Does AFASA Track Phishing Payments Through Social Media?
Introduction
Phishing schemes increasingly use social media, messaging applications, and other digital platforms to deceive users into surrendering passwords, account details, one-time passwords, and other credentials. The resulting payments may pass through several bank accounts, e-wallets, payment platforms, and intermediaries before reaching the individuals or syndicates behind the fraud.
The Anti-Financial Account Scamming Act (AFASA) addresses this problem by criminalizing certain financial account scams, requiring regulated financial institutions to maintain fraud controls, and giving the Bangko Sentral ng Pilipinas (BSP) investigative powers. However, the law does not generally impose a blanket duty on social-media companies to monitor all communications or automatically disclose user information. Its principal regulatory duties fall on banks, non-bank financial institutions, payment service providers, and other institutions under BSP supervision.
What Is the Anti-Financial Account Scamming Act?
Republic Act No. 12010, or the Anti-Financial Account Scamming Act (AFASA), seeks to protect financial accounts from cybercriminals and syndicates that use deception, unauthorized access, and other fraudulent methods. It also seeks to prevent account owners from being induced to participate, knowingly or unknowingly, in the movement of illicit funds.
The statute covers financial accounts used to obtain financial products or services, including accounts maintained with banks, electronic-money issuers, payment service providers, and other institutions under BSP supervision. Its policy recognizes that digital financial services create additional channels through which criminals may target consumers and move fraud proceeds. (Anti-Financial Account Scamming Act, R.A. No. 12010)
How Social Media Is Used in Phishing Schemes
A typical phishing operation begins outside the financial institution. A syndicate may use a social-media advertisement, a direct message, a fake customer-support account, or a deceptive link that imitates a bank, e-wallet provider, online marketplace, or government agency.
The victim may then be induced to disclose sensitive identifying information, such as usernames, passwords, account numbers, card details, e-wallet credentials, or one-time authentication information. The criminal group uses those details to access a financial account or persuade the victim to authorize a transfer.
AFASA defines social-engineering schemes to include obtaining sensitive identifying information through deception or fraud for the purpose of gaining unauthorized access to a financial account. The scheme may involve pretending to represent an institution or using electronic communications to obtain the information. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, G.R. No. 273720, 2025)
Does AFASA Require Social Networks to Coordinate With Fintech Companies?
Not as a general matter. The available statutory and regulatory materials primarily impose obligations on BSP-supervised financial institutions and payment-related entities. They require those institutions to detect suspicious transactions, protect accounts, investigate fraud, and share relevant information in appropriate circumstances.
Social-media companies may become relevant sources of evidence when a phishing campaign is investigated, particularly where investigators need information about accounts, advertisements, messages, links, or technical activity. However, the materials identified here do not establish a general AFASA duty requiring every social-media platform to continuously coordinate with fintech companies or to automatically provide user data.
Coordination may instead occur through lawful requests, cybercrime warrants, investigative proceedings, applicable data-protection rules, or cooperation with law-enforcement authorities. The legal basis and procedure will depend on the information sought and the entity possessing it.
What Duties Do Financial Institutions Have?
Section 6 of AFASA requires BSP-supervised financial institutions to employ adequate risk-management systems and controls to protect clients’ financial accounts. The BSP has reiterated that these controls must address unauthorized transactions, fraud, and other risks affecting financial accounts.
The BSP’s implementing measures identify controls such as multi-factor authentication and fraud-management systems. Financial institutions are expected to use automated and real-time monitoring and detection capabilities to identify, block, or investigate disputed and suspicious online transactions. (BSP Memorandum No. M-2024-029; BSP Circular No. 1213, 2025)
Depending on the institution and transaction, appropriate controls may include:
- multi-factor authentication;
- transaction-velocity checks;
- geolocation and device monitoring;
- behavioral-anomaly detection;
- real-time fraud alerts; and
- temporary restrictions on suspicious transactions.
The purpose of these controls is not merely to identify the person who initiated a transaction after the money has disappeared. They are also intended to interrupt the movement of funds while a transaction is being assessed.
Tracking the Movement of Fraudulent Payments
Tracking generally involves the reconstruction of the payment path: the originating account, receiving account, intermediary accounts, payment channels, device or access information, and subsequent withdrawals or transfers. Financial institutions may compare transaction data across institutions when fraud involves more than one bank, e-wallet, or payment service provider.
The BSP has recognized that financial institutions may share relevant information for fraud investigations when the requirements of applicable law and data-protection principles are observed. The information may include the customer’s name, address, email address, telephone number, account information, and transaction details. The BSP’s guidance states that an existing court order or pending court case is not always a prerequisite for information-sharing in a fraud investigation, subject to lawful purpose, transparency, proportionality, and other safeguards. (BSP Memorandum No. M-2021-059)
This authority does not mean that institutions may disclose all information without limits. Information-sharing must remain connected to a legitimate fraud investigation and must comply with applicable confidentiality, privacy, security, and record-keeping requirements.
Can Bank Secrecy Prevent Investigators From Identifying an Account Holder?
Bank secrecy remains a general rule, but it is not absolute. The Supreme Court has ruled that the Cybercrime Prevention Act did not expressly or impliedly repeal the Bank Secrecy Law. At the same time, a bank acting as a service provider may disclose subscriber information, including the identity and contact details of an account holder, when authorized by a valid court-issued warrant to disclose computer data in a cybercrime investigation.
The Court distinguished basic identifying information from the financial details of deposits. A warrant may authorize the disclosure of relevant account-holder information when the statutory requirements and safeguards for cybercrime investigations are satisfied. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, G.R. No. 273720, 2025)
AFASA also gives the BSP authority to investigate financial accounts and share relevant information with law-enforcement and other competent authorities, subject to the limitations of the law. The BSP may apply for cybercrime warrants and related orders under the Cybercrime Prevention Act, without prejudice to the existing investigative powers of the National Bureau of Investigation and the Philippine National Police.
For financial accounts under BSP investigation for prohibited acts covered by AFASA, the Court recognized that relevant provisions restricting inquiry into or disclosure of deposits do not prevent the authorized investigation and disclosure contemplated by the statute. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, G.R. No. 273720, 2025)
Temporary Holding of Disputed Funds
When a victim promptly reports an unauthorized or fraudulent electronic transfer, the involved financial institutions may be able to place a temporary hold on disputed funds while verification and investigation proceed. BSP regulations provide for a coordinated verification process involving the institutions connected with the transaction.
The applicable rules allow a temporary hold for up to 30 calendar days, subject to the prescribed procedures, notifications, and verification requirements. The hold is not the same as a final forfeiture or a judicial determination of ownership. It is an interim protective measure intended to reduce the risk that the money will be withdrawn or transferred before the complaint is assessed. (BSP Circular No. 1215, 2025; BSP Memorandum No. M-2024-030)
What Happens When a Financial Institution Fails to Maintain Required Controls?
AFASA distinguishes between institutions that maintain the required account-protection systems and those that fail to meet the prescribed standards. An institution that has complied with the applicable requirements may receive statutory protection from liability for certain losses caused by covered financial crimes, subject to the conditions of the law.
Conversely, a BSP-supervised institution that fails to implement the required safeguards may be subject to restitution obligations for losses suffered by affected account owners. The institution’s liability may arise from noncompliance with its regulatory duties even without a criminal conviction against an employee or officer.
The BSP has reiterated that the required systems must be adequate to the institution’s risk profile and capable of detecting and responding to suspicious activity. (BSP Memorandum No. M-2024-029)
Role of Banks, Fintech Companies, and Social-Media Platforms
| Entity | Typical legal and operational role |
|---|---|
| Banks and e-wallet providers | Monitor transactions, protect accounts, investigate complaints, share relevant fraud information, and comply with lawful holds or investigative orders. |
| Payment service providers | Detect suspicious transfers, preserve transaction records, coordinate with other institutions, and assist in tracing payment flows. |
| BSP | Supervise covered institutions, investigate financial accounts under AFASA, issue regulations, and coordinate with law-enforcement bodies. |
| NBI and PNP cybercrime units | Investigate cybercrime offenses, seek appropriate warrants and court orders, identify perpetrators, and support prosecution. |
| Social-media platforms | May hold relevant account, advertisement, message, or technical evidence and may respond to lawful requests, subject to applicable law and platform procedures. |
Relationship With the Cybercrime Prevention Act
The Cybercrime Prevention Act remains relevant when phishing involves unauthorized access, computer-related fraud, identity theft, or the use of computer systems to commit an offense. It also supplies procedures for obtaining certain computer data through judicially authorized warrants.
The Supreme Court has recognized that the statute provides a lawful basis for limited disclosure of identifying information held by service providers when the required warrant and safeguards are present. The disclosure must remain connected to a cybercrime investigation and cannot be treated as unrestricted access to confidential financial information. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, G.R. No. 273720, 2025)
Practical Steps for Victims
A person who receives a suspicious social-media message or discovers an unauthorized transfer should act immediately. Delay increases the risk that the funds will be moved through additional accounts or withdrawn in cash.
- Contact the bank, e-wallet provider, or payment service immediately through its official channel.
- Request account restriction, transaction review, and appropriate protective measures.
- Preserve screenshots, URLs, usernames, telephone numbers, messages, receipts, transaction references, and timestamps.
- Change passwords and revoke suspicious sessions or devices, subject to the institution’s instructions.
- Report the matter to the appropriate law-enforcement or cybercrime authority.
- Do not delete the original messages or click additional links supplied by the suspected fraudster.
The complaint should identify the complete payment trail as far as possible. Important details include the originating account, recipient account, amount, date and time, reference number, platform used, social-media profile, and the exact link or message that induced the transaction.
Practical Steps for Financial Institutions
Financial institutions should maintain documented procedures for detecting phishing-related transactions and escalating them for investigation. Their systems should be capable of identifying unusual payment behavior, repeated transfers to newly added beneficiaries, rapid movement of funds, device anomalies, and other indicators of account takeover or social engineering.
Institutions should also preserve relevant logs and records, coordinate with other institutions through lawful information-sharing channels, and provide customers with clear instructions for reporting suspected fraud. Their personnel and third-party service providers should be trained to avoid unauthorized disclosure while ensuring that legitimate investigations are not delayed.
Limits on the Use of Customer Information
AFASA does not eliminate privacy and confidentiality obligations in every circumstance. Information should be collected, used, retained, and disclosed only for a lawful and legitimate purpose, with appropriate safeguards and proportionality.
The Supreme Court has emphasized that the disclosure recognized in cybercrime investigations is limited and must comply with the safeguards established by law. Financial institutions should therefore distinguish between information necessary to identify an account or trace a transaction and information that requires a more specific legal authorization.
Conclusion
AFASA strengthens the Philippine response to phishing and financial-account fraud by combining criminal penalties, institutional safeguards, investigative authority, and temporary measures for protecting disputed funds. It enables the BSP and law-enforcement authorities to trace fraudulent payment flows and obtain relevant information under lawful procedures.
Nevertheless, AFASA does not create a general rule that all social-media platforms must automatically coordinate with fintech companies. Its direct regulatory focus is on financial institutions and payment providers. Effective enforcement will usually require cooperation among financial institutions, the BSP, the NBI, the PNP, and digital platforms through lawful requests, preservation measures, and judicially authorized processes where required.
Consumers should report suspicious transactions immediately, while regulated institutions should maintain real-time fraud controls, preserve evidence, and respond promptly to complaints. The speed and accuracy of the initial report may determine whether the funds can still be held, traced, and recovered.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

