How Can Victims Prosecute Messenger Account Scammers?
Introduction
Scammers who take control of a person’s Messenger account may impersonate the account owner, contact friends or relatives, and solicit money through false emergencies, investment offers, or other deceptive stories. These incidents may give rise to separate or combined criminal charges, particularly computer-related identity theft under the Cybercrime Prevention Act and estafa under the Revised Penal Code.
The proper charge depends on the evidence: how the account was accessed, whether identifying information was used without authority, whether victims were deceived into giving money, the role of each participant, and whether the acts were committed through a coordinated group or syndicate.
What Crimes May Apply?
Computer-Related Identity Theft
Section 4(b)(3) of the [Cybercrime Prevention Act of 2012](#L1.7) covers the intentional acquisition, use, misuse, transfer, possession, alteration, or deletion of identifying information belonging to another person or juridical entity, without right. If no damage has yet been caused, the imposable penalty is one degree lower.
A hacked Messenger account may involve identity theft when the offender uses the victim’s name, profile, photographs, account credentials, contact information, or other identifying details to impersonate the victim and communicate with other persons. The prosecution must still establish intentional and unauthorized conduct; the mere existence of a suspicious or fake account is not automatically sufficient.
The Supreme Court recognized that identifying information may include a person’s name, residence, contact number, date and place of birth, occupation, and similar data. It also explained that identity theft requires the acquisition or use of identity information for an illegitimate purpose. (Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 11, 2014.)
Names and e-mail addresses may also be relevant identifying information where, in the circumstances, they can be used to enable phishing, identity fraud, or unauthorized access to important accounts. (NPC BN 20-124, In re: E-Science Corporation, September 10, 2020.)
Estafa Through Deceit
Estafa may arise when the offender uses a hacked account to make a false representation, induces another person to part with money or property, and causes damage as a result. The prosecution generally needs evidence of the deceptive representation, the victim’s reliance, the transfer or delivery of money, and the resulting prejudice.
For example, a message stating that the account owner urgently needs money for medical treatment may constitute deceit if it is false and is used to induce a transfer. The use of Messenger does not by itself establish estafa; the prosecution must connect the false representation to the victim’s decision to surrender money.
Where the deception is committed through information and communications technology, Section 6 of the [Cybercrime Prevention Act of 2012](#L1.10) provides that crimes under the Revised Penal Code and special laws committed through ICT are covered by the law, with the penalty imposed one degree higher than that provided by the Revised Penal Code or special law.
The Supreme Court has explained that Section 6 treats the use of ICT as a circumstance warranting a higher penalty because digital means may make the offender more difficult to identify and may allow the offender to reach more victims or cause greater harm. (Disini, Jr., et al. v. The Secretary of Justice, et al., G.R. No. 203335, February 11, 2014.)
Can Both Charges Be Filed?
Potentially, yes. Computer-related identity theft focuses on the unauthorized use of another person’s identifying information. Estafa focuses on the fraudulent inducement that caused a victim to part with money or property.
The same incident may therefore contain different criminal acts: first, the unauthorized use of the victim’s account and identity; and second, the deception of a separate victim who transferred money because of the false message. Whether both charges will prosper depends on the allegations, evidence, and applicable rules against double jeopardy or duplicity of offenses.
Prosecutors should identify the separate acts and avoid treating every digital communication as a separate offense without factual support. The complaint should specify the account used, the identifying information misused, the false representation made, the amount obtained, and the participation of each accused.
When Does Conspiracy or Syndicate Liability Arise?
A syndicate theory requires evidence that two or more persons acted together pursuant to a common plan. Relevant proof may include coordinated use of several accounts, common recipient accounts, repeated messages using the same script, divided roles, shared devices or IP addresses, and transfers of proceeds among participants.
Evidence that one person hacked an account does not automatically prove that every person who received or transferred money was part of the conspiracy. Each accused must be linked to the common design through competent evidence.
Investigators should distinguish among the possible roles of the participants, such as the person who obtained access to the account, the person who impersonated the victim, the person who recruited money mules, and the person who withdrew or transferred the proceeds.
What Evidence Should the Victim Preserve?
The victim should preserve the original digital evidence before deleting messages or resetting the account. Screenshots are useful but should be supported, when possible, by account records, device information, platform responses, bank documents, and testimony explaining how the messages were received and why they appeared to come from the victim.
Important evidence may include:
- screenshots and screen recordings of the Messenger conversations;
- the account URL, profile name, username, telephone number, and e-mail address;
- dates, times, and complete message threads;
- bank, e-wallet, remittance, or payment records;
- recipient account numbers, names, and transaction references;
- login alerts, password-reset notices, and security notifications;
- device logs, e-mail headers, IP information, and platform correspondence; and
- statements from every person who received the solicitation or transferred money.
The victim should avoid editing screenshots or forwarding messages in a manner that removes relevant portions of the conversation. The original device should be preserved because investigators may need to verify metadata or authenticate the communications.
Where Should the Complaint Be Filed?
The victim may report the incident to the Philippine National Police Anti-Cybercrime Group, the National Bureau of Investigation Cybercrime Division, or the appropriate prosecutor’s office. A complaint-affidavit should be supported by documentary evidence and sworn statements from the victim and other witnesses.
