Philippine IDs for Sale: DWK Tracks More Than 9,000 Suspected Fraudulent Document Offers
A monitoring conducted by the Deep Web Konek (DWK) Threat Monitoring Team since 2024 has identified a persistent online ecosystem involving the advertisement, sale, and distribution of suspected counterfeit Philippine identification documents, as well as genuine identification information allegedly obtained from data breaches.
The monitoring has identified more than 9,000 posts across multiple online and social media platforms involving the advertisement or offering of suspected fraudulent identification cards and other official documents. Approximately half of the monitored activity was observed across Meta platforms, particularly Facebook, Facebook Marketplace, and Telegram, where sellers openly advertised identification documents and related services.
Among the documents specifically classified by the DWK team, the Philippine National ID or PhilSys ID accounted for 2,153 monitored posts or offers, making it the most frequently identified document in the current dataset. The monitoring also recorded 724 posts involving SSS IDs, 456 involving Postal IDs, and 132 involving TIN IDs. The broader dataset includes advertisements involving other documents, including birth certificates, diplomas, clearances, and various government-issued identification and supporting documents.
https://iili.io/ndaGxpt.png
https://iili.io/ndaGovI.png
These figures represent monitored advertisements or offers and should not automatically be interpreted as confirmed transactions. Furthermore, individual advertisements may offer several types of documents simultaneously. Consequently, document-specific figures should be treated as classification counts and should not be added together as an equivalent to the more than 9,000 individual posts monitored by DWK.
Prices observed by the team generally ranged from approximately ₱100 to ₱500, although prices varied depending on the document and the service being advertised. The relatively low advertised cost potentially lowers the barrier for individuals seeking fraudulent documentation, while the repeated appearance of similar advertisements indicates that the activity remains persistent despite platform moderation and account removals.
https://iili.io/ndaG3Qa.png
https://iili.io/ndaG2hg.png
DWK's monitoring also identified advertisements involving PNP-related clearances, alongside birth certificates, diplomas, and other supporting documents. The combination of identification cards and supporting records is particularly relevant because fraudulent identity activity may involve more than simply obtaining a single identification card.
Separate from the social media monitoring, the DWK team also observed at least 126 forum posts associated with previously advertised or allegedly breached datasets in which Philippine identification documents and identity-related information were offered for sale or made available to prospective buyers.
https://iili.io/ndaGTjn.png
Some of these posts reportedly contained or advertised collections involving several types of Philippine identification cards and personal records. Such material may include information that, if genuine and sufficiently complete, could potentially be used for identity impersonation, fraudulent account registration, social engineering, or attempts to bypass identity-verification procedures.
DWK emphasizes that the presence of an identification document within a breach-related dataset does not independently establish that the document was obtained through a particular breach, nor does it establish that the information was subsequently used to commit fraud.
Nevertheless, the combination of counterfeit-document advertisements and allegedly compromised genuine identity information represents a more significant identity-security concern.
Counterfeit documents can provide a fabricated identity, while compromised legitimate information can potentially provide the underlying personal data needed to make that fabricated identity appear more credible.
The monitoring therefore identifies two related but distinct categories of risk.
The first involves suspected counterfeit documents, where an individual may attempt to obtain an identification card that was never legitimately issued to them or that has been altered or fabricated.
The second involves compromised identity information, where legitimate personal information or copies of genuine identification documents may allegedly be obtained from data breaches and subsequently offered in underground forums.
When these two elements intersect, the potential for more sophisticated identity fraud increases. A malicious actor may possess personal information belonging to a real individual while simultaneously having access to fraudulent documents or document-production services.
DWK considers this intersection an important area for continued monitoring because it could potentially affect identity verification systems across both government and private-sector services.
The team also monitored activities referencing the use of identification documents in connection with digital financial platforms.
These observations should not be interpreted as evidence that either platform knowingly accepted counterfeit identification documents. Rather, DWK observed activities and discussions indicating that individuals may attempt to use questionable or fraudulent documents during identity-related processes associated with digital financial services.
