Quick answer
Yes. Posting a supposed scammer’s ID online can expose you to a criminal cyberlibel complaint, a civil damages case, and a data-privacy complaint—even if you genuinely believe the person scammed you.
Calling an identifiable person a “scammer,” “fraudster,” or “magnanakaw” imputes criminal or dishonest conduct. If the accusation is published through Facebook, TikTok, X, Messenger groups, online marketplaces, or another computer system, it may satisfy the basic elements of cyberlibel. Uploading the person’s ID makes identification especially easy and may disclose sensitive information such as an address, birth date, signature, photograph, and government-issued number.
Truth can be a defense, but truth alone is not automatically enough. Philippine libel law generally requires the accused to show that the charge was true and was published with good motives and for justifiable ends. A public “name-and-shame” post is legally riskier than a confidential, evidence-supported report to the police, prosecutor, bank, e-wallet provider, platform, or other proper authority.
There is an additional practical danger: the ID may be stolen, altered, or borrowed. The person shown on it may be another victim rather than the person who operated the scam.
Why calling someone a scammer can be cyberlibel
Section 4(c)(4) of the Cybercrime Prevention Act of 2012 applies the law on libel to statements made through a computer system or similar means. Under Articles 353 and 355 of the Revised Penal Code, libel involves a public and malicious imputation of a crime, vice, defect, act, omission, condition, status, or circumstance that tends to dishonor, discredit, or expose a person to contempt.
A cyberlibel charge generally requires proof of:
A defamatory imputation. Calling someone a scammer normally suggests fraud, estafa, or deliberate dishonesty. Courts consider the words in their full context, including captions, hashtags, images, emojis, and surrounding comments.
Publication. At least one person other than the subject must receive or see the statement. A public post plainly qualifies, but publication can also occur in a private group chat or community page.
Identification. The complainant need not always be expressly named. A photograph, ID, username, phone number, transaction details, workplace, or other clues may make the person identifiable.
Malice. Article 354 generally presumes a defamatory imputation malicious unless good intention and justifiable motive are shown or the communication is privileged. Different rules may apply to qualifiedly privileged communications and statements involving public officials or public figures.
Use of a computer system. The statement must have been made online or through information and communications technology.
The prosecution must still prove every element, including who authored the post, beyond reasonable doubt. A screenshot bearing a person’s name is important evidence, but it does not by itself conclusively establish who controlled the account or made the post.
The Supreme Court upheld the application of libel law to an online author in Disini v. Secretary of Justice. The Court did not, however, uphold automatic criminal liability for everyone who merely clicks “Like,” “Share,” or another reaction under the Cybercrime Prevention Act’s aiding-and-abetting provision. A person who writes a new defamatory caption, adds an accusation, or republishes material as their own may face a different factual analysis.
“But the person really scammed me”—is truth a complete defense?
Not by itself.
Article 361 of the Revised Penal Code permits proof of truth in a criminal libel case. For an accusation of criminal conduct, acquittal generally requires proof that:
- the accusation was true; and
- it was published with good motives and for justifiable ends.
That means a court may examine not only what happened, but also why, how, where, and to whom you disclosed it. Evidence that you were warning likely victims may support a claim of proper motive, but it does not create an automatic “public warning” exemption. Posting a full ID to millions of users, encouraging harassment, using insults, or continuing after doubts arise may undermine that position.
A payment receipt or unanswered message does not necessarily prove criminal fraud. A failed transaction may involve breach of contract, mistake, delay, account takeover, identity theft, or another explanation. Describing a person as a convicted scammer is especially dangerous when there has been no conviction.
Safer factual wording also does not guarantee immunity, but it reduces avoidable conclusions. Compare:
“This person is a scammer. I-post natin para mag-viral.”
with:
“I paid ₱___ on [date] for ___. The item has not arrived, and I have received no response since [date]. I have reported the transaction to [provider/authority]. Please contact the proper authority if you have information.”
The second version reports verifiable events without declaring guilt. Even then, disclose only information reasonably necessary for a legitimate purpose.
A report to authorities is different from a public exposé
Article 354 recognizes qualifiedly privileged communications, including a private communication made in the performance of a legal, moral, or social duty. A good-faith complaint sent to the police, prosecutor, financial institution, employer with a legitimate role, or platform fraud team may fall within this protection.
Qualified privilege is not absolute. Liability may still arise if actual malice is proved—for example, if the accusation was knowingly false, made with reckless disregard for the truth, or circulated beyond people who had a legitimate reason to receive it.
The privilege attached to a confidential report does not automatically extend to a public Facebook post containing the same allegations. “I already reported it to the police” is therefore not a blanket defense for publishing the person’s ID to the public.
Posting the ID creates a separate privacy risk
An ID normally contains personal data. Government-issued information peculiar to an individual—such as license or identification numbers—falls within the Data Privacy Act’s definition of sensitive personal information. An accusation or record concerning an alleged offense may also involve sensitive personal information.
Under Sections 11 to 13 of the Data Privacy Act of 2012:
- processing must be fair, lawful, transparent, and for a legitimate purpose;
- the information used must be accurate, relevant, and not excessive;
- ordinary personal information requires a lawful basis;
- sensitive personal information is generally prohibited from being processed unless a specific statutory exception applies; and
- information necessary to establish, exercise, or defend legal claims, or information provided to a government or public authority, may be processed under the applicable exception.
“Processing” is broad enough to include collecting, storing, using, and disclosing personal data. The National Privacy Commission specifically warns that sharing photos and videos containing personal data must have a lawful basis and comply with transparency, legitimate purpose, and proportionality. It also notes that exposed IDs can facilitate identity theft, fraud, harassment, or stalking. See the NPC’s reminder on sharing content containing personal data.
Providing an unredacted ID privately to investigators may be necessary for a legal claim. Posting the same document publicly is harder to justify when the purpose can be achieved through a police report, platform report, or narrowly worded warning without revealing the ID number, address, birth date, signature, or other sensitive fields.
Data Privacy Act liability is fact-dependent. It may turn on the data involved, how it was obtained, the purpose and reach of the disclosure, whether an exception applies, and whether the person posting it is acting as a personal information controller. The fact that an ID was sent during a transaction—or was already visible somewhere online—does not automatically authorize unrestricted republication.
The person shown on the ID may not be the scammer
Treat an ID as a lead, not conclusive proof. Online scammers commonly use:
- stolen or lost IDs;
- screenshots taken from legitimate transactions;
- edited IDs;
- mule accounts;
- compromised social-media or e-wallet accounts;
- another person’s name paired with a different phone number; or
- fabricated documents containing a real person’s photograph.
Before publicly connecting an identity to a crime, ask whether the evidence reliably links the person—not merely the document—to the account, messages, payment destination, and fraudulent act. A mismatch can injure an innocent person and seriously weaken a defense based on truth or good motive.
Can the person also sue for damages?
Yes. “Sued” is often used loosely, but several proceedings are possible:
- a criminal complaint for cyberlibel;
- an independent civil action for defamation;
- a civil claim based on privacy, abuse of rights, or another wrongful act; and
- an administrative or criminal data-privacy complaint, depending on the facts.
Article 33 of the Civil Code permits an independent civil action for damages in cases of defamation. It uses the civil standard of preponderance of evidence, which is lower than proof beyond reasonable doubt. Articles 19, 20, 21, and 26 may also apply to conduct that unlawfully or abusively harms another person’s rights, dignity, privacy, or peace of mind.
Available relief depends on the pleaded cause of action and proof. It may include removal or prevention of further publication and actual, moral, nominal, or exemplary damages where legally justified. A complainant does not automatically win simply because an ID was posted; the court or agency must evaluate the complete evidence and applicable defenses.
Cyberlibel deadlines require immediate attention
Cyberlibel has a one-year prescriptive period. In its April 8, 2026 en banc resolution in Causing v. People, the Supreme Court affirmed that the period is counted from discovery of the offense by the offended party, the authorities, or their agents—not automatically from the original posting date.
Prescription can involve disputed facts, including when discovery occurred and whether a proper complaint interrupted the period. The filing of a complaint for preliminary investigation can interrupt prescription under the applicable rules. Do not wait for the one-year mark if you are a complainant, and do not assume an old post is legally harmless if you are the poster.
Separate civil, privacy, or other claims may follow different limitation periods and procedures.
What to do instead of posting the full ID
If you believe you were scammed:
Contact the bank, card issuer, or e-wallet immediately. Ask whether the transfer can be held, traced, disputed, or recalled. Obtain a reference number and written confirmation.
Report the account through the platform’s fraud channel. Preserve the report number and the platform’s response.
Prepare a chronological evidence file. Include the advertisement, profile URL, username, chat history, call logs, transaction receipts, account numbers, delivery records, promises made, and your attempts to resolve the matter.
Report the incident to law enforcement or prosecutors. The DOJ Office of Cybercrime acts on cybercrime complaints and referrals. You may also approach the NBI cybercrime unit, PNP Anti-Cybercrime Group, or the prosecutor’s office with jurisdiction. Confirm current submission requirements directly with the receiving office.
Give investigators the complete ID privately. Do not redact the evidentiary copy supplied securely to the proper authority unless instructed to do so.
If a public warning is genuinely necessary, minimize it. State verified transaction facts, avoid declaring guilt, omit unrelated family or employment details, and fully cover the ID number, address, birth date, signature, QR code, barcode, and other identifiers. Consider omitting the ID image entirely.
Update or remove the warning when circumstances change. A refund, mistaken identity, hacked account, or contrary evidence should be addressed promptly and visibly.
Evidence to preserve
Keep original files whenever possible, not only cropped screenshots. Preserve:
- the complete post or profile URL;
- username and profile identifiers;
- date and time, including the time zone;
- full-page screenshots showing context;
- screen recordings showing how the page was reached;
- original chat exports and attachments;
- transaction confirmations and official statements;
- emails and SMS messages with headers or sender details;
- platform, bank, police, and complaint reference numbers;
- delivery documents and tracking history;
- witness names and affidavits, if appropriate; and
- the device or account from which the material was accessed.
Do not edit the original evidence. Work from copies and keep a simple record of when and how each item was obtained. Electronic evidence may require authentication; a screenshot’s evidentiary value depends on its source, completeness, and supporting testimony or records.
If you already posted the ID
Act promptly:
- Save a private evidentiary copy, including the URL, date, comments, and original file.
- Remove the public ID or replace it with a thoroughly redacted version.
- Stop encouraging shares, tagging relatives, contacting employers, or inviting confrontation.
- Delete threats, personal addresses, unrelated allegations, and identifying information posted by commenters where you control the page.
- If the identification or accusation may be wrong, publish a clear correction through a channel likely to reach the original audience.
- Preserve any demand letter, platform notice, subpoena, prosecutor’s notice, or summons.
- Consult a Philippine lawyer before submitting an affidavit or detailed public response.
Removing the post does not erase a completed publication or copies already made by others. It can, however, reduce continuing harm and may be relevant to motive, mitigation, or settlement.
Common mistakes
- Treating an ID as proof that its owner operated the scam.
- Believing that “PM me for proof” prevents publication.
- Assuming a private Facebook group or group chat cannot satisfy publicity.
- Thinking “allegedly” cures an otherwise baseless accusation.
- Posting the ID number, address, signature, birth date, or QR code when none is needed.
- Relying on “truth is an absolute defense” without considering good motive and justifiable purpose.
- Tagging the person’s relatives, employer, school, or customers to pressure them.
- Reposting another person’s allegation with a new accusatory caption.
- Editing or deleting all evidence before making a report.
- Waiting until the cyberlibel prescriptive period is nearly over.
- Ignoring a prosecutor’s subpoena, court summons, or NPC notice.
When legal help is urgent
Speak with a lawyer promptly if:
- you received a subpoena, complaint-affidavit, demand letter, summons, or NPC order;
- the one-year cyberlibel period may be close;
- the post went viral or was copied across platforms;
- the ID may belong to an innocent person;
- threats, addresses, children’s information, bank details, or biometrics were exposed;
- you added allegations not supported by your records;
- law enforcement is requesting access to a device or account;
- the disputed transaction involves many complainants or a large amount; or
- there are threats of violence, stalking, or immediate financial loss.
If you cannot afford private counsel, ask the Public Attorney’s Office whether you meet its eligibility and merit requirements, or inquire with the Integrated Bar of the Philippines or a local legal-aid office.
Frequently asked questions
Is it cyberlibel if I post only the ID without writing the person’s name?
It can be. The photograph and details may identify the person, while the caption and context may communicate that the person committed fraud. Courts assess the post as a whole.
Is writing “alleged scammer” safe?
Not automatically. A disclaimer cannot cure an accusation made without a reliable factual basis. The surrounding wording, images, audience, and purpose still matter.
Can I post the ID if I blur the number?
Blurring the number reduces privacy risk but does not eliminate cyberlibel. The face, name, caption, and transaction details may still identify and defame the person. Other fields—including the address, birth date, signature, QR code, and barcode—must also be considered.
What if the scammer used a fake name?
You may report the alias and account details to investigators and the platform. Avoid claiming that the real person whose ID or photograph appears in the account committed the crime unless reliable evidence establishes that connection.
Can the person complain even if the post is true?
Yes. A person may file a complaint; whether it succeeds is another question. You may need evidence of truth, good motive, justifiable purpose, privilege, or the absence of another required element.
Am I liable merely for sharing someone else’s post?
The Supreme Court rejected automatic aiding-and-abetting liability for ordinary “Like,” “Comment,” and “Share” reactions to cyberlibel. But writing a new defamatory caption, adopting the accusation as your own, altering the material, or independently publishing it can create separate risk.
Where can a privacy complaint be filed?
The National Privacy Commission explains its current forms, evidence requirements, filing methods, and exhaustion requirement in its official complaint mechanics. Ordinarily, the complainant must first notify the respondent in writing and allow an opportunity to act; the NPC states that proof of no timely or appropriate action, or no response within 15 calendar days after receipt, must accompany the complaint, subject to the governing rules and exceptions.
Should I delete a post after receiving a complaint?
Preserve an accurate private copy first, then obtain advice about removing or correcting the public material. Do not destroy evidence, fabricate records, pressure witnesses, or replace the post with fresh accusations.
Official legal sources
- Cybercrime Prevention Act of 2012, Republic Act No. 10175
- Revised Penal Code, particularly Articles 353–362
- Disini v. Secretary of Justice, G.R. No. 203335, February 11, 2014
- Causing v. People, G.R. No. 258524, April 8, 2026
- Data Privacy Act of 2012 and official NPC text
- NPC reminder on sharing photos and videos containing personal data
- Civil Code of the Philippines
- DOJ Office of Cybercrime
This article provides general legal information, not advice for a specific case and not an attorney-client relationship. Outcomes depend on the exact words, audience, evidence, identity of the account user, manner of disclosure, and procedural history. Sources and procedures were checked as of July 24, 2026.