How Can Ransomware Attacks Be Prosecuted in the Philippines?
Introduction
Ransomware attacks can paralyze a company’s operations by encrypting files, disabling systems, and demanding digital payment for restoration. In the Philippines, the responsible individuals may face criminal charges under the Cybercrime Prevention Act, together with liability under other laws depending on the conduct, affected data, and resulting damage.
Successful prosecution requires more than showing that a network became inaccessible. Investigators must establish the unauthorized act, identify the persons responsible, preserve digital evidence, comply with warrant requirements, and prove the required criminal intent. Corporate victims should therefore treat the incident as both a cybersecurity emergency and a potential criminal case.
Primary Law Governing Ransomware Attacks
The principal statute is R.A. No. 10175, or the Cybercrime Prevention Act of 2012. It penalizes offenses committed against or through computer systems, including illegal access, illegal interception, data interference, system interference, misuse of devices, and computer-related fraud or forgery, when the facts satisfy the elements of the particular offense.
Ransomware commonly involves unauthorized access to a computer system, alteration or encryption of computer data, interference with the availability of a system, and demands for payment. The precise charge depends on the evidence gathered and on how the attack was carried out.
Section 6 of R.A. No. 10175 also provides a higher penalty when crimes under the Revised Penal Code or special laws are committed through or with the use of information and communications technology. The prosecution must sufficiently allege and prove the use of ICT in the Information. This rule was recognized in Disini, Jr. v. Secretary of Justice, G.R. No. 203335, February 18, 2014. [Disini, Jr. v. Secretary of Justice (2014)](#J3.15)
Possible Criminal Charges
The following offenses may be considered, subject to the evidence and the specific facts of the incident:
- Illegal access: entering or accessing a computer system without authority.
- Data interference: altering, damaging, deleting, deteriorating, or suppressing computer data without authority.
- System interference: seriously hindering or obstructing the functioning of a computer system by inputting, transmitting, damaging, deleting, deteriorating, altering, or suppressing computer data without authority.
- Computer-related fraud or other offenses: where the attacker obtains property, causes loss, or uses manipulated computer data to induce payment.
- Traditional crimes committed through ICT: such as grave threats, extortion, or other offenses under the Revised Penal Code, when their elements are established and the use of ICT is properly alleged and proved.
Older laws should not be used as substitutes for the Cybercrime Prevention Act when the conduct is specifically covered by the later statute. In Laurel v. Abrogar, G.R. No. 155076, January 13, 2009, the Supreme Court emphasized that intangible services cannot simply be treated as the subject of theft unless the law expressly provides for it. [Laurel v. Abrogar (2009)](#J2.38)
What Must Be Proved in a Ransomware Case?
The prosecution must establish the elements of the particular cybercrime charged beyond reasonable doubt. In general, the evidence should show that:
- the affected device, network, or server constitutes a computer system or ICT system;
- the accused accessed the system, introduced malicious code, encrypted data, deleted or altered files, or obstructed system operations;
- the act was unauthorized or exceeded the authority granted by the system owner;
- the accused acted knowingly and unlawfully when the offense requires such circumstances;
- the accused was the person who committed, directed, aided, or otherwise participated in the attack; and
- the resulting damage, loss, disruption, or demand for payment is supported by admissible evidence.
Attribution is often the most difficult part of prosecution. An IP address alone may not identify the offender. Investigators may need to combine server logs, authentication records, wallet or payment information, malware indicators, email headers, device images, cryptocurrency tracing, communications, account records, and evidence linking the suspect to the infrastructure used in the attack.
Preserving Digital Evidence
Corporate victims should preserve evidence before systems are rebuilt or restored. The incident-response team should isolate compromised devices without unnecessarily destroying volatile evidence, record the time and manner of discovery, preserve logs, and document every person who handled the affected equipment or data.
Forensic copies should be created using reliable procedures. Hash values may be used to confirm that a forensic image has not been altered. The Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, provide specialized procedures for the preservation, disclosure, interception, search, seizure, and examination of computer data. [Rules on Cybercrime Warrants (2018)](#J1.6)
The Rules recognize that computer data can be stored in devices, networks, online accounts, and other locations. They also provide procedures for obtaining data from service providers located outside the Philippines through the Department of Justice–Office of Cybercrime. [Rules on Cybercrime Warrants (2018)](#J1.15)
Obtaining Cybercrime Warrants
Investigators should coordinate with the Philippine National Police Anti-Cybercrime Group, the National Bureau of Investigation Cybercrime Division, or another competent law-enforcement unit. The investigating agency may then apply for the appropriate cybercrime warrant or related order, depending on the evidence sought.
Potential applications include warrants or orders for:
- preservation of computer data;
- disclosure of subscriber or traffic information;
- interception of computer data;
- search, seizure, and examination of computer data; and
- examination of computer data lawfully obtained by investigators.
The application must identify the offense under investigation and establish the factual basis for the requested judicial action. Warrants should not be used as general authority to search unrelated systems or collect data beyond the scope authorized by the court.
For persons or service providers outside the Philippines, service of warrants and other court processes is coursed through the Department of Justice–Office of Cybercrime in accordance with applicable international instruments or agreements. [Rules on Cybercrime Warrants (2018)](#J1.15)
Filing the Criminal Complaint
The corporation should prepare a complaint-affidavit supported by the available technical and documentary evidence. The complaint may be filed with the prosecutor’s office or referred to the appropriate investigative agency for investigation and case build-up.
The complaint should identify, as far as presently known:
- the date and time of the intrusion;
- the affected systems, devices, accounts, and data;
- the suspicious indicators and technical findings;
- the steps taken by the attacker, including encryption or deletion;
- the ransom demand, payment instructions, wallet addresses, or communications;
- the financial and operational losses; and
- the persons, accounts, devices, or infrastructure believed to be connected with the attack.
The complaint should attach forensic reports, incident-response records, screenshots, ransom notes, system logs, access records, email messages, payment records, witness affidavits, and proof of ownership or control of the affected systems. Technical conclusions should be explained by a qualified forensic examiner who can testify about the methods used and the integrity of the evidence.
Venue and Jurisdiction
Under the Rules on Cybercrime Warrants, criminal actions for violations of the Cybercrime Prevention Act may be filed before the designated cybercrime court of the province or city where the offense or any of its elements was committed, where any part of the computer system used is situated, or where damage to a natural or juridical person occurred. The court where the criminal action is first filed acquires jurisdiction to the exclusion of other courts. [Rules on Cybercrime Warrants (2018)](#J1.10)
This rule may permit filing in the place where the company’s affected systems were located or where the financial or operational damage occurred, subject to the facts established in the complaint and the applicable court designation.
Ransom Payments and Related Liability
Payment of ransom does not automatically erase the criminal character of the attack. It may, however, create additional legal and operational concerns, including the possibility that the payment may support a prohibited organization or involve funds connected with unlawful activity.
Before making any payment, the victim should obtain legal advice, preserve the demand and payment instructions, conduct appropriate sanctions and counterparty checks, and coordinate with law-enforcement authorities. Payment also does not guarantee data restoration or deletion of copied information.
Data Privacy Duties After a Ransomware Attack
If personal or sensitive personal information is affected, the incident may also raise obligations under the Data Privacy Act of 2012 and the rules of the National Privacy Commission. Ransomware is not limited to an availability problem. The attacker may retain control over data, and encrypted files may later be disclosed or exfiltrated.
The National Privacy Commission has held that ransomware incidents may require notification even without conclusive proof that data was actually exfiltrated. In In re: TravelPeople Ltd., Inc., NPC BN 20-170, the Commission explained that loss of control over personal data and the possibility of a confidentiality breach may require notification to the Commission and affected data subjects. [In re: TravelPeople Ltd., Inc. (2020)](#I1.7)
The same approach was applied in In re: TravelServices, Inc., NPC BN 20-167, where the Commission considered the possibility that ransomware-affected information could be used for identity fraud, identity theft, phishing, harassment, discrimination, or other risks of real and serious harm. [In re: TravelServices, Inc. (2023)](#I4.8)
Similarly, In re: University of Perpetual Help Dalta Medical Center, Inc., NPC BN 22-208, rejected an attempt to limit notification to only some affected data subjects or to issue notifications in batches. The decision emphasized the need to notify all affected individuals without delay when the applicable conditions are present. [In re: University of Perpetual Help Dalta Medical Center, Inc. (2024)](#I7.7)
Unauthorized Access Under the Data Privacy Act
Where the attacker breaks into a system containing personal or sensitive personal information, Section 29 of the Data Privacy Act may also be considered. The National Privacy Commission has identified three elements: the system stores personal or sensitive personal information; the accused breaks into the system; and the accused knowingly and unlawfully breaks into it in a manner that violates data confidentiality and security.
These elements were stated in ACN v. DT, NPC 18-109, and reiterated in subsequent Commission decisions. [ACN v. DT (2021)](#I5.11) The charge should be evaluated separately from offenses under R.A. No. 10175 because the statutory elements and evidentiary requirements may differ.
Why Attribution and Evidence Matter
Ransomware groups commonly use compromised credentials, anonymization services, rented servers, cryptocurrency wallets, and intermediaries. The person whose account appears in a log may be a victim, an unwitting participant, or an operator using stolen credentials.
Investigators should therefore avoid relying on a single indicator. A stronger case results when independent evidence connects the suspect to the attack, such as exclusive control of an account, possession of attack tools, communications with the victim, access to the ransom infrastructure, receipt of payment, or conduct showing knowledge of the intrusion.
Evidence must also be obtained lawfully. The Supreme Court in Disini, Jr. v. Secretary of Justice recognized the State’s authority to address cybercrime but required safeguards against unconstitutional intrusions into privacy, speech, and due process. [Disini, Jr. v. Secretary of Justice (2014)](#J3.15)
Typical Corporate Response
A corporation facing a ransomware attack should take the following steps:
- Contain the incident. Isolate affected devices and accounts while avoiding unnecessary destruction of evidence.
- Preserve evidence. Save logs, ransom notes, email messages, access records, malware samples, and forensic images.
- Engage qualified experts. Obtain a written forensic report describing the methodology, findings, and limitations.
- Notify authorities. Coordinate with the PNP Anti-Cybercrime Group, NBI, or other competent authorities.
- Assess data privacy obligations. Determine whether personal or sensitive personal information was affected and whether notification is required.
- Prepare the complaint. State the facts chronologically and connect each allegation to the available evidence.
- Protect business continuity. Restore from clean backups, reset credentials, remove persistence mechanisms, and preserve a record of remediation.
Important Limits and Common Errors
A victim should not immediately wipe every compromised device, negotiate through unverified channels, or publish unconfirmed accusations against a suspected hacker. Such actions may destroy evidence, expose additional data, or create defamation and privacy concerns.
A complaint should also avoid charging every possible offense without factual support. The better approach is to identify the conduct proved by the evidence and allow investigators and prosecutors to determine the appropriate statutory charges as the investigation develops.
Conclusion
Ransomware attacks may support prosecution under R.A. No. 10175 and, depending on the affected data and conduct, under the Data Privacy Act and other applicable laws. The strongest cases are built through prompt reporting, careful forensic preservation, lawful acquisition of electronic evidence, and proof connecting the accused to the unauthorized access and resulting interference.
Corporate victims should establish an incident-response protocol before an attack occurs, maintain tested backups, preserve access and audit logs, designate responsible personnel, and obtain legal and forensic assistance immediately after discovering the incident. Where personal information is involved, the organization should separately assess its notification and accountability duties before restoring systems or communicating publicly.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

