What to Do If Someone Uses Fake IDs in Your Name to Commit Fraud

Quick answer

Act immediately on three fronts: dispute the fraudulent transaction in writing, preserve the records, and report the identity misuse to law enforcement and the ID issuer.

A fake ID bearing your name does not automatically make you liable for the fraud, loan, purchase, account, or contract. A valid contract generally requires your consent; if another person forged your signature or impersonated you without authority, that consent may be entirely absent. However, institutions and investigators may initially rely on records bearing your name, so a prompt, documented denial is essential. The Supreme Court has recognized that forged loan and mortgage documents may be void for lack of the supposed signer’s consent, but forgery and non-participation must still be proved from the evidence. See the Civil Code, Article 1318 and G.R. Nos. 222369 and 222502.

Do not pay, restructure, acknowledge, or sign anything merely to stop collection calls before understanding its effect. Do not rely solely on a telephone call, social-media report, or blotter entry.

What to do immediately

1. Notify the institution where the fake ID was used

Contact the bank, lender, remittance company, e-wallet, telecommunications provider, merchant, government office, employer, or other institution involved. Use its official fraud or consumer-assistance channel—not a number or link supplied by a caller.

State clearly in writing that:

  • You did not apply for, sign, authorize, or benefit from the transaction.
  • The ID or identity information presented was used without your permission.
  • Any signature, photograph, selfie, biometric capture, email address, telephone number, address, device, or account used by the applicant should be checked against your genuine information.
  • You dispute the account and all related charges.
  • You request that collection, disbursement, account access, or further transactions be stopped where legally possible.
  • You request preservation of all application and transaction records.
  • You want a case or complaint reference number and a written final response.

Ask the institution to preserve, subject to applicable law:

  • The complete application and every attachment;
  • Copies or images of the fake ID;
  • Signatures, selfies, liveness checks, biometric or know-your-customer records;
  • Email addresses, telephone numbers, delivery addresses, beneficiaries, and receiving accounts;
  • Device, access, login, IP, date-and-time, and audit logs;
  • Call recordings and customer-service notes;
  • CCTV footage from branches, stores, ATMs, or delivery locations; and
  • Records showing where loan proceeds, goods, cards, or documents were delivered.

The institution may not be able to disclose every record directly to you, especially information identifying another person. Preservation is nevertheless important because investigators may later obtain protected records through a subpoena, court warrant, or other lawful process.

For a BSP-supervised institution, its Financial Consumer Protection Assistance Mechanism or FCPAM is the first-level complaint channel. Philippine financial-consumer law recognizes rights to protection against fraud, data protection, and timely redress. While an alleged unauthorized transaction or disputed amount is under investigation, the institution must suspend interest, fees, and charges or provide a similar reasonable accommodation. See Republic Act No. 11765, Section 8.

If the institution does not resolve the matter satisfactorily, escalate it to the appropriate regulator:

  • For banks, e-wallets, payment providers, and other BSP-supervised institutions: follow the BSP Consumer Assistance procedure.
  • For financing or lending companies and their online lending platforms: use the SEC’s official I-Message Mo portal.
  • For insurance products: contact the Insurance Commission.
  • For credit cooperatives: contact the Cooperative Development Authority, subject to the regulator’s jurisdiction.

A regulator’s complaint process addresses the institution’s conduct. It does not replace a criminal complaint against the impersonator.

2. If money left your own account, use the 24/7 fraud channel now

For a disputed electronic fund transfer from your account, notify your originating financial institution through its 24/7 fraud-reporting channel immediately. Under the current rules implementing the Anti-Financial Account Scamming Act, disputed funds may initially be held for up to five calendar days and, when the legal conditions are met, for an additional period of up to 25 calendar days while coordinated verification is conducted.

The bank may require a sworn complaint, affidavit, police report, or similar supporting document during the initial holding period. A temporary hold is not guaranteed, may cover only funds that can still be traced and held, and is not itself a final finding that fraud occurred. See the official BSP AFASA booklet and implementing rules.

3. Secure the accounts that could enable further impersonation

From a device you reasonably believe is safe:

  • Change the passwords of your primary email, financial, government, cloud-storage, and social-media accounts.
  • Sign out other sessions and remove unknown devices or recovery details.
  • Enable multi-factor authentication, preferably through an authenticator or other secure method where available.
  • Contact your mobile provider immediately if your SIM lost service unexpectedly, was stolen, or may have been taken over.
  • Review bank, e-wallet, email, mobile, and government-account activity for unfamiliar changes.
  • Remove publicly posted ID images, specimen signatures, QR codes, addresses, birth dates, or account documents—but preserve evidentiary copies first.
  • Warn close contacts privately if the impersonator is soliciting money in your name.

