Last materially reviewed: September 3, 2026
Direct Answer
Republic Act No. 10175, or the Cybercrime Prevention Act of 2012, is the Philippines’ principal law defining and addressing crimes committed against, through, or with the use of computer systems and information and communications technologies. It covers offenses such as illegal access, illegal interception, data and system interference, misuse of devices, cybersquatting, computer-related forgery, computer-related fraud, computer-related identity theft, and cyber libel.
The law also designates the National Bureau of Investigation and Philippine National Police as cybercrime law-enforcement authorities and created a national framework for cybercrime coordination and international cooperation.
Primary authority: Republic Act No. 10175 — Cybercrime Prevention Act of 2012.
Key Takeaways
- RA 10175 covers both crimes directed at computer systems and traditional crimes committed through ICT.
- Illegal access, computer-related fraud and identity theft are expressly defined cybercrime offenses.
- Cyber libel is libel under the Revised Penal Code committed through a computer system or similar means.
- Section 6 generally increases by one degree the penalty for crimes under the Revised Penal Code or special laws when committed through ICT.
- NBI and PNP are the law-enforcement authorities named in Section 10.
- Several original provisions of RA 10175 were reviewed by the Supreme Court, so the statute should be read together with controlling decisions such as Disini v. Secretary of Justice.
Jump to a Section
- Cybercrime offenses
- Computer-related offenses
- Content-related offenses
- Penalties
- Investigation and enforcement
- What victims should do
Offenses Against Computer Data and Systems
Illegal Access
Accessing the whole or any part of a computer system without right can constitute illegal access. This can include unauthorized entry into accounts, servers, devices, databases, or networks depending on the facts.
Illegal Interception
The law penalizes interception by technical means, without right, of non-public computer-data transmissions.
Data Interference
Intentional or reckless alteration, deletion, damage or deterioration of computer data without right can fall under data interference, including conduct involving malicious code or viruses.
System Interference
Intentionally altering or recklessly hindering the functioning of a computer or network through unauthorized manipulation of data or programs can be system interference.
Misuse of Devices
The Act addresses certain devices, programs, passwords, access codes and similar data designed or intended for use in committing covered cybercrime offenses.
Cybersquatting
Bad-faith acquisition of a domain name to profit, mislead, destroy reputation, or deprive another person of a name or protected mark can fall within the law when statutory conditions are met.
Computer-Related Offenses
Computer-Related Forgery
This can involve unauthorized input, alteration or deletion of computer data that produces inauthentic data intended to be treated as authentic for legal purposes, or knowingly using such data for a fraudulent or dishonest design.
Computer-Related Fraud
Unauthorized input, alteration or deletion of computer data or interference with a computer system that causes damage with fraudulent intent can constitute computer-related fraud.
Computer-Related Identity Theft
The intentional acquisition, use, misuse, transfer, possession, alteration or deletion of identifying information belonging to another without right can fall within computer-related identity theft.
Content-Related Offenses and Cyber Libel
RA 10175 originally listed several content-related offenses. The Supreme Court subsequently reviewed provisions of the Act in Disini v. Secretary of Justice, so readers should not rely on the original statutory text without considering later judicial rulings.
Cyber Libel
Section 4(c)(4) covers libel as defined by the Revised Penal Code when committed through a computer system or similar means. The Supreme Court has repeatedly explained that RA 10175 did not invent an entirely new underlying defamation offense; it applies the existing law of libel to publication through ICT.
See our dedicated guide: Online Libel in the Philippines.
Decision Snapshot
| Conduct | Possible RA 10175 issue |
|---|---|
| Breaking into another person’s account | Illegal access |
| Deleting or corrupting data | Data interference |
| Disrupting a network or service | System interference |
| Manipulating data to obtain money | Computer-related fraud |
| Using another person’s identifying information | Computer-related identity theft |
| Publishing potentially libelous material online | Cyber libel |
What Are the Penalties Under RA 10175?
Section 8 provides penalties for specified cybercrime offenses, including imprisonment, fines, or both. The exact penalty depends on the offense and circumstances. Attacks against critical infrastructure can carry more serious consequences.
Section 6 also provides that crimes defined and penalized by the Revised Penal Code or special laws, when committed through ICT, are covered by the relevant provisions of RA 10175 and generally carry a penalty one degree higher than the ordinary penalty.
Because criminal penalties are technical and offense-specific, a person facing investigation or prosecution should obtain legal advice based on the actual charge rather than relying on a simplified online estimate.
Who Enforces the Cybercrime Prevention Act?
Section 10 identifies the NBI and PNP as the law-enforcement authorities responsible for cybercrime enforcement. Specialized units include the NBI Cybercrime Division and PNP Anti-Cybercrime Group.
The law also created a central DOJ role for international cybercrime cooperation and established the Cybercrime Investigation and Coordinating Center for national coordination.
Does RA 10175 Apply Only to Hackers?
No. The Act is broader than unauthorized hacking. Computer-related fraud, identity theft, online defamation, misuse of devices, and traditional crimes committed through ICT can all fall within the cybercrime framework.
What Should a Cybercrime Victim Do?
- Preserve the original digital evidence.
- Secure affected accounts and devices.
- Contact banks, e-wallets, platforms, telecom providers, or employers when relevant.
- Document losses, threats, transactions and identifiers.
- Report the matter promptly through CICC, PNP-ACG, NBI-CCD, or the proper prosecutor.
Use Where and How to Report Cybercrime in the Philippines for a practical reporting checklist.
Frequently Asked Questions
Is hacking someone’s Facebook account a cybercrime?
Unauthorized access to an account can potentially fall within illegal access under RA 10175, depending on the evidence and circumstances.
Does RA 10175 cover scams?
Online scams can involve computer-related fraud, identity theft, forgery, estafa or other offenses depending on how the scheme operates.
Does the law protect businesses too?
Yes. Cybercrime can target individuals, companies, organizations, databases, networks and critical infrastructure.
Is every offensive online post cyber libel?
No. The legal elements of libel still need to be established. Offensiveness alone is not enough.
Related Cybercrime Guides
- Cybercrime Philippines Hub
- Where and How to Report Cybercrime
- Unauthorized Account Access Philippines
- Computer-Related Identity Theft Philippines
