Think you have been hacked in the Philippines? Start with the asset that can cause the fastest further harm. If money is moving, call your bank or e-wallet through its official app or number immediately. If a device may have malware, disconnect it from Wi-Fi and mobile data. If an account was taken over, use a different, trusted device to start the platform’s recovery process. Save evidence as you go, then report to the right agency. A suspicious message alone does not prove a hack.
Hacked? Your first 15 minutes
- Stop the damage. Contact the bank or e-wallet about unauthorized transactions and ask it to secure the account and trace or dispute the transfer. If a phone number suddenly stops working, call your telco about a possible SIM swap. Disconnect an infected laptop or server from the network; do not delete logs or format a business device before the incident team can assess it.
- Secure the keys from a clean device. Recover the main email first, then banking, messaging, social, work and cloud accounts. Change reused passwords, sign out other sessions, remove unknown recovery methods and forwarding rules, and turn on multifactor authentication (MFA).
- Record what happened. Keep screenshots, transaction and reference numbers, URLs, sender addresses, phone numbers, timestamps in Philippine time, and the original messages. Write a short timeline. Do not send passwords or one-time codes to anyone offering “recovery.”
- Report through the right channel. The service provider can lock or restore its own account. CICC’s 1326 hotline can receive and route a cybercrime complaint; PNP Anti-Cybercrime Group or NBI can investigate suspected crime. A company with affected personal data may also have National Privacy Commission obligations.
If you clicked a link, the response depends on whether you merely opened a page, entered credentials, installed software, or approved a payment. Use the first-hour phishing guide to sort those cases.
Not sure where to start? Use the free Scam or Hack Triage tool. Answer one or two questions and it gives you an action plan for your situation: first steps, evidence to keep and where to report.
Follow the flow: what was hit?
Money or SIM
First: bank/e-wallet or telco’s official support. Ask for a case number and protective action. Next: preserve the transaction trail and report suspected fraud to CICC or law enforcement. Escalate an unresolved complaint against a BSP-supervised provider to BSP.
Email or social account
First: the provider’s official account-recovery page from a trusted device. Review sessions, recovery addresses, app access and mail forwarding. Warn contacts if the account sent scam messages. Next: report impersonation or illegal access if appropriate.
Laptop or phone
First: isolate a device showing active malware behavior, then secure linked accounts elsewhere. An employer’s IT team should handle work devices. Next: preserve evidence and obtain qualified technical help before reinstalling if investigation matters.
Website or server
First: contact the host and incident lead to isolate compromised services, preserve snapshots and logs, and protect backups. Next: investigate the entry point, rotate credentials from clean systems, restore a verified copy and assess data exposure and reporting duties.
How big is the problem? Read the numbers carefully
The Cybercrime Investigation and Coordinating Center’s 2024 figures reported by the Philippine News Agency show 10,004 complaints to CICC, up from 3,317 in 2023, and almost ₱198 million in losses reported by victims in that 2024 set. Of the 10,004, 3,534 were classified as consumer fraud and 3,242 as online fraud. These are complaints received by CICC, not a count of all Philippine hacks, a national total of scam losses, or proof that every complaint involved a hacked device. More awareness and reporting can also raise complaint counts.
Fraud may start with a fake seller, job offer, investment pitch or impersonated contact. A technical takeover may start with a reused password, a phishing login page, malicious software, an exposed server or a stolen recovery code. The CICC categories do not reveal a percentage for each entry method. The impacts extend beyond stolen money: lost access, identity misuse, disrupted work, customer notification, recovery costs and further scams sent from trusted accounts.
Who can help in the Philippines, and what should you expect?
| Where to go | Best for | Likely help and realistic limit |
|---|---|---|
| Bank/e-wallet, then BSP Consumer Assistance | Unauthorized payment or financial account access | The provider can secure the account, examine the transaction and handle a dispute; contact it immediately. If its response is unresolved, BSP’s consumer mechanism can evaluate and refer a complaint involving a supervised institution. A case number or referral is not a promise that funds will be returned. |
| Platform, email provider, telco or employer IT | Account lockout, SIM swap, compromised work system | These operators control their own recovery, account restriction, SIM and system access. Use their official app/site or a number on a statement, not a link sent by the alleged helper. Restoration depends on verification and the provider’s findings. |
| CICC Inter-Agency Response Center: 1326 | Initial cybercrime or scam report; unsure where to start | The CICC’s Inter-Agency Response Center describes 1326 as a 24/7 hotline for reporting scams; it can receive a complaint and coordinate or refer it. Record your reference number. It cannot itself guarantee a refund or reset a platform account. |
| PNP Anti-Cybercrime Group or NBI Cybercrime Division | Suspected illegal access, identity theft, fraud or extortion | Law-enforcement intake and possible investigation, evidence preservation and lawful process. Under the NBI Citizen’s Charter, a complainant files at the Cybercrime Division, is interviewed by an agent who helps complete a sworn complaint, and pays no fee. Evidence and jurisdiction affect next steps; an investigation does not assure identification, prosecution or recovery. |
| DICT CERT-PH | Technical incident reporting and coordination, especially organizations | Receives and reviews computer-security incident reports and coordinates technical response and advisories. It is not a guaranteed personal device repair service or criminal investigator. |
| National Privacy Commission | Potential exposure of personal data by an organization; data-subject privacy complaint | Privacy oversight and its breach-notification system. Organizational notification is required when the NPC’s legal test is met; a personal account takeover does not automatically trigger an NPC breach report. A data subject can use the NPC’s complaint process. |
For addresses and more complaint routes, use CyberCode’s Philippine cybercrime reporting directory; for the official fraud lines of specific banks, e-wallets, telcos and shopping apps, see the hacked or scammed help directory. If there is a direct physical threat or extortion, contact local police promptly as well. Preserve the original evidence; avoid publishing another person’s private details in an attempt to investigate yourself.
Bank or e-wallet money taken: your rights under AFASA
If the hack reached a bank, e-wallet or other BSP-supervised financial account, the Anti-Financial Account Scamming Act (Republic Act No. 12010 (our RA 12010 explainer), approved 20 July 2024) matters for three reasons:
- Funds can be held quickly. Section 7 lets the institution temporarily hold funds subject of a disputed transaction, for the period BSP prescribes but not more than 30 calendar days unless a court extends it. A complaint from the aggrieved party is one of the listed triggers, which is why a fast report to your provider matters (BSP AFASA booklet, Sec. 7).
- Restitution is possible, not automatic. Section 6 makes institutions liable to restore funds to account owners when they fail to employ adequate risk-management systems and controls or fail to exercise the highest degree of diligence in preventing loss from the offenses the law defines (Sec. 6). Whether that standard was breached is decided on the facts, so ask the provider for its written findings.
- BSP can investigate. Section 12 gives BSP authority to investigate and inquire into financial accounts that may be involved in a prohibited act. Your route to BSP as a consumer is still its consumer assistance channels (BSP Online Buddy chatbot, or the Complaints, Inquiries and Requests form by email to consumeraffairs@bsp.gov.ph).
See CyberCode’s GCash scam and account-problem guide or the Maya scam and phishing guide for a wallet-specific walk-through.
What to do next: deadlines and your first action
- First action now: call or message the provider that controls the affected account (bank, e-wallet, telco, email or platform) through its official app or a number you already trust, and get a reference number.
- Within the same day: write the timeline, save the evidence listed below, and report to CICC 1326 or file with PNP-ACG or NBI if a crime or loss is involved.
- Deadlines: for individuals, no fixed legal deadline to report a hack to CICC, PNP or NBI was verified, but a disputed-transaction hold under AFASA cannot exceed 30 calendar days without a court order, so delay can cost you. Organizations whose incident is a notifiable personal data breach must notify the NPC within 72 hours of knowledge or reasonable belief of the breach (NPC breach reporting).
- If the provider does not resolve it: escalate a bank or e-wallet complaint to BSP with the provider’s reply attached; a personal-data complaint against an organization goes to the NPC complaint process; a criminal case goes through PNP-ACG or NBI to the prosecutor.
Typical situations: signs, first response and fix
| Situation and likely route in | What to do now | What a resolution looks like |
|---|---|---|
| Email takeover: unexpected login notice, changed password, scam mail from your address. A phishing page or reused password is possible. | Recover via the provider, revoke sessions, remove unfamiliar forwarding rules and connected apps, change reused passwords and alert contacts. | Access restored and unauthorized sessions removed; watch for downstream resets and payment changes. See the password guide. |
| Phone/SIM: sudden loss of signal with bank OTPs or account changes. This may be a SIM swap; ordinary network failure is also possible. | Call the telco and bank from another phone, ask to secure the number and accounts, document the interruption and transactions. | Number and account control restored after identity checks; disputed transfers investigated. See SIM swap fraud. |
| Laptop malware: suspicious download, security warning, unusual processes or encrypted files. | Disconnect the affected device; use a clean one for account changes. Tell work IT. Save relevant messages and alerts; get professional triage if data or evidence is important. | Malware removed or system rebuilt from a trusted image, credentials rotated, data restored from a clean backup. See malware response. |
| Social account impersonation: friends receive a payment request from your profile or a fake copy. | Use platform recovery or impersonation reporting, save profile URLs/screenshots, warn contacts by a separate channel. | Account recovered or fake profile reviewed by the platform; victims of payments also contact their provider. See Facebook recovery. |
| Business email invoice change: a supplier’s “new account” request may be a spoofed or compromised mailbox. | Verify using a known phone number, stop payment if possible, ask bank to trace a sent transfer, preserve full email headers and notify both businesses’ IT teams. | Payment route corrected, mailbox and forwarding rules secured, fraud assessed. See business email compromise. |
| Server or software compromise: site defacement, unknown admin, ransomware note or odd outbound traffic. A vulnerable plugin or exposed credential may be involved. | Isolate with the host, preserve logs and snapshots, protect backups, investigate before reconnecting and assess whether customer data was accessed. | Entry point fixed, clean restore and monitoring in place; applicable notification handled. See website recovery and breach notification rules. |
Priority checklist: prevent the next incident
- Protect the main email and financial accounts first. Give each account a unique password in a password manager; turn on MFA, ideally a passkey or security key where supported. Review recovery phone/email, active sessions and transaction alerts.
- Update devices and software. Enable automatic operating-system, browser, app, router, plugin and server updates. Remove software you no longer use.
- Keep recoverable backups. Maintain a separate, versioned or offline copy of important files and test a restore. A sync service alone can copy encrypted or deleted files too.
- Verify high-risk requests out of band. Call a known number for a bank alert, invoice change, urgent payment or “support” message. Never give anyone a one-time code or approve an MFA prompt you did not initiate.
- Limit access and watch for changes. Give admin rights only when needed, enable login and payment notices, review app permissions, and remove former users and unused integrations.
Device and system setup guide
| Surface | Settings and habits to prioritize | Recovery preparation |
|---|---|---|
| Mobile phone | Strong screen lock and biometrics; OS updates; install from trusted stores; review app permissions; enable find/lock/erase controls; set a SIM PIN where appropriate. | Back up photos and essential data; keep account recovery codes somewhere separate. Review phone/account warning signs. |
| Laptop/desktop | Automatic security updates, built-in antivirus, disk encryption, screen lock and a standard daily user account. Avoid untrusted attachments and pirated installers. | Keep versioned backups and a known-good restore path; know who handles work devices. |
| Email and apps | Unique passwords plus MFA/passkeys; check forwarding, recovery methods, sessions, OAuth access and connected apps. Turn on security notifications. | Store recovery codes securely; verify contacts and payment changes independently. |
| Website/server | Patch OS, CMS, plugins and dependencies; require MFA for control panels; minimize admin and remote access; rotate secrets; monitor logs and known exploited vulnerabilities. | Test isolated backups, retain logs, document host and incident contacts. Use the WordPress security checklist where relevant. |
These are risk-reduction steps, not a guarantee. CISA’s Secure Our World guidance emphasizes strong passwords/password managers, MFA, software updates and phishing recognition.
Where to watch for new warnings
- CERT-PH Alerts and Tips for Philippine technical advisories and incident reporting. Check the exact
ncert.gov.phdomain; fake CERT messages exist. - CISA Known Exploited Vulnerabilities catalog for actively exploited software flaws; server admins should pair it with vendor patch advisories and their own asset list.
- Official bank, telco, platform, operating-system and hosting-provider security notices for account or product-specific action. Open the app or type the official address yourself instead of following an alert’s link.
- NPC advisories for data-privacy issues and CyberCode for Philippine explainers; confirm urgent actions against the primary agency or vendor notice.
Evidence and action: what to keep
For providers
Account identifier, device details, last legitimate access, unauthorized transaction IDs, dates and the protective action requested. Keep the ticket or complaint reference.
For investigators
Original emails and messages, URLs, screenshots with dates, payment records, relevant logs and a plain-language timeline. Preserve originals and note how copies were made. See electronic evidence.
For organizations
System scope, discovery time, containment actions, logs, affected data and decision owners. Assess NPC notification against the actual legal test and clock; do not assume every incident is notifiable.
Frequently asked questions
Can 1326 get my money back or retrieve my Facebook account?
It is an intake and coordination route, not a guaranteed refund or platform recovery service. Contact the bank/e-wallet or platform first for actions only it can perform, then keep the CICC reference for reporting.
Should I wipe my phone or laptop immediately?
Usually secure accounts and isolate an actively affected device first. A wipe can destroy evidence and leave the compromised cloud account open. Ask your IT or a qualified responder before resetting a business device or a device relevant to a complaint.
Does a data breach have to be reported within 72 hours?
For organizations, the NPC’s mandatory notification rules apply when its stated conditions are met; the deadline follows the relevant knowledge or reasonable-belief trigger. A private individual’s suspicious login is not automatically that type of report. Read the NPC’s breach guidance and get case-specific advice.
Sources and scope
- Philippine News Agency, CICC 2024 complaint and loss figures (31 January 2025).
- DICT CERT-PH, mandate and role; incident submission.
- Philippine News Agency, CICC Inter-Agency Response Center hotline 1326 (14 August 2023).
- Republic Act No. 12010 (Anti-Financial Account Scamming Act), Official Gazette; BSP AFASA booklet with implementing rules.
- NBI Citizen’s Charter, investigative assistance for victims of computer crimes.
- BSP, consumer assistance and escalation.
- NPC, breach reporting and mandatory-notification criteria.
- CISA, Secure Our World and Known Exploited Vulnerabilities.
Related articles
- Cyber incident response: ransomware, phishing and hacked accounts compared
- Where and how to report cybercrime in the Philippines
- Clicked a phishing link? First-hour steps
- What to do after a business cyberattack
Disclaimer: This is general security and Philippine reporting information as of 28 September 2026, not legal advice, forensic diagnosis or a promise of account or fund recovery. Provider processes and government channels can change; verify them on official sites for your case.
Related: unauthorised e-wallet transactions and how to dispute them, if money left a wallet during the compromise.
Sources rechecked as of: 28 September 2026

