Unauthorized Bank Transfers After Account Hacking: What to Do in the Philippines

Quick answer

Report the unauthorized transfer immediately to the bank or e-wallet from which the money was sent—the originating financial institution. Use its official fraud hotline or in-app support, secure the compromised account, and obtain a written complaint reference number. State clearly that the transfer resulted from hacking, phishing, SIM swapping, malware, stolen credentials, or another form of unauthorized account access.

Ask the institution to:

  • block further access and outgoing transactions;
  • trace the transfer chain;
  • notify every receiving institution involved;
  • temporarily hold any disputed funds still available; and
  • begin the coordinated verification process required by Philippine law and BSP regulations.

Do not wait for a police report before contacting the bank. Current BSP rules allow an initial hold of up to five calendar days, extendible by up to 25 additional calendar days—a maximum of 30 days unless a court orders a further extension. Supporting documents such as an affidavit, sworn complaint, or police report may be needed within the initial five-day period.

A refund is not automatic. The result depends on the transaction records, how the account was compromised, the customer’s actions, the institution’s security controls, and whether the institution complied with its legal duties. But the mere use of a correct password, PIN, or one-time password does not necessarily prove that the account owner personally authorized the transfer.

What to do immediately

1. Contact the originating bank or e-wallet

Use only a phone number or channel shown on the institution’s official website, mobile app, card, or statement. Do not use contact details provided in a suspicious message.

Tell the fraud team:

“I am disputing an unauthorized electronic fund transfer caused by account hacking or account takeover. I did not authorize or benefit from this transfer. Please secure my account, initiate temporary holding and coordinated verification, notify the receiving institutions, and give me a written reference number.”

Provide, as accurately as possible:

  • your name and affected account;
  • transaction date and time;
  • amount and currency;
  • transaction reference number;
  • transfer channel, such as InstaPay, PESONet, QR Ph, or an internal transfer;
  • receiving institution and beneficiary details shown in your records;
  • when and how you discovered the transaction;
  • why you believe the account was compromised; and
  • any other unauthorized logins, password changes, device registrations, loans, cash advances, or transfers.

The formal dispute should be filed with the originating institution. You may also alert the receiving institution, but that does not replace the complaint to your own bank or e-wallet.

Under BSP Circular No. 1160, institutions should maintain free, active fraud-reporting channels available 24/7, and a consumer who contacts the reporting channel should receive an immediate written acknowledgment. The originating institution is primarily responsible for assisting its customer and coordinating with the receiving institution.

2. Secure the account from a clean device

If the phone or computer may contain malware, disconnect it from Wi-Fi and mobile data. Use another trusted device to:

  • change the password of the email account connected to the bank;
  • change bank and e-wallet passwords and PINs;
  • revoke unknown devices, sessions, passkeys, and account linkages;
  • reset multifactor authentication;
  • lower transfer limits and disable online transfers where available;
  • lock affected cards;
  • check whether contact details or security questions were changed; and
  • inspect other financial accounts using the same email, phone number, or password.

If your mobile signal unexpectedly disappeared or you suspect a SIM swap, contact the telecommunications provider immediately and request suspension or recovery of the number. Secure any messaging and social-media accounts that could be used to impersonate you.

Changing credentials does not replace the fraud complaint. Ask the institution to confirm that it has disabled the attacker’s existing sessions and any newly enrolled devices.

3. Request temporary holding and coordinated verification

Under Republic Act No. 12010, the Anti-Financial Account Scamming Act, covered institutions may temporarily hold funds involved in disputed transactions and must participate in coordinated verification in the circumstances prescribed by the BSP.

BSP Circular No. 1215 provides for:

  • an initial hold of up to five calendar days;
  • an extended hold of up to 25 additional calendar days when justified;
  • a maximum administrative holding period of 30 calendar days; and
  • further extension only by a court of competent jurisdiction.

These are maximum periods, not guaranteed recovery windows. The institution can hold only disputed funds or equivalent amounts that remain reachable. A temporary hold does not mean that the claim has already been decided in the customer’s favor.

For an extended hold, the source-account owner generally should submit supporting documents during the initial five-day period, subject to exceptions under the applicable industry protocol. Ask the institution immediately whether it requires:

  • a sworn complaint or affidavit;
  • a police or NBI report;
  • proof of account ownership;
  • screenshots or transaction records; or
  • a detailed chronology of the compromise.