Nevertheless, the activity demonstrates why identity verification remains a critical security control for financial platforms. If compromised personal information is combined with a fraudulent identification document, an attacker may potentially attempt to create an identity that appears legitimate during an initial verification process.
Another area identified during monitoring involved registered SIM cards allegedly associated with the use of fraudulent identification documents.
Several monitored activities pointed to SIM cards that were allegedly registered using fake identification cards before being offered or sold to other individuals. DWK has not independently established that every SIM card advertised in these activities was fraudulently registered, and the findings should therefore be treated as indicators requiring further investigation.
However, they could create challenges for identity attribution. A SIM card registered under a fraudulent identity and subsequently transferred to another individual could result in a discrepancy between the registered subscriber and the actual user.
This creates a potential attribution chain in which a fraudulent identification document is used during registration, the resulting SIM card is transferred, and subsequent activity involving the number may be associated with an identity that does not correspond to its actual user.
The findings are particularly relevant amid renewed government discussions regarding the use of the Philippine National ID for social media account verification.
The Department of Information and Communications Technology has recently pushed for stronger identity verification measures involving social media platforms, including discussions with Meta regarding the possible integration of the Philippine National ID into account verification.
The proposal comes at a time when DWK monitoring has already identified more than 2,100 advertisements or offers specifically involving National IDs.
This creates an important identity-assurance challenge.
A verification system must distinguish between asking a person to provide an identification document and actually authenticating that document and the identity associated with it.
A photograph or scanned copy of a National ID may demonstrate that a user possesses an image of an identification document, but it does not by itself establish that the document is authentic, was legitimately issued, has not been altered, or belongs to the person submitting it.
The Philippine Statistics Authority has repeatedly warned against fake National IDs and emphasized the importance of proper authentication. The PSA has also identified official mechanisms for verifying National ID credentials rather than relying solely on visual inspection.
The availability of suspected counterfeit National IDs online demonstrates why an identity-verification framework based solely on document submission could face significant challenges. An identification card can be fabricated or altered. A genuine identification document can also potentially be stolen, misused, or associated with compromised personal information.
This distinction becomes increasingly important as identification documents are used across multiple services, including financial applications, telecommunications registration, government transactions, employment processes, and online platforms.
The PSA's PhilSys authentication mechanisms provide a means of determining whether information associated with a National ID can be verified through official systems. The agency has also encouraged relying parties to utilize appropriate authentication services when accepting National ID credentials.
For organizations implementing identity verification, the objective should therefore extend beyond determining whether an ID looks legitimate. Verification should establish, where legally and technically appropriate, whether the credential was genuinely issued and whether the person presenting it is legitimately associated with that identity.
DWK assesses that the monitored activity represents a persistent identity-fraud risk spanning both open social media platforms and underground online communities.
The more than 9,000 monitored posts since 2024 demonstrate sustained online advertising of suspected fraudulent identification documents. At the same time, forum monitoring has identified posts offering or selling allegedly compromised Philippine identification documents and identity-related information originating from breach-related activity.
These two environments present different but interconnected risks. Social media platforms can provide accessible marketplaces for suspected counterfeit documents, while underground forums may provide access to personal information and copies of genuine identification documents allegedly obtained through breaches.
The potential combination of these resources could provide malicious actors with multiple avenues for attempting identity fraud.
DWK stresses that the current findings do not establish that all advertised documents are genuine counterfeits, that all breach claims are legitimate, or that every identified document has been used for fraudulent activity. Those determinations require case-by-case validation and, where appropriate, law-enforcement investigation.
However, the volume and persistence of the activity warrant continued monitoring and stronger authentication practices.
The growing discussion surrounding National ID-based verification should be accompanied by an equally serious discussion about how those identities are authenticated.
For DWK, the central finding is straightforward:
An identification requirement is only as strong as the authentication mechanism behind it.
Other contents