Report Fraud is urging the public to protect their online accounts after stolen sums from email and social media hacking surged by 417 per cent in the last year.
Reported stolen sums from email and social media account hacking rose in the 2025/26 financial year to £6.3 million, up from £1.2 million in 2024/25.
This type of hacking remains the most reported form of cyber crime in the UK, with the number of reports also increasing by a third (34 per cent) from the previous year. Other types of hacking were also identified within reports, including gaming and streaming account takeovers, as well as the compromise of travel and online delivery accounts.
As part of Cybersecurity Awareness Month, Report Fraud has today (5 October 2026) launched an awareness campaign, urging the public to protect their online accounts from hackers by switching to passkeys and securing accounts.
Hacking, in the context of online accounts, refers to criminals gaining unauthorised access someone’s email, social media, or other online account to commit further fraudulent activity such as impersonating the account owner to defraud family and friends by asking for money or offering fake tickets.
One of the most common themes identified from reports is compromised accounts being used to impersonate family members and friends.
Chief Superintendent Amanda Wolf, Head of Report Fraud Operations, said:
“For most people, being hacked isn’t just a cyber issue, it’s personal. It can leave victims locked out of important accounts, worried about what information has been accessed, and concerned that criminals may use their identity to target others.
“What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud.
“The good news is that there are simple steps people can take to protect themselves. Switching to passkeys and enabling two-step verification adds a strong extra layer of security and makes it much harder for criminals to gain access to your accounts.”
Jonathon Ellison, Director for National Resilience at the National Cyber Security Centre (NCSC) said:
“We know that most cyber harm to individuals starts with criminals attempting to steal login details, which is why we strongly encourage users to choose passkeys where they are available across digital services and use two-step verification where they aren’t.
“Passkeys are simpler, faster and more secure to use, raising our national resilience against phishing attacks whilst leaving password headaches behind.
“Reporting scams is an effective way to make yourself a harder target to cyber criminals and protect others too. Cyber security is a shared responsibility, and the NCSC provides a range of resources and support to help everyone stay safe online.”
Maureen Costello, Vice President, UKI and SSA – Google Cloud, said:
“For over two decades, Google has been dedicated to protecting people from online scams and fraud. Beyond technical protections, empowering users to spot risks and secure their accounts is essential to online safety. We strongly support the UK authorities’ campaign and look forward to partnering across the industry to keep citizens safe online.”
Nathaniel Gleicher, Global Head of Counter Fraud and Director of Security Policy at Meta, said:
“Scammers are relentless, and they often hack people’s accounts to run their scams. That’s why we’re constantly rolling out new protections to keep people safe and shut threat actors out.
“Passkeys are resistant to guessing or theft by criminals, or exploit via malicious websites or scam links. This makes them a powerful defence against common account takeover tactics.
“We’re proud to work with partners including the City of London Police and Report Fraud, to promote stronger account security.”
Dr Elisabeth Carter, Criminologist and Forensic Linguist at Kingston University, said:
“The financial and psychological impacts of social media and email hacking ripple well beyond the initial harm. When victims have their identity stolen through hacking, it can then be used as the very tool that criminals need to target, gain trust and then harm that person’s friends, family and trusted contacts. This increases the financial harm, exposes many others to identity theft and compounds the psychological harms to the original victim beyond the initial hack, knowing that it was their identity that convinced their contacts to respond.”
Protect yourself from being hacked:
Use passkeys wherever they are available. They are more secure and easier to use.
- Where passkeys are unavailable, use strong passwords, for example generated by a password manager.
- You should also enable 2 Step-Verification if you can.
Who has access to the content you’re posting?
- Make sure your privacy settings are configured so that it’s only visible to the people you want to see it, for example only your friends.
Beware of sharing personal details online:
- try not to share too many personal details that a fraudster could use to build a picture of you. They can use facts, such as your birthday, where you live, family relationships or pet names to steal your identity or make their fraud more convincing.
If you are contacted by someone you know via social media or email:
- don’t automatically trust that person is who you think they are. Contact them through another route, such as in person, by sending an SMS or phoning them.
For anyone who has already been hacked:
- If you have been hacked, tell Report Fraud by making a report at reportfraud.police.uk or by calling 0300 123 2040. If you live in Scotland, cyber crime is reported to Police Scotland directly on 101.
- The UK’s National Cyber Security Centre has published guidance explaining what you can do to minimise the damage, and how you can regain access to your accounts. You can find this here: https://www.ncsc.gov.uk/guidance/recovering-a-hacked-account
Click Here For The Original Source.
