CyberCode.ph · Philippines

Hacked or Scammed in the Philippines? Help Directory for Banks, Wallets, Telcos and Shopping Apps

Last updated October 5, 2026 · Practical privacy, cybersecurity and technology-law guidance

Hacked, scammed or locked out in the Philippines? The fastest help usually comes from the company that controls the affected account: the bank or wallet can secure a payment account, the telco can secure a SIM, and the platform can restore its own login. Report suspected crime as well, but do not wait for a police case number before asking a provider to stop an active loss. This directory links to official help routes, then shows what to do after a phishing attempt and how to protect each account.

Directory checked 28 September 2026. Service menus and contacts change. Open the official app or type the provider’s domain yourself. This page is a guide, not an incident-reporting desk; do not send CyberCode passwords, OTPs or bank details.

Not sure which of these to contact first? The free Scam or Hack Triage tool gives you an action plan for your situation, with where to report in order.

Banking help: unauthorized transfer, card charge or login

Ask for: immediate protective restriction, a transaction dispute/fraud case, the time your report was received, a reference number, and written next steps. Give the bank the transaction ID, recipient details if visible, amount, time and any scam message. A trace, hold, chargeback or refund is fact-dependent and cannot be promised by a directory.

Provider Official help route Use it when
BPI BPI Contact Us and the BPI app; its published 24-hour contact center is (+632) 889-10000. Unknown transfer, card charge, compromised app or lost card.
BDO BDO official contact page and the BDO app; use the hotline printed on your card or shown on that page. Fraud, unauthorized transaction, phishing or lost card.
Metrobank Metrobank fraud reporting and Contact Us; its fraud page lists (02) 88-700-700 and domestic toll-free 1-800-1888-5775. Unknown debit, card charge, transfer or possible account takeover.
UnionBank UnionBank dispute and support route. Unrecognized banking or card activity; request urgent account protection and a dispute reference.
RCBC RCBC official contacts and 24/7 urgent hotlines, including RCBC Customer Care (02) 8877-7222 and domestic toll-free 1-800-10000-7222. Lost device/card, compromised account or unauthorized transaction.
Another bank or card issuer BSP directory of bank and e-money consumer assistance channels, then cross-check the provider’s app, website or card. Find the institution’s current channel without trusting a search ad or a texted number.

Digital banks: fraud and account access

Provider Official route Useful first request
Maya Bank Maya Bank Contact Us or the Maya app; its page allows after-hours emergency calls for a lost or stolen phone or suspected unauthorized transactions at +632 8845 7788 or toll-free 1800 1084 57788. Secure bank and app access and open a fraud case. Check whether the incident concerns Maya wallet, bank, credit or a linked card.
GoTyme Bank GoTyme help and fraud contact (in-app chat or hotline #GO8888 / #468888, listed as 24/7); fraudulent transfer guide. Report immediately; ask about coordination with the receiving bank and account protection.
Tonik Tonik Contact Us and suspicious transaction guide. Lock the card in app if applicable and report the transaction by in-app chat or Tonik Customer Care at +63 2 5322 2645; its contact page says the fraud hotline is available 24/7.
CIMB Bank PH CIMB Get Help and the CIMB app. Report lost card or suspicious transfer through the urgent route, then submit evidence in app.
MariBank (formerly SeaBank) MariBank scam reporting (chat, or call (+632) 8424 8050) and in-app help. Report scam, unknown transfer or lost security control; ask for a case reference.
UNOBank UNOBank Contact Us or the app; its page says urgent fraud support is 24/7. Secure the account and report the disputed activity.
OwnBank and other BSP-supervised institutions OwnBank Help Center or the BSP consumer-channel directory. Use the institution’s verified current fraud or complaint route; avoid a number supplied by an alleged agent.

“Digital bank,” “wallet,” and “bank account inside an app” can have different legal providers. Identify the institution named in the transaction or account terms, then use its own complaint channel. For an unresolved issue with a BSP-supervised provider, see BSP escalation below.

Digital wallets, payments and other money apps

Service Official help What to report
GCash Unauthorized-transaction report, scam report, and official contact page (hotline 2882 toll-free for Globe/TM mobile, or (02) 7213-9999 for Globe landline; emergencies involving fraud, scams and unauthorized transactions are handled round the clock). Specify whether you authorized a transfer after a scam or did not make the transaction at all; these follow different review paths. GCash’s unauthorized-transaction guide asks you to reset your MPIN and report through in-app chat within 15 days. See CyberCode’s GCash help explainer.
Maya app/wallet Maya official contacts and fraud report; after-hours emergency lines +632 8845 7788, toll-free 1800 1084 57788, or *788 free from Smart. Lost phone, unknown payment or account access; use the emergency route promptly.
ShopeePay ShopeePay unauthorized transaction guidance (24/7 fraud support at shopeepay_fraudsupport_ph@support.shopee.ph; the guide lists the ID, transaction screenshots and narrative to send) and in-app Customer Service. Wallet transaction, linked funding source and any related Shopee order; notify the issuer of a linked card too.
Grab/GrabPay Grab PH Help Centre via the relevant in-app ride, food or payment transaction; Grab security guidance. Unknown booking or charge, lost account access or wallet activity; also notify the card issuer for an unknown card charge.
PayPal PayPal PH fraud guidance and Contact Us. Unauthorized activity or suspected spoof; distinguish a seller dispute from account intrusion.
Other e-money issuers BSP directory plus the provider’s official app. Use a verified fraud channel and keep the transaction and ticket reference.

Mobile apps, phone numbers and SIM incidents

If your signal disappears and you did not request a SIM change, treat a possible SIM swap as urgent. A network outage is possible, so ask the telco to verify the status. Notify linked banks and wallets; changing only the telco password may not stop payment attempts.

Network Official route What it can do
Globe/TM Report lost phone/SIM, SIM replacement, StopSpam reports. Discuss suspension/replacement after identity checks; report scam texts and fake pages. Globe’s lost-SIM page routes prepaid users to a store and postpaid users to Messenger or 211; replacement asks for proof of ownership and a notarized affidavit of loss.
Smart/TNT Lost or stolen phone, SIM replacement. Report the loss by *888 from a Smart line or (02) 8888-1111 by landline; a free same-number SIM replacement is done at a Smart Store by the registered owner with one valid government ID.
DITO DITO Help Center and in-app support. Report a lost SIM, suspected number misuse or account issue; confirm the current verification and replacement process.
Spam/scam text Report to the telco; Globe StopSpam provides an example and links to NTC’s reporting route. Spam reporting may help block a sender; it does not secure a compromised bank account or recover money.

See CyberCode’s SIM swap guide and phone/account warning signs. For app permissions and device security, use the phone manufacturer’s official security settings and update channel.

Shopee, Lazada, Facebook Marketplace and online sellers

Where it happened Official assistance Practical route and limit
Shopee order or seller Shopee Help Center; off-platform payment warning/report. Open the specific order in app and use return/refund or report-seller tools. Preserve chat, listing, order and payment record. If you paid outside Shopee, its order protection may not cover that transfer; contact the payment provider.
Lazada order or seller Lazada PH Help Center and in-app order support. Report through the order and use the applicable return/refund flow; include listing screenshots and delivery evidence. For an unknown card charge, contact the issuer too.
Facebook Marketplace Report a Marketplace scam; Marketplace scam guidance. Report listing, buyer or seller and preserve Messenger/payment evidence. If money was sent directly to a bank/wallet, report there immediately. Marketplace reporting alone does not guarantee a refund.
Independent shop or another marketplace Seller’s official order channel, payment provider, then DTI consumer complaint guidance where the dispute is within DTI’s scope. Ask the merchant for a remedy with a deadline; save the listing, receipt and correspondence. A criminal scam can also be reported to CICC/PNP/NBI.

Important split: A missing or misdescribed item, a fake seller, and an unauthorized card transaction need different tickets. Open the platform case for the order, the payment dispute with the issuer, and a criminal report for suspected fraud where appropriate. DTI may handle consumer transaction complaints; it is not the bank’s chargeback desk.

Email, social accounts, software, computers and servers

Service/surface Official recovery or support First step
Google/Gmail Secure a compromised Google Account. Recover the account, inspect security events and connected apps, remove unfamiliar recovery methods and check Gmail forwarding/filters.
Microsoft/Outlook Microsoft compromised-account guide. Check the PC for malware, then recover and secure the account; inspect recent activity and mail rules.
Apple Account/iPhone Apple Support PH and Apple compromised-account steps. Change the account password, review trusted devices and phone numbers, and protect a lost device.
Facebook and Messenger Facebook hacked-account flow. Try a device previously used to sign in; warn contacts by another channel if scam messages were sent.
Instagram Instagram hacked-account support. Choose the access issue and follow identity verification; beware paid “recovery agents.”
WhatsApp WhatsApp compromised-account guide. Recover control of the phone number/account and alert contacts if messages were sent.
TikTok TikTok login troubleshooting. Choose the hacked-account path; check linked email/phone and signed-in devices.
Steam and games Steam stolen-account support. Scan the device and secure email before recovering the game account.
Laptop/desktop or installed software Employer IT for work devices; official Apple, Microsoft or software-vendor support for personal devices; CERT-PH incident submission for technical incident coordination. Disconnect active malware, preserve evidence and use a clean device for account changes. A technician may need to investigate and rebuild the system.
Website, WordPress, cloud or server Your host/cloud provider’s authenticated support portal and incident team; CERT-PH for incident coordination. Isolate affected services, save logs/snapshots, rotate secrets from a clean system, investigate the entry point and restore a tested backup. See website recovery.

If multiple apps are affected, start with the main email, phone number and password manager. Account recovery can fail if an attacker still controls the email or SIM. A software vendor can help with its product, while a qualified incident responder or internal IT team handles device and server forensics.

Philippine escalation: which agency does what?

See how to report cybercrime and how to preserve electronic evidence. Report a threat to physical safety to local police promptly.

Phishing guide: identify the lure and choose the response

Phishing impersonates a trusted service to obtain a password, one-time code, payment approval or software installation. It may arrive by email, SMS (“smishing”), call (“vishing”), social DM, QR code, sponsored search result or a fake support page. A genuine brand logo or sender name is not proof; an attacker can copy it. A fake “delivery fee,” “account suspension,” “SIM expiry,” “refund,” “job interview” or “security check” tries to rush a decision.

  1. Pause and inspect. Check the full domain and destination, sender address and unusual payment or OTP request. A shortened link or misspelled domain deserves extra care, but a normal-looking link can still be unsafe.
  2. Open the app yourself. Do not use the message’s link or phone number to verify the message. Type the known website or use a bookmarked app, then check account notices or contact support.
  3. Do not hand over codes or approve prompts. An OTP, password, passkey prompt or MFA approval is part of access or payment authorization. Decline any prompt you did not initiate.
  4. Respond to what you actually did: merely viewing a page, typing a password, entering an OTP, approving a payment, installing an app or giving remote control have different risks. Use the matrix below.
  5. Report and retain evidence. Save the message and URL without reposting it as a clickable lure. Use the brand’s phishing channel, telco spam route and CICC/law enforcement where a crime or loss occurred.

Our clicked-a-phishing-link guide gives a fuller first-hour checklist.

Phishing response and protection matrix

What happened Immediate action Next protection / expected help
Message received, nothing opened Do not reply or click. Verify in the official app and report the lure. Block sender after preserving evidence; review alerts. A message alone does not prove compromise.
Link opened, no information entered or file installed Close the page. Check browser downloads and device/app updates; watch account activity. Usually focus on verification and monitoring; escalate if an unexpected download, login or charge appears.
Password typed into fake page On a clean device change that password and every reused copy; revoke sessions, check recovery details and turn on MFA. Provider’s recovery/security tools can restrict account access; check email rules and connected apps.
OTP given, MFA approved or QR login scanned Contact the relevant bank/app immediately if payment or financial access is involved; revoke sessions, change credentials and inspect activity. Ask for protective restriction and a fraud case. Do not assume changing the password alone cancels an approved transaction.
Card details entered or money sent Call the card issuer or sending institution immediately to block/dispute/trace; contact receiving platform if known. Keep transaction IDs and report suspected fraud. A reversal depends on payment method and investigation.
App/file installed or remote access given Disconnect the device from networks and end remote access; call bank from another device; ask IT/qualified support to examine it. Rebuild if warranted, rotate credentials from a clean device, restore verified files and monitor for follow-on access.
Work mailbox or server affected Alert the incident lead, isolate affected systems, preserve logs and warn relevant payment approvers. Investigate scope, containment, recovery and applicable privacy notification. See business cyberattack response.

Priority protection checklist

Priority Protection Where to apply it
1 Unique passwords in a manager; MFA/passkeys; recovery codes stored separately. Main email, bank/wallet, shopping and social accounts.
2 Transaction and login alerts, card controls and a known official fraud contact saved in advance. All financial apps and cards.
3 Automatic updates, screen lock, encryption and limited app permissions; install from trusted sources. Phone, laptop, browser and apps.
4 Confirm invoice changes, urgent transfers and support calls using a previously known channel. Shopping, Marketplace, work email and family messaging.
5 Versioned/offline backups, least-privilege admin access, patched plugins and retained logs. Computer, website and server.

CISA’s Secure Our World campaign covers passwords, MFA, updates and phishing recognition. For a Philippine business, also use CyberCode’s website security and backup and recovery guides.

What to include in every help request

  • Your own account identifier, affected service and a safe callback method; never put the password, complete card number or OTP in a public post.
  • Transaction IDs, amount, receiving account information as shown, order number, date/time in Philippine time and when you first noticed the issue.
  • Original email/message, sender, URL, screenshot and what action you took; attach files only through the provider’s verified secure form.
  • The exact relief sought: block card/account, preserve records, investigate transaction, recover login, refund/return an order, or issue a written outcome.
  • Case numbers and replies from every provider and agency, kept in one timeline for follow-up and escalation.

Frequently asked questions

Can a platform or agency guarantee my money back?

No. A provider may restrict access, investigate, trace a transfer or process a dispute; a regulator may review or refer an unresolved complaint; police may investigate suspected crime. Outcomes depend on evidence, timing, payment route and applicable rules.

Who should I call first after a Facebook Marketplace payment scam?

Contact the sending bank or wallet immediately, then report the buyer/seller and listing through Facebook Marketplace. Keep the Messenger thread, profile URL, listing and payment reference. If you suspect criminal fraud, report it to CICC or law enforcement. Facebook reporting by itself is not a bank transfer reversal.

Should I post screenshots of the scammer publicly?

Preserve originals for the platform, provider and investigators. Publicly posting IDs, phone numbers, account details or a live phishing link can expose private data or spread the lure. Redact details if you warn others.

My case is not listed. Where do I begin?

Go to the affected service’s official app or website and search for “security,” “fraud,” “unauthorized transaction,” “account recovery” or “help.” If funds moved, notify the issuer first. The BSP directory covers many supervised financial institutions. For suspected cybercrime, CyberCode’s agency directory explains the reporting route.

Source and maintenance notes

Provider links in the tables lead to their own official support pages. Government routes are drawn from BSP Consumer Assistance, DTI complaint guidance, DICT CERT-PH and NPC. CyberCode checked these pathways, and every phone number shown, against the providers’ and agencies’ own pages on 28 September 2026. Other sources used: PNA on the CICC 1326 hotline, the NBI Citizen’s Charter and the BSP AFASA booklet. Recheck the provider’s own site at the moment of an incident; this directory deliberately favors stable help pages over copied contact lists.

Related articles

Related: Money lost to an investment or crypto scheme has its own three-lane route — see investment or crypto scam: how to report it and what the SEC can do.

Related: Money lost to a fake online job or a “like and earn” task app has its own route too, and it is not the same as illegal recruitment — see job or task scam in the Philippines.

Disclaimer: General information, not legal advice, an emergency hotline or a guarantee of recovery. Support routes, provider terms and regulations can change. Verify urgent contact details directly with the institution and seek qualified technical or legal advice for a serious incident.

Related: one problem that belongs in no other entry in this directory is a payment you addressed wrongly yourself. It is neither a hack nor a scam, and the usual routes do not reach it — see sending money to the wrong recipient on InstaPay for the one institution that owes you an answer and the civil claim behind it.

Sources rechecked as of: 28 September 2026

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.