What to Do When a Hacked Social Media Account Is Used for Scams

Quick answer

Act immediately on three tracks:

  1. Secure and recover the account through the platform’s official recovery process.
  2. Warn contacts publicly and through another trusted channel that messages, payment requests, links, and investment offers from the account may be fraudulent.
  3. Preserve evidence and report any money transfer immediately to the sender’s bank or e-wallet and, where appropriate, to the NBI, police cybercrime authorities, or the National Privacy Commission.

A hacked account owner is not automatically liable for money that a scammer obtained merely because the scam used the owner’s name, photo, or profile. Criminal or civil responsibility depends on evidence of participation, authorization, negligence, receipt of funds, benefit, or another legally sufficient basis. Prompt documentation and reporting help establish that the account was taken over without consent.

What to do immediately

1. Protect the email account connected to social media

Your email is often the key to resetting the social-media password. Using a device you reasonably believe is safe:

  • Change the email password to a strong, unique password.
  • Sign out unknown or unnecessary sessions.
  • Check whether the attacker added a forwarding rule, recovery email, phone number, passkey, or authentication method.
  • Remove unfamiliar connected applications.
  • Turn on multi-factor authentication, preferably through an authenticator app, passkey, or security key.
  • Secure the mobile number associated with the account. Ask the telecommunications provider for help if the SIM suddenly stopped working or you suspect an unauthorized SIM replacement.

Do not reuse the new password on another service.

2. Use the platform’s official account-recovery process

Go directly to the platform’s website or mobile application. Do not use a recovery link sent by an unknown person claiming to be support.

Report the account as hacked or compromised and provide the platform with:

  • The account name and exact profile URL;
  • The original email address or mobile number;
  • The approximate date and time access was lost;
  • Copies of genuine security alerts;
  • A safe email address where you can be reached; and
  • Identification only if requested through the platform’s verified recovery procedure.

If the attacker created a separate account impersonating you, report both the impersonating profile and each scam post, advertisement, group, or message that remains visible. Ask affected contacts to submit their own reports as recipients of the fraudulent messages.

3. End the attacker’s access

If you regain control:

  • Change the social-media password.
  • Sign out all other sessions.
  • Remove unknown email addresses, phone numbers, passkeys, devices, administrators, and recovery contacts.
  • Regenerate backup or recovery codes.
  • Review connected apps, browser extensions, business integrations, advertising accounts, pages, and payment methods.
  • Check whether the attacker changed privacy settings, downloaded account data, created advertisements, or added another page administrator.
  • Review recent posts, messages, archived conversations, deleted items, and marketplace activity.

Changing the password alone may not remove an attacker who still has an active session, connected app, stolen email account, or added administrator access.

4. Warn people through a separate trusted channel

Use another verified account, SMS, email, a company website, or direct calls. A useful warning states:

  • The account was compromised;
  • The approximate period during which messages were unauthorized;
  • That people should not send money, disclose one-time passwords, click links, or install applications based on those messages;
  • The payment accounts, phone numbers, usernames, or links used by the scammer, if known; and
  • How people can verify future communications with you.

Avoid publishing victims’ full account numbers, identification documents, home addresses, or other unnecessary personal information.

If someone sent money

The person whose money was transferred should contact the originating bank, electronic-money issuer, or e-wallet immediately, using its official fraud channel. The hacked account owner should assist but generally cannot make the sender’s financial complaint in the sender’s place unless properly authorized.

Provide:

  • The transaction reference number;
  • Date, time, and amount;
  • Source and recipient account details;
  • Screenshots and the full message history;
  • The compromised profile’s URL or account identifier;
  • The scammer’s phone number, email address, QR code, or payment link;
  • A clear statement that the transaction resulted from impersonation or social engineering; and
  • A police, NBI, or cybercrime report number when available.

Ask the financial institution to mark the transaction as disputed, trace the funds, secure the source account, and coordinate with the receiving institution.

Under the Anti-Financial Account Scamming Act, Republic Act No. 12010, covered financial institutions may temporarily hold funds involved in a disputed transaction and conduct coordinated verification. BSP rules provide for an initial holding of disputed funds for up to five calendar days in applicable cases, with the total statutory holding period not exceeding 30 calendar days unless extended by a competent court. A hold is not automatic, may be ineffective if the funds have already left the financial system, and does not by itself guarantee reimbursement. See the AFASA and its implementing BSP rules.

If the institution does not resolve the complaint, first complete its internal complaint process and then consider the BSP Consumer Assistance Mechanism. Keep the institution’s acknowledgment and case number.

Preserve evidence before it disappears

Save evidence as early as possible, without continuing to engage the scammer unnecessarily.

Keep:

  • Full-screen screenshots showing the account name, URL, message, date, and time;
  • Screen recordings showing how the profile, conversation, or advertisement was reached;
  • Original emails, including available message headers;
  • Complete chat exports or downloaded account data;
  • Platform security alerts and recovery correspondence;
  • Login-history details, device notices, and unfamiliar IP or location information shown by the platform;
  • Payment receipts, transaction references, bank statements, QR codes, and recipient details;
  • Call logs, text messages, usernames, phone numbers, and email addresses;
  • Copies of scam posts, comments, stories, marketplace listings, and advertisements;
  • Statements from people who received messages or sent money; and
  • A written timeline recording when access was lost, when the scam was discovered, and every recovery or reporting step taken.

