Last materially reviewed: September 21, 2026
Sources rechecked as of: September 30, 2026
Direct answer
A SIM-swap victim does not automatically bear the financial loss, but reimbursement is also not automatic. Liability depends on how the replacement SIM was issued, how the bank authenticated the disputed transfer, whether each provider used reasonable security, and whether the customer promptly reported the takeover. Under RA 12010, a bank or e-wallet that lacked adequate security controls or diligence must restore the funds even without a criminal conviction. Call your bank and e-wallet first, then the telco, preserve the timeline, and dispute every unauthorized transaction in writing.
Authority-to-action bridge
| Question | Cybercode answer |
|---|---|
| What the authority says | The SIM Registration Act, the Financial Products and Services Consumer Protection Act, BSP rules and contract obligations can operate alongside cybercrime and privacy law. |
| What it means | An OTP sent to a hijacked number does not by itself prove that the customer authorized a transfer. |
| What changes the answer | The result turns on customer conduct, telco identity checks, bank fraud controls, warnings, transaction patterns and response time. |
| What to do next | Freeze the mobile number and financial accounts, obtain reference numbers, request logs and submit a formal transaction dispute. |
Key takeaways
- SIM registration does not guarantee that a replacement SIM was lawfully issued.
- Bank and telco responsibility must be examined separately.
- An OTP proves control of a channel at one moment, not necessarily the account owner’s consent.
- Minutes matter: contact the telco, bank and e-wallet before arguing about final liability.
- Keep the original device, messages, emails, call logs and support records.
The rules that can decide liability
The bank or e-wallet: RA 12010 (AFASA)
The Anti-Financial Account Scamming Act (RA 12010) is the most important law for a SIM-swap victim who lost money. Three provisions matter most (text as reproduced in the BSP AFASA booklet):
- Section 6: banks, e-wallets and other BSP-supervised institutions must protect account access with adequate risk controls such as multi-factor authentication and fraud management systems. An institution is liable to restore the funds if it failed to use adequate controls or failed to exercise the highest degree of diligence, and a criminal conviction is not needed for that restitution. An institution the BSP finds compliant is not liable for the loss.
- Section 7: the institution may temporarily hold funds subject of a disputed transaction for the period the BSP sets, not exceeding 30 calendar days unless a court extends it. A hold only helps while the money is still in a receiving account, which is why reporting within minutes matters.
- Section 9: an institution that fails to hold disputed funds as required is liable for the resulting loss, including restitution.
Stealing OTPs or passwords through deception to take over an account is itself a crime under Section 4(b) (social engineering schemes), punishable by 10 to 12 years’ imprisonment or a fine of ₱500,000 to ₱1,000,000, and more if the victim is a senior citizen (Section 16(b)). See our RA 12010 explainer.
The Financial Products and Services Consumer Protection Act (RA 11765) adds general duties of fair treatment, protection of client assets and effective recourse, and is the basis of the BSP complaint route described below.
The telco: RA 11934 and its IRR
The SIM Registration Act (RA 11934) and its implementing rules, NTC Memorandum Circular No. 001-12-2022, set these duties that matter in a SIM swap:
- You must immediately report a lost or stolen SIM to your telco, giving your name, address, date of birth and mobile number (IRR Sec. 9(b)).
- The telco must immediately bar a SIM reported lost or stolen so it cannot be used for calls, texts or data (IRR Sec. 10(f)), and must deactivate it within 24 hours of the report (IRR Sec. 10(d)).
- The telco keeps data on a deactivated SIM for 10 years (IRR Sec. 10(i)), and discloses subscriber details to investigators only on a subpoena issued on a sworn complaint that the number was used in a crime (IRR Sec. 12). That is why a sworn police or NBI complaint matters for identifying who obtained the replacement SIM.
A registered SIM can still be taken over through fraudulent replacement, insider misconduct or stolen identity documents. Using fake identity documents to register a SIM is punishable under the Act (IRR Sec. 13). Whether the telco is liable for your loss turns on how it verified the person who asked for the replacement.
Cybercrime and privacy rules may also apply where attackers obtained credentials, impersonated the subscriber, accessed systems without right or misused personal data. A criminal complaint and a reimbursement dispute are related but different processes.
Evidence to preserve
Build one synchronized timeline across the phone account and every affected financial account.
- Time the original SIM lost service and time the replacement SIM was activated.
- Telco tickets, branch records, identity documents used and SIM-replacement logs.
- Bank or e-wallet login, device, IP, OTP, beneficiary and transaction records.
- SMS, email and app alerts before and after the takeover.
- Police or cybercrime report, affidavits and written disputes.
What to do next
First action, right now: if your phone suddenly shows “No service” or “SIM not provisioned” and you did not change anything, call your bank and e-wallet from another phone first, then your telco. Money moves in minutes; the number can be restored later.
- Bank and e-wallet (first hour): use the hotline or in-app fraud channel of every institution linked to the number. Ask them to lock the account, stop pending transfers and hold any disputed funds under RA 12010, and write down the reference number, the time and the agent’s name.
- Telco (same hour): report the SIM as lost or stolen so the telco bars it (IRR Sec. 10(f)). Ask them to record that you did not request the replacement, and to preserve the replacement record: when, where, and what ID was presented.
- Your accounts (same day): from a clean device, change the passwords of your email and financial apps, sign out other sessions, and switch to an authenticator app where offered. See our MFA guide.
- Written dispute (within days): send each institution a written dispute listing every unauthorized transaction (date, amount, recipient), stating that you did not authorize it, that your SIM was hijacked, and asking it to preserve login, device and OTP logs. Ask for its dispute timeline in writing. We did not verify a single fixed reimbursement deadline for this guide, so do not wait for one.
- Police or NBI complaint: file with the PNP Anti-Cybercrime Group or the NBI Cybercrime Division. A sworn complaint is what lets investigators subpoena the telco’s registration records (IRR Sec. 12).
- BSP (if the bank or e-wallet refuses or does not answer): file through the BSP Consumer Assistance channels (the BOB chatbot, consumeraffairs@bsp.gov.ph, mail or in person). Attach your complaint to the institution and its reply. See how to complain to the BSP about a bank or e-wallet.
- Telco complaint: if the telco issued the replacement to someone else and will not explain how, raise a written complaint with the telco and then the National Telecommunications Commission.
- Court (last resort): if restitution is refused and the amount justifies it, a civil action for the lost funds and damages is possible. Consult a lawyer or the Public Attorney’s Office before filing.
What to bring to the bank, BSP, police or NBI: a valid ID; your timeline (loss of signal, replacement activation, each transaction); telco and bank reference numbers; screenshots of alerts and transactions; account statements; and copies of your written disputes and any replies.
Common mistakes
- Assuming an OTP makes the transaction legally conclusive.
- Resetting the phone before preserving alerts, call logs and timestamps.
- Reporting only to the bank while leaving the hijacked number active.
- Accepting a verbal denial without submitting a formal written dispute.
Frequently asked questions
Is the telco automatically liable for every SIM-swap loss?
No. The claimant must connect the telco’s act or omission to the takeover and loss. Identity-verification records and replacement procedures are central.
Can the bank deny a claim because the correct OTP was used?
The OTP is important evidence, but it is not the only evidence. A fair assessment should consider device changes, unusual beneficiaries, transaction velocity and the compromised phone channel.
Should I ignore disputed loan or credit amounts?
No. Follow the institution’s written dispute process and ask how the contested amount will be treated. Preserve proof that it was formally disputed.
Related Cybercode guides
- Multi-Factor Authentication Guide
- Online Scam Complaint Procedure
- Online Scam Evidence Checklist
- Cybercrime Reporting Directory
Official sources
- Republic Act No. 12010 — Anti-Financial Account Scamming Act (Official Gazette)
- BSP — AFASA booklet with BSP Circular Nos. 1213, 1214 and 1215 (2025)
- Republic Act No. 11934 — SIM Registration Act (Official Gazette)
- NTC Memorandum Circular No. 001-12-2022 — SIM Registration Act IRR (Supreme Court E-Library)
- Republic Act No. 11765 — Financial Products and Services Consumer Protection Act (Official Gazette)
- BSP consumer assistance channels
- Republic Act No. 10175 — Cybercrime Prevention Act (Official Gazette)
Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology, or business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety, or legal exposure may be affected.

