What Are the Penalties for Corporate Phone Spoofing?

What Are the Penalties for Corporate Phone Spoofing?

Introduction

Consumers may receive calls appearing to come from a bank, telecommunications company, delivery service, or other corporation when the caller has actually manipulated the displayed caller ID. This practice can be used to obtain money, passwords, one-time passwords, or other personal information.

Under Philippine law, the SIM Registration Act specifically penalizes spoofing a registered SIM. Criminal liability does not arise merely because a caller uses a corporate name or because a recipient is deceived. The prosecution must establish the statutory elements of spoofing, including the transmission of misleading or inaccurate information about the source of a call or text message and the required fraudulent or harmful intent.

What Is Spoofing Under Philippine Law?

Section 3(g) of R.A. No. 11934, or the Subscriber Identity Module (SIM) Registration Act, defines spoofing as the act of transmitting misleading or inaccurate information about the source of a phone call or text message, with the intent to defraud, cause harm, or wrongfully obtain anything of value.

The same definition appears in the Implementing Rules and Regulations of R.A. No. 11934. The offense therefore focuses on the manipulation or falsification of the apparent source of the communication, together with a qualifying intent.

What Crime Covers Spoofing Corporate Phone Numbers?

Section 11(e) of R.A. No. 11934 penalizes spoofing a registered SIM. The provision applies when a person causes the transmission of misleading or inaccurate information about the source of a phone call or text message, with the intent to:

  • defraud another person;
  • cause harm; or
  • wrongfully obtain anything of value.

A caller who makes a consumer believe that the call originates from an official corporate number may fall within the provision if the caller ID or other source information was manipulated and the required intent is proven.

What Penalty May Be Imposed?

Under Section 11(e) of R.A. No. 11934 and Section 15 of its IRR, a person who spoofs a registered SIM may be punished by:

  • imprisonment of not less than six years;
  • a fine of P200,000; or
  • both imprisonment and the fine.

The statutory language states “no less than six years.” Accordingly, the imprisonment penalty is expressed as a minimum period rather than as a range beginning at six months or one year.

What Must the Prosecution Prove?

For a criminal case involving spoofing, the prosecution generally must prove the following circumstances beyond reasonable doubt:

  • the accused caused a phone call or text message to be transmitted;
  • the transmission contained misleading or inaccurate information about its source;
  • the spoofed communication involved a registered SIM;
  • the accused acted with intent to defraud, cause harm, or wrongfully obtain anything of value; and
  • the accused was the person who caused, directed, or participated in the transmission.

The use of a corporate name, logo, or business identity may support the allegation of deception, but it does not by itself prove every element of the offense. Investigators and prosecutors must still establish the source of the transmission, the manner of manipulation, and the accused’s intent.

Examples of Potentially Criminal Conduct

A person may potentially be prosecuted when the person manipulates caller ID so that a call appears to come from a bank and then asks the customer to disclose an OTP or transfer money. The case becomes stronger when technical records, call-routing information, recorded conversations, payment records, or witness testimony connect the accused to the spoofed transmission and the intended fraud.

Similarly, a person who makes a call appear to originate from a telecommunications company and uses that representation to obtain payment, personal information, or access credentials may face liability if the statutory elements are proven.

By contrast, an inaccurate caller ID caused by a technical error, without proof that a person intentionally transmitted misleading source information and acted with one of the required forms of intent, may not satisfy the offense.

Statutory Exceptions

The penalty for spoofing does not apply when the transmission is exempted because it was made in connection with:

  • authorized activities of law enforcement agencies; or
  • a court order specifically authorizing the use of caller ID manipulation.

The exception is limited. A person cannot rely on it merely by claiming to assist law enforcement or by asserting that caller ID manipulation was useful for an investigation. The activity must be authorized, or there must be a court order specifically permitting the manipulation.

Relation to Earlier Jurisprudence

Before the enactment of legislation specifically addressing telecommunications fraud, the Supreme Court observed that the Revised Penal Code was enacted before modern telecommunications technology and did not automatically cover every form of misappropriation involving intangible telecommunications services. In “Laurel v. Abrogar,” G.R. No. 155076, 13 April 2006, the Court emphasized that criminal liability must rest on a law clearly defining and penalizing the conduct.

The SIM Registration Act supplies a specific statutory basis for prosecuting spoofing involving a registered SIM. The case therefore illustrates the importance of applying the statutory offense as written rather than relying solely on older criminal provisions concerning theft or fraud.

How May a Spoofing Case Be Supported?

A complainant or investigating agency should preserve evidence that can establish both the transmission and the accused’s intent. Relevant evidence may include:

  • screenshots of the displayed caller ID or message sender information;
  • recordings or transcripts of the call, when lawfully obtained;
  • telephone numbers, SIM details, device identifiers, and relevant subscriber records;
  • bank, payment, wallet, or delivery records showing the attempted or completed transaction;
  • phishing links, messages, scripts, or instructions used by the caller; and
  • technical or platform records connecting the transmission to the suspected offender.

A report should be made promptly to the relevant public telecommunications entity and law-enforcement authorities. The SIM Registration Act also requires public telecommunications entities to provide reporting mechanisms for potentially fraudulent texts or calls and, after due investigation, to deactivate temporarily or permanently the SIM used for the fraudulent communication.

Corporate Responsibility and Related Offenses

The spoofing offense is directed at the person who causes the misleading transmission. A corporation whose name or number was impersonated is ordinarily the potential victim rather than the offender. Corporate officers or employees may be investigated, however, if evidence shows that they personally participated in the spoofing or authorized it.

Other offenses may also be considered depending on the conduct and evidence, including fraud, unauthorized access, or offenses under other special laws. The proper charge depends on the specific acts, the harm caused, the means used, and the evidence available. A spoofing charge under R.A. No. 11934 should not be treated as automatically established merely because a consumer lost money.

Practical Guidance for Businesses

Businesses should warn customers that official personnel will not request passwords, OTPs, or similar authentication credentials through unsolicited calls. They should also maintain an incident-response process for impersonation reports, preserve relevant records, coordinate with telecommunications providers, and promptly notify affected customers when appropriate.

A company whose identity is being impersonated should document the false communications and distinguish its legitimate numbers, domains, and customer-contact procedures. Prompt preservation of technical and transaction evidence may assist investigators in identifying the person who caused the spoofed transmission.

Conclusion

Spoofing a corporate phone number may constitute a criminal offense under R.A. No. 11934 when a person causes misleading or inaccurate source information to be transmitted through a registered SIM, with the intent to defraud, cause harm, or wrongfully obtain anything of value.

The penalty is imprisonment of not less than six years, a fine of P200,000, or both. Criminal prosecution requires proof of the statutory elements and does not rest solely on the fact that a caller used a company’s name or that a consumer was deceived. Evidence should therefore focus on the manipulated source information, the registered SIM, the accused’s participation, and the required intent.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH