Quick answer
If your Facebook account was hacked and is being used to ask contacts for money, sell fake items, solicit investments, or commit other scams, act on four tracks immediately:
- Recover and secure the account through Facebook’s official hacked-account process.
- Warn possible victims through another trusted channel, without deleting evidence or making unverified accusations.
- Preserve the account, message, payment, and login evidence and report the incident promptly to Philippine cybercrime authorities.
- If money was transferred, contact the sending bank or e-wallet immediately through its official 24/7 fraud channel and request temporary holding and tracing of the disputed funds.
Unauthorized access, fraudulent manipulation of computer data, and misuse of another person’s identifying information may constitute offenses under the Cybercrime Prevention Act. A scam carried out through Facebook may also amount to estafa or another offense committed through information and communications technology, depending on the evidence.
Reporting does not guarantee that Facebook will restore the account, that authorities will identify the offender, or that transferred money will be recovered. Speed matters because access can be changed again, funds can be moved, and service-provider data may not remain available indefinitely.
What to do immediately
1. Use Facebook’s official recovery process
Go directly to facebook.com/hacked, preferably using a device and internet connection previously used for the account.
Follow the prompts to identify the account, reverse unauthorized changes, and reset the password. If you still have access:
- Change the Facebook password immediately.
- Change the password of the email account connected to Facebook.
- Review logged-in devices and end unfamiliar sessions.
- Remove unknown email addresses, mobile numbers, linked accounts, applications, and business administrators.
- Turn on two-factor authentication using an authenticator app or another secure method.
- Check Messenger, Marketplace, Pages, advertising accounts, Meta Business assets, and saved payment methods.
- Download or preserve available account activity before removing relevant evidence.
Use a new, unique password. If the old password was reused elsewhere, change it on every affected account, especially email, banking, e-wallet, cloud-storage, and mobile-provider accounts.
Do not rely on “account recovery agents” who contact you through Messenger or demand payment, an OTP, a recovery code, remote access, or a copy of your ID through an unofficial channel.
2. Secure the email address and mobile number
Facebook recovery may fail if the hacker also controls the linked email or SIM.
For the email account:
- Review login history, recovery addresses, forwarding rules, filters, and authorized applications.
- Remove unfamiliar recovery methods or forwarding addresses.
- Sign out other sessions and enable two-factor authentication.
- Preserve security alerts showing when passwords or recovery details were changed.
If the phone suddenly lost signal or the SIM may have been replaced, contact the telecommunications provider immediately. Ask whether a SIM replacement, porting request, or account change occurred, and request protection against further unauthorized changes.
3. Warn contacts without destroying evidence
Use another verified account, SMS, email, phone calls, or trusted relatives to announce that the Facebook account has been compromised.
The warning should identify:
- The exact profile name and profile URL.
- The approximate time the owner lost control.
- The kinds of messages or offers that should be ignored.
- A clear instruction not to send money, disclose OTPs, click links, or continue negotiating.
- An alternative verified contact method.
Ask recipients to preserve the entire conversation and transaction records before blocking or reporting the account. If possible, have several contacts use Facebook’s built-in reporting tools against the scam messages or compromised profile.
Avoid publicly naming a suspected hacker unless reliable evidence supports the identification. An IP address, phone number, payment-account name, or screenshot alone may not establish who actually controlled the account.
4. Contact banks and e-wallets at once if money was sent
The person who sent the money—the source account owner—should immediately use the originating bank’s or e-wallet issuer’s official 24/7 fraud-reporting channel. Do not wait for a police report before making the initial fraud report.
Provide:
- Source account name and masked account number.
- Amount, date, and exact time of each transfer.
- Transaction reference number.
- Transfer method, such as InstaPay, PESONet, QR Ph, card, or e-wallet transfer.
- Receiving institution, account number, account name, and mobile number, if known.
- A short explanation that the transfer resulted from a Facebook impersonation scam.
- Screenshots and other documents requested by the institution.
Ask for:
- A complaint or case-reference number.
- Temporary holding of any remaining disputed funds.
- Tracing through receiving and subsequent financial institutions.
- Written confirmation of the documents and deadlines needed for coordinated verification.
Under the Anti-Financial Account Scamming Act and current BSP rules, an originating financial institution may initiate a complaint-based temporary hold when the source account owner reports a disputed transaction. The initial hold may last up to five calendar days and, when the governing conditions are met, may be extended by up to 25 additional calendar days. The total administrative holding period may not exceed 30 calendar days unless extended by a competent court. A hold is not automatic reimbursement: funds may already have been withdrawn or transferred, and their eventual disposition depends on verification and the applicable rules. See Republic Act No. 12010 and the BSP’s Manual of Regulations for Payment Systems.
If the financial institution does not resolve the complaint, first complete its internal complaint process and then use the BSP Consumer Assistance Mechanism. A BSP complaint is separate from a criminal complaint.
Preserve evidence before it disappears
Keep the original electronic files whenever possible. Screenshots are useful, but they should not be the only record.
Preserve:
- The exact Facebook profile URL, username, user ID if visible, and Page or Marketplace URLs.
- Full-screen screenshots showing the account name, dates, times, and surrounding conversation.
- Screen recordings that show how the profile, posts, and message threads were accessed.
- Complete Messenger conversations, including voice messages, attachments, deleted-message notices, and payment instructions.
- Scam posts, advertisements, listings, comments, and reactions.
- Facebook and email security alerts, login notices, password-reset messages, and notifications of changed contact details.
- Dates and times when access was lost, recovered, or changed.
- Devices and browsers previously used for the account.
- Mobile numbers, email addresses, links, QR codes, bank accounts, e-wallet accounts, and transaction references supplied by the scammer.
- Receipts, bank statements, e-wallet histories, and communications with financial institutions.
- Names and contact details of recipients who received scam messages.
- Copies of reports submitted to Facebook, banks, CICC, PNP, NBI, or DOJ, including acknowledgment and case numbers.
Do not crop away identifying context. Keep both the original and a working copy. Record who obtained each item, when it was obtained, and from which device or account. Export conversations or account data when the platform permits.
Electronic messages and files are not automatically excluded merely because they came from Facebook, but their authenticity, relevance, manner of acquisition, and integrity may have to be established. The Supreme Court has recognized that Facebook Messenger material obtained by private individuals can be admissible in appropriate circumstances; admissibility still depends on the facts and the rules of evidence. See the Supreme Court’s official discussion in Cadajas v. People.
Do not secretly intercept communications, break into another account, or install spyware to obtain evidence. Law-enforcement access to nonpublic computer data may require the appropriate judicial warrant.
Where to report the incident
PNP Anti-Cybercrime Group
A victim may report to the Philippine National Police Anti-Cybercrime Group or an appropriate regional cybercrime unit. Bring identification, a chronological account, the compromised profile URL, electronic evidence, and transaction records.
Because unofficial pages sometimes impersonate police offices, verify contact details through the PNP-ACG’s official government domain or office before sending sensitive documents.
National Bureau of Investigation
The NBI Cybercrime Division investigates computer-related offenses. The NBI provides an online complaint page and publishes its Cybercrime Division and regional-office details through the official NBI directory.
An online report may be only the first step. Investigators may require an in-person appearance, original records, an affidavit, or additional documents.
CICC and DOJ Office of Cybercrime
Cyber incidents may also be reported to the Cybercrime Investigation and Coordinating Center through its official reporting channels, including hotline 1326 when available. The Department of Justice maintains an official cybercrime incident reporting page.
CICC and DOJ reporting can facilitate referral or coordination, but it does not replace Facebook recovery, the financial institution’s fraud process, or any affidavit and complaint required by investigators or prosecutors.
What offenses may apply
The precise charge depends on how access was obtained, what the offender did inside the account, what representations were made, and whether anyone suffered loss.
Illegal access
Section 4(a)(1) of the Cybercrime Prevention Act of 2012 penalizes access to the whole or any part of a computer system without right. The Act’s concept of a computer system is broad enough to cover internet accounts and devices; simply calling the incident “hacking” is not a substitute for proving unauthorized access.
Computer-related identity theft
Using, misusing, possessing, altering, or deleting another person’s identifying information without right may fall under computer-related identity theft under Section 4(b)(3). Using the owner’s name, photograph, account, contacts, or other identifying information to impersonate that person may be relevant evidence.
Computer-related fraud or forgery
Unauthorized alteration or use of computer data for a fraudulent purpose may potentially constitute computer-related fraud or computer-related forgery. Whether either provision applies turns on the specific manipulation, resulting data, intent, and damage proved.
Estafa or another offense committed through ICT
If the offender made false representations that induced a person to part with money or property, the facts may support estafa under Article 315 of the Revised Penal Code. Section 6 of the Cybercrime Prevention Act addresses offenses under the Revised Penal Code and special laws when committed by, through, and with the use of information and communications technology.
Not every hacked account produces every offense. Investigators and prosecutors determine which charge is supported by the evidence; the complainant should describe facts accurately rather than select or exaggerate a charge.
Financial-account scamming offenses
If bank, e-wallet, payment, or other financial accounts were obtained, sold, lent, controlled, or used for prohibited money-mule or social-engineering activity, the Anti-Financial Account Scamming Act may also apply. A receiving account name is an investigative lead, not conclusive proof that the named person planned the Facebook hack.
Can the real Facebook owner be held liable to people who sent money?
Not automatically.
The genuine owner does not become the scammer merely because the offender used the owner’s account. Criminal liability ordinarily requires proof of the owner’s own participation, intent, or legally relevant acts. A person who truly lost control of the account should document the compromise, warn contacts promptly, cooperate with investigators, and avoid making admissions about transactions they did not conduct.
Civil liability is also fact-dependent. A victim who lost money may pursue recovery and damages against the person or persons legally responsible, but a claim against the genuine account owner would require a valid factual and legal basis. Relevant questions can include whether the owner participated, benefited, made the representation, ratified the transaction, or committed an independent wrongful or negligent act that caused damage. Mere ownership of the hacked profile, standing alone, does not prove those matters.
If you receive a demand letter, subpoena, prosecutor’s summons, or police invitation because your account was used, do not ignore it. Preserve proof of the compromise and consult a lawyer before submitting a detailed sworn statement.
Criminal complaint, civil recovery, and platform action are different remedies
These processes can proceed separately:
- Facebook recovery and reporting seek to restore control or remove harmful content.
- Bank or e-wallet procedures seek to hold, trace, verify, and possibly return disputed funds.
- Criminal investigation seeks to identify and prosecute an offender.
- Civil remedies may seek restitution or damages from a legally responsible person.
A police report does not itself reverse a transfer. A Facebook takedown does not identify the hacker. Recovery of the account does not erase possible criminal liability, and a criminal complaint does not guarantee compensation.
A lawyer can assess whether a separate civil action, recovery through the criminal case, an application for urgent court relief, or another remedy is appropriate. The answer depends on the identities of the parties, amount and location of loss, available evidence, and status of the investigation.
Why prompt reporting is important
Under Section 13 of the Cybercrime Prevention Act, service providers must preserve specified traffic data and subscriber information for at least six months from the transaction date, while specified content data must be preserved for six months from receipt of a lawful preservation order. Law enforcement may order a one-time extension for another six months, subject to the law. Data used as evidence in a case may be preserved further under the applicable procedure.
This does not mean that every relevant item will remain available for six months or that a private complainant can compel disclosure personally. Platforms may retain different categories of data for different periods. Investigators generally need the proper preservation request, disclosure process, or cybercrime warrant. Report promptly and specifically identify the account, URLs, dates, time zone, transactions, and data at risk of being lost.
The Supreme Court’s Rule on Cybercrime Warrants provides judicial procedures for disclosure, interception, search, seizure, and examination of computer data. A complainant may request investigators to consider urgent preservation, but only authorized officials and courts can issue the relevant orders or warrants.
Practical complaint checklist
Prepare a clear incident packet containing:
- Your full name, contact information, and valid identification.
- The compromised account’s profile URL and identifying details.
- A dated timeline from the first suspicious event to the latest scam report.
- Proof that you controlled the account before the incident.
- Facebook and email security notifications.
- Samples of scam posts and complete conversations.
- A list of known recipients and witnesses.
- All payment instructions and transaction records.
- Facebook, bank, e-wallet, and government report acknowledgments.
- A statement distinguishing what you personally know from what others told you.
For each recipient who sent money, include a separate transaction summary and supporting receipt. Avoid editing or annotating the only copy of an electronic record.
Common mistakes to avoid
- Waiting for Facebook to respond before warning contacts or reporting financial loss.
- Deleting scam conversations immediately after recovering the account.
- Posting unmasked IDs, account numbers, addresses, or other sensitive evidence publicly.
- Assuming the name on a receiving account identifies the mastermind.
- Paying a stranger who claims to be a hacker, Meta employee, police officer, or fund-recovery specialist.
- Sharing an OTP, authentication code, backup code, password, or remote-access session.
- Using unofficial phone numbers or links supplied in comments and private messages.
- Filing an exaggerated or knowingly false report to force a financial-account hold.
- Trying to “hack back,” access the suspect’s account, or intercept private communications.
- Resetting or disposing of a relevant device before preserving available evidence.
- Ignoring a summons or demand because you believe everyone already knows the account was hacked.
When legal help is urgent
Seek prompt assistance from a Philippine lawyer and report immediately when:
- Large or multiple transfers are still moving through financial accounts.
- A business Page, advertising account, customer database, or employer account was compromised.
- The hacker obtained government IDs, financial records, intimate images, or confidential business information.
- The account is being used for threats, extortion, sexual exploitation, trafficking, or offenses involving a child.
- Police, prosecutors, banks, victims, or Facebook request a sworn statement or extensive disclosure.
- You are being accused of participating in the scam.
- A receiving account has been placed under hold and you claim the transaction was legitimate.
- The offender is known, is continuing the conduct, or may destroy evidence.
- You need court action to preserve data, restrain conduct, or pursue substantial losses.
Qualified persons who cannot afford private counsel may ask the Public Attorney’s Office about eligibility and available assistance.
Frequently asked questions
Should I report even if nobody sent money?
Yes. Unauthorized access and misuse of identifying information may be independently relevant even before financial damage occurs. A prompt report may also help preserve data and establish that later scam messages were unauthorized.
Can I ask Facebook to disclose the hacker’s IP address?
You may give investigators the account details and ask that relevant data be preserved, but Facebook generally will not disclose nonpublic subscriber or traffic data merely because a private person requests it. Disclosure may require formal law-enforcement process and an appropriate cybercrime warrant.
Will screenshots alone prove the case?
Not necessarily. Screenshots can be important, but investigators may also need testimony from the person who captured or received them, original messages or files, device records, platform data, financial records, and proof connecting the activity to a particular person.
Should victims report to the bank or to the police first?
Do both, but contact the originating bank or e-wallet immediately because funds can move within minutes. The institution may later require an affidavit, police report, or other supporting document for continued verification.
Does a temporary hold mean the money will be returned?
No. It prevents available disputed funds from being withdrawn during the applicable period. Return depends on whether funds remain available, the verification results, applicable BSP rules, any court order, and the evidence concerning the transaction.
Can the account owner reimburse contacts and settle privately?
The owner may choose to assist, but payment can have legal and evidentiary consequences and does not necessarily end a criminal investigation. Before signing an admission, waiver, settlement, or reimbursement agreement—especially when liability is disputed—obtain legal advice.
What if I recovered the account already?
Still change all connected credentials, preserve evidence, check Pages and payment methods, warn contacts, and report any actual or attempted scam. Recovery does not show how the intrusion occurred or whether the offender still controls the linked email, SIM, application, or business account.
Is there a fixed deadline for reporting?
There is no single deadline covering Facebook recovery, financial disputes, evidence preservation, criminal prescription, and civil actions. Each process has different rules, and some electronic or financial evidence can disappear quickly. Report immediately instead of treating a possible legal prescription period as a safe waiting period.
Official sources
- Republic Act No. 10175 — Cybercrime Prevention Act of 2012
- Disini v. Secretary of Justice, G.R. No. 203335
- Republic Act No. 12010 — Anti-Financial Account Scamming Act
- BSP Manual of Regulations for Payment Systems
- BSP Consumer Assistance Channels
- DOJ Cybercrime Incident Reporting
- NBI Online Complaint
- Facebook Hacked-Account Recovery
This article provides general legal information, not legal advice or a prediction of any case’s outcome. Procedures and remedies depend on the evidence, financial institution, platform records, and individual circumstances. Sources and publicly available procedures were checked as of September 3, 2026.