Submit available documents promptly and keep proof of delivery.

4. Preserve evidence

Save original electronic records where possible, not only cropped screenshots. Preserve:

  • account statements and transaction histories;
  • SMS, email, and in-app transaction alerts;
  • login, password-reset, device-enrollment, and contact-change notices;
  • full screenshots showing dates, times, sender details, and URLs;
  • suspicious messages, email headers, call logs, and recordings lawfully in your possession;
  • phishing links and fake-website addresses;
  • names, aliases, phone numbers, social-media accounts, and email addresses used;
  • mobile-network notices concerning a SIM replacement;
  • a list of unfamiliar applications, remote-access tools, or device profiles;
  • complaint reference numbers and notes of calls with the institution;
  • copies of every affidavit, police report, and letter submitted; and
  • a written timeline prepared while the events are still fresh.

Do not edit original files. Keep secure backup copies. If a device may need forensic examination, document its condition before uninstalling suspicious software or performing a factory reset. Stop using that device for banking in the meantime.

5. Report the crime in parallel

A bank complaint seeks financial redress and preservation of funds. A criminal complaint allows investigators to pursue the perpetrators and obtain evidence through lawful processes. One does not replace the other.

Current official reporting options include:

  • Cybercrime Investigation and Coordinating Center: hotline 1326 or report@cicc.gov.ph;
  • PNP Anti-Cybercrime Group: acg@pnp.gov.ph; and
  • NBI Cybercrime Division: ccd@nbi.gov.ph.

The BSP’s official complaint guide also lists these law-enforcement channels. Bring your identification, transaction records, chronology, bank complaint reference, and preserved communications. The NBI process may include a sworn complaint, preliminary interview, supporting documents, witness statements, and examination of a relevant device.

Depending on the evidence, account hacking may involve illegal access, computer-related fraud, or computer-related identity theft under the Cybercrime Prevention Act of 2012. The proper offense and responsible persons must be determined by investigators and prosecutors.

Can the institution be required to return the money?

Possibly, but liability is fact-dependent.

The Financial Products and Services Consumer Protection Act recognizes consumers’ rights to protection of assets against fraud and misuse, data privacy and protection, and timely complaint handling. For an alleged unauthorized transaction, the institution must suspend applicable interest, fees, and charges pending its final investigation or provide a similar reasonable accommodation.

Under BSP rules, the institution should assess the claim fairly and may consider:

  • the customer’s actions before, during, and after the transaction;
  • the institution’s acts or omissions;
  • the conduct of employees, agents, outsourced entities, and service providers;
  • device, network, authentication, and transaction logs;
  • whether fraud-monitoring alerts were triggered or ignored;
  • whether the transaction departed from the customer’s usual behavior;
  • whether required security controls were followed; and
  • whether prompt action could have prevented further transfers.

If the investigation finds that the transaction was unauthorized or fraudulent, BSP rules call for the institution to correct or reverse it, including related interest, fees, and charges, or make any provisional credit permanent. The institution must formally inform the customer of the result within three banking days after the investigation is concluded.

AFASA imposes an important standard. Institutions must employ adequate risk-management systems and controls and exercise the highest degree of diligence in preventing losses from covered financial-account scams. Failure to do so may make an institution liable for restitution; conviction of the scammer is not a prerequisite.

An institution that fails to hold disputed funds when required may also be liable for loss caused by that failure, including restitution. Conversely, AFASA protects an institution from liability under that law when the BSP determines that it complied with the required risk-management systems and controls. The actual security measures, alerts, transaction logs, customer conduct, and response times therefore matter.

What if the institution says the correct OTP was used?

Request a written, evidence-based decision. Correct credentials may explain how the system authenticated a transaction, but they do not necessarily establish the account owner’s personal consent. Malware, phishing, remote-access software, SIM swapping, email takeover, fraudulent device enrollment, and social engineering can compromise authentication factors.

Ask the institution to examine and, where legally disclosable, address:

  • the IP address and approximate location;
  • device fingerprint and whether the device was newly enrolled;
  • login and session history;
  • changes to passwords, contact details, transfer limits, or beneficiaries;
  • the type and delivery route of each authentication factor;
  • fraud-monitoring alerts and how they were handled;
  • the time between login, device enrollment, account changes, and transfer;
  • recipient-account and transfer-chain information; and
  • why the activity was considered consistent with your normal behavior.

Explain truthfully whether you clicked a link, installed an application, shared an OTP, approved a prompt, or did none of these. Sharing a credential may affect the liability assessment, but it does not cancel your right to complain or excuse the institution from investigating its own controls.

How temporary holding may end

At the end of the applicable holding period, the funds generally must be released unless:

  • a court has extended the holding period;
  • the beneficiary has waived any claim to the funds; or
  • the coordinated verification supports a reasonable conclusion that the funds relate to money muling, an unlawful activity, a transaction without an economic purpose, social engineering, or an analogous ground.

If the beneficiary establishes that the transaction was legitimate, the institution must lift the hold even before the period expires. If the verification supports returning the funds to the source-account owner, the institutions must process the return and notify the affected parties.

A bank’s decision about where to release the funds does not eliminate other legal remedies available to an aggrieved party.

Escalating an unresolved complaint to the BSP

The institution’s Financial Consumer Protection Assistance Mechanism is the required first-level remedy. Keep the original complaint, reference number, supporting documents, and the institution’s response.

If the institution fails to act or its response is unsatisfactory, escalate through the BSP Consumer Assistance Mechanism:

  • use the BSP Online Buddy or BOB on the BSP website;
  • continue until you receive a BSPCMS reference number; or
  • if BOB is unavailable, complete the BSP Complaint/Inquiry/Reply form and email it with proof of your prior complaint to consumeraffairs@bsp.gov.ph.

State the specific remedy requested, such as reversal of the identified transactions and related charges. Attach only relevant records. The BSP warns consumers not to send PINs, passwords, full card credentials, passbooks, passports, or unnecessary identification documents through CAM.

BSP-CAM facilitates communication between the consumer and the institution; it is not a criminal investigation. The BSP’s official FAQ estimates that CAM may take approximately 55 to 65 days. If CAM ends without resolution, the consumer may pursue mediation or, where available, adjudication under BSP Circular No. 1169.

BSP mediation and adjudication

Mediation is a voluntary settlement process. BSP’s published guidance estimates approximately 50 to 60 days from referral, with a usual mediation period of 30 days from the initial conference unless extended for meritorious reasons and by agreement.

BSP adjudication generally covers a purely civil claim seeking only payment or reimbursement not exceeding ₱10 million, excluding legal interest, attorney’s fees, and costs. Important limits include:

  • BSP-CAM must be completed first.
  • The formal complaint must be verified under oath and accompanied by the required documents.
  • Filing is currently by personal delivery or postal mail under the prescribed rules.
  • No filing fee is collected.
  • A claim exceeding ₱10 million may be dismissed unless the consumer limits or waives the excess; otherwise, the entire claim may be pursued through another appropriate legal remedy.
  • Claims seeking relief other than payment or reimbursement—such as a standalone claim for damages—may fall outside BSP adjudication.

The BSP’s guidance estimates that adjudication may take approximately 180 to 240 days. Once a decision or resolution is received, some available remedies have periods as short as 10 days, so legal advice may be urgent at that stage.

Claims arising under the Financial Products and Services Consumer Protection Act generally prescribe five years from the transaction, or five years from discovery of deceit or nondisclosure of material facts, subject to an outside limit of ten years from the violation. Other legal causes of action may have different prescriptive periods. These periods are not reasons to delay reporting fraud.

Situations covered differently

You sent money to the wrong account

That is generally an erroneous transaction, not account hacking. Circular No. 1215’s temporary-holding rules exclude erroneous transactions, although the originating institution must still assist under applicable consumer-protection rules. Recovery may depend on the recipient’s cooperation or appropriate legal process.

You personally sent the money because of a fraudulent offer

A purchase, investment, romance, or impersonation scam in which you knowingly issued the transfer instruction may raise different authorization and liability questions from a hacker taking control of the account. Report it immediately, but describe the facts accurately rather than calling it an account takeover if you initiated the payment yourself.

The transaction was a card purchase or ATM withdrawal

The AFASA temporary-holding regulations generally do not cover ordinary credit-card transactions, except when a credit card is used to perform an electronic fund transfer through an automated clearing house. Card purchases, cash advances, and ATM withdrawals should be reported through the issuer’s applicable card-fraud process.

Only part of the money remains

The institution may be able to hold and return only the reachable portion. Coordinated verification must still trace the transaction chain even if some or all of the funds have already been withdrawn or moved.

The transfer occurred before AFASA took effect

Circular No. 1215 defines covered disputed transactions by reference to transactions occurring after AFASA’s effectivity. Older incidents may still be subject to the Financial Products and Services Consumer Protection Act, BSP consumer-protection regulations, contracts, and other civil or criminal laws, but the AFASA holding mechanism may not apply in the same way.

Common mistakes to avoid

  • Waiting for a branch to open instead of using the official fraud channel.
  • Reporting only to the receiving institution.
  • Describing the transfer merely as “wrong” without stating that it resulted from unauthorized access.
  • Failing to obtain a written acknowledgment and complaint number.
  • Missing the initial five-day period for supporting documents.
  • Deleting messages or resetting the compromised device before preserving evidence.
  • Continuing to bank from a device that may contain malware.
  • Omitting facts such as clicking a phishing link or sharing an OTP.
  • Paying a supposed investigator or recovery agent to “unlock” the money.
  • Sending another transfer supposedly required to reverse the first one.
  • Publicly posting recipient-account details instead of giving them to the institution and investigators.
  • Accepting an oral rejection without requesting written findings.
  • Filing false or exaggerated information. Malicious reports that cause funds to be held can result in criminal liability under AFASA.

When legal help is urgent

Consult a Philippine lawyer promptly if:

  • the loss is substantial or exceeds BSP’s ₱10 million adjudication limit;
  • the institution denies the claim without addressing evidence of account takeover;
  • funds are being held but the 30-day maximum is approaching and a court extension may be necessary;
  • the incident involves business, payroll, trust, or client funds;
  • there are indications of insider participation or a broader data breach;
  • fraudulent loans, cards, or accounts were opened in your name;
  • cross-border records, preservation orders, or cybercrime warrants may be needed;
  • you are being threatened, blackmailed, or coerced;
  • the institution asks you to sign a release or settlement you do not understand; or
  • you receive a BSP adjudication decision or resolution with a short deadline.

Frequently asked questions

Is there a fixed deadline for reporting the transfer?

The applicable rules call for immediate reporting; they do not provide a safe grace period during which delay is harmless. The five-day initial holding period is not five days given to the victim to decide whether to complain. Report within minutes or hours if possible.

Does filing a police report guarantee reimbursement?

No. It supports the investigation and may help justify an extended hold, but the institution must still investigate the transaction and assess liability. Criminal reporting and the financial-consumer complaint should proceed in parallel.

Must the institution give provisional credit?

Not automatically. BSP rules identify provisional credit as a possible reasonable accommodation. Its availability may depend on the institution’s policies and the facts. Applicable interest, fees, and charges on the disputed amount should meanwhile be suspended, or a similar reasonable accommodation provided, pending the final investigation.

Can the receiving account’s entire balance be frozen?

Not automatically. The temporary-holding mechanism concerns disputed funds or equivalent traceable amounts. Freezing the whole account may require a separate legal basis or an order from a court or competent authority.

Can bank secrecy prevent the institutions from tracing the money?

For coordinated verification under AFASA, specified bank-secrecy and data-privacy restrictions do not prevent legally authorized information sharing. The institutions must still secure the information and limit its use to the permitted process.

Can account terms waive my right to complain or sue?

No contractual term may lawfully deprive a financial consumer of the right to sue, receive information, have complaints addressed and resolved, or have non-public client data protected under the Financial Products and Services Consumer Protection Act.

Should I negotiate directly with the recipient?

Usually not. Direct contact may alert the perpetrators, expose you to another scam, or interfere with an investigation. Provide the recipient details to the financial institutions and law-enforcement authorities.

This article provides general Philippine legal information, not advice for a specific case. Rights, liability, and available remedies depend on the transaction records, account agreement, security evidence, relevant dates, and institutions involved. Official legal and procedural sources were checked as of 23 July 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.