How Are Cyber Warrants Used in Corporate Data Theft?
Introduction
Corporate data theft may involve unauthorized access to confidential files, customer information, employee records, financial data, trade secrets, or account credentials stored on computers and remote servers. When law enforcement must obtain and examine this information, the investigation must comply with the Philippine rules governing cybercrime warrants.
A cyber warrant is not a general authority to inspect every device, account, or server connected with a company. The application must identify the offense, the data sought, the relevant computer system, and the factual basis for probable cause. These safeguards are especially important when the data is stored by a cloud provider, internet service provider, data center, or other remote service provider.
Governing Philippine Laws and Rules
The principal statute is the Cybercrime Prevention Act of 2012, R.A. No. 10175. It provides the legal basis for the preservation, disclosure, search, seizure, interception, and examination of computer data in cybercrime investigations.
The procedural requirements are supplied by the Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, July 3, 2018. The Rules were promulgated because cybercrime investigations require procedures suited to electronic evidence, including data held by service providers and data stored outside the immediate physical control of investigators.
For trafficking and online child exploitation investigations, the 2022 Revised Rules and Regulations Implementing R.A. No. 9208, as amended, and the IRR of R.A. No. 11930 contain additional provisions on the preservation, examination, and retention of computer data. These special rules should be considered when the suspected corporate data theft is connected with trafficking, online sexual abuse or exploitation of children, or child sexual abuse and exploitation materials.
What Cyber Warrant Is Appropriate?
The proper warrant depends on the type of evidence sought and the investigative act required.
| Warrant | Primary Use |
|---|---|
| Warrant to Disclose Computer Data | Requires a person or service provider to disclose subscriber information, traffic data, or other relevant computer data in its possession or control. |
| Warrant to Intercept Computer Data | Authorizes the listening to, recording, monitoring, or surveillance of communications while they are occurring, including the acquisition of communication content. |
| Warrant to Search, Seize, and Examine Computer Data | Authorizes the search of a particular place or items, the seizure of computer devices or data, and the forensic examination of the data identified in the warrant. |
| Warrant to Examine Computer Data | Required before searching a computer device or system already lawfully obtained through a warrantless arrest or another lawful method, for the purpose of forensic examination. |
For corporate data stored on a remote server, a Warrant to Disclose Computer Data is ordinarily relevant when the immediate objective is to compel the service provider to produce account, subscriber, traffic, or other identified data. A Warrant to Search, Seize, and Examine Computer Data may be necessary when investigators must search and conduct forensic examination of identified computer data or devices.
A disclosure warrant and a search-and-examination warrant should not be treated as interchangeable. The application should match the warrant to the specific evidence and investigative activity requested.
Where Should the Application Be Filed?
Under the Rules on Cybercrime Warrants, an application concerning violations of the cybercrime offenses and other offenses covered by the Rule may generally be filed before a designated cybercrime court in the province or city where the offense or any of its elements was committed, is being committed, or is about to be committed.
The application may also be filed where any part of the computer system used is situated or where any part of the damage caused to a natural or juridical person occurred. This is significant in corporate data theft cases because the company’s office, affected computer system, server, or location of resulting damage may be in different places.
Designated cybercrime courts in Quezon City, Manila, Makati, Pasig, Cebu, Iloilo, Davao, and Cagayan de Oro have special authority to act on certain cybercrime warrant applications and issue warrants enforceable nationwide and outside the Philippines, subject to the limits of Philippine law and applicable cooperation arrangements.
Where the offense is a violation of another crime committed through information and communications technology under Section 6 of R.A. No. 10175, the application is filed with the regular or other specialized regional trial court having territorial jurisdiction, as applicable.
What Must the Application Establish?
The applicant must present facts showing probable cause that a cybercrime or another offense covered by the Rules has been committed, is being committed, or is about to be committed. The application must be supported by the applicant’s examination under oath and the testimony of witnesses who can establish the relevant facts.
The application should explain why the requested computer data is connected to the suspected offense and why the requested disclosure, search, seizure, interception, or examination is necessary. General allegations that a company suffered a breach are insufficient without facts linking the suspected conduct to particular accounts, devices, communications, files, or server locations.
For corporate data theft, the application should ordinarily identify, as specifically as the facts permit:
- the corporate victim and the affected systems;
- the suspected offense and its statutory basis;
- the relevant account, user, device, domain, server, or service provider;
- the categories of computer data sought;
- the date range covered by the request;
- the connection between the data and the suspected offense; and
- the reason other means of obtaining the evidence are unavailable or inadequate.
The request should be limited to data reasonably related to the offense. Overbroad language may raise constitutional and procedural concerns and may make the warrant vulnerable to challenge.
Remote Corporate Servers and Cloud-Based Data
Data stored on a remote corporate server may be physically located in a data center, cloud environment, or system operated by a third-party provider. Physical distance does not eliminate the need for a valid Philippine court process when Philippine law enforcement seeks to compel disclosure or conduct an investigative act covered by the Rules.
The application should identify the service provider or custodian that has possession or control of the data. It should also distinguish between subscriber information, traffic data, and content data because the categories may involve different privacy and evidentiary concerns.
A request should not simply state that all information connected with a company’s account must be produced. It should describe the relevant corporate account, user identifiers, server instance, cloud storage location, communications, files, logs, or transaction records with sufficient particularity.
If the provider or server is located abroad, the enforcing authorities must consider the limits of territorial jurisdiction and the need for appropriate international cooperation. A Philippine warrant may authorize acts within the authority recognized by Philippine law, but it does not automatically confer unrestricted power to enter or search a foreign facility.
Preserving Data Before Applying for Disclosure
Preservation is distinct from disclosure. A law enforcement officer may request an internet service provider to keep, preserve, and maintain the integrity of computer data subject of an investigation.
Under the 2022 Revised Rules and Regulations Implementing R.A. No. 9208, as amended, subscriber information and traffic data must be preserved by the internet service provider for at least six months from the date of the transaction. Content data must be preserved for six months from the provider’s receipt of the preservation order.
A one-time extension of another six months may be ordered. If the preserved data is used as evidence, receipt by the provider of the transmittal document to the prosecutor is treated as notice to preserve the data until final termination of the case or until further order of the court.
Preservation does not by itself authorize investigators to examine or use the contents of the data. The appropriate disclosure, search, seizure, interception, or examination warrant must still be obtained when required.
Disclosure of Corporate Subscriber and Account Information
Section 14 of R.A. No. 10175 allows law enforcement authorities, after securing a court warrant, to issue an order requiring a person or service provider to disclose or submit subscriber information, traffic data, or relevant data in its possession or control within seventy-two hours from receipt of the order.
The disclosure must relate to a valid complaint officially docketed and assigned for investigation. It must also be necessary and relevant to the investigation.
In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Supreme Court held that R.A. No. 10175 did not expressly or impliedly repeal the Bank Secrecy Law. The Court nevertheless recognized that a bank acting as a service provider may disclose basic subscriber information, including the identity and contact details of an account holder, when authorized by a valid Warrant to Disclose Computer Data.
The decision distinguishes identifying information from the financial details of bank deposits. A disclosure order does not provide a general license to obtain confidential deposit information. The statutory and constitutional safeguards must still be observed.
Searching, Seizing, and Examining Computer Data
Section 15 of R.A. No. 10175 authorizes law enforcement authorities, when a search and seizure warrant has been properly issued, to secure a computer system or storage medium, make and retain a copy of computer data, maintain the integrity of the data, conduct forensic analysis, and render data inaccessible or remove it when authorized by law and the warrant.
Investigators may also require a person who has knowledge of the functioning of the computer system or the measures used to protect the data to provide reasonable information necessary to conduct the search, seizure, and examination.
The warrant should specify the data, device, account, or system to be searched and examined. The form for a Warrant to Search, Seize, and Examine Computer Data contemplates a particular description of the computer data and related items, including the persons or entities whose data are sought and those who have control, possession, or access to them when known.
The warrant may also state the place of enforcement, the search strategy, and whether the search will be conducted on-site or off-site. These details are particularly important where the evidence is stored on a corporate network or remote server and investigators must avoid collecting unrelated business information.
Handling Data Obtained Through a Cyber Warrant
Investigators should preserve the integrity and authenticity of the acquired data. The forensic process should document who acquired the data, when and how it was acquired, what tools were used, how copies were created, and where the evidence was stored.
Under Section 15 of R.A. No. 10175, law enforcement authorities may request additional time to complete the examination and make a return, but the extension may not exceed thirty days from court approval.
The original or required evidentiary copy should be deposited with the court in accordance with the applicable rules. Separate working copies may be used for forensic analysis if properly documented and protected from alteration.
In OSAEC and CSAEM cases, the IRR of R.A. No. 11930 authorizes law enforcement agencies, when a cybercrime warrant has been issued, to retain a copy of the result of digital forensic examinations without further court intervention. The retained data may include content and traffic data for identifying additional child victim-survivors and suspects, conducting further investigation, or case build-up, subject to the requirements of the law.
Common Problems in Corporate Data Theft Investigations
Overbroad requests. A demand for an entire company database, all employee accounts, or all communications over an indefinite period may exceed what is reasonably connected to the suspected offense.
Using the wrong warrant. A request for subscriber information should not be presented as though it were authority to intercept live communications. Likewise, lawful possession of a device does not automatically authorize a search of all data stored in it.
Failure to preserve metadata. Investigators should preserve relevant logs, timestamps, access records, hash values, and system information. A copied document without reliable context may be difficult to authenticate or interpret.
Ignoring third-party custody. If the data is held by a cloud provider or service provider, the application should identify the custodian and explain the provider’s control over the requested data.
Confusing investigation with admissibility. Obtaining data through a warrant does not end the inquiry. The prosecution must still establish authenticity, relevance, integrity, and compliance with the Rules on Electronic Evidence and other applicable evidentiary requirements.
Recommended Steps for Corporate Victims
- Secure the affected systems. Isolate compromised accounts and devices without destroying logs or other evidence.
- Record the incident. Prepare a chronology identifying unusual access, suspected downloads, affected accounts, and possible offenders.
- Notify the appropriate authorities. Coordinate with law enforcement and provide technical information that can support a warrant application.
- Request preservation promptly. Identify the providers holding relevant logs, account data, traffic data, or content.
- Define the requested evidence. Specify the accounts, dates, systems, files, and data categories connected with the suspected theft.
- Maintain chain-of-custody records. Keep acquisition notes, forensic images, hash values, access logs, and documentation of every transfer or examination.
Conclusion
Applying for a cyber warrant to prosecute corporate data theft requires more than showing that a company experienced unauthorized access. The applicant must establish probable cause, identify the offense and data sought, select the correct warrant, and comply with the safeguards governing disclosure, interception, search, seizure, and forensic examination.
For data stored on remote corporate servers, the application should clearly identify the service provider, the affected account or system, the categories of data requested, and the territorial and technical circumstances surrounding the evidence. Prompt preservation, narrowly drawn requests, and reliable forensic handling can substantially improve the prospects of a lawful and admissible investigation.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

