UK account-hack losses surge as new reporting system exposes hidden cases | #cybercrime | #infosec


Reported losses tied to hacked email, social media and other online accounts in Britain rose 417% over the last financial year, although police say much of the jump reflects changes in how incidents are reported rather than a sudden fivefold increase in attacks.

In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier. The number of victims reporting a financial loss rose from 226 to 2,325, an increase of 929%.

Despite the increases, the figures likely represent a small fraction of total cybercrime losses because they rely on voluntary self-reporting.

The increases coincide with the rollout of Report Fraud, the national service that replaced the widely criticized Action Fraud system in a formal launch in January. Onlookers widely believed the shortcomings of Action Fraud suppressed the total number of victim-reported crimes.

In an indication that this hurdle has been cleared, police said 92% of the account-hacking reports involving a financial loss were recorded in the second half of the financial year, directly overlapping with the move to the new platform.

The police cautioned this improvement makes direct comparisons with the previous year less straightforward, as some of the increase reflects more incidents being identified and recorded rather than necessarily matching a real-world rise in offenses.

Unlike its predecessor, Report Fraud was designed to collect more useful information from victims and the private sector, allowing police to identify patterns and give law enforcement and other agencies a clearer picture of a crime problem that has long been considered underreported.

The change comes as the British government tries to overhaul its broader response to fraud. In March, it unveiled a strategy that places more responsibility for stopping scams on telecom companies, technology platforms and financial firms.

Fraud has become the most common crime in England and Wales, accounting for roughly 40% of offenses measured by official surveys. Police estimate that more than two-thirds of that fraud is cyber-enabled — meaning technology is used to carry out or scale the crime, even when the underlying offense is not itself a hacking crime.

Report Fraud separately counts cyber-dependent crimes — offenses such as hacking and malware that could not take place without computer networks — and said it received 64,608 reports in that category during 2025-26, up 34%, with account hacking by far the largest part of that total, accounting for 44,355 reports.

Reported losses from those cyber-dependent crimes rose 90% to £14.3 million ($19.3 million), with the average loss per victim increasing to £220 ($309) from £155 ($209).

The category of cyber-dependent crimes does not represent the total cost of fraud committed online by cybercriminals. Investment scams, payment diversion, online shopping fraud and bank-account fraud are counted in separate fraud categories, even when digital tools play a central role in how they are committed. Across those categories, Report Fraud recorded £3.2 billion ($4.3 billion) in reported losses during the year, up more than a quarter.

The assessment notes that hacking and fraud can be recorded separately even when they are part of the same incident. A victim whose email account is compromised and then used to facilitate a scam may report the fraud without knowing the account was hacked, meaning the financial loss is recorded under the fraud rather than the initial compromise.

Organizations accounted for 2,271 cybercrime reports. Where the size of the organization was known, small and medium-sized businesses made up 62% of cases. Police said smaller firms often have fewer resources for cybersecurity and can also be used as a route into larger companies through suppliers and other business relationships.

The assessment acknowledged that ransomware figures were harder to draw conclusions from. Report Fraud received 323 reports during the year, down 25% from 430, but police said ransomware attacks are reported through several different channels and warned that the decline may reflect underreporting rather than fewer attacks.

Proposals in Britain to introduce mandatory reporting of ransomware attacks and payments are currently stalled following a government consultation last year. That consultation followed a series of high-profile ransomware incidents affecting the country, including several that left multiple high-street grocery store shelves empty and one that contributed to the death of a hospital patient in London.

Separate figures from the Information Commissioner’s Office recorded 452 ransomware-related data breaches between the second and fourth quarters of 2025. Although the datasets ultimately derive from the same criminal activity, they measure different things — the ICO records data protection breaches, while Report Fraud records crime reports — again complicating a direct comparison.

Back in 2023, British authorities said they were “increasingly concerned” that ransomware victims in the country are keeping incidents secret. “If attacks are covered up, the criminals enjoy greater success and more attacks take place,” the National Cyber Security Centre said at the time.



Click Here For The Original Source.

——————————————————–

..........

.

.