Can Former IT Employees Be Prosecuted for Unauthorized Access?

Can Former IT Employees Be Prosecuted for Unauthorized Access?

Introduction

Former information technology employees may retain administrator credentials, remote-access tools, or knowledge of a company’s server environment after leaving employment. If they use that access to delete files, disable services, alter configurations, install malware, or disrupt operations, the conduct may expose them to criminal, civil, and administrative consequences.

The principal criminal statute is the Cybercrime Prevention Act of 2012. The central issue is not merely whether the person once had authorized access, but whether the later access or interference was undertaken without right, beyond the scope of authority, or with a purpose inconsistent with the employer’s authorization.

What Law Governs Unauthorized Computer Access?

Republic Act No. 10175, or the Cybercrime Prevention Act of 2012, penalizes several computer-related offenses, including illegal access, illegal interception, data interference, system interference, misuse of devices, and computer-related identity theft.

Illegal access generally concerns intentionally accessing an entire or part of a computer system without right. The use of retained administrator credentials does not automatically establish lawful access. The circumstances of the access, the employee’s continuing authority, the employer’s instructions, and the employee’s purpose must be examined.

Where an employee accesses a system to damage, delete, alter, or render unavailable corporate data or services, the conduct may also fall within data interference or system interference, depending on the acts proved and the resulting harm.

The Supreme Court recognized in Disini, Jr. v. Secretary of Justice, G.R. No. 203335, 11 February 2014, that cybercrime provisions must be applied consistently with constitutional guarantees of due process and privacy. The Court also sustained the validity of provisions addressing intentional unauthorized access and related computer offenses when applied to clearly identifiable criminal conduct.

Does Former Authorization Continue After Employment Ends?

Not necessarily. Authorization is determined by the employer’s grant of access and its continuing terms, not merely by the fact that the accused previously worked for the company.

A former employee may be prosecuted when the evidence shows that:

First, the person accessed a computer system or server;

Second, the access was without right or exceeded the authority granted by the company;

Third, the access was intentional and knowing; and

Fourth, the conduct satisfies the elements of the particular cybercrime charged, such as unauthorized access, data interference, or system interference.

Access may be considered unauthorized where the company revoked the person’s credentials, directed the person not to access the system, terminated the employment relationship, disabled the account, or limited the person’s authority to specified systems or purposes.

However, the mere fact that a former employee’s account remained technically active is not conclusive. The prosecution must still establish that the access was legally unauthorized and that the accused acted with the mental state required by the offense.

When Can Retained Administrator Privileges Become Criminal?

Retained administrator privileges become significant when they are used to perform acts outside the person’s continuing authority. Examples include resetting passwords, creating hidden accounts, disabling security controls, deleting databases, changing server configurations, or preventing the company from accessing its own systems.

Under Disini, Jr. v. Secretary of Justice, G.R. No. 203335, 11 February 2014, the Court distinguished legitimate security testing from unauthorized intrusion. Ethical hacking ordinarily depends on prior permission defining the systems, methods, and limits of the engagement. That reasoning supports the opposite conclusion when a former employee acts without permission or after the authority to test or administer the system has ended.

The prosecution should therefore avoid relying solely on the employee’s former job title. It should prove the specific authorization previously granted, the date and manner of its termination, the access performed afterward, and the damage or interference caused.

Unauthorized Access Versus Data and System Interference

The offenses may overlap, but they address different conduct.

Potential offenseTypical conductImportant proof
Illegal accessEntering a computer system or restricted account without rightLogin records, authentication data, revoked permissions, and proof of lack of authority
Data interferenceDeleting, damaging, altering, suppressing, or deteriorating computer dataFile histories, backups, forensic images, deletion records, and evidence of alteration
System interferenceSeriously hindering or obstructing the functioning of a computer systemDowntime, service interruption, configuration changes, denial-of-service activity, and restoration records
Misuse of devicesPossessing, producing, distributing, or using tools intended for committing cybercrimeMalware, exploit tools, scripts, credentials, and evidence of their intended criminal use

The charging decision should match the proven conduct. A company should not characterize every unauthorized login as system interference unless the evidence demonstrates substantial obstruction or disruption of the system.

What Must the Company Prove?

A credible criminal complaint should establish both the technical event and the absence of legal authority. The following evidence is commonly material:

Employment and access records. Preserve the employment contract, resignation or termination documents, confidentiality agreements, acceptable-use policies, access-control policies, and written instructions revoking or limiting privileges.

Authentication and audit logs. Secure server logs, VPN records, cloud audit trails, firewall records, privileged-access-management records, and multifactor authentication logs. These should identify the account, device, Internet Protocol address, time, and activity performed.

Forensic evidence. Obtain forensic images and hash values where appropriate. Preserve deleted-file records, event logs, malware samples, scripts, and configuration histories in a manner that permits authentication in court.

Proof of damage or interruption. Document unavailable services, corrupted or deleted data, restoration expenses, lost transactions, downtime, and the scope of affected systems.

Attribution evidence. A username alone may not prove that the former employee personally performed the act. Investigators should examine device ownership, remote-access records, authentication factors, communications, physical access, and other facts connecting the accused to the activity.

What If the Employee Used Valid Credentials?

Valid credentials do not automatically defeat a cybercrime complaint. Credentials may be used without right when the authority to use them has ended or when they are used for a purpose outside the authorization granted.

At the same time, a company must prove more than the existence of suspicious activity. The prosecution must establish the accused’s knowing and intentional conduct and must address reasonable alternative explanations, such as automated processes, shared credentials, compromised accounts, or incomplete account-deactivation procedures.

The Supreme Court has emphasized that cybercrime liability must not be applied so broadly that legitimate security work or authorized activity becomes criminal. Permission, scope, purpose, and technical attribution should therefore be documented before filing a complaint.

Can the Data Privacy Act Also Apply?

The Data Privacy Act of 2012 may apply when the affected systems store personal or sensitive personal information. Section 29 of Republic Act No. 10173 penalizes persons who knowingly and unlawfully, or while violating data confidentiality and security systems, break into a system where personal or sensitive personal information is stored.

The National Privacy Commission has identified three elements of unauthorized access or intentional breach under Section 29:

First, the data system stores personal or sensitive personal information;

second, the accused breaks into the system; and

third, the accused knowingly and unlawfully breaks into the system in a manner that violates data confidentiality and security.

These elements were discussed in ACN v. DT, NPC 18-109, 5 May 2021, and applied in In re: Commission on Elections, Smartmatic Group of Companies, RVA, WS, and Other John Does and Jane Does, NPC SS 22-001 and NPC SS 22-008, 2022.

The Data Privacy Act should not be invoked merely because a server was accessed. The company must show that personal or sensitive personal information was stored in the system and that the conduct satisfies the statutory elements. Evidence must also establish that the access was knowing, unlawful, and inconsistent with data confidentiality or system security.

What If Government or Election Data Is Involved?

Additional laws may apply when the system contains PhilSys information, election-related data, or government records. Unauthorized access to or unauthorized processing of PhilSys data may be penalized under Republic Act No. 11055, subject to the specific role of the offender and the circumstances of the violation.

Government information systems are also subject to statutory security requirements under the E-Governance Act. Republic Act No. 12254 requires government information and systems to be protected against interference and unauthorized access, while limiting access to duly authorized officers and agents.

These laws do not automatically replace Republic Act No. 10175. Prosecutors must identify the statute whose elements are satisfied by the evidence and must avoid duplicative or legally inconsistent charges.

How Should a Company Preserve Evidence?

The company should immediately preserve relevant evidence without altering the affected systems unnecessarily. A sound incident-response process should include the following steps:

1. Contain the incident. Disable compromised accounts, rotate credentials, terminate remote sessions, isolate affected systems, and preserve volatile evidence where technically appropriate.

2. Preserve records. Issue a written litigation or investigation hold covering logs, email, messaging applications, endpoint data, cloud records, access-control records, and backup media.

3. Establish a timeline. Record the employee’s last day, the revocation of privileges, the first suspicious event, each system accessed, and the resulting damage.

4. Conduct a forensic examination. Use qualified personnel and document the collection method, chain of custody, hash values, tools used, and persons who handled the evidence.

5. Report to the proper authorities. Depending on the facts, the company may coordinate with the National Bureau of Investigation, the Philippine National Police Anti-Cybercrime Group, the Department of Justice Office of Cybercrime, or the National Privacy Commission.

What Warrants May Be Used During Investigation?

Investigators may need court authority to obtain subscriber information, preserve computer data, intercept computer data, or search and examine computer systems. The Supreme Court’s Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, 2018, provides specialized procedures for these applications.

The Rules recognize that warrants may involve computer data and may require technical procedures different from an ordinary physical search. For persons or service providers outside the Philippines, service of warrants and other court processes is coursed through the Department of Justice Office of Cybercrime in accordance with relevant international instruments and agreements.

Companies should avoid independently accessing an accused person’s private devices, accounts, or communications without legal authority. Evidence gathered through unlawful access may be challenged and may expose the company or its personnel to separate liability.

Can the Company Pursue Civil or Employment Remedies?

Yes. Criminal prosecution does not exclude civil claims for the cost of restoration, data recovery, business interruption, lost revenue, or other legally compensable injury. The company may also pursue remedies based on confidentiality agreements, employment contracts, trade-secret obligations, and internal policies, subject to the applicable law and the evidence.

Administrative or employment action may also be available if the person remains employed, is subject to a post-employment obligation, or committed related misconduct while still occupying a position of trust. The employer should observe due process and should not treat the criminal accusation as established before competent adjudication.

Common Weaknesses in Unauthorized-Access Complaints

Complaints are vulnerable when they rely only on an employee’s former position, a suspicious login, or the fact that the person possessed technical knowledge.

Other weaknesses include the absence of proof that access was revoked, shared administrator credentials, incomplete logs, failure to preserve original evidence, uncertainty about who controlled the relevant device, and failure to identify the specific data altered or the system function disrupted.

The complaint should also distinguish between an unsuccessful attempt, completed unauthorized access, data alteration, and system disruption. The legal consequences depend on the offense actually proved.

Practical Recommendations for Employers

Employers should adopt documented offboarding procedures that immediately disable accounts, revoke privileged credentials, recover company devices, terminate VPN and cloud access, rotate shared secrets, and review administrator activity after separation.

Access should be assigned according to role and limited by system, function, duration, and purpose. Shared administrator accounts should be avoided or closely monitored, and privileged activity should be logged in a tamper-resistant system.

Employment agreements and company policies should clearly state that authorization ends upon separation or upon written revocation. They should also prohibit the retention, use, disclosure, alteration, or destruction of company data after employment ends.

Conclusion

A former IT employee may be prosecuted for using retained administrator privileges to enter or interfere with corporate systems, but criminal liability is not automatic. The prosecution must prove the particular cybercrime, the absence or excess of authority, the accused’s knowing and intentional conduct, and—where applicable—the required damage, interference, or presence of personal information.

Companies should secure systems immediately, preserve reliable technical evidence, obtain appropriate warrants when necessary, and coordinate with competent investigative and privacy authorities. A well-documented access-control and offboarding process is often decisive in showing when lawful employment access ended and unauthorized computer activity began.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH