Direct Answer: Republic Act No. 10175, the Cybercrime Prevention Act of 2012, criminalises hacking-type offences, computer-related fraud, forgery and identity theft, and content offences such as cyber libel, and it sets penalties, a warrant-and-preservation regime and an enforcement structure. It does not now authorise warrantless real-time traffic-data collection, government blocking of content, or a spam offence, because the Supreme Court voided those provisions in Disini v. Secretary of Justice (2014). It also names no specific offence for dummy accounts, disinformation or large-scale scam operations. Several House bills filed in the 20th Congress propose to fill these gaps. None of them is law as of this review.
Key Takeaways
- RA 10175 remains the core Philippine cybercrime statute. Its offences under Section 4 and its penalty rules still apply.
- Three provisions were voided in full: Section 4(c)(3) on unsolicited commercial communications, Section 12 on real-time collection of traffic data, and Section 19 on restricting or blocking access to computer data.
- Two provisions were cut back. Section 5 (aiding, abetting and attempt) no longer applies to child pornography, spam or cyber libel. Section 7 no longer allows a second prosecution for cyber libel or child pornography.
- Other laws have closed some gaps without amending RA 10175. Examples are the SIM Registration Act (RA 11934), the Anti-Financial Account Scamming Act (RA 12010) and the Supreme Court’s Rule on Cybercrime Warrants.
- Pending bills would add offences for dummy accounts (HB 2249) and disinformation (HB 6969), would create a new national anti-cybercrime and anti-scam framework (HB 8048), and would treat mass phishing as economic sabotage (HB 1333).
- A filed bill is not law. Until Congress passes one and it takes effect, the rules as the Supreme Court left them in 2014 are the rules.
Jump to a Section
- Decision Snapshot
- What RA 10175 Covers
- What the Supreme Court Removed
- The Gaps: What RA 10175 Does Not Cover
- Pending Amendment Bills (20th Congress)
- From Legislation to Action: What to Do Now
- Practical Scenarios
- FAQs
- Official Sources
Decision Snapshot
| Question | Practical Answer |
|---|---|
| Is RA 10175 still in force? | Yes. It stands, minus the provisions the Supreme Court voided in 2014. |
| Can police collect traffic data in real time without a warrant under Section 12? | No. The Supreme Court declared Section 12 unconstitutional. |
| Can the DOJ block a website on its own under Section 19? | No. The Supreme Court declared Section 19 unconstitutional. |
| Is sending spam a cybercrime under RA 10175? | No. Section 4(c)(3) was struck down. Other laws, such as privacy rules on direct marketing, may still apply. |
| Is liking or sharing a libellous post cyber libel? | The Court limited cyber libel to the original author. Aiding or abetting cyber libel under Section 5 was struck down. |
| Is running a fake or dummy account a cybercrime in itself? | Not as a separate offence. It may still fall under computer-related identity theft or other laws, depending on the facts. HB 2249 would make it one. |
| Is posting disinformation a cybercrime? | Not under RA 10175 as it stands. HB 6969 proposes one. |
| Have any of the 20th Congress amendment bills become law? | None had been verified as enacted as of September 28, 2026. |
Why This Matters: When Crime Goes Digital
RA 10175 was written in 2012. Since then, scams have moved to e-wallets and messaging apps, fake accounts can be produced in bulk, and AI can clone a face or a voice. A victim, a prosecutor or a compliance officer has to know which parts of the 2012 law still apply, which parts the Supreme Court removed, and which problems no statute reaches yet. Those three answers tell you whether to file under RA 10175, file under another law, or accept that the law has not caught up.
What Does RA 10175 Cover?
