When a complaint about unauthorised access to a Facebook, X or Discord account reaches a Spanish examining court, what opens is a preliminary investigation in which the judge can order what you cannot obtain on your own. Under articles 588 ter j and 588 ter k of the Criminal Procedure Act, the court requires the platform to hand over the account’s connection data, meaning IP addresses, login dates and times and device identifiers, and requires the telecoms operator to identify the subscriber behind that IP, a record operators must keep for twelve months under Law 25/2007. If money was requested from your contacts through the account, the court writes to the banks to identify the holder of the receiving account and, when it is in time, to freeze the funds. The actual investigation is carried out by the National Police or the Guardia Civil through their technology crime units, and where the platform is based in Ireland, as Meta is, requests go through European cooperation channels, which work but take time. All of this starts with a complaint and with evidence you have preserved. Without both, the court has nothing to act on.
The guides you will find on this subject explain how to change your password and stop there. At the firm we see the matter when technical recovery has failed or when there is already damage, with contacts scammed, advertising charged to the company card or private photos circulating, and that is the part I develop here.
Which offence it is when someone gets into your account
Accessing another person’s account without authorisation, by defeating its security measures, is the offence of unlawful access to a computer system under article 197 bis of the Spanish Criminal Code, punishable by six months to two years in prison. It is committed even if the attacker does nothing once inside. What usually follows is where the serious consequences lie.
If the attacker reads or takes your private messages, article 197 applies, which punishes the discovery of secrets with one to four years in prison plus a fine. If the attacker then passes on what was found to third parties, paragraph 3 of the same article raises the penalty to two to five years in prison. If your posts, photos or page are deleted, that is computer damage under article 264, with six months to three years in prison where the result is serious. And if your name and image are used to open profiles or run advertisements that cause you harassment or humiliation, article 172 ter.5 punishes that conduct with three months to one year in prison or a fine.
Civil status usurpation under article 401, carrying six months to three years in prison, comes up in many searches, but the Supreme Court interprets it strictly and requires a complete and sustained impersonation of the person. Someone writing to your friends from your account asking for a Bizum transfer does not usually reach that threshold. What does fit is fraud, which I cover below.
| Attacker’s conduct | Criminal Code article | Penalty |
|---|---|---|
| Getting into the account without permission | 197 bis | 6 months to 2 years in prison |
| Reading or taking private messages and data | 197.1 and 197.2 | 1 to 4 years in prison plus a fine |
| Passing on what was obtained to third parties | 197.3 | 2 to 5 years in prison |
| Deleting photos, posts or the page | 264 | 6 months to 3 years in prison |
| Asking your contacts for money while posing as you (over 400 euros) | 248 and 249 | 6 months to 3 years in prison |
| Opening profiles or adverts with your image causing harassment | 172 ter.5 | 3 months to 1 year in prison or a fine |
The offences in articles 197 and 197 bis are only prosecuted if the person affected files a complaint, under article 201 of the Criminal Code, unless they affect a plurality of people or the general interest. If you do not report it, there is no criminal case, however much the platform or the police know about it. The fraud against your contacts, on the other hand, is a public offence and is prosecuted as soon as anyone brings it to the authorities.
The first hours, what you can do today
The signs are well known. Login emails from a city you have never been to, being suddenly logged out on your phone, a change of recovery email or phone number you did not make, contacts writing to you on WhatsApp about a message you never sent, campaigns running in a business manager you have not touched. On Discord the usual pattern is that the account starts sending “free Nitro” or “try my game” links to every server you belong to.
If you can still log in, change the password, close every open session from the security settings and review the apps and devices with access. If you cannot log in because the attacker has already changed the email, phone and password, use the platform’s compromised account form, which Facebook keeps at facebook.com/hacked and X and Discord keep in their help centres, and do not waste time on the so-called “recovery services” offered over Telegram or by private message, because they are a second scam.
What matters for everything that comes afterwards is what you keep. Do not delete the login alert emails, even if they look like spam, because they carry the date, the time and sometimes the IP and the device. Take screenshots of everything you see in the account before cleaning it up, including the messages the attacker sent to your contacts. Ask those contacts to forward you the conversations and the payment receipts if they paid. If a card was linked, keep the charges as they appear on the statement. And if the Facebook account also opened Instagram, or the Discord account was linked to Steam, Xbox or PlayStation, change those credentials the same day, because the attacker has them within reach.
Then switch on two-step verification with a code app rather than SMS and review third-party app permissions. Those measures protect you for the future. None of them replaces what follows.
Where to report it and what to bring
The complaint can be filed with the National Police, the Guardia Civil or directly at the duty examining court, under articles 259 and following of the Criminal Procedure Act. You do not need to know who did it or where they acted from. The National Police accepts online complaints for some offences, but in cases involving money I prefer the police station, because it allows you to submit documents and request specific investigative steps from the outset.
You can report it in A Coruña even if the attacker is in another province or another country. For offences committed online, the Supreme Court applies the ubiquity criterion, under which the offence is deemed committed in every place where any of its elements occurs, and in practice the court of the place where you suffered the harm and where the first complaint was filed conducts the investigation.
Bring, printed or on a device, the platform’s alert emails, the screenshots of the account and of the messages sent to third parties, the list of affected contacts with their details and the payment receipts they have given you, the statement showing the card charges and the platform’s replies, including the automated ones. The IP addresses and session identifiers in the alerts are the first thing the police ask the platform for, and having them already in the complaint saves weeks.
As for time limits, unlawful access and ordinary fraud become time-barred after five years, and fraud under 400 euros, which is a minor offence, after one year. That does not mean you have five years to think about it, because connection data is kept by operators for twelve months and by platforms for considerably less. Reporting in the first week and reporting six months later produce very different results.
If your contacts have been scammed from your account
The most common pattern on Facebook and X is the message to a friend asking for an urgent Bizum transfer, a loan or the purchase of a gift card with a plausible excuse. On Discord you can add the link that downloads a programme stealing the session and the sale of game accounts or virtual items that never arrive. The person who pays makes a mistake, but the offence is committed by the attacker, who is liable for fraud under articles 248 and 249 of the Criminal Code, with six months to three years in prison if the amount exceeds 400 euros and a fine if it does not. Where the number of victims is high or the total exceeds 50,000 euros, article 250 raises the penalty to one to six years in prison.
The question I am asked most often is whether the account holder is liable for what their friends paid. No. You are the victim of the unlawful access and bear no criminal or civil liability for what a third party did with your identity, unless you took part or consented. What you should do is warn your contacts as soon as possible through another channel and ask them to file their own complaints, each for their own payment, because it is the payer’s complaint that allows the receiving account to be traced. If any of them paid by card or transfer, they should read how to get a refund from the bank after a scam before writing the money off, and if the payment went through Bizum, what to do after a Bizum scam.
There is one situation worth keeping in mind. Sometimes the attacker does not ask for money for himself but asks one of your contacts to receive a transfer and forward it to another account “because my bank has blocked me”. Whoever agrees becomes a money mule and may end up investigated for money laundering under article 301 of the Criminal Code, which is punishable even through gross negligence. If this has happened to someone around you, they should speak to a lawyer before giving a statement, not after.
The company account, the advertising and the linked card
Business pages and Meta business managers are a preferred target because they have a payment method attached. The attacker launches campaigns on your card, often adverts for cryptocurrency or counterfeit products, and can burn through thousands of euros in a weekend. On top of the penalty for the access and the fraud, the attacker is civilly liable for all the damage caused, under articles 109 and following of the Criminal Code, which includes the advertising charges, the sales lost while the page was out of your control and the harm to the brand’s reputation if it was used to deceive customers. That compensation is set in the criminal proceedings themselves if the perpetrator is identified, or claimed through the civil courts.
The card charges are transactions you did not authorise, and payment services rules oblige the bank to refund them unless it proves you acted with gross negligence. Meta, for its part, has an internal procedure for disputing advertising charges on compromised accounts. How each of those two claims is framed, in what order and with what documents, is the lawyer’s job, because a badly drafted letter to the bank becomes the argument the bank will later use to refuse.
At the firm we act as private prosecutor and conduct the civil claim in these matters from the first complaint, and we usually come in when the company account has been out of control for days and the platform is not responding. You can see what we do under cybercrime and bank fraud.
What you can demand from Meta, X or Discord
Platforms are not liable for the hack itself, but they have specific obligations most users are unaware of. Regulation (EU) 2022/2065, the Digital Services Act, requires hosting providers to maintain mechanisms for notifying illegal content (article 16) and online platforms to operate an internal complaint-handling system (article 20) against their decisions, including decisions to suspend or terminate an account, with a response that cannot be solely automated. Article 21 adds the option of taking the matter to a certified out-of-court dispute settlement body when the internal complaint fails. In Spain the digital services coordinator is the Comisión Nacional de los Mercados y la Competencia.
Added to that is article 16 of Law 34/2002 on information society services, which exempts the hosting provider from liability only while it has no actual knowledge of the illegal content. A formal notification, with the police complaint attached, changes its position. If it keeps the fraudulent adverts or the cloned profile live after receiving it, it may be liable for the damage that continues to occur.
Then there is data protection. The General Data Protection Regulation gives you the right of access to the data the platform holds on your account (article 15), including login records, and the right to erasure (article 17) of content published without your consent. The Spanish Data Protection Agency accepts complaints when the platform fails to honour those rights. Article 33, which obliges the controller to notify security breaches to the authority within 72 hours, applies when the breach is on the platform’s side, not when access is gained with your stolen credentials, although it does come into play in mass data leaks.
What can be obtained through these routes is the return of the account, the removal of the content and the adverts, the access data that will later serve in court and, in some cases, compensation under article 82 of the Regulation. In what order and with what submissions this is put to Meta Platforms Ireland, which is the entity that answers in the European Union, is part of the professional engagement.
Photos, private messages and third parties’ data
If the attacker has published or sent to others your photos, your conversations or the data of people who appeared in your messages, the offence is no longer the access but the disclosure under article 197.3, with two to five years in prison, in the upper half if the data concerns health, sex life, ideology or minors, under paragraph 5. Intimate images shared without permission also have their own offence under article 197.7. If what you receive are demands for money in exchange for not sharing them, the offence is a different and more serious one, and you should seek advice straight away.
Against the platform, the right to erasure under article 17 of the General Data Protection Regulation obliges it to remove that content without delay. Against the attacker, every act of dissemination gives rise to compensable moral damage, quantified in the criminal case. Keep the URLs of the posts, the screenshots with the date visible and the usernames of those who shared them. That material is what allows the court to ask the platform to identify the profiles involved, and it disappears as soon as the platform takes the content down.
When the perpetrator is not identified and the case is closed
A share of these complaints end in a provisional dismissal under article 641 of the Criminal Procedure Act, because the attacker operated from outside the European Union, used an anonymous network or the platform took longer than the records last. Provisional dismissal does not end the matter. The case is reopened if new information emerges, and it is common for the same group to fall in another investigation months later and for the earlier complaints to be joined to it.
Nor does the dismissal affect the other claims. The complaint with its police report number and the dismissal order serve just as well against the bank for the unauthorised charges, against the platform for the return of the account and before the Data Protection Agency. They are the documents that prove there was unlawful access and that you acted in time.
As for computer forensic reports, which some companies offer as a first step, my view is that they are only worthwhile when a high amount is in dispute, when the bank or the platform maintains that the transaction came from your device, or when the attacker is someone close to you and it is necessary to prove where they acted from. For a personal account with a couple of contacts deceived, the police report and the platform’s records are enough, and the forensic report costs more than what is at stake.
What you risk on your own and what we do
If you handle it on your own, the specific risk is twofold. First, that the claim to the bank for the card charges is badly framed and the bank uses it to argue that you were negligent. Second, that the complaint is filed without the connection data and without the affected contacts, so that by the time the police ask for them they no longer exist. At the firm we act as private prosecutor in cybercrime cases, conduct the civil claim for damages and put the claims to the platform and the payment institution in an order that does not undermine one with the other. You can see the detail under cybercrime and bank fraud. Call +34 677 841 007 or write through the contact page. Have ready the platform’s alert emails, the screenshots of the account and of the messages sent to third parties, the list of affected contacts with what each one paid, the statement with the charges and any reply you have received from Meta, X or Discord. With that on the first call we know which route to open and how much can be recovered.
Frequently asked questions
Is it an offence to have my Facebook hacked even if nothing was stolen?
Yes. Getting into someone else’s account by defeating its security measures is the offence of unlawful access under article 197 bis of the Spanish Criminal Code, punishable by six months to two years in prison, even if the attacker does nothing afterwards. For it to be prosecuted you have to report it, because it is an offence that is only investigated at the request of the person affected.
If my friends have been scammed from my account, do I have to pay them back?
No. You are the victim of the access and are not liable for what a third party did with your identity, unless you took part. The attacker is the one who is liable. What you should do is warn them through another channel, ask each of them to report their own payment and to claim from their bank, because the transfers and charges from a scam can be recovered in many cases.
Can I take action against Meta if it does not return my account or takes months?
Yes. The Digital Services Act requires platforms to have an internal complaint system with a non-automated response and allows you to go to an out-of-court dispute settlement body if they do not respond. The Data Protection Regulation also gives you the right to access your account records and to demand the erasure of content published without your permission. If the platform keeps fraudulent adverts or profiles live after receiving a formal notification, it may be liable for the damage.
Do I need a lawyer for this or can I do it on my own?
It depends on what is at stake. If you have recovered the account, nobody has paid and there are no charges on your card, a complaint at the police station with the screenshots and the alert emails is enough. A lawyer makes sense when money has been lost by your contacts or your company, when adverts or purchases have been charged to your card, when private photos or data have been shared, or when the platform will not return an account your business depends on. In those cases the order in which you claim from the bank, the platform and the court decides how much you recover.