How to Report a Hacked Social Media or Online Account

Quick answer

Act immediately on two tracks:

  1. Recover and secure the account through the platform’s official recovery page.
  2. Report the incident to Philippine authorities if someone accessed the account without permission, impersonated you, sent fraudulent messages, stole money or data, threatened anyone, or used the account for another crime.

Unauthorized access may constitute illegal access under the Cybercrime Prevention Act of 2012. A platform report may restore or disable the account, but it is not the same as a police or NBI complaint. Conversely, reporting to law enforcement does not automatically recover the account—the platform controls account access.

What to do immediately

1. Preserve essential evidence

Before removing content or making major changes, quickly save what you can without delaying containment:

  • The account’s exact username, profile name, URL, and user ID, if visible
  • Screenshots or screen recordings of unauthorized posts, messages, profile changes, advertisements, or transactions
  • Password-reset, login-alert, and recovery-change emails or text messages
  • Dates and times, including the displayed time zone
  • Login history showing unfamiliar devices, locations, IP addresses, or sessions
  • The phishing message, website address, QR code, attachment, or conversation that may have caused the compromise
  • Platform support tickets, reference numbers, and replies
  • Transaction numbers, recipient accounts, amounts, and receipts if money was involved
  • Names and contact details of people who received scam messages from the account

Capture the full screen where possible. Avoid cropping out the URL, username, date, or other context. Keep original emails, files, recordings, and devices rather than relying only on screenshots.

If a phone or computer may contain malware, disconnect it from the internet and use a different trusted device for recovery. Do not factory-reset or dispose of the suspected device until important evidence has been preserved or an investigator has advised you.

2. Secure the email account and mobile number first

Your email and phone number are often the keys to every other account.

  • Change the email password to a new, unique password.
  • End unfamiliar email sessions.
  • Remove unknown recovery addresses, phone numbers, forwarding rules, filters, app passwords, and connected applications.
  • Turn on multi-factor authentication, preferably through an authenticator app, passkey, or security key where available.
  • If your SIM suddenly lost service or you stopped receiving one-time passwords, contact your telecommunications provider immediately about a possible SIM replacement or account takeover.

Change any other account that used the same or a similar password. Never send a password, recovery code, authentication code, or backup code to someone claiming to be platform support.

3. Use only the platform’s official recovery process

Type the official address yourself or open the Help or Security section inside the genuine app. Common recovery routes include:

For another service, navigate from its official app or verified website. Avoid sponsored search results, unofficial “recovery agents,” and people who ask for advance payment or remote access to your device.

If you still have access:

  • Change the password.
  • Sign out other sessions and remove unfamiliar devices.
  • Restore the correct recovery email and phone number.
  • Remove unknown administrators, linked accounts, applications, API access, and advertising or payment permissions.
  • Check scheduled posts, archived messages, deleted items, email-forwarding rules, and business-manager roles.
  • Save your account data and security history if the platform permits.
  • Review and reverse unauthorized changes through the platform’s official tools.

If you are locked out, submit the recovery form from a device, browser, and location you previously used when possible. Give consistent information and retain the case number.

4. Warn people who may be targeted

Tell contacts through a different trusted channel that the account was compromised. Ask them not to send money, open links, share codes, or respond to unusual requests. Businesses should also warn customers if the attacker is using the account to collect payments or personal information.

Do not post sensitive evidence publicly. Publicly naming a suspected hacker without reliable proof can create separate legal and safety problems.

Where to report in the Philippines

Report to the PNP Anti-Cybercrime Group

The Philippine National Police is one of the law-enforcement authorities expressly assigned to investigate cybercrime under Section 10 of Republic Act No. 10175.

You may:

  • Use the official PNP Anti-Cybercrime Group e-Complaint page; or
  • Visit the nearest PNP Anti-Cybercrime Group regional office or police station and ask that the incident be recorded and referred to the appropriate cybercrime investigator.

Under PNP Memorandum Circular No. 2021-141, cybercrime reports received through walk-in, SMS, e-Complaint, hotline, referral, or other means should be attended to and referred to an investigator. An online report may still require an interview, validation, additional evidence, and a sworn complaint.

If the e-Complaint page is unavailable, do not wait for it to return—report in person.

Report to the NBI Cybercrime Division

You may file personally with the National Bureau of Investigation’s Cybercrime Division or an appropriate regional office. The NBI’s published investigative-assistance procedure for computer-crime victims states that the service is available to the general public without a filing fee. The process may include:

  • Completion of a sworn complaint sheet
  • A preliminary interview
  • Submission of witness statements or affidavits
  • Presentation and possible examination of the relevant device
  • Collection of supporting documents

Use the official NBI regional and district office directory to find an office. As of August 7, 2026, the NBI’s public online complaint form states that it is closed, so do not rely on that form as your only report.

