or PNP.
Scam text or suspicious SIM activity Report to telco and consider 1326 NTC for telecom issue; NBI or PNP for a crime. See SIM guide.

See our reporting directory for updated agency routes and the online scam complaint process for documents and follow-up.

The inter-agency hotline

Hotline 1326: The DICT Caraga notice published by PIA on 31 December 2025 describes it as a 24/7 central reporting channel for online selling scams, fraudulent texts or emails, phishing, impersonation, romance and investment scams and other cybercrimes. It says the I-ARC links the CICC, DICT, NPC and NTC and connects victims with agencies including PNP and NBI. The same notice also mentions reporting through the eGovPH app.

  • Use it when: you need a quick report or help finding the responsible agency, especially while a scam is active.
  • Tell the operator: what happened, when, the platform or account involved, whether money or data is at risk, and the steps already taken. Ask for a reference number and the referral destination.
  • Then follow through: contact your financial provider or platform promptly if relevant, and file the required complaint and evidence with NBI or PNP-ACG for investigation. A 1326 call does not guarantee recovery, a takedown or prosecution.

The National Cybersecurity Plan

Direct answer: RA 10175 Section 26(a) originally assigned the CICC the formulation of a national cybersecurity plan and immediate CERT assistance. RA 10844 Section 15(b)(3)(i) later transferred cybersecurity powers and functions, expressly including formulation of the plan and establishment of the national CERT, to the DICT. The CICC remains a DICT-attached body that coordinates cybercrime prevention and monitors participating agencies’ cases; do not describe it as the sole present owner of the plan.

Executive Order No. 58, dated 4 April 2024, adopted the National Cybersecurity Plan 2023–2028 and directs implementation. The order assigns the DICT a system for implementation, monitoring and review. The distinction matters: a national strategy concerns prevention, resilience, capacity and coordination, while a victim’s criminal complaint still goes through investigating and prosecuting authorities.

CICC Compared With the Other Cybercrime Bodies

Body Role Where a victim goes
CICC / I-ARC DICT-attached inter-agency cybercrime coordination and case monitoring; participates in Hotline 1326 reporting and referrals. RA 10175 Secs. 24–26; RA 10844 Sec. 15(b). 1326 for quick scam report or referral; NBI/PNP for a criminal investigation.
NBI Cybercrime Division Specialized investigation and law enforcement under RA 10175 Sec. 10. Criminal complaint with evidence.
PNP Anti-Cybercrime Group Specialized police investigation and law enforcement under RA 10175 Sec. 10. Criminal complaint, including urgent incidents.
DOJ Office of Cybercrime DOJ central authority for international cooperation and extradition under RA 10175 Sec. 23; prosecution coordination. Follow its official referral process where applicable; NBI/PNP are clearer first stops for investigation.
National Privacy Commission Regulator and complaint forum under RA 10173 for personal-data matters. Data-subject complaint or breach-related regulatory issue.
DICT National cybersecurity policy, plan implementation and CERT functions under RA 10844 Sec. 15(b) and EO 58, s. 2024. Policy and incident-response coordination; individual criminal cases go to NBI/PNP.

Worked Scenarios

1. A shopper is defrauded by an online seller

Contact the payment provider promptly. Preserve the listing, chat and transaction details. Call 1326 for a quick report and referral; if seeking a criminal investigation, file with NBI Cybercrime Division or PNP-ACG and keep both reference numbers.

2. A company suffers a ransomware attack

Activate its incident-response plan, isolate affected systems without wiping evidence, and engage its technical team. A suspected crime can go to NBI or PNP-ACG. If personal data is affected, separately assess NPC breach-notification obligations. The national CERT function sits with DICT under RA 10844; technical coordination does not replace those steps.

3. An LGU plans cyber-safety outreach

CICC’s coordination and capacity-building functions under RA 10175 Sections 26(e) and (h) make it relevant for prevention work. DICT also leads national cybersecurity policy under RA 10844.

4. A victim needs provider data preserved

Bring account identifiers, URLs, dates and records promptly to NBI or PNP-ACG. Legal preservation, disclosure and search procedures under RA 10175 run through authorized investigators and courts, not a request to CICC alone. See what happens after reporting.

5. A trade association proposes a policy change

RA 10175 Section 26(f) allows CICC to recommend laws, issuances and policies. DICT is the relevant department for national cybersecurity functions; neither a recommendation nor a hotline report is a binding legal order.

What to Preserve Before You Report

Do these in order where safe; do not delay an urgent bank freeze or account recovery to make a perfect evidence file.

