Is Selling Hacked Social Media Accounts a Crime?
Introduction
Selling a hacked social media account or its login credentials may expose the seller to criminal liability under Philippine law. The legal consequences become more serious when the account was obtained through phishing, unauthorized access, identity theft, fraud, or the misuse of personal information.
The number of followers or commercial value of the account does not determine whether a crime was committed. The important questions are how the account was obtained, whether the seller had authority to access or transfer it, whether another person’s identifying information was used, and whether the conduct caused damage or was intended to deceive or defraud.
What Conduct May Constitute a Cybercrime?
The Cybercrime Prevention Act of 2012 penalizes computer-related identity theft, computer-related fraud, computer-related forgery, illegal access, and other acts involving information and communications technology. These offenses may apply at different stages of the scheme—from stealing login credentials to taking control of an account and selling it to another person (R.A. No. 10175).
Computer-related identity theft includes the intentional acquisition, use, misuse, transfer, possession, alteration, or deletion of identifying information belonging to another person or juridical entity, without right. If no damage has yet been caused, the law provides for a penalty one degree lower for this offense (R.A. No. 10175).
Login credentials, recovery information, email addresses, usernames, and other information that permit access to an account may be relevant identifying information. The National Privacy Commission has recognized that names and email addresses may be used to enable identity fraud, particularly where they can support phishing attacks or access to important accounts (NPC 20-124).
How Phishing Can Lead to Criminal Liability
Phishing generally involves deceiving a person into disclosing passwords, one-time passwords, authentication codes, recovery links, or other information. A person who uses a deceptive message, imitation website, fake customer-support account, or fraudulent offer to obtain credentials may be liable for the unlawful acquisition or use of identifying information.
The subsequent sale of the account may strengthen the inference that the acquisition was intentional and unauthorized. It may also show that the offender acted with a fraudulent or dishonest purpose, particularly when the account was marketed as belonging to another person or was sold for access to the victim’s audience, business contacts, private messages, or payment-related information.
However, selling an account is not automatically a cybercrime. Criminal liability depends on proof that the account or credentials were obtained, used, transferred, or possessed without right and that the statutory elements of the particular offense are present.
Computer-Related Identity Theft
Computer-related identity theft may be charged when a person intentionally acquires, uses, misuses, transfers, possesses, alters, or deletes identifying information belonging to another without authority (R.A. No. 10175).
A typical example is a person who obtains the credentials of a high-follower account through phishing, changes the recovery email and password, and sells the credentials to a buyer. The conduct may involve the unauthorized acquisition and transfer of identifying information, as well as the taking over of the victim’s digital identity.
The offense may exist even before the account is sold. The sale is significant because it may establish the transfer of the identifying information and may help prove the offender’s intent, knowledge, and lack of authority.
Computer-Related Fraud and Forgery
Computer-related fraud covers the unauthorized input, alteration, or deletion of computer data or programs, or interference with the functioning of a computer system, when the conduct causes damage and is accompanied by fraudulent intent. If no damage has yet been caused, the law provides for a penalty one degree lower (R.A. No. 10175).
This offense may be relevant where the offender changes account-recovery details, removes the legitimate owner’s access, redirects payments, impersonates the account holder, or causes financial or reputational loss. The prosecution must still establish the statutory elements, including the unauthorized computer-related act, fraudulent intent, and damage where required.
Computer-related forgery may also arise when computer data is input, altered, or deleted without right so that it becomes inauthentic data intended to be treated as authentic for legal purposes. Knowingly using such data to carry out a fraudulent or dishonest design is likewise covered by the provision (R.A. No. 10175).
Illegal Access and Unauthorized Entry
A seller who personally breaks into an account or system may face liability for illegal access or another applicable cybercrime. The use of stolen credentials does not necessarily become lawful merely because the credentials work or because the seller later transfers them to a buyer.
Authorization is a material issue. A person who is an authorized administrator, employee, editor, or service provider may have lawful access within defined limits. Access beyond that authority, acquisition for an unrelated purpose, or transfer to an unauthorized buyer may produce a different legal result.
The National Privacy Commission has explained, in applying Section 29 of the Data Privacy Act, that unauthorized access requires proof that: the data system stores personal or sensitive personal information; the accused broke into the system; and the accused knowingly and unlawfully broke into it in a manner violating the confidentiality and security of the data system (NPC 18-109; NPC 23-166).
Possible Liability Under the Data Privacy Act
The Data Privacy Act of 2012 penalizes persons who knowingly and unlawfully break into a system where personal and sensitive personal information is stored, or who violate data confidentiality and security in doing so. The stated penalty is imprisonment of one to three years and a fine of ₱500,000 to ₱2,000,000 (R.A. No. 10173).
Not every misuse of an online account automatically establishes a violation of Section 29. The prosecution must show the required system, the act of breaking into it, and the accused’s knowing and unlawful conduct. The National Privacy Commission has repeatedly emphasized that allegations, suspicion, or weak circumstantial evidence are insufficient without substantial evidence directly connecting the respondent to the unauthorized access (NPC 19-030 and NPC 19-132; NPC 23-166).
Other provisions of the Data Privacy Act may become relevant when personal information is processed, disclosed, or used without authority. The specific charge depends on the information involved, the conduct proved, the person responsible, and the applicable lawful basis or authorization.
Penalty Increase When ICT Is Used
Section 6 of the Cybercrime Prevention Act provides that crimes defined and penalized under the Revised Penal Code or special laws, when committed by, through, and with the use of information and communications technology, are covered by the Act. The penalty imposed is one degree higher than the penalty provided under the Revised Penal Code or the applicable special law (R.A. No. 10175).
The Supreme Court has explained that the provision treats the use of information and communications technology as a qualifying circumstance because digital methods may help offenders avoid identification, reach more victims, or cause greater harm (Disini, Jr., et al. v. Secretary of Justice, et al., G.R. No. 203335, 11 February 2014).
The increased penalty is not automatic in every case involving a device or online communication. The use of information and communications technology must be sufficiently alleged and established in the case. The Supreme Court applied this rule where the offense was committed through internet and social-media means (Catan v. People of the Philippines, G.R. No. 261156, 2023; Tria v. People of the Philippines, G.R. No. 255583, 2023).
When the Buyer May Also Be Liable
The buyer of a hacked account may face criminal exposure if the buyer knowingly purchases, possesses, uses, or transfers stolen credentials or identifying information. Liability may be more apparent when the buyer knows that the account was obtained through hacking or phishing and intends to impersonate the owner, deceive followers, access private information, or commit fraud.
A buyer who merely receives an unsolicited offer without knowing that the account was unlawfully obtained is in a different position. Knowledge, intent, possession, use, and participation must be established from the evidence.
Evidence may include chat messages, payment records, account-recovery notifications, phishing links, device logs, IP records, advertisements, account-transfer instructions, and communications showing that the buyer knew the credentials were stolen.
What Happens When the Account Is Used for Fraud?
A hacked account may be used to solicit money, promote false investments, impersonate the account holder, distribute malicious links, or obtain additional credentials. These acts may create separate criminal liabilities under the Cybercrime Prevention Act, the Revised Penal Code, the Data Privacy Act, or other applicable special laws.
The account’s large following may aggravate the practical harm because a fraudulent post or message can reach many persons quickly. It does not, by itself, create a separate offense; the relevant legal consequences depend on the particular fraudulent act and the evidence proving it.
Important Evidence in a Criminal Complaint
A complainant should preserve the original phishing message, complete URLs, screenshots showing the account takeover, emails concerning password or recovery changes, copies of advertisements offering the account for sale, payment records, and communications with the suspected seller or buyer.
Evidence should be preserved in a manner that supports authentication and continuity. Relevant information may include message headers, platform-generated notifications, transaction references, device information, account activity logs, and sworn statements from persons who received the phishing messages or saw the sale offer.
The complainant should also report the incident promptly to the platform, the Philippine National Police Anti-Cybercrime Group, the National Bureau of Investigation Cybercrime Division, or another appropriate law-enforcement authority. Immediate reporting may assist in preserving platform records and preventing further misuse.
Important Defenses and Limits
A person accused of selling an account may raise lack of knowledge, lack of intent, authorization, mistaken identity, absence of damage where damage is an element, or failure of the prosecution to prove that the person accessed or transferred the account.
Authorized access is particularly important. An administrator or employee may lawfully access an account or system for a defined purpose, but that authority does not necessarily extend to copying credentials, changing ownership information, selling access, or using personal information for an unrelated purpose.
The Supreme Court has recognized that cybercrime laws must be applied consistently with constitutional rights, including due process and privacy. Provisions that are narrowly directed at defined cybercrimes may be upheld, while unconstitutional applications remain subject to judicial review (Disini, Jr., et al. v. Secretary of Justice, et al., G.R. No. 203335, 11 February 2014).
Practical Legal Assessment
For a preliminary assessment, investigators and counsel should identify the account’s lawful owner, determine how access was obtained, establish whether credentials were transferred, identify the buyer and seller, document the use of phishing or deception, and quantify any resulting damage.
The analysis should distinguish between the original phishing conduct, the unauthorized account takeover, the possession or transfer of credentials, the sale transaction, and any later fraud committed through the account. Each act may involve different statutory elements and different evidentiary requirements.
Online posts, screenshots, or usernames alone may not prove who controlled the account. Additional evidence—such as payment trails, device records, account-recovery data, platform logs, and admissions—may be needed to connect the accused to the offense.
Conclusion
Selling hacked social media accounts and credentials may constitute computer-related identity theft, computer-related fraud, computer-related forgery, illegal access, or an offense under the Data Privacy Act, depending on the facts proved. Phishing, unauthorized takeover, possession, and sale should be examined as separate but related acts.
The use of ICT may increase the penalty for an underlying crime by one degree when the statutory conditions are alleged and proven. Persons affected should preserve digital evidence, report the incident promptly, and obtain legal advice before communicating with suspected sellers or buyers.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

