How Does AFASA Punish Social Media Account Hijacking?
Introduction
Fraudsters increasingly hijack personal social media accounts and use them to deceive relatives, friends, customers, and business contacts. After obtaining control of a profile, they may send urgent payment requests, solicit money, impersonate the account holder, or redirect victims to fraudulent bank and e-wallet accounts.
The Anti-Financial Account Scamming Act (AFASA) directly addresses this conduct when the scheme involves unauthorized access to financial accounts, the use of stolen identifying information, or the transfer and receipt of scam proceeds. The law may apply not only to the person who controls the hacked profile, but also to account holders who knowingly allow their financial accounts to receive or move criminal proceeds.
What Conduct Does AFASA Penalize?
Republic Act No. 12010, or the Anti-Financial Account Scamming Act, identifies financial account scamming as including money muling activities and social engineering schemes.
Money muling occurs when a person uses, borrows, rents, sells, lends, or permits the use of a financial account for the purpose of obtaining, receiving, depositing, transferring, or withdrawing proceeds known to be derived from crimes or social engineering schemes. Recruiting or inducing another person to perform these acts is also covered (R.A. No. 12010).
A social engineering scheme occurs when a person obtains another individual’s sensitive identifying information through deception or fraud, resulting in unauthorized access to and control over the victim’s financial account. The statute specifically includes:
- Misrepresenting oneself as acting for or on behalf of an institution;
- Making false representations to solicit sensitive identifying information; and
- Using electronic communications to obtain another person’s sensitive identifying information.
Although the unlawful conduct may begin with a hacked social media profile, the offense under AFASA is directed at the fraudulent acquisition of information, unauthorized account access, and movement of scam proceeds.
How Does Social Media Account Hijacking Fit the Law?
A hijacked social media account may be used as the communication channel for a fraud scheme. The offender may impersonate the account holder and send messages such as:
- “I am in an emergency. Please send money to this account.”
- “My bank account is temporarily unavailable. Use this e-wallet instead.”
- “Click this link and provide your verification code.”
- “Send your account details so I can process the payment.”
The account takeover itself may implicate the Cybercrime Prevention Act of 2012 where the offender acquires, uses, misuses, transfers, possesses, alters, or deletes another person’s identifying information without right. This is the offense of computer-related identity theft under R.A. No. 10175.
Where the stolen information is used to obtain money or access a financial account, the same conduct may also support charges for computer-related fraud, estafa, unauthorized access, or violations of AFASA, depending on the evidence and the precise acts alleged in the Information.
The Supreme Court has recognized that crimes committed through information and communications technology may receive a penalty one degree higher under Section 6 of R.A. No. 10175, provided the use of ICT is properly alleged and proven. (Catan v. People of the Philippines, G.R. No. 261156, 2023.)
Who May Be Prosecuted?
The Person Who Hijacked the Profile
The principal offender may be prosecuted if the evidence shows that the person unlawfully obtained access to the social media account, impersonated the victim, obtained identifying information, or used the account to induce victims to transfer money.
Evidence may include login records, device identifiers, IP addresses, subscriber information, message history, payment records, screenshots, recovery-email changes, and communications with victims or account holders.
The Person Who Operated the Scam
The person controlling the communication campaign may be liable even if that person did not personally hack the account. The prosecution may establish liability through proof that the accused knowingly used the compromised profile to solicit funds, obtain account information, or direct victims to financial accounts controlled by the syndicate.
The Money Mule
A person may incur liability as a money mule if the person knowingly allows a financial account to receive, deposit, transfer, or withdraw proceeds derived from a crime or social engineering scheme.
AFASA covers the use, borrowing, renting, selling, and lending of financial accounts. It also penalizes recruiting, contracting, hiring, utilizing, or inducing another person to perform these acts. A person cannot avoid liability merely by claiming that the account was used by someone else if the surrounding facts show knowledge, participation, or deliberate disregard of the criminal source of the funds.
The Recruiter or Coordinator
A syndicate may use recruiters to find account holders, obtain prepaid SIM cards, create e-wallet accounts, or persuade individuals to receive and forward funds. The person who organizes or induces these activities may be prosecuted even if the person never communicates directly with the victims.
When Does the Offense Become Economic Sabotage?
AFASA treats money muling and social engineering as economic sabotage when specified aggravating circumstances are present. These include commission by a group of three or more persons conspiring or confederating with one another, commission against three or more persons individually or as a group, or the use of a mass mailer (R.A. No. 12010).
The number of participants, number of victims, and method of communication should therefore be documented at the earliest stage of the investigation. Group chats, recruitment messages, payment instructions, transaction logs, and coordinated use of multiple profiles may help establish the existence of a conspiracy or confederation.
A prosecution should not automatically assume economic sabotage merely because several accounts or victims are involved. The prosecution must still prove the statutory circumstance and the accused’s participation beyond reasonable doubt.
How Do AFASA and the Cybercrime Prevention Act Interact?
AFASA operates alongside R.A. No. 10175. The Cybercrime Prevention Act covers offenses involving computer systems, computer data, identity theft, fraud, and other cybercrime-related conduct. AFASA specifically addresses financial account scams, money muling, social engineering, and the regulatory investigation of financial accounts.
Section 6 of R.A. No. 10175 provides for a penalty one degree higher when a crime under the Revised Penal Code or a special law is committed by, through, or with the use of information and communications technologies. The prosecution must allege and prove the ICT connection; it should not rely solely on the fact that a mobile phone or social media platform happened to be involved.
In Disini, Jr. v. Secretary of Justice, the Supreme Court upheld the validity of provisions authorizing disclosure, preservation, search, and examination of computer data under judicial safeguards, while invalidating provisions that impermissibly impaired constitutional rights. (Disini, Jr. v. Secretary of Justice, G.R. No. 203335, 2014.)
What Evidence Is Needed?
A successful prosecution usually requires evidence connecting the accused to both the digital conduct and the financial transaction. Relevant evidence may include:
- Records showing the unauthorized takeover or use of the social media account;
- Copies of fraudulent messages, posts, links, and payment instructions;
- Victim affidavits identifying the representations made and the money transferred;
- Bank, e-wallet, remittance, and cash-withdrawal records;
- Know-your-customer records and account-opening documents;
- Subscriber information, device records, and account-login data obtained through lawful process;
- Communications among the alleged members of the syndicate; and
- Evidence showing knowledge that the money came from a crime or fraudulent scheme.
Digital screenshots are useful but should be preserved with information showing when, where, and how they were obtained. Investigators should also preserve the original devices, relevant applications, message exports, account-recovery records, and available platform data.
Can Authorities Obtain Account-Holder Information?
The Supreme Court has ruled that the Cybercrime Prevention Act did not repeal the Bank Secrecy Law. However, a bank acting as a service provider may disclose basic subscriber information, including the identity and contact details of an account holder, when authorized by a court-issued warrant for disclosure of computer data in a cybercrime investigation. Financial details remain subject to confidentiality rules except where a valid legal exception applies. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025.)
AFASA also gives the Bangko Sentral ng Pilipinas authority to investigate financial accounts and share relevant information with law-enforcement agencies and other competent authorities, subject to the law’s limitations. Section 13 of R.A. No. 12010 authorizes the BSP or its duly authorized officer or body to apply for cybercrime warrants and related orders under R.A. No. 10175 concerning electronic communications used in violations of AFASA.
Accordingly, investigators should identify the specific information sought and use the appropriate legal process. A general demand for all banking information may be challenged if it is not supported by the applicable statutory authority or judicial safeguards.
How Does the BSP’s Authority Affect Bank Secrecy?
AFASA recognizes that financial cybercrime investigations may require access to accounts used to receive or transfer scam proceeds. The Supreme Court has stated that the current statutory scheme, including the Cybercrime Prevention Act, the Data Privacy Act, and AFASA, permits disclosure of information concerning bank deposits in investigations of cybercrimes, subject to legal limitations. (Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025.)
This does not mean that every financial account may be examined without cause. The account must be connected to an investigation covered by the applicable law, and the agency must observe the requirements governing warrants, disclosure, preservation, privacy, and use of the information obtained.
What Happens to Disputed Funds?
AFASA authorizes measures intended to prevent the dissipation of funds connected with financial account scams. In practice, the investigation may involve coordination among the BSP, banks, e-money issuers, the National Bureau of Investigation, the Philippine National Police, and prosecutors.
Victims should promptly report the transaction to the originating bank or e-wallet provider and provide the transaction reference, recipient details, screenshots, communications, and proof of fraud. Speed is important because funds may be transferred through several accounts within minutes.
Recovery is not automatic. A freeze, hold, or investigation does not by itself establish ownership of the funds or guarantee restitution. The complainant may still need to participate in the criminal case and comply with procedures for the preservation, forfeiture, or return of the money.
How Can a Syndicate Be Established?
Conspiracy may be inferred from coordinated acts, even when the participants perform different functions. A profile hijacker, recruiter, account holder, message sender, cash-out person, and coordinator may each perform separate tasks that advance one fraudulent plan.
Investigators should examine whether the participants shared instructions, used common contact numbers or devices, transferred proceeds according to a coordinated scheme, or repeatedly used the same accounts and communication channels. Mere association, however, is not enough. The evidence must show intentional participation in the unlawful plan.
Common Defenses and Evidentiary Issues
An accused money mule may claim lack of knowledge, mistaken identity, unauthorized use of the account, or deception by the actual scammers. These defenses make the circumstances surrounding account opening, receipt of funds, communications, withdrawals, and subsequent conduct particularly important.
A person who unknowingly receives money is not automatically guilty of money muling. The prosecution must establish the required mental element—that the person knew the proceeds were derived from crimes or social engineering schemes, or knowingly performed the prohibited account-related acts.
Digital evidence may also be challenged on grounds of authenticity, integrity, attribution, or unlawful acquisition. Investigators should maintain a clear chain of custody and obtain account and subscriber records through the appropriate warrant or legal process.
What Should Victims and Account Holders Do?
- Immediately notify the bank, e-wallet provider, and social media platform.
- Request account restriction, transaction review, and preservation of relevant records.
- Change passwords and revoke unknown sessions, devices, applications, and recovery methods.
- Preserve messages, profile links, transaction references, phone numbers, and screenshots.
- Report the incident to the PNP Anti-Cybercrime Group, NBI cybercrime authorities, or the appropriate prosecutor’s office.
- Do not negotiate with suspected scammers or delete communications that may be evidence.
Financial account holders who discover suspicious incoming funds should not withdraw, forward, or return the money through an unverified channel. They should immediately inform their bank or e-wallet provider and request written instructions. Moving the funds after receiving notice of their suspicious character may create additional evidentiary problems.
Final Observations
AFASA provides a direct basis for prosecuting social-engineering schemes that use hijacked social media accounts to obtain financial information, access accounts, and transfer scam proceeds. Liability may extend beyond the person who controlled the stolen profile to recruiters, coordinators, and money mules who knowingly support the movement of criminal proceeds.
For prosecutors, the essential task is to establish the chain connecting the account takeover, fraudulent representation, victim’s transfer, receiving account, and accused’s knowing participation. For victims and financial institutions, immediate reporting and preservation of digital and transaction records may determine whether the funds can be traced and whether the responsible persons can be identified.
Legal assessment should be made from the specific facts, including the method of account takeover, the representations made to victims, the identities of the account holders, the number of victims, the number of participants, and the timing and movement of the funds.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