  1. Stop ongoing loss: contact your bank or e-wallet to block a transaction or account, secure the affected account and use a trusted device if compromise is suspected. Keep the case or reference number.
  2. Capture the full context: save screenshots or screen recordings showing the URL, account handle, complete conversation, dates and timestamps. Record the original links and profile IDs without opening suspicious links again.
  3. Keep originals: preserve messages and emails in their accounts, export full email headers where possible, and retain suspicious files without editing or forwarding malware to others.
  4. Collect money trail and device details: transaction IDs, amounts, recipient details, statements, OTP or login alerts, affected accounts, device type and time of first detection. Do not publish sensitive identifiers in a public post.
  5. Write a chronology: note when the contact, payment, login or discovery occurred, what you did, and every platform, provider or agency you contacted. Save acknowledgments and report numbers.
  6. Hand over copies through official channels: keep untouched originals, share only what the receiving agency asks for, and request an acknowledgment or case number. Our scam evidence checklist provides a fuller worksheet.

Common Mistakes

  • Stopping at 1326 after a serious loss. Keep its reference number, then contact the bank or platform and file with NBI or PNP-ACG when criminal investigation is needed.
  • Assuming a report guarantees recovery. A referral, bank dispute, investigation and prosecution are different processes with different outcomes.
  • Reading the old CICC chair as current. RA 10844 Section 15(b) makes the DICT Secretary chair.
  • Calling CICC the sole owner of the national plan. RA 10844 transferred cybersecurity plan and CERT powers to the DICT.
  • Deleting originals after taking screenshots. Keep the messages, headers, transaction IDs and a dated chronology.
  • Sending a personal-data complaint only to a criminal hotline. Use NPC procedures for privacy complaints while separately reporting any crime.

Frequently Asked Questions

Where can I file a cybercrime complaint in the Philippines?

For a criminal investigation, approach the NBI Cybercrime Division or PNP Anti-Cybercrime Group with your evidence. Call 1326 for rapid scam reporting or referral. Contact your bank or e-wallet first if a transaction is ongoing. See the reporting directory.

Can I file directly with the CICC?

You can report a scam or cybercrime through the CICC-linked I-ARC Hotline 1326 for routing and assistance. A hotline report is not automatically a sworn complaint or a police investigation. Follow its referral to NBI or PNP-ACG when you want a criminal case pursued.

Is the CICC under the DICT or the Office of the President?

It is attached to the DICT for policy and program coordination under RA 10844 Section 15(b), and the DICT Secretary chairs it. RA 10175’s earlier Office of the President wording explains its origin.

What does Hotline 1326 handle?

The government describes it as a 24/7 I-ARC number for online scams, suspicious messages, phishing, impersonation, romance or investment fraud and other cybercrime reports. Ask for a reference number and referral, then contact the appropriate investigator or financial provider as needed.

Does the CICC investigate cases?

The CICC coordinates and monitors cases handled by participating agencies. RA 10175 Section 10 designates NBI and PNP cybercrime units for law enforcement.

What is the CICC’s role in the National Cybersecurity Plan?

RA 10175 originally listed plan formulation in Section 26(a), but RA 10844 transferred cybersecurity functions, including the national plan and CERT, to the DICT. CICC remains a DICT-attached coordination body. EO 58, dated 4 April 2024, adopted the NCSP 2023–2028.

Who else works with the CICC?

NBI and PNP investigate; DOJ Office of Cybercrime handles international cooperation and prosecution coordination; DICT leads national cybersecurity functions; NPC handles privacy complaints; and NTC deals with telecom regulation. The I-ARC links several of these agencies for report routing.

Can CICC make binding rules or issue warrants?

Its RA 10175 recommendation and coordination functions do not themselves authorize it to legislate, prosecute or issue court warrants.

Where can I check current contacts?

Use cicc.gov.ph and official agency pages. For a quick scam report, the government’s published 1326 hotline is a starting point; confirm operating details if a call does not connect.

Source and Currency Check

Material legal and routing review: 29 September 2026. The following primary sources support the answers on this page:

Agency phone lines, portals and complaint requirements can change. Check the official destination when filing, and keep the acknowledgment or case number.

Official Sources

Related Cybercode Guides

About This Guide

Author: Cybercode.ph Editorial Team.

Review status: this page has not been reviewed by a named external legal reviewer. Cybercode does not attribute review to a person who has not carried it out. In place of a reviewer’s name, the verification log above records every government source consulted for this page, what was asked of it and what it returned, so that any statement here can be checked against the same material.

Corrections: if any statement on this page does not match the primary source it cites, the primary source governs. Statutory text is supported by RA 10175 and the later RA 10844 Section 15(b); current hotline behavior is attributed to DICT Caraga’s notice published by PIA.

Last materially reviewed: 29 September 2026.

Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.