How Can Companies Prosecute Online Brand Impersonators?
Introduction
Fake corporate websites, social-media pages, and customer-service accounts can cause more than reputational harm. They may be used to obtain names, email addresses, passwords, one-time passwords, payment details, or other identifying information from customers who believe they are dealing with a legitimate company.
In the Philippines, these acts may support criminal charges for computer-related identity theft, computer-related fraud, computer-related forgery, estafa, or other offenses, depending on the evidence and the manner in which the scheme was carried out. This article focuses on prosecuting syndicates that impersonate corporate brands to deceive customers and acquire or misuse identifying information.
What Is Computer-Related Identity Theft?
Section 4(b)(3) of R.A. No. 10175, or the Cybercrime Prevention Act of 2012, defines computer-related identity theft as the intentional acquisition, use, misuse, transfer, possession, alteration, or deletion of identifying information belonging to another, whether natural or juridical, without right.
The law covers identifying information belonging not only to individuals but also to juridical persons, including corporations. The offense may therefore apply when an offender unlawfully obtains or uses a company’s identifying information, such as its corporate name, brand-related account information, website credentials, or other data used to impersonate the company.
The same provision states that when no damage has yet been caused, the imposable penalty is one degree lower. This means that the absence of completed financial loss does not automatically prevent prosecution; it may affect the applicable penalty.
What Must the Prosecution Establish?
For computer-related identity theft, the prosecution must generally establish the following circumstances:
- The accused intentionally acquired, used, misused, transferred, possessed, altered, or deleted identifying information;
- The identifying information belonged to another natural or juridical person;
- The act was done without right or authority; and
- The conduct was connected with an illegitimate purpose, including the impersonation of a corporate brand to deceive customers.
In Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 11, 2014, the Supreme Court discussed the nature of identity theft under the Cybercrime Prevention Act. The Court recognized that identifying information may be used to perpetrate identity theft and explained that the offense involves the acquisition or use of such information without right, implicitly to cause damage or for an illegitimate purpose.
The usual identifying information regarding a person includes a name, citizenship, residence address, contact number, date and place of birth, spouse’s name, occupation, and similar information. In a corporate-brand impersonation case, the relevant information may include the company’s name, trademarks, official contact details, customer-service identifiers, website appearance, logos, and account credentials, provided the evidence shows that these were used without authority.
How Fake Corporate Pages May Constitute an Offense
A fraudulent page or website does not become criminal merely because it resembles a legitimate business page. The evidence must show unauthorized use and an intent connected with deception, unlawful acquisition of information, or fraud.
Examples that may support a criminal complaint include:
- A fake bank or merchant website asks customers to enter usernames, passwords, or one-time passwords;
- A social-media account uses a company’s name and logo while directing customers to a fraudulent payment account;
- An impostor customer-service representative requests identification documents or account credentials;
- A counterfeit promotion requires customers to provide personal information to claim a supposed reward; or
- A group creates several pages, domains, phone numbers, or payment accounts to impersonate the same company and target its customers.
Names and email addresses may also be significant. In In re: E-Science Corporation, NPC BN 20-124, September 10, 2020, the National Privacy Commission recognized that names and email addresses may be information capable of enabling identity fraud, particularly because email addresses may be used in phishing attacks that lead to identity theft and financial loss.
Computer-Related Fraud and Forgery
The same scheme may support additional charges under R.A. No. 10175. Computer-related fraud covers unauthorized input, alteration, or deletion of computer data or programs, or interference with the functioning of a computer system, when these acts cause damage and are done with fraudulent intent. If no damage has yet been caused, the penalty is one degree lower.
Computer-related forgery covers the unauthorized input, alteration, or deletion of computer data resulting in inauthentic data intended to be treated as authentic for legal purposes. It also covers the knowing use of computer data produced through computer-related forgery to carry out a fraudulent or dishonest design.
Thus, a fake corporate website may present issues under several provisions when the perpetrators alter or generate digital information so that customers will treat it as an official company communication or transaction channel.
When Estafa May Also Apply
Depending on the facts, prosecutors may also consider estafa under Article 315 of the Revised Penal Code. This may be relevant when the offender uses a fictitious name, falsely claims to possess authority or business capacity, or employs another similar deception to induce a customer to part with money or property.
Identity theft and estafa are not automatically interchangeable. Computer-related identity theft focuses on the unauthorized handling of identifying information, while estafa generally requires proof of deceit, reliance, and resulting damage. The evidence must establish each offense independently.
A company should therefore avoid alleging only that a page was “fake.” The complaint should identify the specific false representation, the information acquired or used, the customer’s reliance, the money or property delivered, and the resulting injury, where estafa is being considered.
Possible Cyber-Squatting Issues
Creating a domain name that is identical, similar, or confusingly similar to an existing registered trademark may also raise cyber-squatting issues under R.A. No. 10175. The law covers the acquisition of a domain name in bad faith to profit, mislead, destroy reputation, or deprive another of the right to register it, when the domain name meets the statutory conditions.
The corporation should preserve proof of trademark registration, domain registration details, the date the domain was acquired, website content, payment instructions, and communications showing that the domain was used to mislead customers.
How to Prepare and File the Criminal Complaint
The corporate victim should first identify the persons or entities responsible, if possible, and preserve the digital evidence before requesting its removal. A complaint may be initiated through the appropriate prosecutor’s office, with assistance from the Philippine National Police Anti-Cybercrime Group or the National Bureau of Investigation, depending on the circumstances and investigative coordination required.
The complaint-affidavit should clearly state:
- The company’s legal identity, business operations, registered marks, official websites, and authorized social-media accounts;
- The URLs, usernames, domain names, telephone numbers, email addresses, payment accounts, and other identifiers used by the suspected offenders;
- The specific content that falsely represented the account or website as official;
- The customer complaints, screenshots, transaction records, messages, and other proof of the scheme;
- The identifying information allegedly acquired, used, or misused;
- The acts showing lack of authority and fraudulent or illegitimate purpose; and
- The damage suffered by the company or its customers, including financial loss, unauthorized transactions, account compromise, or reputational injury.
The complainant should attach a certification or affidavit from an authorized corporate officer explaining the company’s official channels and confirming that the accused accounts, websites, messages, or payment instructions were not authorized.
Digital Evidence That Should Be Preserved
Digital evidence is vulnerable to deletion, alteration, or disappearance. The company should preserve the evidence in a manner that allows investigators and prosecutors to establish authenticity and continuity.
| Evidence | Purpose |
|---|---|
| Complete screenshots and screen recordings | Show the appearance, statements, links, and payment instructions of the fake account or website. |
| URLs, domain information, usernames, and account IDs | Identify the digital channels used in the impersonation. |
| Customer messages and complaint records | Show reliance, deception, requests for information, and resulting harm. |
| Bank, e-wallet, or payment records | Trace payments and identify possible beneficiaries or related accounts. |
| Email headers, logs, and technical records | Assist in linking communications and access activity to particular accounts or devices. |
| Corporate registrations and trademark records | Establish ownership of the impersonated company name, mark, or official channel. |
Copies should be accompanied by affidavits explaining who obtained the evidence, when and how it was obtained, and why the records are accurate. The original device, account records, or server logs should be preserved whenever available.
Obtaining Subscriber and Computer Data
Investigators should not rely solely on screenshots. Identifying the operators may require subscriber information, account-registration details, connection records, payment information, stored communications, or computer data held by service providers.
The Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, provide procedures for court-issued warrants suited to cybercrime investigations. Depending on the evidence sought, investigators may seek a warrant to disclose computer data, a warrant to intercept computer data, or a warrant to search, seize, and examine computer data.
A warrant application must be supported by facts establishing the offense and the relevance of the computer data sought. Investigators should identify the accounts, devices, data categories, date ranges, and service providers with sufficient particularity.
In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Supreme Court held that a bank may be treated as a service provider for purposes of disclosing subscriber information when authorized by a court-issued warrant to disclose computer data in a cybercrime investigation. The ruling distinguished basic identifying information from the confidential financial details protected by bank secrecy laws.
Privacy and Data-Breach Considerations
Companies investigating impersonation schemes must also handle customer information lawfully. Internal investigations should limit access to the information necessary for the investigation, document the purpose of processing, and use appropriate security measures.
If customer information was compromised, the company should assess whether mandatory breach notification duties apply. Under the applicable data-privacy rules, notification may be required when the breach involves sensitive personal information or information that may enable identity fraud and creates a real risk of serious harm.
National Privacy Commission decisions have recognized that names and email addresses may, in appropriate circumstances, constitute information that may enable identity fraud. However, not every breach involving an email address automatically requires notification. The surrounding facts, the nature and volume of the information, the likelihood of misuse, and the risk of serious harm must be assessed.
Why a Syndicate Theory Requires Careful Proof
A company may suspect that several accounts are operated by one syndicate, but a criminal charge must be supported by evidence linking the actors. Similar logos or identical scripts may suggest coordination, but investigators should seek additional proof such as shared payment accounts, common device or IP information, repeated contact details, coordinated posting times, common domain-registration information, or communications among the suspects.
The complaint should distinguish between known respondents and unidentified persons. It should avoid naming employees, customers, or unrelated account holders as respondents without evidence tying them to the unlawful acts.
Effect of Section 6 of the Cybercrime Prevention Act
Section 6 of R.A. No. 10175 provides that crimes under the Revised Penal Code and special laws committed through information and communications technologies are covered by the penalty one degree higher, subject to the statute and the applicable jurisprudence.
Accordingly, if the evidence establishes an underlying offense such as estafa or another covered crime and shows that information and communications technology was used in its commission, prosecutors should assess whether Section 6 applies. The charging document should allege the technological means used and the facts supporting the underlying offense.
Common Problems in Corporate Complaints
Complaints often fail or become difficult to prosecute when they merely attach screenshots without proving ownership of the official brand, the lack of authorization, the identity of the customers affected, or the connection between the online account and the suspected operators.
Other recurring problems include:
- Failure to preserve the original digital evidence;
- Failure to obtain sworn statements from affected customers;
- Failure to identify the exact information requested from customers;
- Failure to distinguish attempted fraud from completed financial loss;
- Failure to establish the relationship among multiple accounts or respondents; and
- Failure to seek timely preservation or disclosure of data before it is deleted.
Recommended Corporate Response
Companies should maintain a written incident-response process for brand impersonation and phishing incidents. The process should assign responsibility to legal, information-technology, cybersecurity, compliance, communications, and customer-support personnel.
Upon discovery of a suspected scheme, the company should promptly:
- Capture and preserve the fake pages, websites, messages, payment instructions, and relevant metadata;
- Confirm and document the company’s official websites, accounts, logos, and customer-service channels;
- Obtain affidavits and records from affected customers;
- Coordinate with the PNP Anti-Cybercrime Group or the NBI for investigation and evidence preservation;
- Evaluate possible charges under R.A. No. 10175, the Revised Penal Code, and other applicable laws;
- Assess data-breach notification and data-protection duties; and
- Issue verified public warnings through the company’s legitimate channels without unnecessarily disclosing customer information.
Conclusion
Fake corporate websites and social-media pages may support criminal prosecution when they intentionally use corporate or customer-identifying information without authority to deceive, obtain information, or cause unlawful loss. The strongest complaint connects the digital impersonation to specific acts, affected customers, acquired information, financial or other harm, and evidence identifying the persons behind the scheme.
Companies should act quickly but carefully. They should preserve digital evidence, document the company’s official channels, coordinate with cybercrime investigators, obtain appropriate court warrants when necessary, and assess privacy obligations at the same time. The absence of completed financial loss does not necessarily end the inquiry, but the applicable penalty and additional charges depend on the precise facts proved.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

