Can Companies File Charges Against Unknown Perpetrators?

Can Companies File Charges Against Unknown Perpetrators?

Introduction

Companies may discover that a theft, fraud, cyberattack, or unauthorized access occurred before they can identify the person responsible. Philippine criminal procedure allows a complaint or information to proceed against an accused whose true name is not yet known, provided the person is described under a fictitious name and the alleged offense is sufficiently stated.

This procedure is commonly associated with a “John Doe” complaint or information. It does not, however, permit law-enforcement officers to obtain a general warrant against an unidentified person. A criminal charge and a search warrant serve different purposes and must satisfy separate legal requirements.

What Is a John Doe Criminal Charge?

Section 7, Rule 110 of the [Revised Rules of Criminal Procedure](#L1.8) permits the use of a fictitious name when the accused’s identity cannot be ascertained. The complaint or information may identify the person as “John Doe,” “Jane Doe,” or by another designation, together with a statement that the person’s true name is unknown.

Once the person’s identity is discovered through the investigation or proceedings, the court must cause the true name to be inserted in the complaint or information and in the record. The procedure prevents the temporary lack of identification from defeating a valid criminal prosecution.

The pleading must still allege the elements of the offense, the acts or omissions constituting the violation, the approximate time and place of commission, and the identity of the offended party, subject to the special rules under Rule 110.

When May a Company Use “John Doe”?

A company may use a fictitious designation when it has a reasonable factual basis to believe that an offense was committed but the available evidence does not yet establish the perpetrator’s true name. Examples include a theft by an unidentified employee, unauthorized access traced only to an unknown user, or the use of an unknown account to transfer company funds.

The designation cannot be used merely because the company has not conducted an adequate investigation. The complaint should describe the unknown accused through the available facts, such as the person’s conduct, access credentials, device, location, role, or other identifying circumstances.

In [Ricarze v. Court of Appeals, et al. (2007)](#J1.19), G.R. No. 160451, the Supreme Court discussed the requirement that the accused be identified by name, nickname, or fictitious name when the true identity cannot yet be determined. The Court also recognized that, in property offenses, the identity of the offended party is not always indispensable if the criminal act and the property involved can still be properly identified.

What Must the Complaint or Information Contain?

Under Section 7, Rule 110 of the [Revised Rules of Criminal Procedure](#L1.8), the pleading should state:

  • the fictitious name or designation of the accused;
  • that the accused’s true name is presently unknown;
  • the specific offense allegedly committed;
  • the acts or omissions constituting the offense;
  • the approximate date or period of commission;
  • the place where the offense was committed; and
  • the name of the offended party or a sufficient description of the property involved.

For property offenses, Section 12 of Rule 110 provides that if the offended party’s name is unknown, the property must be described with enough particularity to identify the offense. If the offended party is a corporation or another juridical person, stating its name or recognized designation is generally sufficient.

Can a John Doe Complaint Support a Warrant of Arrest?

A John Doe complaint may initiate investigative or prosecutorial proceedings, but the issuance of a warrant of arrest remains subject to the judge’s independent determination of probable cause. The judge must personally examine the complaint, supporting affidavits, and other evidence presented.

In [Pen v. De Castro (1998)](#J2.1), G.R. No. 104645, the Supreme Court held that a warrant of arrest may issue even before the preliminary investigation is completed, provided that the judge independently determines the existence of probable cause from the evidence submitted.

Once the accused is identified, the prosecution should promptly seek the amendment of the pleading and the corresponding correction of the record. The amendment should not alter the offense or prejudice the accused’s substantial rights.

Are “John Doe Warrants” Valid Search Warrants?

The expression “John Doe warrant” is often used loosely. A search warrant is not valid merely because it is directed against an unknown person. It must particularly describe the place to be searched and the property or items to be seized.

The constitutional and procedural requirements for search warrants include:

  • probable cause personally determined by the issuing judge;
  • an examination under oath of the applicant and witnesses;
  • a finding that an offense has been committed or is being committed; and
  • a particular description of the place to be searched and the things to be seized.

The absence of the suspect’s name may be acceptable where the search warrant sufficiently identifies the place and property and the evidence establishes probable cause. But a warrant that authorizes officers to search unspecified locations or seize broadly described materials would risk becoming a prohibited general warrant.

Search Warrants for Digital Evidence

Where the suspected offense involves computers, mobile phones, online accounts, or other digital systems, investigators must comply with the applicable rules on cybercrime warrants. The 2022 Revised Rules and Regulations Implementing Republic Act No. 9208, as amended, recognizes the following types of cybercrime warrants:

WarrantPurpose
Warrant to Disclose Computer DataRequires a person or service provider to disclose specified computer data in its possession or control.
Warrant to Intercept Computer DataAuthorizes the interception, monitoring, recording, or surveillance of communications while occurring.
Warrant to Search, Seize and Examine Computer DataAuthorizes the search of a particular place and the seizure or examination of specified computer data or devices.
Warrant to Examine Computer DataRequired before law-enforcement officers examine computer data from a device lawfully acquired through an arrest or another lawful method.

The [2022 Revised Rules and Regulations Implementing Republic Act No. 9208, as amended](#L5.42), identifies these forms of cybercrime warrants and emphasizes that digital searches must be authorized and properly limited. The rule is especially relevant when the hacker’s identity is unknown but the company can identify the affected server, device, account, or data set.

Particularity Requirements for Search Warrants

The application should identify the target location or device with reasonable certainty. Depending on the circumstances, this may include a physical address, server, workstation, company-issued laptop, mobile phone, cloud account, internet protocol address, domain, user account, or specified data repository.

The items to be seized should also be described with reasonable particularity. A request for “all computers and all information” may be challenged as overbroad. The application should instead connect the requested items to the suspected offense, relevant period, users, file types, accounts, or transaction records.

The [Guidelines on Mutual Legal Assistance in Criminal Matters](#I2.32) similarly describe probable cause as facts and circumstances that would lead a reasonably discreet and prudent person to believe that an offense was committed and that the objects sought are located in the place to be searched. The Guidelines also stress reasonable particularity so that the warrant does not become a roving commission.

Recommended Company Procedure

1. Preserve the evidence

The company should immediately preserve logs, access records, CCTV footage, emails, messages, transaction histories, device images, and relevant documents. Investigators should avoid altering or overwriting the original data.

2. Establish the offense

The company should identify the possible violation, such as theft, qualified theft, estafa, damage to computer systems, illegal access, or another offense under Philippine law. The facts must support the elements of the particular offense selected.

3. Identify the unknown perpetrator through available facts

Even if the name is unknown, the complaint should describe the suspected person or account through objective details. These may include login times, employee access rights, IP addresses, device identifiers, payment accounts, delivery records, or other evidence linking the conduct to a particular source.

4. Coordinate with counsel and investigators

The company should coordinate with the appropriate prosecutor and law-enforcement agency. Digital investigations may require preservation requests, subpoenas or disclosure processes, cybercrime warrants, and forensic examination by qualified personnel.

5. File the complaint against the fictitious accused when justified

If the evidence establishes that an offense was committed but the perpetrator’s identity remains unknown, the complaint may designate the accused as John Doe or another fictitious name. The pleading should expressly state that the true name is unknown and should provide the facts supporting the charge.

6. Apply for the correct warrant

The company should not request a generic warrant against “John Doe.” The application must seek the specific type of warrant required and must particularly identify the place, device, account, data, or items connected with the offense.

7. Amend the record after identification

When the suspect is identified, the prosecution should move to insert the true name in the complaint or information and the court record. The amendment should preserve the identity of the offense originally charged and should not cause unfair surprise or prejudice.

Common Errors to Avoid

  • Using “John Doe” without stating why the person’s identity is unknown;
  • Filing a complaint that alleges conclusions instead of specific acts;
  • Requesting a search of all company or third-party systems without factual limits;
  • Failing to preserve the original digital evidence and its metadata;
  • Confusing a warrant of arrest with a search warrant; and
  • Failing to amend the pleading promptly after the accused is identified.

Effect on the Company’s Civil Claims

A criminal case may also involve civil liability arising from the offense, subject to the rules on the implied institution, reservation, waiver, or independent prosecution of civil actions. The company should therefore document the amount and basis of its losses, including stolen property, unauthorized transfers, restoration costs, business interruption, and damage to systems.

The company should also determine whether insurance, subrogation, data-protection obligations, employment remedies, or regulatory reporting duties are implicated. These matters may proceed alongside, but are legally distinct from, the criminal case.

Data Privacy Considerations

Investigating an unknown hacker or thief may involve personal information belonging to employees, customers, contractors, or third parties. The company should limit collection and disclosure to information relevant to the investigation and should observe applicable duties under the Data Privacy Act and its implementing rules.

In [In re: Commission on Elections (2022)](#I1.57), NPC SS 22-001 and NPC SS 22-008, the National Privacy Commission recommended prosecution of identified respondents and other John Does or Jane Does for unauthorized access under Section 29 of Republic Act No. 10173, while dismissing the case against the Commission on Elections and Smartmatic for lack of merit. The decision illustrates that unknown perpetrators may be referred for prosecution, but liability must still rest on sufficient evidence of the specific unlawful act.

Practical Illustration

Suppose a company discovers that an unknown user accessed its payroll system, changed bank-account details, and diverted salary payments. The company may file a complaint describing the unauthorized access, the altered records, the diverted funds, and the available technical evidence, naming the responsible person as John Doe if the person cannot yet be identified.

The company may separately support an application for a warrant to disclose computer data, a warrant to search, seize, and examine computer data, or another appropriate process. The application must identify the relevant system, accounts, dates, devices, and data sought; it cannot authorize an unrestricted search for any possible evidence.

Conclusion

Companies are not required to wait indefinitely before reporting an offense simply because the perpetrator’s name is unknown. A properly supported John Doe complaint may be used when the offense and the accused’s relevant conduct can be adequately alleged.

The procedure does not eliminate the requirements of probable cause, particularity, due process, or evidentiary authentication. Companies should preserve evidence promptly, describe the unknown perpetrator through available facts, file the appropriate complaint, seek a specifically tailored warrant, and amend the record once the person’s identity is established.

About Nicolas and De Vega Law Offices

  Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH