Can Philippine Banks Extradite Foreign Hackers?

Can Philippine Banks Extradite Foreign Hackers?

Introduction

Cyberattacks against Philippine banks often involve foreign perpetrators, overseas servers, cryptocurrency transfers, and victims located in several jurisdictions. When the suspected hacker is outside the Philippines, local authorities generally cannot simply arrest and bring that person before a Philippine court.

The usual legal routes are extradition, mutual legal assistance, international cooperation, and, where legally permitted, prosecution based on the extraterritorial reach of Philippine criminal laws. The applicable process depends on the suspect’s location, nationality, the offense charged, the available treaty, and whether the alleged conduct is criminal in both countries.

Philippine Laws Governing Offshore Cybercrime

The principal statute is the Cybercrime Prevention Act of 2012, or R.A. No. 10175. It covers offenses such as illegal access, illegal interception, data interference, system interference, misuse of devices, computer-related fraud, and computer-related identity theft.

R.A. No. 10175 also recognizes circumstances in which Philippine courts may acquire jurisdiction over cybercrime committed outside the country. In Calleja, et al. v. Executive Secretary, et al., G.R. No. 252578, December 7, 2021, the Supreme Court referred to Section 21 of R.A. No. 10175 as extending Philippine jurisdiction to violations committed by a Filipino national regardless of the place of commission. [Calleja, et al. v. Executive Secretary, et al. (2021)](#J2.325)

That rule does not mean that every foreign hacker who attacks a Philippine bank may automatically be tried in the Philippines. The prosecution must still establish a sufficient jurisdictional connection, comply with applicable procedural rules, and obtain custody of the accused through lawful means.

When Extradition May Be Requested

Extradition is the formal surrender of an accused or convicted person by one State to another for criminal prosecution or service of sentence. Under Presidential Decree No. 1069, the Philippine Extradition Law, extradition proceedings must be grounded on an applicable extradition treaty or convention.

For cybercrime, the Philippines must therefore determine whether the country where the suspect is located has an extradition treaty with the Philippines, is a party to an applicable multilateral treaty to which the Philippines is also a party, or is covered by another legal basis recognized by Philippine law.

A request cannot be sustained merely because the alleged attack affected a Philippine bank. The requesting authorities must identify the legal basis for surrender and satisfy the requirements of the governing treaty and Philippine extradition law.

The Double Criminality Requirement

A major requirement in extradition is double criminality. The conduct described in the extradition request must constitute a crime both under Philippine law and under the law of the requested State.

In Government of Hongkong Special Administrative Region v. Muñoz, G.R. No. 207342, August 16, 2016, the Supreme Court explained that the requested State is not required to surrender a person if the conduct identified in the request is not criminal under its own laws. The offense need not always have the same name in both jurisdictions, but the underlying conduct must be criminal in both. [Government of Hongkong Special Administrative Region v. Muñoz (2016)](#J7.18)

For example, an allegation that a foreign suspect unlawfully entered a Philippine bank’s computer system may satisfy double criminality if the conduct constitutes illegal access under R.A. No. 10175 and an equivalent computer offense under the law of the requested State.

What Philippine Authorities Must Establish

An extradition request involving an alleged bank cyberattack should ordinarily identify the person sought, the location of that person, the facts of the offense, the procedural history of the case, the applicable criminal provisions, the possible penalty, and any applicable limitation period.

The request should also be supported by the documents required by the relevant treaty and by P.D. No. 1069. These may include a warrant of arrest, charging document, judgment of conviction, affidavits, statements, technical reports, and evidence sufficient to establish the required level of probable cause under the governing arrangement.

In Secretary of Justice v. Lantion, G.R. No. 139465, October 17, 2000, the Supreme Court discussed the executive evaluation of an extradition request, including the identity and location of the person sought, the facts and procedural history of the case, the essential elements of the offense, the punishment, limitation periods, and supporting documents such as a warrant or charging instrument. [Secretary of Justice v. Lantion (2000)](#J4.11)

Extradition Procedure in the Philippines

The process generally begins when the requesting State transmits an extradition request through diplomatic or other designated channels. Philippine executive authorities examine whether the request complies with P.D. No. 1069 and the applicable treaty before the matter is brought before the proper court.

Once a petition for extradition is filed, the Regional Trial Court determines whether the legal and evidentiary requirements for arrest and extradition have been met. The person sought may contest the request under the applicable procedural safeguards.

The Supreme Court has distinguished the evaluation stage from the judicial stage. In Secretary of Justice v. Lantion, the Court’s discussion reflects the importance of due process in extradition proceedings, while also recognizing the State’s interest in preventing flight and complying with treaty obligations. [Secretary of Justice v. Lantion (2000)](#J3.15)

In Government of the United States of America v. Purganan, G.R. No. 148571, September 24, 2002, the Supreme Court held that bail in extradition proceedings is not a matter of right. It may be allowed as an exception upon a clear and convincing showing that the applicant is not a flight risk or a danger to the community and that special, humanitarian, and compelling circumstances exist. [Government of the United States of America v. Purganan (2002)](#J6.10)

How Cybercrime Warrants Support the Case

The evidentiary foundation for an extradition request may include digital evidence obtained through Philippine cybercrime warrants. The Rules on Cybercrime Warrants, A.M. No. 17-11-3-SC, provide procedures suited to the preservation, disclosure, interception, search, seizure, and examination of computer data.

Where a person or service provider is located outside the Philippines, service of a warrant or other court process must be coursed through the Department of Justice–Office of Cybercrime, consistently with applicable international instruments or agreements. [Rules on Cybercrime Warrants (2018)](#J1.15)

This requirement is important in bank-hacking cases. Philippine investigators should not assume that a domestic warrant may be served directly on a foreign cloud provider, telecommunications company, exchange, or hosting provider. The request should use the proper international channel and comply with the law of the requested country.

Mutual Legal Assistance Before or Alongside Extradition

Extradition secures the person of the accused. Mutual legal assistance secures evidence and investigative cooperation. The two processes may proceed separately or in coordination.

Assistance from a foreign State may include obtaining witness statements, locating suspects, serving judicial documents, examining objects and sites, providing certified records, executing searches and seizures, tracing criminal proceeds, freezing property, and assisting in forfeiture or confiscation proceedings.

For trafficking-related cyber offenses, Section 70 of the 2022 Revised Rules and Regulations Implementing R.A. No. 9208, as amended, recognizes requests for foreign legal assistance on the basis of law, treaty, or reciprocity and lists these forms of cooperation. The same type of request may be relevant where a cyberattack is connected with trafficking, online exploitation, or related financial crimes. [The 2022 Revised Rules and Regulations Implementing Republic Act No. 9208, as amended (2023)](#L1.79)

For ordinary bank hacking, the specific mutual legal assistance treaty or other legal basis between the Philippines and the foreign State must be verified. If no treaty applies, assistance may depend on reciprocity, domestic law, or another recognized agreement.

Extradition Treaties and Cyber Offenses

The relevant bilateral extradition treaty must be examined carefully. Some treaties list extraditable offenses by reference to minimum penalties; others use a list of offenses, a conduct-based test, or both. The treaty may also contain requirements concerning probable cause, documents, specialty, refusal grounds, nationality, limitation periods, and political offenses.

The fact that a treaty predates modern cybercrime statutes does not automatically prevent extradition. A computer-related fraud or unauthorized access case may qualify if the treaty covers equivalent conduct, fraud, offenses punishable above a prescribed threshold, or offenses recognized as extraditable under the treaty’s terms.

However, the treaty’s exact language controls. Philippine authorities should not assume that every cybercrime offense is extraditable without checking the treaty, the requested State’s law, and the penalty applicable to the charged offense.

Prosecution After Surrender

If the suspect is surrendered to the Philippines, prosecution remains subject to the Constitution, the Rules of Criminal Procedure, R.A. No. 10175, and the limitations imposed by the applicable extradition treaty.

The rule of specialty generally prevents the requesting State from prosecuting the surrendered person for an offense different from the offense for which surrender was granted, unless the treaty or the requested State permits such prosecution. Prosecutors should therefore ensure that the information filed in the Philippines corresponds to the offense described in the extradition request.

Evidence collected abroad must also satisfy Philippine admissibility requirements. Investigators should preserve its chain of custody, document the method of acquisition, obtain certifications where necessary, and maintain reliable records showing that the data is authentic and has not been altered.

Other Measures Against Offshore Hackers

Extradition is not the only response. Philippine authorities may coordinate with foreign counterparts to identify the suspect, preserve computer data, trace stolen funds, freeze assets, and obtain subscriber or account records.

Where the proceeds pass through banks, payment platforms, or virtual asset service providers, financial investigation may proceed under the Anti-Money Laundering Act of 2001, R.A. No. 9160, as amended, subject to its requirements and the applicable court or administrative process.

If the conduct involves terrorism financing, R.A. No. 10168 may provide an additional basis for international cooperation. Section 20 allows the International Convention for the Suppression of the Financing of Terrorism to be considered, subject to reciprocity, as a legal basis for requesting or granting extradition for offenses under that law. [Republic Act No. 10168 (2012)](#L5.26)

Issues in Bank-Hacking Extradition Cases

Uncertain identity. Online aliases, stolen credentials, proxy servers, and cryptocurrency wallets do not by themselves prove that a particular foreign person committed the offense. Investigators must connect the digital identifiers to a real individual.

Insufficient technical evidence. Logs should be preserved promptly and correlated with authentication records, device identifiers, malware indicators, payment records, and communications. A general allegation that an overseas internet address was involved may be insufficient.

Failure to satisfy double criminality. The charging theory must be translated into conduct that is punishable under both Philippine law and the law of the requested State.

Improper service of foreign processes. Philippine authorities should use the Department of Justice and the proper international channel rather than directly serving domestic warrants on foreign persons or entities.

Treaty mismatch. The offense, penalty, documents, limitation period, and procedural history must fit the specific treaty. A request based on a similar but inapplicable treaty may be rejected.

Recommended Steps for Philippine Financial Institutions

Banks should immediately preserve relevant logs, access records, transaction histories, device information, communications, surveillance footage, and records of customer notifications. The institution should coordinate with the Philippine National Police Anti-Cybercrime Group, the National Bureau of Investigation Cybercrime Division, the Bangko Sentral ng Pilipinas when appropriate, and other competent authorities.

The bank should prepare a technical chronology showing the initial compromise, affected systems, unauthorized transactions, suspected infrastructure, and financial trail. It should also identify the foreign jurisdictions involved, including the location of servers, exchanges, hosting providers, intermediaries, and suspected offenders.

Authorities should then determine whether the immediate objective is preservation of evidence, identification of the offender, freezing of proceeds, issuance of a domestic warrant, a mutual legal assistance request, or an extradition request. These objectives may require different legal instruments and should not be treated as interchangeable.

Conclusion

Foreign hackers who target Philippine financial institutions may be prosecuted in the Philippines only through a legally sufficient jurisdictional and evidentiary process. Extradition generally requires an applicable treaty or other recognized legal basis, compliance with P.D. No. 1069, satisfaction of double criminality, and sufficient documentation to support the request.

For a successful case, Philippine authorities and financial institutions should preserve digital evidence immediately, establish the suspect’s identity, trace the financial proceeds, use proper international channels, and verify the precise requirements of the treaty with the State where the suspect is located. If the suspect cannot lawfully be surrendered, mutual legal assistance and coordinated foreign prosecution may still provide effective remedies.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH