How to File a Cybercrime Complaint Against an Unknown Hacker

Quick answer

Yes. You may report a cybercrime even if you do not know the hacker’s real name, address, or location. File promptly with the NBI Cybercrime Division or the PNP’s cybercrime unit, describing the offender as an unknown person and supplying every available identifier—usernames, profile links, email addresses, phone numbers, IP or login alerts, wallet addresses, transaction references, and timestamps.

The NBI or PNP can investigate and, when legally justified, apply for cybercrime warrants to obtain subscriber information, traffic data, or other relevant records from service providers. You cannot personally compel a platform, telecommunications company, bank, or internet provider to reveal another user’s protected account information.

Do not wait until you identify the hacker yourself. Service-provider records may be retained only for limited periods, and an early, officially docketed complaint gives investigators a better opportunity to seek preservation and disclosure of data.

What conduct may qualify as “hacking”?

Under the Cybercrime Prevention Act of 2012, illegal access means accessing all or part of a computer system “without right.” Depending on what happened, the investigation may also involve:

  • Data interference, such as deleting, corrupting, altering, or damaging files or introducing malware;
  • System interference, such as intentionally or recklessly disrupting a device, account, network, website, or service;
  • Computer-related fraud, when unauthorized manipulation or interference causes damage with fraudulent intent;
  • Computer-related identity theft, involving unauthorized acquisition, use, possession, alteration, or deletion of identifying information;
  • Misuse of devices, including specified tools, credentials, or access codes intended for committing cybercrime; or
  • Another offense committed through information and communications technology, such as fraud, threats, extortion, or unauthorized use of financial accounts.

A forgotten password, unexplained device malfunction, or suspicious message does not by itself prove illegal access. Investigators will look for evidence that access occurred without authority and determine which offense, if any, the facts support.

Where to file the report

Republic Act No. 10175 designates both the National Bureau of Investigation and Philippine National Police as cybercrime law-enforcement authorities.

National Bureau of Investigation

You may approach the NBI Cybercrime Division or an NBI Regional Cybercrime Center. The NBI’s published procedure directs a complainant to appear before the division, complete a complaint sheet, undergo an initial interview, execute a sworn statement or submit a prepared affidavit, provide supporting documents, and make relevant devices available for examination when requested. The service is listed as free. See the NBI’s official investigative-assistance procedure for victims of computer crimes.

The NBI also maintains an online complaint page. Because an online submission may not complete every sworn-statement or device-examination requirement, keep its acknowledgment and follow any instruction to appear personally. Current NBI office details are available on its official contact page.

Philippine National Police

You may report to the PNP’s cybercrime investigators or ask the nearest police station to refer you to the appropriate cybercrime unit. Obtain the receiving officer’s name, office, date of submission, and complaint or reference number.

Use only contact details published through an official government website or verified government account. Cybercriminals sometimes impersonate investigators and demand “recovery,” “processing,” or cryptocurrency fees.

Prosecutor’s office

A police or NBI report starts the investigation; it is not necessarily the same as a criminal complaint already filed for preliminary investigation.

Once investigators develop sufficient evidence identifying a probable offender, a sworn complaint may be filed with the proper city, provincial, or state prosecutor. Under Rules 110 and 112 of the Rules of Criminal Procedure, a prosecutor-level complaint generally must be supported by the complainant’s and witnesses’ affidavits and other documents establishing probable cause. A formal criminal case in court is filed by the prosecutor through an information if probable cause is found.

When the offender remains unknown, begin with the NBI or PNP. An unknown username alone is usually insufficient for a prosecutor to subpoena and give notice to a respondent whose identity and address have not yet been established.

What to do before filing

1. Stop further harm

Using a different, trusted device if possible:

  • Change the password of the affected account and any other account using the same or a similar password.
  • Sign out unknown sessions and revoke unfamiliar devices, applications, forwarding rules, recovery addresses, and API access.
  • Enable multi-factor authentication and save recovery codes securely.
  • Secure the email account and mobile number used for password recovery.
  • Ask the telecommunications provider to protect the number if SIM swapping is suspected.
  • Contact banks, electronic-wallet providers, card issuers, or cryptocurrency services immediately if money or credentials may be at risk.
  • Report the compromised account through the platform’s official recovery and abuse channels.

If changing credentials could erase active-session information or other evidence, first photograph or record what you can safely see. Do not leave the account exposed merely to gather more proof.

2. Preserve the evidence

Keep the original electronic material whenever possible. Useful evidence may include:

  • Full screenshots showing the account name, URL, date, time, and surrounding context;
  • Screen recordings of unauthorized settings, messages, posts, transfers, or login activity;
  • Original emails, including full headers—not only screenshots of the message;
  • Security alerts, access histories, device lists, password-reset notices, and login notifications;
  • Exact usernames, profile URLs, channel IDs, email addresses, telephone numbers, domain names, and account numbers;
  • IP addresses or technical logs actually supplied by a system or provider;
  • Dates, times, and time zones for each event;
  • Transaction receipts, bank or wallet statements, reference numbers, beneficiary details, and cryptocurrency transaction hashes;
  • Copies of ransom demands, threats, malicious files, links, and chat exports;
  • Proof that you own or were authorized to use the affected account, system, or data;
  • Platform-support tickets, recovery emails, and preservation requests; and
  • Names and contact details of witnesses with personal knowledge.

Keep an untouched copy and a working copy. Record when and how each item was obtained. Export original files instead of repeatedly forwarding or editing them. The Rules on Electronic Evidence place the burden of authenticating an electronic document on the party offering it, so context, source, and integrity matter.

Do not publish sensitive evidence online. Public disclosure may expose personal information, alert the offender, encourage deletion of accounts, or compromise investigative steps.

3. Prepare a clear chronology

Write a factual timeline containing:

  1. When you last had normal access;
  2. When and how you discovered the intrusion;
  3. What account, device, system, or data was affected;
  4. What unauthorized acts occurred;
  5. What losses, threats, or disruptions followed;
  6. What recovery or security measures you took;
  7. Which providers you contacted and their responses; and
  8. Every identifier associated with the unknown offender.

Separate facts you personally observed from conclusions. For example, write “At 9:14 p.m., I received a login alert from this IP address” instead of stating that a named person hacked you unless reliable evidence supports that claim.

How to file, step by step

  1. Choose the NBI or PNP cybercrime unit. If money is still moving, threats are continuing, or accounts remain under the offender’s control, report urgently rather than waiting for a perfect evidence package.

  2. Bring identification and account-ownership proof. Also bring printed copies and securely stored electronic copies of your chronology and supporting materials. Ask the office beforehand whether it requires additional photocopies or a particular storage medium.

  3. Describe the respondent accurately. State that the offender’s civil identity and address are unknown. List every known digital identifier. Do not substitute the name of someone you merely suspect.

  4. Execute a truthful sworn statement. Include only facts you can attest to and clearly identify information learned from records, providers, or witnesses. False or exaggerated details can damage the investigation and expose the complainant to legal consequences.

  5. Allow lawful forensic handling where necessary. Investigators may ask to examine the affected device. Ask for documentation of any device or storage medium you surrender and keep a copy of the receipt or inventory. Do not factory-reset, reformat, or reinstall the operating system before investigators advise you, unless an urgent security reason makes that necessary.

  6. Request a docket or reference number. Record the investigating officer’s official contact information and the date the complaint was received.

  7. Ask whether immediate data preservation is needed. Identify the platforms, banks, telecommunications companies, hosting providers, registrars, or other entities likely to hold relevant records. Investigators—not the victim—decide whether the legal requirements for a preservation order or warrant are met.

  8. Submit new evidence through the assigned investigator. Preserve later messages, login alerts, transactions, or provider responses and refer to the same case number. Do not create multiple reports about the same incident without disclosing the earlier report.

How investigators can identify an unknown hacker

The displayed account name, email address, telephone number, or IP address may be false, shared, stolen, masked, or routed through another country. Attribution therefore requires more than matching a screen name.

Under Republic Act No. 10175 and the Supreme Court’s Rule on Cybercrime Warrants, law-enforcement authorities may seek a Warrant to Disclose Computer Data when the legal requirements are satisfied. It can authorize an order requiring a person or service provider to submit subscriber information, traffic data, or other relevant data in its possession or control.

A disclosure warrant is tied to a valid complaint that has been officially docketed and assigned for investigation. Upon receipt of the resulting lawful order, the person or service provider is required by Section 14 of the Act to disclose the covered data within 72 hours. That 72-hour period applies to the recipient of the order; it is not a promise that the victim’s entire investigation will be completed within three days.

Other cybercrime warrants may authorize interception, search, seizure, or forensic examination in circumstances covered by the Rule. The victim does not apply for these warrants personally. A qualified law-enforcement officer applies, and a judge determines whether the required probable cause and particularity exist.

An IP address or registered subscriber is normally an investigative lead, not automatic proof that a particular person committed the offense. Investigators may need device evidence, access times, account recovery records, payment information, admissions, witness testimony, or other corroboration.

Why prompt reporting matters

Section 13 of Republic Act No. 10175 provides that service providers must preserve the integrity of traffic data and subscriber information for at least six months from the transaction. Content data is preserved for six months from the provider’s receipt of a law-enforcement preservation order. Law enforcement may order one extension for another six months in the circumstances allowed by law.

These rules do not guarantee that every company possesses every record for six months, that deleted content can be recovered, or that a foreign provider will immediately comply. Report as soon as practicable, particularly where logs, disappearing messages, CCTV recordings, transaction tracing, or account content may be lost.

The Act does not establish a universal short deadline requiring every hacking victim to complain within a fixed number of days. Criminal prescription instead depends on the exact offense, governing law, prescribed penalty, when the offense was committed or discovered, and what action interrupted prescription. Act No. 3326 supplies prescriptive periods for many violations of special laws, but calculating the applicable period can be legally and factually complex. Do not treat a potentially long prescriptive period as a reason to delay.

Jurisdiction and incidents involving foreign platforms or hackers

A foreign email service, social-media platform, VPN, server, or suspected offender does not automatically place the incident outside Philippine law.

Section 21 of Republic Act No. 10175 recognizes Philippine jurisdiction when, among other grounds, an element occurred in the Philippines, a computer system used was wholly or partly situated here, or the offense caused damage to a person who was in the Philippines when it occurred. Criminal actions under Sections 4 and 5 are filed before the designated cybercrime court in a qualifying province or city, subject to the Rule’s venue provisions.

Cross-border evidence may require international cooperation, foreign legal process, or action by the provider in another country. This can affect speed and outcome. Give investigators the provider’s exact name, URL, country information if known, and copies of any response from the provider.

If money was stolen

Treat financial containment and criminal reporting as parallel tasks:

  • Notify the bank, card issuer, electronic-wallet provider, exchange, or remittance company immediately through its official fraud channel.
  • Request blocking, recall, freezing, or tracing where still possible.
  • Preserve transaction references, recipient-account details, timestamps, authentication notices, and all correspondence.
  • Change compromised banking, email, and mobile credentials.
  • File the NBI or PNP report without waiting for the provider’s final investigation.
  • Inform the investigator immediately if funds continue moving.

A criminal complaint does not guarantee reimbursement. Recovery depends on matters such as the payment rail, speed of reporting, provider rules, available funds, contractual terms, and evidence of authorization or compromise. Do not pay anyone who promises guaranteed recovery, secret tracing, or access to an investigator in exchange for an advance fee.

Where the incident involves the misuse of financial accounts, other laws—including the Anti-Financial Account Scamming Act—may also be relevant. The investigating authority and prosecutor should determine the proper charges from the evidence.

Common mistakes to avoid

  • Waiting to learn the hacker’s real identity before reporting;
  • Deleting messages, wiping devices, or closing accounts before preserving evidence;
  • Submitting cropped screenshots that omit the URL, username, date, time, or conversation context;
  • Editing, annotating, renaming, or repeatedly converting the only copy of a file;
  • Treating an IP address, subscriber name, or profile photo as conclusive identification;
  • Publicly accusing a suspected person without sufficient evidence;
  • Attempting to hack back, install spyware, access another person’s account, or buy unlawfully obtained data;
  • Paying ransom or “recovery agents” without consulting law enforcement;
  • Giving an alleged investigator passwords, one-time PINs, recovery codes, or remote control of a device;
  • Assuming a platform abuse report is already a criminal complaint; or
  • Failing to secure the email account or mobile number through which other accounts can be reset.

When help is urgent

Contact law enforcement and the affected service providers immediately if:

  • There is a threat to life, physical safety, or critical infrastructure;
  • The offender is extorting you or threatening to publish intimate images or sensitive personal data;
  • A child may be in danger or sexual-abuse material is involved;
  • Bank, wallet, or cryptocurrency transfers are continuing;
  • Business, government, health, or other essential systems remain compromised;
  • Malware may be spreading to other users or systems;
  • The hacker still controls your email, mobile number, administrator account, or backups; or
  • Evidence is disappearing or a provider’s retention period may soon expire.

For immediate physical danger, contact the local police or emergency services first. A lawyer experienced in cybercrime or digital evidence may be especially important where the incident affects a business, involves substantial loss, crosses national borders, exposes regulated personal data, or may lead to claims against an employee, contractor, or service provider.

Frequently asked questions

Can I file without the hacker’s name or address?

Yes. Report the offender as unknown and provide the digital identifiers and evidence you possess. The NBI or PNP may investigate identity through lawful process. A later prosecutor-level complaint will require enough information and evidence to proceed against an identifiable respondent.

Is a screenshot screenshot enough?

A screenshot can be useful, but it is stronger when supported by the original message or file, full headers, URLs, account records, device or platform logs, transaction documents, and testimony explaining how it was obtained. Electronic evidence must be authenticated.

May I demand the hacker’s IP address from Facebook, Google, an ISP, or another provider?

You may ask a provider to preserve your own records or assist with account recovery, but providers generally will not disclose another user’s protected subscriber or traffic data merely because a private person demands it. Law enforcement can seek disclosure through the process required by Republic Act No. 10175 and the Rule on Cybercrime Warrants.

Should I report to both the NBI and PNP?

You may seek help from either authority. Duplicate filings can cause confusion, so disclose any existing complaint and its docket number. If a second agency becomes involved, ask how the investigations will be coordinated.

Do I need a lawyer to make the initial report?

Not ordinarily. The NBI’s published procedure contemplates direct assistance to complainants. A lawyer can nevertheless help organize affidavits, preserve privilege and business interests, assess related civil or regulatory duties, and follow the prosecutor’s proceedings.

Must I surrender my phone or computer?

Not in every case. Investigators may need access to a relevant device for forensic examination, particularly when logs or original communications are stored only there. Ask what examination is needed, whether a forensic image will suffice, and obtain an inventory or receipt for anything surrendered. Law-enforcement examination of computer data remains subject to applicable constitutional and warrant rules.

Can investigators act if the hacker is abroad?

Potentially, yes. Philippine jurisdiction may exist when the statutory grounds are met, but identifying and prosecuting a foreign offender or obtaining overseas evidence may require international cooperation and may take longer.

Will filing guarantee an arrest, conviction, or recovery of money?

No. The result depends on evidence, attribution, jurisdiction, provider records, applicable offenses, prosecutorial probable cause, and proof in court. A complaint enables lawful investigation; it does not predetermine the outcome.

Official sources

General-information disclaimer

This article provides general Philippine legal information, not legal advice or a prediction of any case’s outcome. The proper offense, venue, procedure, prescriptive period, and available remedies depend on the actual records and circumstances. Official legal and procedural sources were last checked on September 4, 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.