The complaint should identify the place where the victim received the messages, where the money was delivered or transferred, where the accused is believed to be located, and the location of relevant bank, e-wallet, telecommunications, or platform records. Jurisdictional issues may arise in online offenses because the acts and consequences can occur in different places.
In appropriate cases, investigators may seek judicially authorized orders under the [Cybercrime Prevention Act of 2012](#L1.10) to preserve or obtain computer data. A bank may be treated as a service provider for purposes of disclosing subscriber information when authorized by a court-issued warrant for disclosure of computer data, subject to statutory safeguards. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025.)
What Must Be Proved Against the Accused?
For computer-related identity theft, the evidence should establish that the accused intentionally acquired, used, misused, transferred, possessed, altered, or deleted identifying information belonging to another, without right. The prosecution should also establish the accused’s identity and connect the accused to the relevant account, device, communication, or transaction.
For estafa, the evidence should establish the false representation or fraudulent act, the victim’s reliance, the delivery of money or property, and the resulting damage. A mere failure to return money is not always sufficient to prove estafa if the original transaction was not induced by deceit.
For conspiracy, the evidence must show a common criminal purpose and intentional cooperation. Mere acquaintance, receipt of money, or ownership of a bank account may be relevant but is not necessarily conclusive proof of participation in the entire scheme.
What If the Scammer Used Phishing or Vishing?
Account takeovers commonly begin with phishing, malicious links, deceptive login pages, or telephone-based social engineering. In a vishing scheme, the offender may impersonate a bank employee or another trusted person to obtain an OTP, password, or other access information.
The use of identifying information in a phishing scheme may support a computer-related identity theft theory when the statutory elements are present. It may also support other offenses depending on the method used, the type of account accessed, and the property obtained.
In a banking fraud investigation, investigators should preserve the call records, sender numbers, URLs, OTP messages, device alerts, bank notifications, and transaction records. The victim should immediately contact the bank or payment service provider and request account restriction, transaction review, and preservation of relevant records.
How Does Data Privacy Affect the Investigation?
Personal information may be collected and disclosed for lawful investigation and prosecution, but investigators and private complainants should limit disclosure to what is relevant and necessary. Unrestricted publication of account credentials, identification documents, contact information, or private conversations may expose the victim to further harm.
The National Privacy Commission has emphasized that liability for an unauthorized disclosure or breach requires substantial evidence directly linking the respondent to the unauthorized access or disclosure. Mere suspicion or the occurrence of fraud does not, by itself, establish liability under the Data Privacy Act. (NPC 20-283, MAG v. Bank of the Philippine Islands, 2021; NPC 23-166, 2024.)
This principle is important because a victim may be defrauded through a hacked account without the bank, platform, or other service provider necessarily being legally responsible for the criminal act. The evidence must show the particular act or omission attributable to the proposed respondent.
Can Victims Recover Their Money?
Criminal proceedings may include civil liability arising from the offense, but recovery is not automatic. The victim should identify the exact amount lost, the date and method of payment, the recipient account, and any amount already recovered.
Prompt reporting is important because banks, e-wallet operators, remittance companies, and other payment providers may have internal procedures for freezing or reviewing disputed transactions. Recovery may become more difficult after funds are withdrawn, transferred through multiple accounts, converted into cash, or sent to another jurisdiction.
Common Problems in Prosecution
Cases involving hacked Messenger accounts often encounter difficulties in proving the identity of the person behind the account. Usernames and profile photographs are easily changed, and an account may be operated from a device or connection registered to another person.
Another difficulty is preserving the chain of custody and authenticity of electronic evidence. The complainant should keep the original device and provide investigators with complete, unaltered records rather than isolated screenshots.
Finally, the victim must distinguish between the amount actually transferred and amounts merely requested. A solicitation without payment may support an attempted or other cybercrime theory only when the statutory requirements are met; it does not automatically establish completed estafa.
Recommended Steps for Victims
- Secure the hacked account by changing the password, terminating unknown sessions, enabling multi-factor authentication, and reporting the compromise to the platform.
- Notify friends, relatives, customers, and other contacts that the account was compromised and that payment requests should not be honored.
- Report unauthorized transfers immediately to the bank, e-wallet provider, remittance company, or payment intermediary.
- Preserve complete digital evidence, including original conversations, account notices, URLs, transaction records, and device information.
- Execute a detailed complaint-affidavit identifying the account, the impersonation, the false representations, the money transfers, and the persons believed to be involved.
- Coordinate with the PNP Anti-Cybercrime Group, NBI Cybercrime Division, or the prosecutor’s office for investigation and filing.
Conclusion
Scammers using hacked Messenger accounts may face computer-related identity theft charges when they intentionally use another person’s identifying information without authority. They may also face estafa charges when their false messages induce victims to transfer money and cause financial damage.
The strongest cases are supported by complete digital records, verifiable payment trails, prompt reports to financial institutions, and evidence connecting each accused to the account takeover, impersonation, deception, or receipt of proceeds. Victims should act quickly, preserve evidence, and obtain legal assistance before filing a complaint.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

