Hacked, scammed or locked out in the Philippines? The fastest help usually comes from the company that controls the affected account: the bank or wallet can secure a payment account, the telco can secure a SIM, and the platform can restore its own login. Report suspected crime as well, but do not wait for a police case number before asking a provider to stop an active loss. This directory links to official help routes, then shows what to do after a phishing attempt and how to protect each account.
Directory checked 28 September 2026. Service menus and contacts change. Open the official app or type the provider’s domain yourself. This page is a guide, not an incident-reporting desk; do not send CyberCode passwords, OTPs or bank details.
Start here: the first-response route
- Money leaving? Call the issuing bank, wallet or card provider now using the app or the number on your card. Ask to block the account/card, investigate the transaction and, where possible, coordinate with the receiving institution. Record the case number. If a purchase was made on a marketplace, open its order dispute too. Speed matters: a disputed-transaction hold under the Anti-Financial Account Scamming Act lasts at most 30 calendar days without a court order, and some providers set their own reporting windows (GCash, for example, asks for unauthorized-transaction reports within 15 days).
- Phone or SIM lost, or signal vanished unexpectedly? Ask the telco to secure or suspend the SIM, then warn the bank/wallet of possible account takeover. Protect email and accounts linked to that number.
- Email, social or shopping account taken? Use its official recovery page from a known clean device. Change the linked email password first, revoke sessions, remove unfamiliar recovery details and turn on MFA.
- Malware or server intrusion? Isolate the affected device or service with your IT/host, preserve logs and backups, and secure connected accounts from another device. Do not wipe a work system before triage.
- Then report and escalate. Keep original messages, URLs, transaction IDs, timestamps, screenshots, ticket numbers and a timeline. CICC’s 1326 hotline receives cybercrime complaints; PNP Anti-Cybercrime Group or NBI may investigate suspected crimes. Use the right regulator for an unresolved provider complaint.
For a more detailed first-hour flow, see Hacked in the Philippines? First 15 Minutes, Who Can Help, and How to Recover.
Not sure which of these to contact first? The free Scam or Hack Triage tool gives you an action plan for your situation, with where to report in order.
Banking help: unauthorized transfer, card charge or login
Ask for: immediate protective restriction, a transaction dispute/fraud case, the time your report was received, a reference number, and written next steps. Give the bank the transaction ID, recipient details if visible, amount, time and any scam message. A trace, hold, chargeback or refund is fact-dependent and cannot be promised by a directory.
| Provider | Official help route | Use it when |
|---|---|---|
| BPI | BPI Contact Us and the BPI app; its published 24-hour contact center is (+632) 889-10000. | Unknown transfer, card charge, compromised app or lost card. |
| BDO | BDO official contact page and the BDO app; use the hotline printed on your card or shown on that page. | Fraud, unauthorized transaction, phishing or lost card. |
| Metrobank | Metrobank fraud reporting and Contact Us; its fraud page lists (02) 88-700-700 and domestic toll-free 1-800-1888-5775. | Unknown debit, card charge, transfer or possible account takeover. |
| UnionBank | UnionBank dispute and support route. | Unrecognized banking or card activity; request urgent account protection and a dispute reference. |
| RCBC | RCBC official contacts and 24/7 urgent hotlines, including RCBC Customer Care (02) 8877-7222 and domestic toll-free 1-800-10000-7222. | Lost device/card, compromised account or unauthorized transaction. |
| Another bank or card issuer | BSP directory of bank and e-money consumer assistance channels, then cross-check the provider’s app, website or card. | Find the institution’s current channel without trusting a search ad or a texted number. |
Digital banks: fraud and account access
| Provider | Official route | Useful first request |
|---|---|---|
| Maya Bank | Maya Bank Contact Us or the Maya app; its page allows after-hours emergency calls for a lost or stolen phone or suspected unauthorized transactions at +632 8845 7788 or toll-free 1800 1084 57788. | Secure bank and app access and open a fraud case. Check whether the incident concerns Maya wallet, bank, credit or a linked card. |
| GoTyme Bank | GoTyme help and fraud contact (in-app chat or hotline #GO8888 / #468888, listed as 24/7); fraudulent transfer guide. | Report immediately; ask about coordination with the receiving bank and account protection. |
| Tonik | Tonik Contact Us and suspicious transaction guide. | Lock the card in app if applicable and report the transaction by in-app chat or Tonik Customer Care at +63 2 5322 2645; its contact page says the fraud hotline is available 24/7. |
| CIMB Bank PH | CIMB Get Help and the CIMB app. | Report lost card or suspicious transfer through the urgent route, then submit evidence in app. |
| MariBank (formerly SeaBank) | MariBank scam reporting (chat, or call (+632) 8424 8050) and in-app help. | Report scam, unknown transfer or lost security control; ask for a case reference. |
| UNOBank | UNOBank Contact Us or the app; its page says urgent fraud support is 24/7. | Secure the account and report the disputed activity. |
| OwnBank and other BSP-supervised institutions | OwnBank Help Center or the BSP consumer-channel directory. | Use the institution’s verified current fraud or complaint route; avoid a number supplied by an alleged agent. |
“Digital bank,” “wallet,” and “bank account inside an app” can have different legal providers. Identify the institution named in the transaction or account terms, then use its own complaint channel. For an unresolved issue with a BSP-supervised provider, see BSP escalation below.
Digital wallets, payments and other money apps
| Service | Official help | What to report |
|---|---|---|
| GCash | Unauthorized-transaction report, scam report, and official contact page (hotline 2882 toll-free for Globe/TM mobile, or (02) 7213-9999 for Globe landline; emergencies involving fraud, scams and unauthorized transactions are handled round the clock). | Specify whether you authorized a transfer after a scam or did not make the transaction at all; these follow different review paths. GCash’s unauthorized-transaction guide asks you to reset your MPIN and report through in-app chat within 15 days. See CyberCode’s GCash help explainer. |
| Maya app/wallet | Maya official contacts and fraud report; after-hours emergency lines +632 8845 7788, toll-free 1800 1084 57788, or *788 free from Smart. | Lost phone, unknown payment or account access; use the emergency route promptly. |
| ShopeePay | ShopeePay unauthorized transaction guidance (24/7 fraud support at shopeepay_fraudsupport_ph@support.shopee.ph; the guide lists the ID, transaction screenshots and narrative to send) and in-app Customer Service. | Wallet transaction, linked funding source and any related Shopee order; notify the issuer of a linked card too. |
| Grab/GrabPay | Grab PH Help Centre via the relevant in-app ride, food or payment transaction; Grab security guidance. | Unknown booking or charge, lost account access or wallet activity; also notify the card issuer for an unknown card charge. |
| PayPal | PayPal PH fraud guidance and Contact Us. | Unauthorized activity or suspected spoof; distinguish a seller dispute from account intrusion. |
| Other e-money issuers | BSP directory plus the provider’s official app. | Use a verified fraud channel and keep the transaction and ticket reference. |
Mobile apps, phone numbers and SIM incidents
If your signal disappears and you did not request a SIM change, treat a possible SIM swap as urgent. A network outage is possible, so ask the telco to verify the status. Notify linked banks and wallets; changing only the telco password may not stop payment attempts.
| Network | Official route | What it can do |
|---|---|---|
| Globe/TM | Report lost phone/SIM, SIM replacement, StopSpam reports. | Discuss suspension/replacement after identity checks; report scam texts and fake pages. Globe’s lost-SIM page routes prepaid users to a store and postpaid users to Messenger or 211; replacement asks for proof of ownership and a notarized affidavit of loss. |
| Smart/TNT | Lost or stolen phone, SIM replacement. | Report the loss by *888 from a Smart line or (02) 8888-1111 by landline; a free same-number SIM replacement is done at a Smart Store by the registered owner with one valid government ID. |
| DITO | DITO Help Center and in-app support. | Report a lost SIM, suspected number misuse or account issue; confirm the current verification and replacement process. |
| Spam/scam text | Report to the telco; Globe StopSpam provides an example and links to NTC’s reporting route. | Spam reporting may help block a sender; it does not secure a compromised bank account or recover money. |
See CyberCode’s SIM swap guide and phone/account warning signs. For app permissions and device security, use the phone manufacturer’s official security settings and update channel.
Shopee, Lazada, Facebook Marketplace and online sellers
| Where it happened | Official assistance | Practical route and limit |
|---|---|---|
| Shopee order or seller | Shopee Help Center; off-platform payment warning/report. | Open the specific order in app and use return/refund or report-seller tools. Preserve chat, listing, order and payment record. If you paid outside Shopee, its order protection may not cover that transfer; contact the payment provider. |
| Lazada order or seller | Lazada PH Help Center and in-app order support. | Report through the order and use the applicable return/refund flow; include listing screenshots and delivery evidence. For an unknown card charge, contact the issuer too. |
| Facebook Marketplace | Report a Marketplace scam; Marketplace scam guidance. | Report listing, buyer or seller and preserve Messenger/payment evidence. If money was sent directly to a bank/wallet, report there immediately. Marketplace reporting alone does not guarantee a refund. |
| Independent shop or another marketplace | Seller’s official order channel, payment provider, then DTI consumer complaint guidance where the dispute is within DTI’s scope. | Ask the merchant for a remedy with a deadline; save the listing, receipt and correspondence. A criminal scam can also be reported to CICC/PNP/NBI. |
Important split: A missing or misdescribed item, a fake seller, and an unauthorized card transaction need different tickets. Open the platform case for the order, the payment dispute with the issuer, and a criminal report for suspected fraud where appropriate. DTI may handle consumer transaction complaints; it is not the bank’s chargeback desk.
Email, social accounts, software, computers and servers
| Service/surface | Official recovery or support | First step |
|---|---|---|
| Google/Gmail | Secure a compromised Google Account. | Recover the account, inspect security events and connected apps, remove unfamiliar recovery methods and check Gmail forwarding/filters. |
| Microsoft/Outlook | Microsoft compromised-account guide. | Check the PC for malware, then recover and secure the account; inspect recent activity and mail rules. |
| Apple Account/iPhone | Apple Support PH and Apple compromised-account steps. | Change the account password, review trusted devices and phone numbers, and protect a lost device. |
| Facebook and Messenger | Facebook hacked-account flow. | Try a device previously used to sign in; warn contacts by another channel if scam messages were sent. |
| Instagram hacked-account support. | Choose the access issue and follow identity verification; beware paid “recovery agents.” | |
| WhatsApp compromised-account guide. | Recover control of the phone number/account and alert contacts if messages were sent. | |
| TikTok | TikTok login troubleshooting. | Choose the hacked-account path; check linked email/phone and signed-in devices. |
| Steam and games | Steam stolen-account support. | Scan the device and secure email before recovering the game account. |
| Laptop/desktop or installed software | Employer IT for work devices; official Apple, Microsoft or software-vendor support for personal devices; CERT-PH incident submission for technical incident coordination. | Disconnect active malware, preserve evidence and use a clean device for account changes. A technician may need to investigate and rebuild the system. |
| Website, WordPress, cloud or server | Your host/cloud provider’s authenticated support portal and incident team; CERT-PH for incident coordination. | Isolate affected services, save logs/snapshots, rotate secrets from a clean system, investigate the entry point and restore a tested backup. See website recovery. |
If multiple apps are affected, start with the main email, phone number and password manager. Account recovery can fail if an attacker still controls the email or SIM. A software vendor can help with its product, while a qualified incident responder or internal IT team handles device and server forensics.
Philippine escalation: which agency does what?
CICC, 1326
Cybercrime and scam intake/referral through its Inter-Agency Response Center, described as a 24/7 hotline for reporting scams. Keep the complaint reference. It is not a guaranteed refund or account-reset line. What CICC handles.
PNP ACG / NBI
Criminal complaint and possible investigation of illegal access, fraud, impersonation, extortion or other offenses. Bring evidence and provider case numbers. At the NBI Cybercrime Division, an agent interviews you and helps complete a sworn complaint, with no fee (NBI Citizen’s Charter). Reporting directory.
BSP
For an unresolved complaint involving a BSP-supervised bank or e-money institution, first raise the issue with that institution, then use BSP Consumer Assistance. Include the provider’s reply and ticket. BSP referral does not predetermine reimbursement. Under the Anti-Financial Account Scamming Act, an institution may temporarily hold disputed funds for no more than 30 calendar days unless a court extends it, and is liable for restitution if it failed to employ adequate risk-management controls or the highest degree of diligence (RA 12010, Secs. 6-7, BSP booklet; our RA 12010 explainer).
DTI
Consumer transaction complaints about an online seller or marketplace when within its jurisdiction. Follow DTI’s official complaint instructions: file online at consumercare.dti.gov.ph, email the complaint form to consumercare@dti.gov.ph, or file in person with the Fair Trade Enforcement Bureau. A bank/wallet dispute still goes to its issuer.
DICT CERT-PH
Receives, reviews and coordinates technical cyber incident reports, especially organizational incidents. Mandate and submit an incident. It is not a guaranteed personal repair service.
NPC / NTC
NPC handles data-privacy concerns and organizational breach reporting under its rules; NTC-linked spam reporting and telco channels address scam texts and telecom issues. These routes do not replace an immediate provider fraud report.
See how to report cybercrime and how to preserve electronic evidence. Report a threat to physical safety to local police promptly.
Phishing guide: identify the lure and choose the response
Phishing impersonates a trusted service to obtain a password, one-time code, payment approval or software installation. It may arrive by email, SMS (“smishing”), call (“vishing”), social DM, QR code, sponsored search result or a fake support page. A genuine brand logo or sender name is not proof; an attacker can copy it. A fake “delivery fee,” “account suspension,” “SIM expiry,” “refund,” “job interview” or “security check” tries to rush a decision.
- Pause and inspect. Check the full domain and destination, sender address and unusual payment or OTP request. A shortened link or misspelled domain deserves extra care, but a normal-looking link can still be unsafe.
- Open the app yourself. Do not use the message’s link or phone number to verify the message. Type the known website or use a bookmarked app, then check account notices or contact support.
- Do not hand over codes or approve prompts. An OTP, password, passkey prompt or MFA approval is part of access or payment authorization. Decline any prompt you did not initiate.
- Respond to what you actually did: merely viewing a page, typing a password, entering an OTP, approving a payment, installing an app or giving remote control have different risks. Use the matrix below.
- Report and retain evidence. Save the message and URL without reposting it as a clickable lure. Use the brand’s phishing channel, telco spam route and CICC/law enforcement where a crime or loss occurred.
Our clicked-a-phishing-link guide gives a fuller first-hour checklist.
Phishing response and protection matrix
| What happened | Immediate action | Next protection / expected help |
|---|---|---|
| Message received, nothing opened | Do not reply or click. Verify in the official app and report the lure. | Block sender after preserving evidence; review alerts. A message alone does not prove compromise. |
| Link opened, no information entered or file installed | Close the page. Check browser downloads and device/app updates; watch account activity. | Usually focus on verification and monitoring; escalate if an unexpected download, login or charge appears. |
| Password typed into fake page | On a clean device change that password and every reused copy; revoke sessions, check recovery details and turn on MFA. | Provider’s recovery/security tools can restrict account access; check email rules and connected apps. |
| OTP given, MFA approved or QR login scanned | Contact the relevant bank/app immediately if payment or financial access is involved; revoke sessions, change credentials and inspect activity. | Ask for protective restriction and a fraud case. Do not assume changing the password alone cancels an approved transaction. |
| Card details entered or money sent | Call the card issuer or sending institution immediately to block/dispute/trace; contact receiving platform if known. | Keep transaction IDs and report suspected fraud. A reversal depends on payment method and investigation. |
| App/file installed or remote access given | Disconnect the device from networks and end remote access; call bank from another device; ask IT/qualified support to examine it. | Rebuild if warranted, rotate credentials from a clean device, restore verified files and monitor for follow-on access. |
| Work mailbox or server affected | Alert the incident lead, isolate affected systems, preserve logs and warn relevant payment approvers. | Investigate scope, containment, recovery and applicable privacy notification. See business cyberattack response. |
Priority protection checklist
| Priority | Protection | Where to apply it |
|---|---|---|
| 1 | Unique passwords in a manager; MFA/passkeys; recovery codes stored separately. | Main email, bank/wallet, shopping and social accounts. |
| 2 | Transaction and login alerts, card controls and a known official fraud contact saved in advance. | All financial apps and cards. |
| 3 | Automatic updates, screen lock, encryption and limited app permissions; install from trusted sources. | Phone, laptop, browser and apps. |
| 4 | Confirm invoice changes, urgent transfers and support calls using a previously known channel. | Shopping, Marketplace, work email and family messaging. |
| 5 | Versioned/offline backups, least-privilege admin access, patched plugins and retained logs. | Computer, website and server. |
CISA’s Secure Our World campaign covers passwords, MFA, updates and phishing recognition. For a Philippine business, also use CyberCode’s website security and backup and recovery guides.
What to include in every help request
- Your own account identifier, affected service and a safe callback method; never put the password, complete card number or OTP in a public post.
- Transaction IDs, amount, receiving account information as shown, order number, date/time in Philippine time and when you first noticed the issue.
- Original email/message, sender, URL, screenshot and what action you took; attach files only through the provider’s verified secure form.
- The exact relief sought: block card/account, preserve records, investigate transaction, recover login, refund/return an order, or issue a written outcome.
- Case numbers and replies from every provider and agency, kept in one timeline for follow-up and escalation.
Frequently asked questions
Can a platform or agency guarantee my money back?
No. A provider may restrict access, investigate, trace a transfer or process a dispute; a regulator may review or refer an unresolved complaint; police may investigate suspected crime. Outcomes depend on evidence, timing, payment route and applicable rules.
Who should I call first after a Facebook Marketplace payment scam?
Contact the sending bank or wallet immediately, then report the buyer/seller and listing through Facebook Marketplace. Keep the Messenger thread, profile URL, listing and payment reference. If you suspect criminal fraud, report it to CICC or law enforcement. Facebook reporting by itself is not a bank transfer reversal.
Should I post screenshots of the scammer publicly?
Preserve originals for the platform, provider and investigators. Publicly posting IDs, phone numbers, account details or a live phishing link can expose private data or spread the lure. Redact details if you warn others.
My case is not listed. Where do I begin?
Go to the affected service’s official app or website and search for “security,” “fraud,” “unauthorized transaction,” “account recovery” or “help.” If funds moved, notify the issuer first. The BSP directory covers many supervised financial institutions. For suspected cybercrime, CyberCode’s agency directory explains the reporting route.
Source and maintenance notes
Provider links in the tables lead to their own official support pages. Government routes are drawn from BSP Consumer Assistance, DTI complaint guidance, DICT CERT-PH and NPC. CyberCode checked these pathways, and every phone number shown, against the providers’ and agencies’ own pages on 28 September 2026. Other sources used: PNA on the CICC 1326 hotline, the NBI Citizen’s Charter and the BSP AFASA booklet. Recheck the provider’s own site at the moment of an incident; this directory deliberately favors stable help pages over copied contact lists.
Related articles
- Hacked in the Philippines? First 15 Minutes and Recovery
- Clicked a Phishing Link? First-Hour Steps
- GCash Scam or Account Problem: Reporting and Support
- Cybercrime Reporting Directory
- Cyber Incident Response: Hacked Accounts, Phishing and Ransomware
Related: Money lost to an investment or crypto scheme has its own three-lane route — see investment or crypto scam: how to report it and what the SEC can do.
Related: Money lost to a fake online job or a “like and earn” task app has its own route too, and it is not the same as illegal recruitment — see job or task scam in the Philippines.
Disclaimer: General information, not legal advice, an emergency hotline or a guarantee of recovery. Support routes, provider terms and regulations can change. Verify urgent contact details directly with the institution and seek qualified technical or legal advice for a serious incident.
Related: one problem that belongs in no other entry in this directory is a payment you addressed wrongly yourself. It is neither a hack nor a scam, and the usual routes do not reach it — see sending money to the wrong recipient on InstaPay for the one institution that owes you an answer and the civil claim behind it.
Sources rechecked as of: 28 September 2026

