Last materially reviewed: September 3, 2026
Direct Answer
The safest way to avoid SMS, text and online scams is to slow the interaction down. Do not click unexpected links, do not share OTPs, passwords or recovery codes, and do not trust caller ID, logos, screenshots or account names by themselves. Verify requests independently through the official app, website, branch, or phone number of the bank, government agency, delivery company, employer, marketplace, or person being impersonated.
Primary authorities: Cybercrime Investigation and Coordinating Center and, where the conduct falls within the statute, Republic Act No. 10175.
Key Takeaways
- Urgency is one of the strongest scam warning signs.
- Legitimate institutions should not need your password, PIN, OTP, CVV, or account-recovery code.
- Do not move a conversation off a trusted marketplace just because a seller or buyer asks you to.
- Verify payment instructions before transferring money.
- Use unique passwords and multi-factor authentication.
- If you already sent money, contact the bank or e-wallet immediately and report the scam.
Common Scam Types in the Philippines
- Smishing: text messages with fake banking, parcel, toll, account-expiry, or government links.
- Impersonation: someone pretends to be a relative, executive, bank employee, police officer, government worker, or delivery company.
- Marketplace scams: fake sellers, fake buyers, counterfeit payment screenshots, off-platform payment requests, and fake courier links.
- Investment and task scams: victims are promised high returns or commissions, then asked to deposit increasing amounts.
- Account takeover: compromised social accounts ask friends or relatives for emergency money.
- Romance scams: emotional trust is built before money, gifts, fees, or investments are requested.
Decision Snapshot
| Red flag | Safer action |
|---|---|
| Message says account will be closed today | Open the official app directly; do not use the message link |
| Friend asks for emergency transfer | Call the person using a number you already know |
| Seller wants off-platform payment | Keep payment and chat inside the trusted platform |
| Caller asks for OTP | End the call and contact the institution independently |
| Job requires upfront payment | Verify employer and never pay merely to receive ordinary employment |
| Investment guarantees high returns | Verify licensing and assume guaranteed returns are a major warning sign |
10 Ways to Reduce Your Scam Risk
- Never share OTPs. Treat them like a password.
- Do not click unexpected message links. Open the service directly.
- Use unique passwords. A password manager makes this easier.
- Enable multi-factor authentication.
- Verify unusual requests by voice or another channel.
- Use marketplace protections. Avoid moving payments outside the platform without a strong reason.
- Check URLs carefully. Look for misspellings, strange subdomains, and unrelated domains.
- Limit public personal information. Scammers use birthdays, family names, workplaces and travel details to make attacks believable.
- Turn on transaction alerts.
- Teach family members a verification rule. A shared family phrase or call-back routine can defeat many impersonation scams.
What If You Already Clicked or Responded?
If you clicked a suspicious link, follow the response checklist in What to Do If You Clicked a Phishing Link. If you disclosed a password, change it immediately and sign out unknown sessions. If you disclosed an OTP or approved a banking prompt, contact the provider urgently.
What If You Already Sent Money?
- Call the bank or e-wallet immediately.
- Ask whether the receiving transaction or account can be flagged, held, disputed, or traced.
- Save the recipient name, number, account, wallet, QR code, transaction reference, and time.
- Preserve the entire chat, advertisement, profile URL, and payment instructions.
- Report the incident through CICC hotline 1326, PNP-ACG, or NBI-CCD.
Use our cybercrime reporting guide for the agencies and evidence checklist.
Why Scam Messages Can Look So Real
Modern scams use copied logos, spoofed names, leaked personal information, compromised accounts, AI-generated text and images, cloned voices, and realistic fake websites. Visual polish is not proof of legitimacy. Verification should depend on an independently confirmed channel, not on how convincing the message looks.
Frequently Asked Questions
Should I reply STOP to a suspicious scam text?
Not usually. Replying can confirm that your number is active. Block and report through your device, carrier, platform, or cybercrime reporting channel where appropriate.
Can a scammer fake a bank’s sender name?
Sender names and caller information should not be treated as conclusive proof of identity. Always verify through the official app, website, branch, or independently obtained number.
Are QR codes safe?
A QR code is simply another way to encode a link or payment destination. Treat an unexpected QR code with the same caution as an unexpected link.