Keep the original files. Do not crop, annotate, rename, or repeatedly convert the only copy. Store working copies separately and back up the originals. Ask recipients to preserve the messages on their own devices because their copies may help establish receipt and context.

Philippine courts recognize electronic documents, but authenticity and the manner in which evidence was obtained still matter. The Rules on Electronic Evidence address electronic documents and communications. Investigators may also need court-authorized procedures under the Rule on Cybercrime Warrants to obtain or examine data held by service providers. A private complainant should not attempt to access the attacker’s device or account without authority.

Where to report

National Bureau of Investigation

Cyber-enabled fraud, identity misuse, and unauthorized account access may be reported to the NBI Cybercrime Division or an appropriate regional office. The NBI provides an online complaint page and publishes its procedure for investigative assistance to victims of computer crimes.

Bring or retain:

  • A government-issued ID;
  • A chronological written account;
  • Printed and electronic copies of the evidence;
  • Platform and financial-institution case numbers;
  • Details of witnesses and persons who sent money; and
  • The device involved, if investigators ask to examine it.

Do not wipe or dispose of a potentially relevant device before asking investigators or counsel whether forensic preservation is needed.

Police cybercrime authorities

A complaint may also be brought to the Philippine National Police’s cybercrime personnel or the appropriate police station. Ask for the receiving officer’s name, the report or reference number, and instructions on submitting digital evidence. For substantial losses, multiple victims, threats, or ongoing withdrawals, clearly explain why immediate coordination with financial institutions or service providers may be necessary.

National Privacy Commission

The NPC is relevant when personal information has been misused, maliciously disclosed, improperly processed, or when rights under the Data Privacy Act may have been violated. Its official guidance explains the right to file a privacy complaint and the formal complaint procedure.

An ordinary individual whose personal account was hacked is not automatically required to file a corporate-style breach notification. Different obligations may apply when the compromised account belongs to a business, employer, professional practice, association, or other personal information controller and exposes personal data under its control.

A covered personal information controller may have to notify the NPC and affected data subjects within 72 hours after knowledge or reasonable belief of a breach requiring notification. The applicable risk, type of information, number of affected persons, and permissible grounds for delay must be assessed under the Data Privacy Act, its rules, and NPC issuances. Official requirements are summarized on the NPC’s breach-reporting page. A business should involve its data protection officer and legal or incident-response team immediately.

What Philippine laws may apply

The precise charge depends on what the attacker did and what the evidence establishes.

Under the Cybercrime Prevention Act of 2012, Republic Act No. 10175:

  • Entering an account or computer system without right may constitute illegal access.
  • Altering, deleting, or damaging data may fall under offenses involving data or system interference.
  • Unauthorized use of another person’s identifying information may constitute computer-related identity theft.
  • Fraudulent input, alteration, deletion, or interference involving computer data or systems, done with intent to cause damage, may constitute computer-related fraud.
  • A crime under the Revised Penal Code or a special law committed through information and communications technology may also fall under Section 6, subject to the facts and controlling case law.

The Supreme Court upheld the statutory prohibition against computer-related identity theft in Disini Jr. v. Secretary of Justice, explaining that the provision addresses unauthorized acquisition or use of another person’s identifying data.

Depending on the scheme, other laws may be relevant, including:

  • Estafa provisions of the Revised Penal Code;
  • Republic Act No. 12010, when financial-account scamming, social engineering, or money-mule conduct is involved;
  • The Access Devices Regulation Act, as amended, for certain unauthorized payment-card or financial-account activities; and
  • The Data Privacy Act when personal data is unlawfully accessed, processed, or disclosed.

These laws are not interchangeable. Investigators and prosecutors determine the appropriate offense from the evidence; a complainant does not need to select the final criminal charge before reporting.

Is the hacked account owner responsible for the scam?

Not simply because the scam appeared under that person’s name.

The key questions may include:

  • Was the access genuinely unauthorized?
  • Did the owner participate in or approve the solicitation?
  • Did the owner receive, control, or benefit from the money?
  • Was a bank account, e-wallet, page, or business account knowingly made available to another person?
  • What security and warning steps were taken after discovery?
  • Did the owner make representations that the victim reasonably relied on?
  • Is there evidence of negligence, concealment, or cooperation?

A profile name or screenshot alone does not establish who was operating the account at a particular time. Conversely, merely claiming “I was hacked” does not prove unauthorized access. Preserve objective evidence such as recovery notices, login alerts, session records, changes to recovery details, reports to the platform, and contemporaneous warnings.

If a demand for payment, a subpoena, a prosecutor’s notice, or a lawsuit is received, do not ignore it. Obtain legal advice and preserve all responsive records.

If the attacker is still messaging people

Do not negotiate, threaten, or try to “hack back.” These actions can endanger victims, alter evidence, alert the offender, or expose you to legal risk.

Instead:

  1. Capture the current activity.
  2. Send a warning through unaffected channels.
  3. Report the profile and specific content to the platform.
  4. Alert financial institutions about any known recipient accounts.
  5. Update the NBI or police report with new transaction or identity details.
  6. Refer threatened or defrauded contacts to their own bank and law-enforcement channels.

If the attacker threatens violence, extortion, sexual exploitation, the release of intimate material, harm to a child, or immediate financial withdrawal, contact law enforcement without delay. Call emergency services when anyone faces an immediate physical danger.

Special steps for businesses and page administrators

A compromised business page can expose customer messages, employee details, advertising accounts, payment methods, and records held through connected applications.

The business should promptly:

  • Activate its incident-response plan;
  • Notify the data protection officer and authorized management;
  • Isolate affected devices and revoke unauthorized access;
  • Preserve administrator, audit, advertising, and payment logs;
  • Identify what personal data was accessible or extracted;
  • Assess whether NPC and data-subject notification is legally required;
  • Coordinate customer warnings so they are accurate and do not reveal unnecessary personal data;
  • Notify insurers where a cyber-risk policy requires prompt notice; and
  • Preserve contracts and records involving social-media managers, agencies, former employees, and third-party applications.

Do not state that “no data was taken” unless logs or a competent investigation support that conclusion.

Common mistakes to avoid

  • Paying a supposed “account recovery agent” found in comments or private messages;
  • Giving anyone a password, one-time password, backup code, or screen-sharing access;
  • Clicking a recovery link without checking the domain;
  • Deleting conversations or posts before preserving them;
  • Resetting only the social-media password while leaving the email account compromised;
  • Warning people only through the hacked account;
  • Waiting for a police report before alerting the bank or e-wallet;
  • Assuming that reporting guarantees reversal of a transfer;
  • Publicly accusing a named person without reliable evidence;
  • Publishing victims’ IDs, account numbers, or private messages unnecessarily;
  • Filing a false or exaggerated financial complaint; or
  • Wiping a device that may contain relevant forensic evidence.

When legal help is urgent

Consult a Philippine lawyer promptly if:

  • A significant amount was lost or several victims are involved;
  • Funds passed through an account in your name;
  • Police, the NBI, a prosecutor, or a court contacts you as a respondent or suspect;
  • You receive a subpoena, demand letter, or complaint;
  • The attacker obtained IDs, banking credentials, customer records, or sensitive personal information;
  • A business may face the NPC’s 72-hour notification period;
  • The scam involves investments, securities, recruitment, lending, children, intimate images, extortion, or threats;
  • The platform refuses recovery and the account continues causing harm; or
  • Evidence must urgently be preserved or obtained from a service provider.

The Public Attorney’s Office may be an option for persons who satisfy its eligibility and case requirements. Private counsel may be necessary where business, privacy, civil-liability, or urgent court-relief issues are involved.

Frequently asked questions

Should I post that I was hacked?

Yes, but use an unaffected and verifiable channel. State what happened, the approximate affected period, what people must disregard, and how they can verify future requests. Avoid unsupported accusations.

Should scam victims report separately?

Yes. Each person who sent money should report the transaction directly to the relevant bank or e-wallet and preserve their own communications and receipts. They may also submit their own law-enforcement complaint.

Can the bank automatically return the money?

No. Reporting may enable tracing, temporary holding, investigation, or recovery, but reimbursement depends on where the funds are, the applicable law and rules, the institution’s findings, and the evidence.

Is a screenshot enough?

A screenshot is useful but may not be sufficient by itself. Preserve the full conversation, original files, URLs, timestamps, transaction records, security notices, witness information, and platform report numbers.

Can I delete the scam messages after recovering the account?

Preserve them first. Deletion can make investigation and proof more difficult. After making reliable copies, follow platform, legal, and investigator guidance on removing harmful public content.

Must every hacked account be reported to the NPC within 72 hours?

No. The 72-hour rule concerns a personal information controller’s notification of a personal data breach that meets the legal requirements. Whether it applies depends on the role of the account holder, the information compromised, and the risk to affected data subjects.

Is there a single deadline for filing every complaint?

No. Different offenses, civil claims, privacy proceedings, platform remedies, insurance notices, and financial disputes have different rules. Do not wait for a limitation period: platform data may disappear and stolen funds can be transferred quickly.

Can I be arrested merely because my name appears on the hacked profile?

The appearance of your name is not, by itself, proof that you committed the scam. Authorities may still ask questions or examine evidence. Cooperate through proper channels, keep records showing the takeover and your response, and seek counsel before giving a detailed statement if you may be treated as a suspect.

Official references

This article provides general legal information, not legal advice for a specific case. The correct response and possible liability depend on the account records, communications, transactions, parties, and other evidence. Laws, regulations, procedures, and official channels were checked as of September 4, 2026.

Disclaimer: This content is not legal advice and may involve AI assistance. Information may be inaccurate.