RA 10175 sorts cybercrime into three groups under Section 4. It adds that crimes under the Revised Penal Code and special laws committed through information and communications technology carry a penalty one degree higher (Section 6). Cybercode’s complete guide to RA 10175 goes through the Act section by section.
| Group | Offences | Status after Disini |
|---|---|---|
| Section 4(a): offences against the confidentiality, integrity and availability of computer data and systems | Illegal access, illegal interception, data interference, system interference, misuse of devices, cyber-squatting | Upheld |
| Section 4(b): computer-related offences | Computer-related forgery, computer-related fraud, computer-related identity theft | Upheld |
| Section 4(c): content-related offences | Cybersex, child pornography, unsolicited commercial communications, libel | Spam provision voided. Cyber libel upheld only as to the original author. |
The Act also sets up an enforcement and procedure framework. It covers preservation of computer data (Section 13), disclosure orders (Section 14), search and seizure (Section 15), and punishment of noncompliance with those enforcement orders as obstruction of justice under Presidential Decree No. 1829 (Section 20), a provision Disini sustained. It also creates the DOJ Office of Cybercrime and the Cybercrime Investigation and Coordinating Center (CICC). For how Sections 4 and 6 work together, see RA 10175 Sections 4 and 6 explained.
What Did the Supreme Court Remove From RA 10175?
In Disini, Jr. v. Secretary of Justice, G.R. No. 203335 (February 11, 2014), the Supreme Court of the Philippines upheld most of RA 10175 but voided Sections 4(c)(3), 12 and 19, and limited Sections 4(c)(4), 5 and 7. Much of what people call the gaps in Philippine cybercrime law comes from this decision. None of these provisions has been re-enacted in a constitutional form since.
| Provision | What it did | What the Court held | The gap it left |
|---|---|---|---|
| Sec. 4(c)(3) | Penalised unsolicited commercial communications (spam) | Void. Commercial speech is protected, and recipients can delete unwanted messages. | No cybercrime offence for spam |
| Sec. 12 | Allowed real-time collection of traffic data “with due cause” | Void. It lacked safeguards and was too broad. | No statutory real-time traffic-data power. Collection now runs through court-issued cybercrime warrants. |
| Sec. 19 | Let the DOJ restrict or block access to computer data on a prima facie finding | Void. It allowed the executive to act without a judicial warrant, which violates free expression and the protection against unreasonable searches. | No statutory blocking or takedown power under RA 10175 |
| Sec. 4(c)(4) | Cyber libel | Upheld, but only as to the original author. People who merely receive or react to a post are not covered. | Unclear liability for sharers, platforms and moderators |
| Sec. 5 | Aiding, abetting and attempt | Void as applied to child pornography, spam and cyber libel | Accomplice liability narrower for content offences |
| Sec. 7 | Separate prosecution under RA 10175 and other laws | Void as to cyber libel and child pornography (double jeopardy) | One prosecution only for those two offences |
For how cyber libel works after Disini, see online libel in the Philippines and the cyber libel prescription period.
What Are the Gaps in RA 10175?
The gaps below are Cybercode’s analysis of the statute’s text, the Disini ruling, and the problems that the bills’ own explanatory notes describe. A gap does not mean the conduct is legal. It means RA 10175 does not name it, so you have to find a different legal route.
1. No real-time traffic-data power in the statute
What the rule says: Section 12 is void. What it means: Investigators apply to a court instead. The DOJ Office of Cybercrime describes four warrant types under the Supreme Court’s Rule on Cybercrime Warrants: to disclose computer data (WDCD), to intercept computer data (WICD), to search, seize and examine computer data (WSSECD), and to examine computer data (WECD). Why it matters: Speed. Scam proceeds and logs can disappear before a warrant issues. Section 13’s preservation duty is what keeps data available in the meantime.
2. No blocking or takedown mechanism
With Section 19 gone, RA 10175 gives no agency the power to block content or order a platform to take it down. Victims usually depend on platform reporting tools, court orders, or powers in other laws. Cybercode’s analysis of what the DICT and CICC can and cannot legally do covers this in detail.
3. No offence for spam
Unsolicited commercial messages are not a cybercrime. If they use personal data, Data Privacy Act rules may apply. If they are part of fraud, computer-related fraud under Section 4(b)(2) may apply.
4. Fake and dummy accounts are not an offence in themselves
RA 10175 punishes computer-related identity theft under Section 4(b)(3), which covers misuse of another person’s identifying information. A made-up persona that impersonates no real person does not fit that provision cleanly. The explanatory note of HB 2249 argues that current laws “penalize the consequences” but not the use of the dummy account.
5. Disinformation is not covered
RA 10175 has no disinformation or “fake news” offence. Any proposal to add one has to fit within the free-expression limits Disini applied to content offences. That tension also runs through HB 4786’s social media franchise proposal.
6. Industrial-scale scams and fragmented enforcement
The 2012 Act spreads enforcement across the NBI, the PNP, the DOJ Office of Cybercrime and the CICC. It has no aggravated category for syndicated, large-scale cyber fraud. The Anti-Financial Account Scamming Act (RA 12010, approved July 20, 2024) partly fills this for scams that run through bank and e-wallet accounts: it punishes money muling and social engineering schemes, and treats them as economic sabotage when committed by three or more persons in conspiracy, against three or more persons, through a mass mailer or through human trafficking, punishable by life imprisonment, a fine of ₱1 million to ₱5 million, or both (RA 12010, Sections 4 and 16(c), BSP text). See CyberCode’s AFASA guide. RA 12010 does not reach scams that never touch a financial account. HB 8048’s explanatory note points to the “speed, scale, sophistication, and transnational character” of modern cybercrime as the reason for a new framework.
7. AI-generated media and deepfakes are not named
RA 10175 never mentions synthetic media. Deepfake harms are handled piece by piece, through identity theft, cyber libel, and gender-based online sexual harassment under the Safe Spaces Act (RA 11313, Section 12), which expressly covers “impersonating identities of victims online” (Philippine Commission on Women). See deepfakes and likeness rights in the Philippines.
8. The institutional text is out of date
Section 25 still names the Executive Director of the ICTO-DOST as CICC chair. That is the 2012 structure. The Department of Information and Communications Technology (DICT) was later created under RA 10844. The statutory text itself has not been amended to reflect this.
9. Critical-infrastructure and ransomware duties
RA 10175 punishes the attacker through data and system interference, including “the introduction or transmission of viruses.” It does not impose security or reporting duties on operators of critical systems. That is the gap addressed by HB 9605 on national cybersecurity and critical infrastructure.
Which Gaps Have Other Laws Partly Closed?
| Gap | Partial fix outside RA 10175 |
|---|---|
| Anonymous mobile numbers used in scams | SIM Registration Act, RA 11934 (approved October 10, 2022), and the NTC’s implementing rules |
| Money mules, social engineering and syndicated account scams | Anti-Financial Account Scamming Act, RA 12010 (approved July 20, 2024): new offences, economic-sabotage tier, BSP authority to investigate financial accounts (Section 12) and temporary holding of disputed funds for up to 30 calendar days unless a court extends it (Section 7) |
| Real-time data collection after Section 12 | Supreme Court Rule on Cybercrime Warrants (WDCD, WICD, WSSECD, WECD) |
| Online impersonation and harassment | Safe Spaces Act, RA 11313, Section 12 |
| Cross-border evidence | Philippine accession to the Council of Europe Budapest Convention on Cybercrime (instrument of accession deposited, announced April 6, 2018), which gives investigators treaty-based cooperation channels |
What Amendment Bills Are Pending in the 20th Congress?
At least four House bills filed in the 20th Congress propose to amend RA 10175. The details below come from the bill texts published in the House of Representatives’ legislative documents repository. Bill numbers follow that repository’s index. Committee status was not verified as of this review and should be checked on the House website before relying on it.
| Bill | Principal author | Gap targeted | Main proposals |
|---|---|---|---|
| HB 2249, Cyber Crime Anti-Dummy Act of 2025 | Rep. Robert Nazal (Bagong Henerasyon Party-List) | Dummy and fictitious accounts, including AI-generated personas | Defines “dummy account”. Platform takedown within 24–48 hours. Victim Protection Orders issuable within 24 hours. Tiered identity verification for users. Penalties 50% higher when minors or deepfakes are involved. Quarterly platform transparency reports to the National Privacy Commission. A National Digital Forensics Task Force. |
| HB 6969, amending Sections 3 and 4 of RA 10175 | Rep. Sittie Shahara “Bai Dimple” I. Mastura (Maguindanao del Norte with Cotabato City) | Disinformation | Defines “disinformation” as intentionally disseminated false information made with malicious political or economic purpose. Adds a content-related offence for creating and spreading disinformation through a computer system. Expands “subscriber’s information” to cover social websites and similar platforms. |
| HB 8048, Anti-Cybercrime Act of 2026 | Rep. Brian Poe (FPJ Panday Bayanihan Party-List) | Scale, fragmentation, outdated definitions | Creates a National Cybercrime Prevention and Investigation Agency, a National Anti-Cybercrime Council and a National Anti-Scam Hub. Treats large-scale organised cybercrime as economic sabotage punishable by life imprisonment. New offences include malicious refusal to surrender computer data and solicitation to commit cybercrime. Real-time traffic data only with a court warrant. |
| HB 1333, strengthening cybercrime prevention measures, amending RA 10175 | Rep. Roman T. Romulo (Lone District, Pasig City) | Mass phishing, outdated definitions, penalties | Amends Sections 2, 3, 4, 5, 6 and 8. Treats ICT-enabled mass phishing and fraud using bulk mailers as economic sabotage. Adds definitions such as phishing and bulk email mass mailer, expands “service provider”, adds solicitation to commit cybercrime, and raises penalties for computer-related fraud. |
A separate bill, HB 6818 (Cybersecurity and Infrastructure Protection Act of 2025, Rep. Alfred C. Delos Santos), would create a cybersecurity commission but does not amend RA 10175.
Editorial note: HB 8048’s warrant-based approach to real-time traffic data follows the path Disini left open, which is judicial authorisation. HB 6969’s disinformation offence and HB 2249’s identity-verification and takedown mandates are likely to face the same free-expression and privacy tests the Court applied in 2014. That is Cybercode’s analysis, not a prediction of any ruling.
From Legislation to Action: What Should You Do Now?
Until an amendment passes, use the tools that exist now.
- Preserve evidence first. Keep original screenshots with URLs and timestamps, profile links, chat exports, transaction reference numbers and e-wallet records. Do not crop or edit the originals.
- Match the conduct to an existing offence. Fake accounts may fit identity theft (Sec. 4(b)(3)) or fraud (Sec. 4(b)(2)). Online sexual harassment falls under RA 11313. Traditional crimes committed through ICT are covered by Section 6.
- Report to the right agency. If money left a bank or e-wallet, report to that institution first: RA 12010 lets it temporarily hold disputed funds, for no more than 30 calendar days unless a court extends it. Then file with the PNP Anti-Cybercrime Group or the NBI Cybercrime Division, or call the CICC’s 1326 hotline. See how to report cybercrime in the Philippines and the bank, e-wallet and telco help directory. Law enforcement, not the victim, applies for cybercrime warrants.
- Use platform tools for takedowns. RA 10175 gives no agency blocking power, so report content to the platform while your complaint proceeds.
- For businesses: keep logs long enough to answer a Section 13 preservation order. Assign someone to handle law-enforcement data requests. Track HB 2249 and HB 8048, since both would add platform and service-provider obligations.
Practical Scenarios
A seller is scammed through a newly created account with a random name. No dummy-account offence exists. The complaint rests on computer-related fraud or estafa through ICT (Section 6), supported by transaction records and SIM or e-wallet data obtained through a warrant.
A company wants a defamatory post removed quickly. RA 10175 gives no agency blocking power. The company has three routes: the platform’s reporting process, a cyber libel complaint against the original author, and civil remedies. Resharers are generally outside cyber libel after Disini.
A marketing team receives bulk unsolicited promotional texts. This is not a cybercrime under RA 10175. If the sender processed personal data without a lawful basis, it may raise Data Privacy Act issues.
FAQs
Has RA 10175 ever been amended?
Cybercode found no amending statute to RA 10175 as of September 28, 2026. Its reach has changed through the Disini ruling, Supreme Court procedural rules and separate laws such as RA 11934.
Is cyber libel still a crime in the Philippines?
Yes. Section 4(c)(4) was upheld as to the original author of the libellous content.
Why was Section 12 struck down?
The Court found that real-time collection of traffic data “with due cause” lacked adequate safeguards and was too broad.
Can the government block websites under the Cybercrime Law?
Not under Section 19, which was declared unconstitutional because it allowed restriction without a judicial warrant.
Are fake accounts illegal in the Philippines?
Creating one is not a separate cybercrime today. Using one to steal another person’s identity, defraud someone, harass or libel can be punished under existing law.
Is fake news a cybercrime?
Not under RA 10175 as it stands. HB 6969 proposes a disinformation offence, but it is a pending bill.
What is the Anti-Cybercrime Act of 2026?
It is the title of House Bill No. 8048, which proposes a new national cybercrime and anti-scam framework amending RA 10175. It is not law.
Where can I check a bill’s status?
On the House of Representatives’ legislative information system and the Senate’s legislative records. Check the bill number, not news reports.
Official Sources
- Republic Act No. 10175, Cybercrime Prevention Act of 2012: Official Gazette
- Disini, Jr. v. Secretary of Justice, G.R. No. 203335, February 11, 2014: Supreme Court
- Republic Act No. 11934, SIM Registration Act: Official Gazette
- Republic Act No. 12010, Anti-Financial Account Scamming Act: Official Gazette; BSP booklet with implementing rules
- Republic Act No. 11313, Safe Spaces Act, Section 12: Philippine Commission on Women
- Rule on Cybercrime Warrants: DOJ Office of Cybercrime
- House Bill No. 2249 (Cyber Crime Anti-Dummy Act of 2025): House of Representatives
- House Bill No. 6969 (amending Sections 3 and 4 of RA 10175): House of Representatives
- House Bill No. 8048 (Anti-Cybercrime Act of 2026): House of Representatives
- House Bill No. 1333 (amending RA 10175): House of Representatives
- House Bill No. 6818 (Cybersecurity and Infrastructure Protection Act of 2025): House of Representatives
- Philippines’ accession to the Budapest Convention: Council of Europe
Verification Log
| Claim | Source checked | Result |
|---|---|---|
| Disini date and rulings | Supreme Court decision PDF (sc.judiciary.gov.ph) | Promulgation date corrected to February 11, 2014. Section 4(a)(1) upheld; Sections 4(c)(3) and 12 struck down; Section 5 void as to Sections 4(c)(2), 4(c)(3) and 4(c)(4); Section 7 void as to online libel and child pornography; Sections 13, 20 and 24 to 26(a) sustained. |
| RA 12010 offences, economic sabotage, penalties, 30-day hold | BSP AFASA booklet (statutory text) | Confirmed |
| RA 11934 approval date | Senate Legislative Reference Bureau | Confirmed (October 10, 2022) |
| HB 1333 and HB 6818 authors and contents | House legislative documents repository | Confirmed from the bill texts |
| Four cybercrime warrant types | DOJ Office of Cybercrime | Confirmed. The A.M. number and effectivity date were not shown on that page, so they are not stated here. |
| HB 2249, 6969, 8048 authors and contents | House legislative documents repository | Confirmed from the bill texts |
| Status of the three bills | Not verified | Treated as pending. Not stated as passed or approved at committee level. |
| Senate counterpart bills (20th Congress) | Senate Legislative Reference Bureau subject index | No 20th Congress entries listed at time of review |
Cybercode.ph provides general educational information about technology, cybersecurity, privacy, and related legal issues. It is not a substitute for legal, cybersecurity, or professional advice for a specific situation.
Sources rechecked as of: 28 September 2026

