How Does AFASA Punish Corporate Phishing Schemes?
Introduction
Corporate phishing attacks often begin with a deceptive email, text message, or telephone call that appears to come from a bank, payment service provider, company officer, or other trusted institution. The objective is to obtain passwords, one-time passwords, account numbers, credit card details, or other credentials that can be used to access and control a financial account.
Under the Anti-Financial Account Scamming Act (AFASA), these acts may constitute social engineering schemes. The law also addresses the persons and organizations that receive, transfer, withdraw, or otherwise handle proceeds obtained through such schemes. Corporate victims, employees, financial institutions, and suspected money mules may therefore face different legal consequences depending on their participation and degree of knowledge.
What Is a Social Engineering Scheme Under AFASA?
Section 4(b) of Republic Act No. 12010, or the Anti-Financial Account Scamming Act, defines a social engineering scheme as obtaining another person’s sensitive identifying information through deception or fraud, resulting in unauthorized access to or control over that person’s financial account.
The statute identifies two principal methods:
- Misrepresenting oneself as acting on behalf of a financial institution, or making false representations to solicit sensitive identifying information; and
- Using electronic communications to obtain another person’s sensitive identifying information.
“Sensitive identifying information” includes usernames, passwords, bank account details, credit card information, e-wallet information, and other electronic credentials or confidential personal information that may be used to access a financial account.
The statutory definition is broad enough to cover corporate phishing emails, fraudulent text messages, telephone-based “vishing,” fake bank websites, and messages impersonating an employer, bank, payment service provider, or company executive. The conduct must nevertheless be connected to the unauthorized access to or control of a financial account.
When Does Corporate Phishing Become a Criminal Offense?
A prosecution under AFASA generally requires proof of the following circumstances:
- The accused obtained, or attempted to obtain, sensitive identifying information;
- The information was obtained through deception, fraud, misrepresentation, or electronic communications;
- The accused’s conduct resulted in, or was intended to result in, unauthorized access to or control over a financial account; and
- The prosecution establishes the accused’s participation and criminal intent beyond reasonable doubt.
A phishing email alone does not automatically establish every element of the offense. Investigators must connect the communication to the acquisition or attempted acquisition of account credentials and, where applicable, to the unauthorized access, transfer, withdrawal, or receipt of funds.
For example, an email falsely claiming to be from a bank and requesting an employee’s password and one-time password may support an AFASA prosecution if the evidence shows that the sender intended to gain unauthorized access to a corporate or personal financial account.
Who May Be Criminally Liable?
AFASA may apply to several participants in a phishing operation, depending on the facts and the evidence.
Phishing Operators
The person who sends the deceptive email, text, or call may be liable for a social engineering scheme if the statutory elements are established. Liability may also extend to persons who create fake websites, prepare fraudulent scripts, harvest credentials, or control the infrastructure used to obtain account information.
Recruiters, Organizers, and Coordinators
A person who recruits, hires, induces, or otherwise causes another individual to carry out prohibited money-muling activities may be separately liable under AFASA. The prosecution should establish the person’s participation, knowledge, and connection to the financial proceeds or the unlawful scheme.
Money Mules and Account Holders
Section 4(a) of AFASA covers money-muling activities. A person may be treated as a money mule when, for the purpose of obtaining, receiving, depositing, transferring, or withdrawing proceeds known to be derived from crimes or social engineering schemes, that person:
- Uses, borrows, or allows the use of a financial account;
- Opens an account under a fictitious name or by using another person’s identity documents;
- Buys or rents a financial account;
- Sells or lends a financial account; or
- Recruits, enlists, contracts, hires, utilizes, or induces another person to perform those acts.
Not every account holder whose account receives suspicious funds is automatically guilty. The prosecution must still prove the required knowledge, purpose, participation, and other statutory elements. A person who knowingly lends an account to receive and transfer phishing proceeds presents a materially different case from an innocent account holder whose account was compromised without consent.
When Is the Offense Economic Sabotage?
AFASA treats the prohibited acts under the money-muling and social-engineering provisions as economic sabotage when specified aggravating circumstances are present. These include commission:
- By a group of three or more persons conspiring or confederating with one another;
- Against three or more persons, individually or as a group; or
- Through the use of a mass mailer.
AFASA defines a mass mailer as a service or software used to send electronic communications to an aggregate of at least 50 recipients. Thus, the number of participants, number of victims, and scale of the electronic campaign may affect the classification of the offense and the applicable penalty.
The presence of one circumstance does not eliminate the need to prove the underlying prohibited act. The prosecution must first establish the social-engineering or money-muling conduct and then prove the circumstance that elevates it to economic sabotage.
Corporate Phishing and the Use of Electronic Communications
Corporate phishing commonly involves messages that appear to come from:
- A bank or payment service provider;
- A chief executive officer, finance officer, or company administrator;
- A supplier requesting a change in bank details;
- An information-technology or security department; or
- A government agency or other trusted organization.
The use of electronic communications is expressly contemplated by AFASA. Related banking regulations describe phishing as the use of electronic communications, such as email, to masquerade as a trusted identity and capture sensitive information to gain access to accounts. The same regulatory materials distinguish spearphishing, which is customized for a particular target such as an executive or privileged user.
These definitions are particularly relevant to business email compromise. A fraudulent message directed at a company treasurer, payroll officer, or accounting employee may be evidence of a targeted social-engineering scheme if it seeks credentials or other information capable of controlling a financial account.
Evidence Used in AFASA Prosecutions
A strong investigation should preserve evidence showing both the deceptive conduct and the movement or attempted movement of funds. Relevant evidence may include:
- The original email, text message, call records, or chat exchanges;
- Email headers, sender addresses, domain-registration information, and internet-protocol records;
- Copies of fake websites, login pages, or payment instructions;
- Bank and e-wallet transaction records;
- Device, server, and access logs;
- Records showing the use of a mass-mailing service; and
- Communications among alleged accomplices or account holders.
Businesses should preserve the original electronic files rather than relying only on screenshots. Investigators should also document how the evidence was obtained, stored, transferred, and authenticated in anticipation of objections concerning integrity and admissibility.
Disclosure of Account Information During Investigation
Bank secrecy and data-privacy rules do not create an absolute barrier to lawful cybercrime investigations. In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720 (2025), the Supreme Court held that the Cybercrime Prevention Act did not repeal the Bank Secrecy Law, but recognized a lawful basis for disclosing subscriber information, including the identity and contact details of account holders, when a court-issued warrant authorizes disclosure of computer data.
The ruling distinguished basic identifying information from the financial details of deposits. Disclosure must still comply with the applicable warrant requirements and statutory safeguards.
AFASA separately grants the Bangko Sentral ng Pilipinas authority to investigate financial accounts and share relevant information with law-enforcement and other competent authorities, subject to the limitations of the law. Section 13 also permits the BSP or its authorized officers to apply for cybercrime warrants and related orders under the Cybercrime Prevention Act.
For accounts under BSP investigation, the relevant statutory restrictions on inquiry into or disclosure of deposits do not apply in the same manner, subject to AFASA’s requirements. This does not authorize unrestricted access by private persons or private investigators; the information must be obtained and used through lawful investigative channels.
Data Privacy Issues in Corporate Phishing Cases
Financial institutions and businesses handling customer or employee information must consider their obligations under the Data Privacy Act. Disclosure to law enforcement may be permitted when processing is necessary for compliance with a legal obligation, the performance of a public-authority function, or the protection of lawful rights and interests in legal proceedings.
In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720 (2025), the Court recognized that the Data Privacy Act may permit the disclosure of personal information relevant to fraud investigations, including names, addresses, email addresses, and contact numbers, when a proper legal basis exists.
At the same time, a phishing incident does not automatically establish that a bank committed a data-privacy violation. In MTS v. Bank of the Philippine Islands, NPC 22-237 (2023), the National Privacy Commission ruled that substantial evidence must link the bank’s processing or negligence to the alleged unauthorized access. Mere proof that a customer was defrauded is insufficient by itself.
Businesses should therefore distinguish between an external phishing attack against account holders and a breach caused by the organization’s own unauthorized processing, inadequate safeguards, or negligence. The legal consequences depend on the evidence concerning the source and manner of the compromise.
Liability of Banks and Financial Institutions
AFASA requires covered financial institutions to implement adequate risk-management systems and controls to protect financial accounts. These controls include measures such as multi-factor authentication and fraud-management systems.
Bangko Sentral ng Pilipinas Memorandum to Authorized Agent Banks M-2024-029 reiterates the obligations relating to risk-management systems and controls under Section 6 of AFASA. The issuance also addresses the consequences for compliant and noncompliant institutions, including restitution obligations in circumstances covered by the law.
Whether a financial institution is liable for a disputed transaction therefore depends on the applicable AFASA requirements, the institution’s compliance with prescribed controls, the nature of the transaction, and the evidence concerning the customer’s conduct and the institution’s systems.
Typical Corporate Scenarios
Fake bank advisory. A finance employee receives an email directing the employee to “reconfirm” online-banking credentials through a linked website. The website records the username, password, and one-time password, after which funds are transferred. The sender may face liability for social engineering if the statutory elements and identity of the sender are proven.
Executive impersonation. An employee receives a text message appearing to come from the company president, directing the employee to send an urgent payment to a new account. If the message seeks access credentials or control over a financial account, AFASA may be implicated. If it merely induces a payment without obtaining sensitive identifying information, other offenses may be more directly applicable depending on the facts.
Account rental. A person permits another to use a personal or corporate account in exchange for a fee. If the account is used to receive or transfer proceeds known to derive from a social-engineering scheme, the account holder may face money-muling liability.
Mass phishing campaign. A group sends deceptive messages to at least 50 recipients using an automated mailing service. If the messages constitute social-engineering schemes, the use of a mass mailer may support the economic-sabotage classification under AFASA.
Recommended Corporate Response
Upon discovering a suspected phishing incident, a company should immediately secure affected accounts, revoke active sessions, reset credentials, preserve electronic evidence, and contact the relevant bank or payment service provider.
The company should also report the incident to appropriate law-enforcement and regulatory authorities. Early reporting is particularly important where funds remain traceable or may still be subject to holding, recovery, or other lawful intervention.
Internal investigators should avoid altering original evidence. They should preserve email headers, message metadata, access logs, transaction confirmations, device images, and the identity of persons who first discovered or handled the evidence.
Companies should maintain written controls requiring independent verification of payment instructions, confirmation of changes in supplier bank details, restricted access to financial credentials, multi-factor authentication, and immediate escalation of unusual requests.
Conclusion
AFASA treats deceptive electronic communications used to obtain financial-account credentials as potential social-engineering schemes. Criminal liability may extend beyond the individual who sends the phishing message to recruiters, organizers, conspirators, and persons who knowingly provide accounts for the receipt or movement of criminal proceeds.
The offense may be classified as economic sabotage when committed by at least three conspiring persons, against at least three victims, or through a mass mailer. Prosecutors must still prove the underlying prohibited act, the accused’s participation, the required knowledge or intent, and the applicable aggravating circumstance beyond reasonable doubt.
Companies should respond through rapid account protection, evidence preservation, lawful reporting, and strong verification controls. Banks and other financial institutions should likewise document compliance with AFASA safeguards, because liability may depend on whether the institution maintained and applied the required protective measures.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

