CyberCode.ph · Philippines

Unauthorised E-Wallet Transactions: Your Rights and the Refund Path

Last updated October 5, 2026 · Practical privacy, cybersecurity and technology-law guidance

Unauthorised e-wallet transaction? Start here

Report it to your e-wallet provider first, in writing, through its own complaint channel — that is the step the rules require before anything else. A Philippine e-wallet is a “financial account” under the Anti-Financial Account Scamming Act (RA 12010), so the provider can temporarily hold the disputed funds and run a coordinated verification with the receiving bank or wallet. Under the BSP’s complaint-handling standards it must acknowledge your complaint within two days and resolve a simple one within seven. If it rejects or ignores you, escalate to the Bangko Sentral ng Pilipinas (BSP), which can order reimbursement of up to ₱10,000,000.

Key takeaways

  • An e-wallet is expressly a “financial account” under RA 12010, so the Act’s disputed-transaction machinery applies to GCash, Maya and every other BSP-supervised wallet, not only to banks.
  • Your provider’s own complaint channel is not optional politeness. The BSP will not take your case until you have used it.
  • The clocks that actually exist are complaint-handling clocks (2, 7/9, 45/47 days) and a fund-holding clock (5 + 25 = 30 calendar days). None of them is a promise of a refund.
  • Whether the money comes back usually turns on one question: was the transfer unauthorised, or were you tricked into authorising it? The two go down different routes.
  • Holding funds is not the same as returning them. Funds are released to the receiving account when the hold lapses or the recipient substantiates the transfer.
  • The BSP can adjudicate a purely civil money claim of up to ₱10,000,000 and order payment or reimbursement.
  • Falsely reporting a transaction as disputed is itself an offence under RA 12010, so keep your account of events accurate.

Jump to a section

Decision snapshot

Five questions people ask in the first hour, with the practical answer.

QuestionPractical answer
Must I complain to the wallet first?Yes. The BSP treats its own process as a second-level route after the provider’s complaint mechanism.
Is there a legal deadline for the provider to answer?Yes. Two days to acknowledge, seven for a simple complaint, forty-five for a complex one, counted from receipt.
Can the provider freeze the money that left my wallet?Yes, if the transaction qualifies as disputed — for up to thirty calendar days in total.
Does a freeze mean I get the money back?No. A hold buys verification time; release or return depends on what the verification finds.
Is a refund guaranteed if I was scammed?No. No statute retrieved for this guide guarantees one; liability depends on compliance and on your terms and conditions.

What to do immediately

Work in this order, ideally within the first hour. The first three steps stop the bleeding; the fourth starts the clock that gives you rights.

  1. Open the app yourself and check the activity log. Do not act on a link or a caller’s instructions. Note every transaction you do not recognise, with its reference number, amount and timestamp.
  2. Lock or freeze the wallet and any linked card. Most wallets have an in-app lock. If yours is fully compromised, use the provider’s official account-freeze or account-recovery route.
  3. Change the credentials from a device you trust. New MPIN or password, new email password if it shares the credential, and check the registered mobile number and email for changes someone else made. If you clicked something first, our guide on what to do after clicking a phishing link covers the containment sequence.
  4. File a written dispute through the provider’s own complaint channel and ask for a case or ticket number. Say plainly that the transaction was not authorised by you, give the reference numbers, and ask the provider to hold the disputed funds and start the coordinated verification process. Put the request in writing even if you called first. Under BSP Circular No. 1215, a complaint-initiated hold starts from a report through the provider’s 24/7 fraud-reporting channel.
  5. Send supporting documents within five calendar days. A sworn complaint, affidavit or police report describing what happened is what lets the provider consider extending the initial five-day hold; the Circular expects it within that initial period unless the industry protocol says otherwise.
  6. Write down the time you discovered it. Every timetable in this guide runs from the provider’s receipt of your complaint, and your own discovery time is the fact that explains any gap.

Provider-specific menus and hotlines change. For the two largest wallets, follow the current in-app routes described in our GCash reporting guide and Maya reporting guide. If a physical card was involved rather than the wallet balance, start with the lost or misused card route instead.

What not to do

  • Do not give an OTP, MPIN, PIN or CVV to anyone, including someone who says they are from the wallet, the BSP or the police. No legitimate investigator needs them.
  • Do not call a number from the message that alerted you. Use the number or in-app channel published by the provider itself.
  • Do not delete the messages, the app or the transaction history. You are destroying the evidence your own dispute depends on.
  • Do not send more money to “unlock”, “verify” or “recover” the first loss. Recovery fraud follows the original fraud closely.
  • Do not overstate what happened. RA 12010 makes malicious false reporting of a disputed transaction an offence (Sec. 11, in relation to Sec. 16(e)), and the provider’s notice to the other account holder says so.
  • Do not contact the recipient yourself to threaten or bargain. It muddies the verification and can expose you to a counter-complaint.

Preserve evidence

What you keep decides what the provider, the BSP or a prosecutor can actually work with. Keep originals, not retyped summaries.

RecordWhy it matters
Transaction entry and reference numberIt identifies the exact transfer in the provider’s and the receiving institution’s systems.
Full in-app activity export or screenshotsShows the sequence — what came before and after the disputed entry.
SMS, email, chat or call log around the incidentEstablishes whether deception, an OTP request or a spoofed sender was involved.
Login, device and SIM change alertsPoints to account takeover or a swapped SIM rather than your own action.
Case or ticket number and every written replyProves you used the provider’s mechanism and when — the gate to BSP escalation.
Your own dated note of discoveryFixes the timeline in your words while it is fresh.

Our online scam evidence checklist sets out how to capture each item so it stays usable, and the scam and hack triage tool produces a plan you can print and bring with you.

Secure your accounts

An unauthorised transfer is usually the visible end of an access problem. Close the access, or it happens again while your dispute is pending.

  • Change the wallet credential, then the email and any other account that shared the password.
  • Turn on every additional verification step the wallet offers, and remove devices or sessions you do not recognise.
  • Check the registered mobile number and email address. If either was changed, say so in the dispute — it is strong evidence of takeover.
  • If the number itself was hijacked, that is a distinct problem with its own liability question: see SIM-swap fraud and who bears the loss.
  • If more than one account is affected, work through the broader sequence in what to do in the first fifteen minutes after being hacked.

Work out what was compromised

Name the failure, because it decides who is answerable. In practice it is one of five things.

  1. A credential — your MPIN or password was phished, guessed or reused from a breached site.
  2. A one-time password — you were talked into reading it out, or it was intercepted.
  3. The registered number — the SIM was swapped or ported and the verification messages went elsewhere.
  4. The device — an unlocked phone, a malicious app, or remote-access software installed during a “support” call.
  5. The account itself — the provider’s own controls failed, or a linked card was cloned. Card misuse can also engage the Access Devices Regulation Act; see our guide to RA 8484 as amended by RA 11449.

If the account was taken over rather than merely used for one transfer, the wider remedies are in unauthorised account access and computer-related identity theft.

Who to notify, and when

Notification is sequenced, not simultaneous. Doing it in this order preserves your escalation rights.

WhoWhenWhat to ask for
Your e-wallet providerImmediately, and in writing the same dayA case number, a temporary hold on the disputed funds, the coordinated verification process, and a written outcome.
The receiving bank or walletOnly through your providerYour provider coordinates with it under RA 12010 Sec. 8; you do not need to approach it yourself.
Your bank, if the wallet was funded from itSame dayA block on further wallet top-ups or linked debits while the dispute runs.
The BSPAfter the provider’s process fails or its deadline passesAssistance, and adjudication where the claim is purely civil and within the ₱10,000,000 ceiling.
Law enforcementAny time, in parallelA criminal complaint where fraud, illegal access or identity theft is involved.
The National Privacy CommissionIf personal data was mishandled by a companyA separate privacy complaint; it does not recover the money.

Where to report it

Four routes exist, and they do different things. Using all four is reasonable; expecting any single one to return the money is not.

RouteWhat it can doWhat it cannot do
The provider’s complaint mechanismHold the disputed funds, verify with the receiving institution, decide the dispute and reverse an entry it finds unauthorised.Act on a complaint it never received in usable form, or recover money already withdrawn and spent.
BSP consumer assistanceTake up an unresolved complaint against a BSP-supervised institution and adjudicate a purely civil money claim up to ₱10,000,000, ordering payment or reimbursement.Substitute for the provider’s own process, or decide a criminal case.
PNP Anti-Cybercrime Group or the NBI Cybercrime DivisionInvestigate the offence, apply for cybercrime warrants and build a criminal case against whoever took the money.Order your wallet to refund you; restitution normally follows the case.
CICC hotline 1326Take a scam report (hotline 1326 or report@cicc.gov.ph). The BSP lists the CICC with the PNP and NBI as agencies that can start a formal investigation into a scam.Replace the written dispute with your provider, which is the step that starts the refund clock.

Our cybercrime reporting directory sets out which agency handles what, the CICC guide explains that agency’s remit, and the bank and wallet help directory collects the provider-side channels in one place.

The dispute timetable the rules set

Two separate sets of periods run at the same time, and people confuse them constantly. One governs how fast your complaint must be handled. The other governs how long the money can be frozen.

ClockPeriodWhat it governs
Acknowledgement of your complaintWithin 2 days of receiptThe provider must tell you it is dealing with the complaint, ask for any further documents, and keep you informed of progress.
Simple complaintResolved within 7 days; outcome communicated by day 9Straightforward cases under the BSP’s consumer assistance standards.
Complex complaintResolved within 45 days; outcome communicated by day 47Cases needing investigation. If the provider needs longer it must give the reason and the date you can expect the outcome; the extra period may not exceed 45 days.
Initial hold on disputed fundsNot more than 5 calendar daysThe first freeze on the money in the receiving account while verification starts.
Extended holdNot more than a further 25 calendar daysApplied when the institution finds reasonable grounds that the funds are disputed.
Maximum hold30 calendar days in totalRA 12010 Sec. 7 caps it; beyond that, only a court order can extend it.
Coordinated verificationWithin the 30-day hold, or 30 calendar days where no funds are held — extendable to 60 for meritorious reasonsThe joint checking between your provider and the receiving institution.

The complaint-handling periods are counted from the provider’s receipt of your complaint; the BSP appendix that sets them says “days” without specifying banking or calendar days, so ask your provider how it counts them. The holding periods are expressly calendar days, counted by excluding the first day and including the last.

Unauthorised, or tricked into paying?

This is the distinction the whole outcome turns on, and it is the one most guides skip.

An unauthorised transaction is one you did not make and did not agree to: someone got into your wallet and moved money, or used a linked card. RA 12010 defines a social engineering scheme as obtaining another person’s sensitive identifying information through deception or fraud, resulting in unauthorised access and control over that person’s financial account. A phished MPIN or a harvested OTP sits squarely here, and the disputed-transaction machinery — hold, coordinated verification, possible restitution — is designed for it.

Being tricked into paying is different. You opened the app, you approved the transfer, and the person on the other end was lying about what you were buying or who they were. Your access was never compromised. That is a fraud problem rather than an unauthorised-access problem, and the provider has far less room to reverse it, because on its records you authorised the payment. The realistic route there is a criminal complaint for estafa or computer-related fraud plus, where a marketplace was involved, the platform’s own buyer protection. Our guide to online estafa covers when a scam becomes a criminal case, and the online scam complaint procedure covers the reporting sequence.

Say which of the two happened, in your own words, in the first line of your dispute. Providers triage on exactly this.

There is a third situation worth naming. If someone else used your account to receive scam proceeds — a favour for a friend, a “commission” for letting money pass through — the exposure is yours, not theirs. RA 12010 penalises using, lending, renting, selling or allowing the use of a financial account for proceeds known to come from crime or social engineering, with imprisonment of six to eight years, a fine of ₱100,000 to ₱500,000, or both (Secs. 4(a) and 16(a)). See money-mule accounts and the account holder’s liability.