Do not send passwords, PINs, one-time passwords, CVVs, or full ID images to anyone claiming to “investigate” the case unless you have independently verified the official channel and the information is genuinely required.

4. Report the matter to law enforcement

For online applications, digital IDs, email, messaging, e-wallets, electronic transfers, or other ICT use, report promptly to one of the designated cybercrime channels:

For a physical or primarily offline incident, you may also report to the police or NBI office with jurisdiction. Bring government-issued identification, the fraudulent records available to you, and an organized chronology.

An online report or blotter entry may document your prompt response, but investigators or prosecutors may still require a formal complaint-affidavit and supporting affidavits. The DOJ publishes a checklist for filing a complaint for preliminary investigation. Requirements may vary with the offense, location, number of respondents, and available evidence.

Ask for:

  • The official reference, docket, or complaint number;
  • The investigator’s name and office;
  • A receiving copy of your complaint and attachments; and
  • Guidance on any immediate preservation request, subpoena, or cybercrime warrant needed.

Under the Cybercrime Prevention Act, traffic data and subscriber information relating to communication services must be preserved for at least six months from the transaction, while content data is preserved for six months from receipt of a law-enforcement preservation order. That does not mean every platform retains every record for six months before an order. Reporting early remains crucial. See Republic Act No. 10175, Section 13.

5. Notify the agency that issued or supposedly issued the ID

Report the fake, altered, copied, or misused identification to the issuing agency. Ask whether it recommends replacement, annotation, additional verification, or another protective measure.

Examples include the PSA for a National ID, DFA for a passport, LTO for a driver’s license, PRC for a professional ID, and the relevant agency for an SSS, GSIS, PhilHealth, or other credential.

For National ID-related fraud, the PSA currently accepts reports through info@philsys.gov.ph, its official PhilSys Facebook channel, and hotline 1388, according to the PSA’s fraud advisory.

If a SIM appears to have been registered or used in your identity, report it to the telecommunications provider and preserve the mobile number and messages involved. The SIM Registration Act specifically penalizes using fictitious identities or fraudulent identification documents to register a SIM. Subscriber information is confidential and ordinarily requires the lawful process described in the Act before it can be disclosed. See Republic Act No. 11934.

Replacing a genuine ID may reduce future risk, but it does not automatically remove a fraudulent loan, account, SIM registration, or transaction from another institution’s records. Dispute each affected record separately.

6. Check and dispute your credit information

If the impersonation involved a loan, credit line, financing agreement, or credit card:

  1. Obtain your credit report through the Credit Information Corporation’s official consumer channels.
  2. Identify every unfamiliar contract or submitting institution.
  3. Dispute inaccurate, incomplete, misleading, or outdated credit data through the CIC Online Dispute Resolution System.
  4. Attach the documents supporting your denial.
  5. Keep the transaction reference number and all communications.

The CIC facilitates the dispute but cannot simply rewrite a lender’s submitted data on its own. The concerned submitting entity must participate in validating and correcting the record.

What your written dispute should say

Keep the wording factual and consistent:

I formally dispute Account/Application No. ______. I did not submit, sign, authorize, or benefit from this application or transaction. The identification document and personal information used were presented without my authority. Please flag the matter as identity fraud, suspend collection and further activity as permitted by law, preserve all application and transaction records, and provide me with the documents I am legally entitled to receive. Please confirm receipt, provide a case reference number, identify the investigation period, and send the final result in writing. Nothing in this notice acknowledges the validity of the alleged debt or transaction.

Attach only what is reasonably necessary. Watermark replacement ID copies when appropriate—for example, “For identity-fraud dispute with [institution], [date]”—without covering security features the institution genuinely needs to verify.

Evidence to preserve

Create one folder, with a backup, containing:

  • The fake ID image or a clear description of it;
  • Demand letters, billing statements, account numbers, and collection messages;
  • Emails with full headers, original message files, chat exports, and call logs;
  • Screenshots showing the full page, profile, URL, username, date, and time;
  • Transaction reference numbers, receipts, delivery details, and beneficiary information;
  • Copies of every complaint and proof of delivery or receipt;
  • Your genuine IDs and specimen signatures from before the incident;
  • Proof of your whereabouts when an in-person transaction allegedly occurred;
  • Employment attendance, travel, CCTV, access-card, or device records where relevant;
  • Bank statements showing that you did not receive the proceeds;
  • Evidence identifying the telephone number, email address, device, address, or account actually used; and
  • A chronological log of discoveries, calls, reports, responses, and losses.

Keep original digital files unchanged. Make working copies rather than cropping, annotating, or repeatedly resaving the only copy. Do not access another person’s account, impersonate the suspect, install tracking software, or obtain protected records illegally.

What Philippine laws may apply

The correct charge depends on the document, technology, transaction, intent, loss, and available proof. The victim does not need to select the final charge; investigators and prosecutors should evaluate the facts.

Computer-related identity theft, forgery, or fraud

When computers, online applications, electronic records, email, or digital platforms are involved, the Cybercrime Prevention Act may apply. It penalizes:

  • Computer-related identity theft: intentionally acquiring, using, misusing, transferring, possessing, altering, or deleting another person’s identifying information without right;
  • Computer-related forgery: creating or knowingly using inauthentic computer data for legal or fraudulent purposes; and
  • Computer-related fraud involving unauthorized manipulation of computer data or systems and resulting damage.

The usual statutory penalty for Section 4(a) and 4(b) offenses is prisión mayor, a fine of at least ₱200,000 up to an amount commensurate with the damage, or both. For computer-related identity theft or fraud where no damage has yet occurred, the law provides a penalty one degree lower. The Supreme Court upheld the computer-related identity-theft provision in Disini v. Secretary of Justice.

A purely physical, offline use of a fake ID is not automatically computer-related identity theft. Other laws may instead govern it.

Falsification, use of falsified documents, fictitious names, and estafa

Depending on the document and conduct, the Revised Penal Code may cover:

  • Falsification of public, official, commercial, or private documents;
  • Knowing use of falsified documents;
  • Public use of a fictitious name to conceal a crime, evade a judgment, or cause damage; and
  • Estafa through false pretenses, a fictitious name, or similar deceit that induced another person to part with money or property.

Article 172, as amended, provides prisión correccional in its medium and maximum periods and a fine of up to ₱1 million for specified acts of falsification by private individuals. The penalty for estafa varies according to the manner of fraud and amount involved. See Republic Act No. 10951, which amended the relevant Revised Penal Code provisions.

Fraud involving cards or other access devices

The Access Devices Regulation Act, Republic Act No. 8484, may apply when the scheme involves counterfeit, unauthorized, or fraudulently applied-for access devices, including certain cards, account numbers, and other means of obtaining money, goods, services, or transfers.

National ID or SIM-specific violations

The Philippine Identification System Act separately penalizes fraudulent use of the PhilID or PSN, unauthorized production or alteration of a PhilID, possession or use of a fake or falsified PhilID, and specified unlawful handling of PhilSys data.

The SIM Registration Act provides imprisonment of six months to two years, a fine of ₱100,000 to ₱300,000, or both for using fictitious identities or fraudulent identification documents to register a SIM. Other SIM-related offenses have different penalties and exceptions.

Data-privacy violations

Unauthorized collection, processing, use, or disclosure of your personal or sensitive personal information may also raise issues under the Data Privacy Act. Not every identity-fraud incident proves that a bank, lender, or other organization violated the Act; the source of the data, legal basis, security measures, response, and evidence matter.

Before filing an ordinary complaint with the National Privacy Commission, you generally must first notify the entity in writing and give it an opportunity to act. If it takes no timely or appropriate action, or gives no response within 15 calendar days, you may proceed using the NPC’s complaint requirements. The NPC may waive exhaustion for good cause or specified serious circumstances. See the 2021 NPC Rules of Procedure, as amended and the NPC complaint guide.

The well-known 72-hour data-breach notification period is generally an obligation of the personal information controller, not the victim’s deadline for reporting identity theft.

Important timing rules

There is no single deadline that applies to every identity-fraud case. Criminal prescriptive periods vary by offense and penalty, while contracts, regulatory complaints, insurance claims, platform records, CCTV systems, and chargeback processes may have different time limits.

Relevant time-sensitive points include:

  • Report unauthorized transfers immediately because disputed funds may quickly be moved or withdrawn.
  • Submit documents requested for an AFASA extended hold within the initial holding period.
  • Ask for digital and CCTV preservation promptly.
  • For an NPC complaint, document your written notice to the entity and the 15-calendar-day response period, unless a waiver applies.
  • Claims specifically arising under the Financial Products and Services Consumer Protection Act generally prescribe five years from consummation of the transaction or discovery of deceit or material nondisclosure, subject to an absolute ten-year limit and the Act’s insurance exception. This is not the deadline for every criminal, civil, contractual, or regulatory remedy.

Do not wait for every institution to finish its internal investigation before consulting law enforcement or counsel.

Common mistakes to avoid

  • Making only telephone calls and keeping no written record;
  • Treating a blotter entry or affidavit of loss as a complete fraud dispute;
  • Paying a “small amount,” signing a restructuring agreement, or promising payment without advice;
  • Deleting chats, replacing devices, or editing the only copy of digital evidence;
  • Posting the fake ID publicly and exposing more personal information;
  • Publicly naming a suspected culprit without sufficient evidence;
  • Confronting the suspect, threatening them, or arranging your own entrapment;
  • Using unofficial “recovery agents” who request fees, passwords, or OTPs;
  • Assuming that replacing an ID automatically removes fraudulent accounts;
  • Sending excessive personal data to complaint channels; and
  • Exaggerating or filing information you know is false. Current financial-fraud law penalizes malicious reporting that causes an unwarranted temporary hold of funds.

When legal help is urgent

Seek a Philippine lawyer promptly if:

  • Police, the NBI, a prosecutor, or a court treats you as a suspect or respondent;
  • You receive a subpoena, warrant, summons, collection case, or formal demand;
  • Land, a vehicle, company shares, a mortgage, or another registered asset was transferred or encumbered;
  • A fraudulent account is causing continuing losses or blocking access to essential funds;
  • The institution refuses to suspend collection or correct a clearly disputed identity record;
  • The fraud involves several institutions, large losses, insiders, organized activity, or cross-border transactions;
  • Your biometrics, passport, National ID, or professional credentials were compromised; or
  • There are threats, extortion, stalking, or immediate safety concerns.

If you cannot afford private counsel, ask the Public Attorney’s Office about eligibility. Do not ignore official process simply because the name or signature used was fake; respond through counsel and submit your evidence on time.

Frequently asked questions

Am I responsible for a loan taken using a fake ID in my name?

Not merely because the documents carry your name. A person who never consented to or authorized a contract has a substantial defense. Still, the outcome depends on proof of impersonation, forgery, lack of benefit, and the institution’s records. Dispute the loan immediately and do not treat a bare verbal denial as sufficient.

Is an affidavit of loss or identity theft enough?

No. An affidavit can support your account, but it does not by itself cancel a loan, establish forgery, correct a credit report, or commence every required criminal or regulatory process.

Should I pay the alleged debt while the investigation is pending?

Do not make a payment or sign a new agreement without understanding the possible consequences. Send a written dispute and invoke the protections applicable to disputed or unauthorized transactions. Obtain legal advice if collection continues or litigation is threatened.

Can I demand the fake account or post be removed?

Yes, report it through the platform’s impersonation or fraud process—but preserve the page, URL, messages, and account identifiers before removal. A takedown may stop further harm but can also make evidence harder to locate.

Can the bank or telco give me the impersonator’s details?

Not necessarily. Privacy, bank secrecy, SIM-confidentiality, and other laws may restrict direct disclosure. Investigators may obtain relevant information through subpoenas, warrants, AFASA procedures, or other lawful authority.

Should I replace every ID?

Not automatically. Report the misuse to each issuer and follow its instructions. Replacement may be appropriate when the genuine credential was lost or compromised, but it will not correct unrelated fraudulent records by itself.

What if I know the person who did it?

Preserve the evidence and identify the person truthfully in your complaint. Do not access their devices or accounts without authority, manufacture evidence, or attempt a private entrapment. A relative, employee, or acquaintance is not exempt from the applicable laws.

Where should I report first?

Report simultaneously to the institution involved and the appropriate law-enforcement agency. Also notify the ID issuer. If a transfer from your account is ongoing, the financial institution’s 24/7 fraud channel is the immediate priority.

Official legal and reporting resources

Disclaimer

This article provides general Philippine legal information, not legal advice or a prediction of any case outcome. Liability and remedies depend on the documents, evidence, transaction, and applicable procedure. Laws and official procedures were checked against primary and government sources current as of 6 August 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.