Legal question
If money is taken from your bank account or e-wallet in an unauthorized online transaction, when is the institution legally required to reimburse you — and what does entering an OTP do to your claim?
Applicable laws and rules
- Republic Act No. 12010 (Anti-Financial Account Scamming Act, or AFASA) — defines and penalizes financial account scamming, imposes fraud management obligations on institutions, and provides enforcement mechanisms
- Republic Act No. 11765 (Financial Products and Services Consumer Protection Act) — the BSP's authority to order restitution to consumers and to impose sanctions
- Republic Act No. 8791 (General Banking Law of 2000), Section 2 — the fiduciary nature of banking and the high standard of diligence required of banks
- Republic Act No. 10173 (Data Privacy Act of 2012) — obligations on personal data used in account takeover and identity fraud
- Republic Act No. 10175 (Cybercrime Prevention Act of 2012) — computer-related fraud and identity theft
- Civil Code, Articles 22 and 2154 — unjust enrichment and solutio indebiti, the doctrines banks invoke to recover mistakenly credited funds
- Civil Code, Article 1173 — the standard of diligence and the effect of gross negligence
Why this matters
The default assumption in Philippine banking disputes used to run against the customer. If a one-time password was entered, the institution treated the transaction as authorized and the loss as the depositor's problem — the reasoning being that only the account holder could have had the OTP. That reasoning has not survived the reality of SIM swaps, phishing sites that relay OTPs in real time, malicious apps, and social engineering that walks victims through the process.
AFASA changes the starting point. It makes fraud detection and prevention an obligation of the institution, backed by a compliance deadline that has now passed. Where the institution has not met the required standard, the loss sits with it. That is a structural shift: the question in a dispute is no longer only "did you give away your OTP?" but also "did the bank have the systems the law requires, and did they work?"
The Supreme Court's August 2026 ruling comes at the same problem from the other direction. Banks routinely try to claw back money from depositors after the bank's own error, using unjust enrichment as the vehicle. The Court has now said that where the bank's gross negligence caused the loss, that route is closed to it.
What AFASA actually does
RA 12010 does two separate things, and conflating them causes confusion. First, it is a criminal statute: it defines and penalizes financial account scamming, including money muling — lending, selling, or renting out a bank account or e-wallet for use in fraud — along with social engineering schemes and the unauthorized use of financial accounts. The mule provisions are significant because they reach the ordinary people whose accounts are used as pass-throughs, not just the syndicate operators.
Second, it is a prudential and consumer-protection statute. It requires covered institutions — banks, e-money issuers, and other BSP-supervised financial institutions — to put in place fraud management systems capable of detecting and preventing suspicious transactions, and it gives regulators mechanisms to act, including on the temporary holding of accounts implicated in fraud. Institutions were given a transition period, ending in June 2026, to build and deploy these systems.
The practical consequence of that deadline is what has been widely reported: for scam cases occurring after the deadline, an institution that has not met the mandated standard bears the loss, and reimbursement of the victim is the expected outcome rather than a discretionary goodwill gesture.
The end of "you entered the OTP, so it was you"
The most consequential operational change is in authentication. Under the AFASA framework, institutions are required to use multi-factor authentication for high-value and higher-risk transactions, and SMS or email one-time passwords are no longer treated as sufficient on their own for those transactions. The direction of travel is toward biometrics, device binding, passwordless login, and risk-based adaptive authentication that reacts to an unusual device, location, or transaction pattern.
Legally, that removes a defense. If the law requires more than an SMS OTP for a high-value transfer, then the fact that an OTP was entered cannot by itself establish that the customer authorized the transaction — because the OTP was never supposed to be the only control. An institution that relied on an SMS OTP alone for a transaction that required stronger authentication has a compliance problem, and that problem is evidence in the customer's favor.
This does not make every loss recoverable. Where the institution can show that its systems met the standard and functioned, and that the customer's own conduct caused the loss, the outcome can still go against the customer. Handing over credentials to someone you were dealing with knowingly, or authorising a transfer to a seller who turns out to be a fraud, is a different scenario from an account takeover. AFASA targets unauthorized transactions; a transfer you were tricked into making yourself is a harder case, and remains primarily a criminal complaint against the scammer plus a civil action.
The Supreme Court's August 2026 ruling: banks cannot claw back their own mistakes
On August 24, 2026, the Supreme Court's Third Division, in a decision written by Associate Justice Japar B. Dimaampao, denied BDO Unibank's petition against depositor Cristina Barcellano and held that a bank cannot require a depositor to return money already withdrawn on the ground of unjust enrichment when the loss was caused by the bank's own gross negligence.
The facts are ordinary, which is what makes the ruling useful. Barcellano deposited a PHP 151,200 regional check drawn on a Landbank branch in Albay into her savings account at BDO's Lucena City branch. The BDO teller mistakenly validated it as a local check rather than a regional one, which shortened the clearing period and allowed the amount to be made available and withdrawn before the check cleared. When the problem surfaced, BDO sought to recover the money from the depositor. The Court held that BDO's disregard of its own banking policy amounted to gross negligence, and that a bank in that position cannot fall back on unjust enrichment to shift the loss to the customer.
The doctrinal significance runs beyond cheque clearing. Banks invoke Articles 22 and 2154 of the Civil Code — unjust enrichment and solutio indebiti — whenever funds reach a customer they say should not have. This ruling establishes that the doctrine is not available where the bank's own gross negligence produced the situation, which is consistent with the long-standing rule under Section 2 of the General Banking Law that banking is imbued with public interest and banks owe a degree of diligence higher than that of a good father of a family.
What to do when money leaves your account
Speed matters more than anything else, because recoverability drops sharply once funds are moved through mule accounts and cashed out.
- Report to the institution immediately, by its official fraud hotline or in-app channel, and ask for a reference or ticket number in writing. Note the exact time you reported. Under AFASA and the BSP framework, a prompt report triggers the institution's obligation to investigate and can support the temporary holding of the receiving account.
- Ask the institution in writing to request a hold or recall on the beneficiary account, naming the receiving institution and account details if the transaction record shows them.
- File a written complaint with the institution's consumer assistance unit. This starts the formal clock and creates the record you will need later. Keep every reference number, screenshot, SMS, and email.
- Report to law enforcement — the PNP Anti-Cybercrime Group or the NBI Cybercrime Division — and secure a copy of the blotter or incident report. This is separate from the bank claim and supports the criminal case under AFASA and the Cybercrime Prevention Act.
- Escalate to the BSP if the institution denies the claim or does not resolve it within its stated turnaround. RA 11765 gives the BSP power to order restitution to a consumer, not merely to sanction the institution, and the BSP Consumer Assistance Mechanism is the route to invoke it.
- Preserve everything. Do not delete the phishing SMS, the fake site URL, the caller's number, or the app you were asked to install. Do not reformat the phone. These are the evidence that the transaction was unauthorized.
What the institution has to show
In a contested claim, the useful questions to put in writing are these. What authentication was applied to this transaction, and was it multi-factor? Was the transaction flagged by the institution's fraud management system, and if not, why not? Was it executed from a new device, a new IP address, or an unusual location, and what risk controls responded? What is the institution's threshold for a high-value transaction, and was this above it? When was the beneficiary account opened, and had it been the subject of prior reports?
These questions matter because they map directly onto the institution's AFASA obligations. An answer showing that a large transfer to a newly-opened beneficiary account from an unrecognized device passed on an SMS OTP alone is, on its face, a compliance failure.
Do not become a money mule
One part of AFASA cuts against consumers and deserves explicit warning. Allowing another person to use your bank account or e-wallet — for a fee, as a favor, or as a condition of an online "job" that involves receiving and forwarding funds — is itself an offense under the law. Recruitment for this is common and is often disguised as part-time work, a crypto or forex arrangement, or help for a friend abroad. The account holder is the person the paper trail identifies, and the account holder is the person charged. The rule is simple: never receive or forward money for someone else through your own account, and never surrender your account credentials, card, or SIM to anyone.
What individuals should know
Treat the June 2026 deadline as the dividing line. For an unauthorized transaction after it, the starting position is that the institution must be able to show its fraud management and authentication systems met the required standard — and if it cannot, the loss is its own. Do not accept a refusal that rests solely on the fact that an OTP was entered; ask, in writing, what authentication the law required for a transaction of that size and what the institution actually applied.
Keep the two tracks separate in your head. The claim against the institution is a consumer-protection matter governed by AFASA, RA 11765, and BSP rules, escalating from the bank's own complaints unit to the BSP. The case against the scammer is criminal, filed with the PNP-ACG or NBI Cybercrime Division under AFASA and the Cybercrime Prevention Act. Pursuing one does not require abandoning the other, and the criminal report strengthens the consumer claim by documenting that the transaction was unauthorized.
Finally, note the limit of the Supreme Court's August 2026 ruling. It concerns a bank trying to recover funds from a depositor after the bank's own gross negligence. It does not hold that every loss must be borne by the bank, and it does not decide an AFASA reimbursement claim. What it does is confirm the underlying principle both lines of authority share: an institution that fails the standard of diligence the law imposes on it cannot transfer the consequences of that failure to its customer.
Ask PHLaw.AI
Try: "₱80,000 was transferred out of my bank account to an account I do not recognize. The bank says I entered the OTP so it will not refund me. What are my rights under AFASA and how do I escalate to the BSP?"
Sources
- Republic Act No. 12010 — Anti-Financial Account Scamming Act (full text) — Supreme Court E-Library
- SC: Bank Cannot Recover Funds Withdrawn Due to Its Own Gross Negligence — Supreme Court of the Philippines (August 24, 2026)
- No more blaming OTPs: Banks now forced to reimburse victims of online account fraud — Manila Bulletin (July 23, 2026)
- Philippine banks now legally required to reimburse online fraud victims — Tech Pilipinas
- Republic Act No. 11765 — Financial Products and Services Consumer Protection Act — LawPhil
- Republic Act No. 8791 — General Banking Law of 2000 — LawPhil
- Bangko Sentral ng Pilipinas — Consumer Assistance Mechanism
- PNP Anti-Cybercrime Group