How Can Companies Prosecute Smishing Syndicates?
Introduction
Smishing—fraud committed through deceptive text messages—can expose a company’s customers to account takeovers, unauthorized transfers, identity theft, and reputational harm. When the messages impersonate a bank, e-commerce platform, telecommunications provider, or other corporate client, the response requires coordinated action by the affected company, telecommunications entities, financial institutions, and law-enforcement agencies.
Philippine law provides several possible legal bases, including the Subscriber Identity Module Registration Act, the Cybercrime Prevention Act, the Access Devices Regulation Act, and the Anti-Financial Account Scamming Act. The most effective response combines immediate preservation of evidence, prompt reporting to telecommunications providers, and a properly supported request for investigative or judicial process.
What Is Smishing?
Smishing is a form of social engineering carried out through fraudulent text messages. The sender commonly impersonates a legitimate company and induces the recipient to disclose an account password, one-time password, payment information, personal data, or an access link.
Depending on the facts, the conduct may involve identity fraud, unauthorized access, computer-related fraud, violation of the Access Devices Regulation Act, social engineering under the Anti-Financial Account Scamming Act, or spoofing under the Subscriber Identity Module Registration Act.
A message that merely advertises a product is not automatically smishing. The stronger indicators are deception, impersonation, an intent to obtain money or sensitive information, and the use of electronic communications to cause unauthorized access or financial loss.
What Laws May Apply?
Subscriber Identity Module Registration Act
The Subscriber Identity Module Registration Act requires the registration of SIM cards, including eSIMs and other covered variations, and links a SIM to verified subscriber information. The Act defines spoofing as transmitting misleading or inaccurate information about the source of a call or text message with intent to defraud, cause harm, or wrongfully obtain anything of value. This definition is directly relevant when a smishing campaign disguises the source of its messages.
Spoofing a registered SIM is punishable by imprisonment of not less than six years, or a fine of P200,000, or both, unless the transmission is connected with authorized law-enforcement activity or a court order specifically authorizing caller-ID manipulation. These statutory exceptions should be considered when investigators examine message-routing or caller-identification methods. (R.A. No. 11934, Section 3 and Section 11(e); IRR of R.A. No. 11934, Rule VI, Section 15.)
Telecommunications entities must provide user-friendly mechanisms for reporting potentially fraudulent texts or calls. After investigation, the provider may temporarily or permanently deactivate the SIM used for the fraudulent communication. Registration data and related information must be retained for ten years, even after deactivation. (R.A. No. 11934, Section 6.)
The Act also penalizes the use of false or fictitious information or fraudulent identification documents to register a SIM. The penalty is imprisonment from six months to two years, or a fine from P100,000 to P300,000, or both. (R.A. No. 11934, Section 11(d).)
Cybercrime Prevention Act
The Cybercrime Prevention Act may apply when the smishing operation uses computer systems or electronic communications to commit computer-related fraud, identity-related offenses, or illegal access. Its application depends on the specific acts proved, the systems involved, and the relationship between the fraudulent message and the resulting unauthorized access or loss.
The Supreme Court has emphasized that cybercrime regulation must operate within constitutional safeguards, particularly privacy, freedom of expression, due process, and judicial oversight. In Disini, Jr. v. Secretary of Justice, G.R. No. 203335, 11 February 2014, the Court upheld provisions directed at specific cybercrimes while invalidating provisions that were vague, overbroad, or insufficiently protected constitutional rights.
Access Devices Regulation Act
Smishing may also fall under the Access Devices Regulation Act when the scheme is designed to obtain, use, or exploit an access device or access-device information. This may include payment-card data, account credentials, authentication information, or other means of accessing a financial account, depending on the evidence.
Financial institutions and other covered access-device issuers must conduct an initial investigation of reported access-device fraud and furnish real-time reports to the National Bureau of Investigation and the Philippine National Police Anti-Cybercrime Group. The report should narrate the fraud and identify the perpetrator if feasible. (R.A. No. 11449, Section 6.)
Anti-Financial Account Scamming Act
Where a smishing campaign seeks to obtain banking credentials, one-time passwords, or other sensitive information to access a financial account, the Anti-Financial Account Scamming Act may apply. The law specifically recognizes social-engineering schemes, including obtaining sensitive identifying information through deception or fraud and misrepresenting oneself as an institution through electronic communication.
The Act also gives the Bangko Sentral ng Pilipinas authority to investigate financial accounts and share relevant information with law-enforcement and other competent authorities, subject to statutory limitations. It authorizes the BSP or its officers to apply for cybercrime warrants and related orders under the Cybercrime Prevention Act. Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, recognized that the applicable laws permit the disclosure of relevant financial-account information in cybercrime investigations when the required legal safeguards are observed.
How Can a Company Work With Telecommunications Providers?
A corporate victim should establish a documented reporting channel with the relevant telecommunications providers. The report should identify the company being impersonated, the message content, the sending numbers, message dates and times, shortened links, originating links, customer complaints, and any known financial or account losses.
The company should request preservation of relevant records and ask the provider to investigate and deactivate numbers used for fraudulent messages, subject to the provider’s procedures and applicable law. Deactivation alone does not identify the perpetrator, but it may limit continuing harm and preserve information for law-enforcement use.
Because the SIM Registration Act requires retention of registration information for ten years, investigators may be able to seek subscriber-related information through the appropriate legal process. A company should not assume, however, that it may directly obtain confidential registration records merely by sending a demand letter or incident report.
What Information Should Be Preserved?
Evidence should be collected before messages, websites, accounts, or devices are altered or deleted. The company should preserve:
- Original text messages, including complete sender information and timestamps;
- Screenshots together with the original device, message thread, and metadata where available;
- URLs, domains, QR codes, landing pages, email addresses, and telephone numbers used by the perpetrators;
- Customer complaints, sworn statements, transaction records, and records of attempted or completed fraud; and
- Internal incident reports, security logs, takedown requests, provider correspondence, and law-enforcement endorsements.
Electronic evidence should be collected in a manner that allows the company to explain who obtained it, when and how it was obtained, where it was stored, and whether it was altered. A chain-of-custody record is particularly important when the company expects the material to be used in a criminal complaint or application for a cybercrime warrant.
How Should the Company Report the Incident?
The company should report the incident promptly to its telecommunications provider and the appropriate law-enforcement agency. Depending on the conduct and losses involved, reports may be made to the Philippine National Police Anti-Cybercrime Group, the National Bureau of Investigation Cybercrime Division, the Bangko Sentral ng Pilipinas, or other regulators with jurisdiction over the affected institution.
The National Bureau of Investigation has jurisdiction over commercial, economic, financial, and similar white-collar crimes, including offenses under the Access Devices Regulation Act. Once the NBI takes cognizance of a covered case, other law-enforcement agencies are required to collaborate and render assistance, subject to the statutory allocation of primary or exclusive jurisdiction. (R.A. No. 10867, Section 5(j).)
The report should distinguish between confirmed facts and preliminary indicators. For example, the company may state that a message impersonated its brand, while separately identifying whether any customer actually disclosed an OTP, clicked a link, or suffered a financial loss.
When May Subscriber Information Be Obtained?
Subscriber information is not ordinarily obtained through informal corporate requests. Investigators may need to secure the appropriate warrant, subpoena, or court-issued order, depending on the information sought and the governing procedure.
Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, explains that a bank may be treated as a service provider for purposes of a warrant to disclose computer data in an appropriate cybercrime investigation. The decision distinguishes basic identifying information from the confidential financial details of deposits and emphasizes that disclosure must comply with statutory safeguards.
Accordingly, a company seeking to identify a smishing operator should provide investigators with sufficient factual material to establish probable cause or another applicable legal basis. The request should specify the telephone numbers, relevant dates and times, suspected accounts or links, and the connection between the messages and the suspected offense.
What Are the Privacy Limits?
Companies must avoid excessive disclosure of customer information while investigating the campaign. Customer data should be shared only with authorized personnel, telecommunications providers, regulators, and law-enforcement agencies that have a lawful purpose and appropriate safeguards.
The existence of fraud does not, by itself, establish that a company or financial institution violated the Data Privacy Act. The National Privacy Commission has repeatedly required substantial evidence linking the alleged unauthorized disclosure or negligent security measure to the acts or omissions of the personal information controller.
In MTS v. Bank of the Philippine Islands, NPC 22-237, 2023, the Commission found that allegations and the occurrence of a vishing incident were insufficient to establish that the bank’s negligence caused the unauthorized access. Similarly, MAG v. Bank of the Philippine Islands, NPC 20-283, 2023, emphasized that personal-information security is a shared responsibility and that contributory negligence may affect liability.
These rulings do not excuse inadequate security. They mean that liability must be supported by evidence connecting the breach or unauthorized processing to the controller’s conduct, negligence, or failure to comply with applicable obligations.
What Should a Corporate Incident Plan Include?
A company responding to smishing should adopt a written incident plan covering the following actions:
- Containment: Warn customers through verified channels, disable malicious links where possible, and coordinate with hosting, messaging, and telecommunications providers.
- Evidence preservation: Secure original messages, technical logs, customer reports, transaction records, and device information.
- Regulatory and law-enforcement reporting: Submit a factual incident report to the appropriate agencies and identify the relief or investigative action requested.
- Customer protection: Advise affected customers not to disclose OTPs or credentials, to change compromised passwords, and to contact their financial institution immediately.
- Legal assessment: Determine whether the evidence supports complaints for spoofing, computer-related fraud, identity-related offenses, access-device violations, social engineering, or other applicable crimes.
Typical Example
Suppose a fraud group sends messages stating that a bank customer’s account will be suspended unless the customer clicks a link and submits an OTP. The link leads to a false banking website, and several customers later report unauthorized transfers.
The bank should preserve the messages and fraudulent website, identify all reported numbers and links, notify the telecommunications provider, request investigation and deactivation of the involved SIMs, and report the incident to the PNP Anti-Cybercrime Group or NBI. If financial accounts were accessed, the bank should also coordinate with the BSP and pursue the appropriate cybercrime process for obtaining subscriber, device, and transaction information.
If the messages used misleading information about their source with intent to defraud, the facts may support a spoofing investigation under the SIM Registration Act. If the scheme obtained OTPs or account credentials through deception, the facts may also support charges under the Anti-Financial Account Scamming Act or the Access Devices Regulation Act, subject to proof of the statutory elements.
Final Recommendations
Companies should maintain a single incident-response team with representatives from legal, information security, fraud prevention, customer service, and communications. The team should preserve evidence immediately, coordinate with telecommunications providers through established reporting channels, and make prompt, accurate referrals to law enforcement.
Corporate victims should also avoid publicly accusing a particular subscriber or customer before the investigation establishes the relevant facts. The proper objective is to preserve the evidence, stop continuing harm, identify the responsible persons through lawful process, and support prosecution with admissible and properly authenticated records.
Smishing cases are strongest when the company can connect the deceptive message to the resulting unauthorized access, financial loss, fraudulent SIM or account, and identifiable investigative leads. Cooperation among the company, telecommunications providers, financial institutions, regulators, and law enforcement is therefore essential to both customer protection and criminal accountability.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