Use Hotline 1326 or eGovPH eReport for coordination

For cybercrime or scam coordination, call the government’s 1326 hotline or use eReport in the eGovPH app. The CICC confirmed these channels in an official government briefing.

A hotline or eReport submission can alert and coordinate authorities, but investigators may still require you to appear, execute a sworn statement, and present evidence before a formal criminal case can proceed.

If money was transferred

Immediately contact the bank, e-wallet, card issuer, cryptocurrency platform, or payment provider using its official fraud channel. Ask it to:

  • Block or secure the affected account
  • Record the transaction as disputed or unauthorized
  • Preserve relevant account and transaction records
  • Give you a complaint reference number
  • Explain any available recall, hold, chargeback, or dispute procedure

Do not wait for social-media recovery before contacting the financial institution.

If the institution is supervised by the Bangko Sentral ng Pilipinas, complain to the institution first. If its response is unresolved or unsatisfactory, escalate through the BSP Consumer Assistance Mechanism. The BSP publishes an updated directory of supervised institutions’ consumer-assistance channels.

If anyone is in immediate danger

Call 911 for an immediate threat to life, physical safety, or property. The Unified 911 system connects callers to police, fire, medical, and other emergency responders.

Report urgently if the compromised account is being used for:

  • Threats, stalking, coercion, kidnapping, or extortion
  • Release or threatened release of intimate images
  • Child sexual abuse or exploitation
  • Requests for emergency payments
  • Fraud that is still in progress
  • Access to government, health, financial, or workplace systems

Do not download, copy, or forward sexual images involving a child. Preserve the account name, URL, message details, and report reference, then seek immediate law-enforcement assistance.

Information to include in your report

Prepare a short chronological statement covering:

  1. Your name and reliable contact information
  2. The platform and exact account URL, username, or user ID
  3. How you normally controlled the account
  4. When you last accessed it normally
  5. When and how you discovered the compromise
  6. Security alerts or recovery details that were changed
  7. Unauthorized posts, messages, purchases, advertisements, or transfers
  8. Any suspected phishing link, malicious file, device theft, or SIM problem
  9. The harm already caused or still threatened
  10. Steps taken with the platform, email provider, telco, bank, or e-wallet
  11. A numbered list of attached evidence
  12. Existing police, NBI, CICC, platform, or financial-provider reference numbers

Separate facts you personally observed from suspicions. If you suspect a particular person, explain the factual basis instead of presenting the suspicion as established fact.

Ask the investigator whether an immediate data-preservation request is appropriate. Do not attempt to trace, enter, or interfere with another person’s account yourself.

What Philippine law may apply

Illegal access

Section 4(a)(1) of Republic Act No. 10175 defines illegal access as access to all or part of a computer system “without right.” A social-media, email, or other online account can fall within the law’s broad treatment of computer systems and computer data.

Illegal access is punishable under Section 8 by prision mayor—generally six years and one day to twelve years—or a fine of at least ₱200,000 up to an amount commensurate with the damage, or both. The actual charge and penalty depend on the proven acts, participation, applicable defenses, and court judgment.

Other possible offenses

Depending on what the intruder did, investigators may also examine:

  • Data interference if data was intentionally altered, damaged, deleted, or suppressed without right
  • System interference if the functioning of a system or network was intentionally or recklessly hindered
  • Computer-related forgery if data was altered or created to appear authentic for legal purposes
  • Computer-related fraud if unauthorized manipulation or interference caused damage with fraudulent intent
  • Computer-related identity theft if another person’s identifying information was intentionally acquired, used, misused, transferred, possessed, altered, or deleted without right
  • Other offenses involving fraud, threats, extortion, intimate images, child exploitation, or unlawful financial activity

A copied or impersonating profile is not necessarily proof that your original account was accessed. It may instead involve unauthorized use of your identity. Report the impersonating profile to the platform and preserve evidence of how it is being used.

Access disputes involving former employees, page administrators, business partners, spouses, or former partners are especially fact-dependent. Investigators may need contracts, role assignments, messages, revocation notices, and account-administration records to determine whether access was “without right” or exceeded previously granted authority.

Why reporting quickly matters

There is no single short deadline in Republic Act No. 10175 for making an initial police report, and the legal prescriptive period can depend on the specific offense. Delay is nevertheless risky.

For service providers covered by Philippine law, Section 13 generally requires traffic data and subscriber information to be preserved for at least six months from the transaction. Content data is preserved for six months after receipt of a lawful preservation order, with a possible one-time extension. Disclosure of protected data ordinarily requires the legal process described in the Rule on Cybercrime Warrants.

The six-month period is not a six-month filing deadline and does not guarantee that every foreign platform possesses every record for that long. Prompt reporting gives investigators a better opportunity to request preservation before records or accounts disappear. For providers outside the Philippines, official processes may be routed through the DOJ Office of Cybercrime.

Special rule for organizations holding personal data

An ordinary person whose personal account was hacked does not automatically have to file a corporate data-breach notification. The position may be different when the compromised account belongs to a company, school, clinic, employer, online seller, association, professional, or other personal information controller processing other people’s data.

Under the National Privacy Commission’s breach-reporting guidance, notification is mandatory when all required elements are present, including:

  • Sensitive personal information or information that may enable identity fraud, such as login credentials, was involved;
  • There is reason to believe an unauthorized person acquired it; and
  • The breach is likely to create a real risk of serious harm to affected individuals.

When mandatory, the personal information controller generally must notify the NPC and affected data subjects within 72 hours from knowledge or reasonable belief that the breach occurred. An incomplete initial report may be made using available information, with the full report generally due within five days unless the NPC grants additional time.

Organizations should immediately activate their incident-response and data-breach procedures and involve their data protection officer and qualified counsel. They should consult the NPC’s current reporting page and its 2026 operational advisory before filing.

Common mistakes to avoid

  • Waiting for the platform to answer before reporting ongoing fraud or threats
  • Using recovery links sent by strangers instead of navigating to the official site
  • Paying someone who promises to “hack back” or recover the account
  • Giving a supposed support agent your password or authentication code
  • Deleting messages, login alerts, posts, or transaction records before saving them
  • Factory-resetting the suspected device too soon
  • Using the same compromised password on the email account and other services
  • Assuming a barangay blotter or public social-media post automatically starts a cybercrime investigation
  • Posting unverified accusations or exposing private evidence online
  • Continuing to negotiate with an extortionist without law-enforcement advice
  • Creating edited or reconstructed screenshots that obscure the original evidence
  • Abandoning the complaint after account recovery even though fraud, threats, or data theft occurred

What may happen after a formal report

An investigator may interview you, have you execute a sworn statement, inspect the available evidence, and ask for consent or appropriate legal authority before examining a device. Authorities may issue a preservation request and, when legal requirements are met, seek a court warrant for disclosure, interception, search, seizure, or examination of computer data.

The matter may later be referred to a prosecutor for evaluation. A report does not guarantee that the offender will be identified, arrested, charged, or convicted. Identification can depend on available platform records, payment trails, subscriber information, foreign cooperation, and proof connecting a person to the unauthorized activity.

Continue the platform recovery process while the investigation is pending and keep every new response or reference number.

Frequently asked questions

Is a changed password enough to prove hacking?

No. It is an important indicator, but investigators consider the entire record: login alerts, recovery changes, unauthorized activity, device history, communications, platform records, and witness statements.

Are screenshots enough?

Screenshots are useful but may not be sufficient by themselves. Preserve original emails, messages, files, URLs, account exports, transaction records, devices, and platform responses so authenticity and context can be evaluated.

Must I know who the hacker is before reporting?

No. Report the known facts and available identifiers. Do not guess or privately attempt to enter the suspected person’s accounts.

Should I report even if I recovered the account?

Yes, when the intrusion involved fraud, financial loss, threats, impersonation, disclosure of private information, intimate images, child safety, or access to business or customer data. Recovery does not erase a completed offense or its consequences.

Will the police recover or delete the account?

Usually, the platform controls recovery, suspension, and content moderation. Law enforcement investigates possible crimes and may seek platform records through proper legal processes. Pursue both tracks.

Does changing the password destroy the case?

Ordinary containment does not prevent you from reporting. Preserve readily available alerts and evidence first when safe, then secure the account. Do not leave an attacker connected merely to gather more evidence.

What if the account is only cloned or impersonated?

Report the fake profile through the platform’s impersonation process and preserve its exact URL, username, posts, messages, and requests for money or information. Also report to law enforcement if it is being used for fraud, threats, or identity theft.

How soon should I report?

Immediately. Data may be deleted, accounts may be renamed, money may move, and other people may be victimized. Statutory data-preservation periods are not a reason to wait.


This article provides general Philippine legal information, not legal advice for a particular case. The proper complaint, offense, deadline, and remedy depend on the facts, evidence, platform records, and applicable law. Seek a Philippine lawyer promptly where substantial loss, arrest risk, sensitive personal data, threats, intimate material, child safety, or cross-border evidence is involved. Laws and official procedures were checked as of August 7, 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.