CyberCode.ph · Philippines

Hacked in the Philippines? First 15 Minutes, Who Can Help, and How to Recover

Last updated October 1, 2026 · Practical privacy, cybersecurity and technology-law guidance

Think you have been hacked in the Philippines? Start with the asset that can cause the fastest further harm. If money is moving, call your bank or e-wallet through its official app or number immediately. If a device may have malware, disconnect it from Wi-Fi and mobile data. If an account was taken over, use a different, trusted device to start the platform’s recovery process. Save evidence as you go, then report to the right agency. A suspicious message alone does not prove a hack.

Not sure where to start? Use the free Scam or Hack Triage tool. Answer one or two questions and it gives you an action plan for your situation: first steps, evidence to keep and where to report.

Follow the flow: what was hit?

How big is the problem? Read the numbers carefully

The Cybercrime Investigation and Coordinating Center’s 2024 figures reported by the Philippine News Agency show 10,004 complaints to CICC, up from 3,317 in 2023, and almost ₱198 million in losses reported by victims in that 2024 set. Of the 10,004, 3,534 were classified as consumer fraud and 3,242 as online fraud. These are complaints received by CICC, not a count of all Philippine hacks, a national total of scam losses, or proof that every complaint involved a hacked device. More awareness and reporting can also raise complaint counts.

Fraud may start with a fake seller, job offer, investment pitch or impersonated contact. A technical takeover may start with a reused password, a phishing login page, malicious software, an exposed server or a stolen recovery code. The CICC categories do not reveal a percentage for each entry method. The impacts extend beyond stolen money: lost access, identity misuse, disrupted work, customer notification, recovery costs and further scams sent from trusted accounts.

Who can help in the Philippines, and what should you expect?

Where to go Best for Likely help and realistic limit
Bank/e-wallet, then BSP Consumer Assistance Unauthorized payment or financial account access The provider can secure the account, examine the transaction and handle a dispute; contact it immediately. If its response is unresolved, BSP’s consumer mechanism can evaluate and refer a complaint involving a supervised institution. A case number or referral is not a promise that funds will be returned.
Platform, email provider, telco or employer IT Account lockout, SIM swap, compromised work system These operators control their own recovery, account restriction, SIM and system access. Use their official app/site or a number on a statement, not a link sent by the alleged helper. Restoration depends on verification and the provider’s findings.
CICC Inter-Agency Response Center: 1326 Initial cybercrime or scam report; unsure where to start The CICC’s Inter-Agency Response Center describes 1326 as a 24/7 hotline for reporting scams; it can receive a complaint and coordinate or refer it. Record your reference number. It cannot itself guarantee a refund or reset a platform account.
PNP Anti-Cybercrime Group or NBI Cybercrime Division Suspected illegal access, identity theft, fraud or extortion Law-enforcement intake and possible investigation, evidence preservation and lawful process. Under the NBI Citizen’s Charter, a complainant files at the Cybercrime Division, is interviewed by an agent who helps complete a sworn complaint, and pays no fee. Evidence and jurisdiction affect next steps; an investigation does not assure identification, prosecution or recovery.
DICT CERT-PH Technical incident reporting and coordination, especially organizations Receives and reviews computer-security incident reports and coordinates technical response and advisories. It is not a guaranteed personal device repair service or criminal investigator.
National Privacy Commission Potential exposure of personal data by an organization; data-subject privacy complaint Privacy oversight and its breach-notification system. Organizational notification is required when the NPC’s legal test is met; a personal account takeover does not automatically trigger an NPC breach report. A data subject can use the NPC’s complaint process.

For addresses and more complaint routes, use CyberCode’s Philippine cybercrime reporting directory; for the official fraud lines of specific banks, e-wallets, telcos and shopping apps, see the hacked or scammed help directory. If there is a direct physical threat or extortion, contact local police promptly as well. Preserve the original evidence; avoid publishing another person’s private details in an attempt to investigate yourself.

Bank or e-wallet money taken: your rights under AFASA

If the hack reached a bank, e-wallet or other BSP-supervised financial account, the Anti-Financial Account Scamming Act (Republic Act No. 12010 (our RA 12010 explainer), approved 20 July 2024) matters for three reasons:

  • Funds can be held quickly. Section 7 lets the institution temporarily hold funds subject of a disputed transaction, for the period BSP prescribes but not more than 30 calendar days unless a court extends it. A complaint from the aggrieved party is one of the listed triggers, which is why a fast report to your provider matters (BSP AFASA booklet, Sec. 7).
  • Restitution is possible, not automatic. Section 6 makes institutions liable to restore funds to account owners when they fail to employ adequate risk-management systems and controls or fail to exercise the highest degree of diligence in preventing loss from the offenses the law defines (Sec. 6). Whether that standard was breached is decided on the facts, so ask the provider for its written findings.
  • BSP can investigate. Section 12 gives BSP authority to investigate and inquire into financial accounts that may be involved in a prohibited act. Your route to BSP as a consumer is still its consumer assistance channels (BSP Online Buddy chatbot, or the Complaints, Inquiries and Requests form by email to consumeraffairs@bsp.gov.ph).

See CyberCode’s GCash scam and account-problem guide or the Maya scam and phishing guide for a wallet-specific walk-through.

What to do next: deadlines and your first action

  • First action now: call or message the provider that controls the affected account (bank, e-wallet, telco, email or platform) through its official app or a number you already trust, and get a reference number.
  • Within the same day: write the timeline, save the evidence listed below, and report to CICC 1326 or file with PNP-ACG or NBI if a crime or loss is involved.
  • Deadlines: for individuals, no fixed legal deadline to report a hack to CICC, PNP or NBI was verified, but a disputed-transaction hold under AFASA cannot exceed 30 calendar days without a court order, so delay can cost you. Organizations whose incident is a notifiable personal data breach must notify the NPC within 72 hours of knowledge or reasonable belief of the breach (NPC breach reporting).
  • If the provider does not resolve it: escalate a bank or e-wallet complaint to BSP with the provider’s reply attached; a personal-data complaint against an organization goes to the NPC complaint process; a criminal case goes through PNP-ACG or NBI to the prosecutor.

Typical situations: signs, first response and fix

Situation and likely route in What to do now What a resolution looks like
Email takeover: unexpected login notice, changed password, scam mail from your address. A phishing page or reused password is possible. Recover via the provider, revoke sessions, remove unfamiliar forwarding rules and connected apps, change reused passwords and alert contacts. Access restored and unauthorized sessions removed; watch for downstream resets and payment changes. See the password guide.
Phone/SIM: sudden loss of signal with bank OTPs or account changes. This may be a SIM swap; ordinary network failure is also possible. Call the telco and bank from another phone, ask to secure the number and accounts, document the interruption and transactions. Number and account control restored after identity checks; disputed transfers investigated. See SIM swap fraud.
Laptop malware: suspicious download, security warning, unusual processes or encrypted files. Disconnect the affected device; use a clean one for account changes. Tell work IT. Save relevant messages and alerts; get professional triage if data or evidence is important. Malware removed or system rebuilt from a trusted image, credentials rotated, data restored from a clean backup. See malware response.
Social account impersonation: friends receive a payment request from your profile or a fake copy. Use platform recovery or impersonation reporting, save profile URLs/screenshots, warn contacts by a separate channel. Account recovered or fake profile reviewed by the platform; victims of payments also contact their provider. See Facebook recovery.
Business email invoice change: a supplier’s “new account” request may be a spoofed or compromised mailbox. Verify using a known phone number, stop payment if possible, ask bank to trace a sent transfer, preserve full email headers and notify both businesses’ IT teams. Payment route corrected, mailbox and forwarding rules secured, fraud assessed. See business email compromise.
Server or software compromise: site defacement, unknown admin, ransomware note or odd outbound traffic. A vulnerable plugin or exposed credential may be involved. Isolate with the host, preserve logs and snapshots, protect backups, investigate before reconnecting and assess whether customer data was accessed. Entry point fixed, clean restore and monitoring in place; applicable notification handled. See website recovery and breach notification rules.

Priority checklist: prevent the next incident

  1. Protect the main email and financial accounts first. Give each account a unique password in a password manager; turn on MFA, ideally a passkey or security key where supported. Review recovery phone/email, active sessions and transaction alerts.
  2. Update devices and software. Enable automatic operating-system, browser, app, router, plugin and server updates. Remove software you no longer use.
  3. Keep recoverable backups. Maintain a separate, versioned or offline copy of important files and test a restore. A sync service alone can copy encrypted or deleted files too.
  4. Verify high-risk requests out of band. Call a known number for a bank alert, invoice change, urgent payment or “support” message. Never give anyone a one-time code or approve an MFA prompt you did not initiate.
  5. Limit access and watch for changes. Give admin rights only when needed, enable login and payment notices, review app permissions, and remove former users and unused integrations.

Device and system setup guide

Surface Settings and habits to prioritize Recovery preparation
Mobile phone Strong screen lock and biometrics; OS updates; install from trusted stores; review app permissions; enable find/lock/erase controls; set a SIM PIN where appropriate. Back up photos and essential data; keep account recovery codes somewhere separate. Review phone/account warning signs.
Laptop/desktop Automatic security updates, built-in antivirus, disk encryption, screen lock and a standard daily user account. Avoid untrusted attachments and pirated installers. Keep versioned backups and a known-good restore path; know who handles work devices.
Email and apps Unique passwords plus MFA/passkeys; check forwarding, recovery methods, sessions, OAuth access and connected apps. Turn on security notifications. Store recovery codes securely; verify contacts and payment changes independently.
Website/server Patch OS, CMS, plugins and dependencies; require MFA for control panels; minimize admin and remote access; rotate secrets; monitor logs and known exploited vulnerabilities. Test isolated backups, retain logs, document host and incident contacts. Use the WordPress security checklist where relevant.

These are risk-reduction steps, not a guarantee. CISA’s Secure Our World guidance emphasizes strong passwords/password managers, MFA, software updates and phishing recognition.

Where to watch for new warnings

  • CERT-PH Alerts and Tips for Philippine technical advisories and incident reporting. Check the exact ncert.gov.ph domain; fake CERT messages exist.
  • CISA Known Exploited Vulnerabilities catalog for actively exploited software flaws; server admins should pair it with vendor patch advisories and their own asset list.
  • Official bank, telco, platform, operating-system and hosting-provider security notices for account or product-specific action. Open the app or type the official address yourself instead of following an alert’s link.
  • NPC advisories for data-privacy issues and CyberCode for Philippine explainers; confirm urgent actions against the primary agency or vendor notice.

Evidence and action: what to keep

Frequently asked questions

Can 1326 get my money back or retrieve my Facebook account?

It is an intake and coordination route, not a guaranteed refund or platform recovery service. Contact the bank/e-wallet or platform first for actions only it can perform, then keep the CICC reference for reporting.

Should I wipe my phone or laptop immediately?

Usually secure accounts and isolate an actively affected device first. A wipe can destroy evidence and leave the compromised cloud account open. Ask your IT or a qualified responder before resetting a business device or a device relevant to a complaint.

Does a data breach have to be reported within 72 hours?

For organizations, the NPC’s mandatory notification rules apply when its stated conditions are met; the deadline follows the relevant knowledge or reasonable-belief trigger. A private individual’s suspicious login is not automatically that type of report. Read the NPC’s breach guidance and get case-specific advice.

Sources and scope

Related articles

Disclaimer: This is general security and Philippine reporting information as of 28 September 2026, not legal advice, forensic diagnosis or a promise of account or fund recovery. Provider processes and government channels can change; verify them on official sites for your case.

Related: unauthorised e-wallet transactions and how to dispute them, if money left a wallet during the compromise.

Sources rechecked as of: 28 September 2026

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.