What RA 11765 gives you

The Financial Products and Services Consumer Protection Act (RA 11765), approved 6 May 2022, states that the State shall implement measures to protect the financial consumer’s right to equitable and fair treatment, to disclosure and transparency, to protection of consumer assets against fraud and misuse, to data privacy and protection, and to timely handling and redress of complaints (Sec. 2). Every financial service provider must establish a single consumer assistance mechanism that gives free assistance on financial transaction concerns (Sec. 8(f)).

The Act also gives the financial regulators — the BSP, for banks and e-money issuers — authority to adjudicate actions arising from financial transactions that are purely civil in nature where the relief sought is solely payment or reimbursement of a sum of money not exceeding ₱10,000,000, and to order the payment or reimbursement of that money (Sec. 6(f)). Wilful violations of the Act carry imprisonment of not less than one year and not more than five, a fine of ₱50,000 to ₱2,000,000, or both (Sec. 15). Our RA 11765 guide goes provision by provision.

What RA 12010 (AFASA) adds

The Anti-Financial Account Scamming Act took effect in 2024 — Sec. 26 sets effectivity at fifteen days after publication, and BSP Circular No. 1215 treats 13 August 2024 as the effectivity date — and it is the reason e-wallet disputes now have machinery of their own. Sec. 3 defines a financial account to include an e-wallet expressly, alongside deposit, trust, investment and credit-card accounts. Sec. 7 gives supervised institutions authority to hold the funds behind a disputed transaction within the period the BSP prescribes, “which shall not exceed thirty (30) calendar days”. Sec. 8 requires the institutions and account owners involved to start a coordinated verification process, either on a complaint or when the institution’s own fraud management system flags the transfer. Sec. 12 lets the BSP inquire into accounts that may be involved in a prohibited act, with bank secrecy under RA 1405 expressly not applying, and Sec. 13 lets it apply for cybercrime warrants.

On liability, Sec. 6 cuts both ways: an institution that complied with its obligations is not liable for loss or damage arising from the offences, while a non-compliant institution is liable for restitution of funds to the account owners — and a conviction is not a prerequisite to that restitution. Sec. 17 adds that a conviction under the Act carries civil liability, which may include restitution to the aggrieved party. Our AFASA guide covers the offences and penalties in full.

What the BSP’s own rules require

The BSP issued the regulations on temporary holding of funds and coordinated verification under Monetary Board Resolution No. 523 of 22 May 2025, published as Circular No. 1215, Series of 2025. They set the five-day initial hold, the twenty-five-day extension, and the thirty-day ceiling; they require the institution to tell the receiving account holder the transaction reference, amount, transfer mode, date and time, the general reasons for the hold, their rights and how to challenge it; they require the complaining side to be given a case reference and to be warned about malicious false reporting; and they require both sides to be told without undue delay, with reasons, when funds are released. Funds are released when the holding period lapses or the recipient substantiates the transfer’s legitimacy — unless a court extends the hold, the recipient waives in writing, or verification suggests money muling, unlawful activity or a social engineering scheme, in which case the equivalent amount is deducted and returned to the sending institution. Institutions must also report temporarily held funds to the BSP. The holding rules apply to electronic transfers between financial accounts made after 13 August 2024; they do not cover erroneous transfers you mis-encoded yourself, or credit-card transactions except card-funded transfers through an automated clearing house.

Separately, Circular No. 1213 (Monetary Board Resolution No. 521, 22 May 2025) amended the information-technology risk management rules to implement AFASA Sec. 6, and confirms that detection by a fraud management system is one of the grounds for holding disputed funds and starting coordinated verification. The BSP’s Manual of Regulations for Banks requires a product’s terms and conditions to include the procedures for reporting unauthorised transactions “as well as the liabilities of parties in such case” (Sec. 1002) — which is why your own contract is part of the answer to “who pays”.

When it is also a crime

Taking money out of someone’s wallet without authority can amount to illegal access, computer-related fraud or computer-related identity theft under the Cybercrime Prevention Act (RA 10175), to estafa under the Revised Penal Code, and where a card or account number was used, to an offence under the Access Devices Regulation Act. A criminal case runs on its own track and its own timetable; it does not pause your dispute, and your dispute does not weaken it. See computer-related fraud for the elements and the complaint steps.

The data-privacy angle

If your details leaked from a company’s systems rather than from your own phone, that is a separate wrong with a separate regulator. A privacy complaint to the National Privacy Commission can address the mishandling of your personal data, but it is not a money-recovery route and should never displace the dispute with your provider.

Your options and what to do next

Four realistic options, what each one actually delivers, and what to bring.

OptionWhere it goes and what it deliversWhat to bring
Dispute with the providerThe provider’s own complaint mechanism. It can hold the funds, verify with the receiving institution and reverse an entry it finds unauthorised. This is the mandatory first step.Transaction reference, discovery time, the messages, a one-line statement that you did not authorise it.
Escalate to the BSPThe BSP Consumer Assistance Mechanism, after the provider rejects the complaint or does not act. File through BSP Online Buddy (BOB). The BSP says this stage may take 55 to 65 days; mediation or adjudication of a purely civil claim up to ₱10,000,000 can follow.The case number, the provider’s written reply, your evidence pack, and a clear statement of the amount claimed.
Criminal complaintPNP Anti-Cybercrime Group or the NBI Cybercrime Division. It pursues the offender and can lead to restitution on conviction; RA 12010 also allows restitution without one where an institution was non-compliant.A sworn statement, the same evidence pack, and any identifying detail about the recipient account.
Civil claimThe regular courts, where the amount exceeds the BSP’s adjudication ceiling or the claim is not purely a money claim. Consider small claims procedure for modest amounts.Your terms and conditions, the full dispute record, and proof of the loss.

The first concrete action: open your wallet app, lock it, then file a written dispute through the provider’s official complaint channel today with the transaction reference and an express request to hold the disputed funds and start the coordinated verification process — and save the case number. Everything else in this guide depends on that one step existing, in writing, with a date on it.

Recovery steps

  1. Diarise the deadlines: two days for acknowledgement, then day 7 and day 9, or day 45 and day 47. Chase in writing the day one passes.
  2. Ask, in writing, whether the funds were held and whether coordinated verification was started. The answer tells you how seriously the case is being treated.
  3. Get the outcome in writing. The BSP’s standards require results to be communicated in writing, in simple and clear language, together with the remedies available — including escalation to the BSP and going to court.
  4. If the answer is no or nothing arrives, escalate to the BSP with the case number and the provider’s reply attached. Chat with BSP Online Buddy (BOB) through the webchat on the BSP website or the BSP Facebook page until you get a BSPCMS reference number; if you cannot use BOB, email the BSP’s complaint form to consumeraffairs@bsp.gov.ph with proof that you used the provider’s complaint channel. Our guide to digital payment consumer rights and BSP protection explains the escalation framework.
  5. Keep the wallet usable but lean while the dispute runs: low balance, no linked auto-debits, fresh credentials.
  6. Check your other accounts that shared the credential or the number. One compromise rarely stops at one app.

Common mistakes

  • Complaining only by phone. With no written record there is nothing to escalate.
  • Going to the BSP first. It will send you back to the provider, and you will have lost the days.
  • Treating a hold as a refund. Money can be held for thirty days and still be released to the recipient.
  • Describing a scam purchase as an unauthorised transaction. It invites rejection, and overstatement carries its own exposure under RA 12010.
  • Deleting the evidence. Wiping the phone or the app to “clean it” destroys the record.
  • Paying a “recovery agent”. No agent has access to the provider’s dispute system that you do not have.
  • Waiting to see if the money comes back. Every clock in this guide starts when you report, not when you notice.

Prevention

  • Never share an OTP, MPIN or card CVV — not with support, not with a courier, not with anyone.
  • Use a unique password for the wallet and for the email address it is registered to, and turn on every extra verification step offered.
  • Keep the working balance low and move the rest to an account without instant outward transfers.
  • Open the app yourself to check anything a message claims. Never follow a link in the alert.
  • Turn on transaction notifications so an unauthorised transfer is discovered in minutes, not at month-end.
  • Treat any request to receive and pass on money as a criminal risk to you, whoever is asking.
  • Know your provider’s official complaint channel before you need it. The digital payment consumer rights guide sets out the framework you are relying on.

FAQs

Does my e-wallet have to refund an unauthorised transaction?

Not automatically. No statute retrieved for this guide guarantees a refund. RA 12010 Sec. 6 makes an institution that complied with its obligations not liable for the loss and makes a non-compliant one liable for restitution, and the BSP requires the liabilities of each party in an unauthorised transaction to be set out in the product’s terms and conditions. So the answer depends on what went wrong, whether the provider met its obligations, and what your contract says.

How long does my provider have to resolve my dispute?

Under the BSP’s consumer assistance standards, it must acknowledge within two days, resolve a simple complaint within seven days and communicate the outcome by the ninth, and resolve a complex complaint within forty-five days and communicate by the forty-seventh. Periods run from receipt of the complaint. If it needs longer it must tell you why and when to expect the outcome, and the extra period may not exceed forty-five days.

Can the money be frozen in the recipient’s account?

Yes. RA 12010 Sec. 7 authorises a temporary hold on the funds behind a disputed transaction, capped at thirty calendar days. The BSP’s regulations split that into an initial hold of not more than five calendar days and an extension of not more than twenty-five. Past thirty days, only a court order can extend it.

Will a hold get my money back?

Not by itself. The funds are released when the holding period lapses or the recipient substantiates the transfer. They are returned to your side’s institution where the recipient waives in writing, a court extends the hold, or verification suggests money muling, unlawful activity or a social engineering scheme.

What if I was tricked into sending the money myself?

Then your access was not compromised, and the provider has much less scope to reverse the transfer. The realistic route is a criminal complaint for estafa or computer-related fraud, plus the platform’s buyer protection if the payment was for a purchase. Report it to your provider anyway, in writing, and describe accurately what happened.

Do I have to complain to the wallet before going to the BSP?

Yes. The BSP’s own material on its consumer complaint rules states that complaints must first go through the institution’s assistance mechanism, and describes its process as the escalation route once your concern is still unresolved.

How much can the BSP order a provider to pay me?

RA 11765 Sec. 6(f) covers purely civil claims where the relief sought is solely payment or reimbursement of a sum not exceeding ₱10,000,000, and allows the regulator to order that payment or reimbursement. Above that ceiling, or for anything that is not purely a money claim, the route is the courts.

Should I file a police report as well as a dispute?

If you believe a crime was committed, yes, and in parallel rather than instead. A criminal complaint pursues the offender; the dispute pursues the money. Bring the same evidence pack to both, and keep the provider’s case number with it.

Is the CICC hotline 1326 the right place to call?

Yes, for reporting the scam itself. The BSP lists the CICC’s 1326 hotline and report@cicc.gov.ph, alongside the PNP and NBI, as channels for scam victims who want a formal investigation. Use it — but it does not replace the written dispute with your provider, which is the step that starts the refund clock.

Official sources

About this guide

Written by the Cybercode.ph Editorial Team. This page has not been reviewed by a named external legal reviewer, and Cybercode does not attribute review to anyone who has not carried it out. Every figure, period and provision above was read from the government sources listed in Official Sources. Where a rule could not be verified from a primary source, the page says so rather than filling the gap. If you find an error, check it against the linked primary source and tell us so we can correct it.

Two limits worth stating plainly. First, no statute or regulation retrieved for this guide fixes a universal rule on who bears the loss in an unauthorised e-wallet transaction; the answer comes from AFASA Sec. 6 read with the provider’s own terms and conditions. Second, provider hotlines, in-app menus and processing times change without notice, so verify them on the provider’s own official pages.

Related: this guide is about money that moved without your authorisation. If you authorised the transfer correctly but keyed the wrong account or mobile number, that is an erroneous transaction and a different regime applies — BSP Circular No. 1195 expressly excludes it from the automatic one-hour return, and no statutory hold is available. See what to do when you send money to the wrong recipient.

Cybercode.ph provides general educational information about technology, cybersecurity, privacy and related legal issues. It is not a substitute for legal, cybersecurity or professional advice for a specific situation.

Related: If you authorised the transfer yourself because you were promised a return, that is a different case — see investment or crypto scam: how to report it and what the SEC can do.

Featured photo: Atlantic Money / Unsplash.

Sources rechecked as of: October 2, 2026

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.