Skip to content

Leadership1 publisher2 min readPublished

UK losses to hijacked email and social media accounts rose fivefold to 6.3 million pounds

Reported losses to criminals who hijack UK email and social media accounts reached 6.3 million pounds in 2025-26, up from 1.2 million, police data shows. The base is small, but fraud that borrows a person's identity gives employers a reason to review how staff log in.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying UK losses to hijacked email and social media accounts rose fivefold to 6.3 million pounds
Generated illustration

What happened

  • In many cases the hijackers use the stolen identity to sell fake tickets, such as for sold-out gigs, to the account owner's friends and family.
  • A related con, dubbed the 'Hi mum' scam, uses WhatsApp or text messages from someone posing as a child or relative in an emergency who urgently needs cash.
  • Santander customer data shows fraudsters posing as someone's son extract the most cash, followed by those posing as a daughter.
  • Report Fraud is launching an awareness campaign urging the public to protect online accounts by switching to passkeys where they are available.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure Employees become reachable through personal email and social accounts their employer does not manage, since Report Fraud says hijackers turn one compromised account against colleagues.
  • decision Moving staff logins to passkeys removes the password a hijacker would steal, at the cost of tying each login to a person's device and biometrics.
  • precedent With the national fraud reporting service now recommending passkeys to the public, an employer still running password-only staff logins will find that harder to defend after a takeover.

The rise is large in proportion and small in money. Reported losses grew 5.25 times, an increase of 425%, adding about 5.1 million pounds in a year [1][2]. The figures come from Report Fraud, the service run by the City of London police, which holds national responsibility for economic crime [2]. The Guardian notes that the true total may be much higher, because many victims do not report, often out of embarrassment and sometimes because their own loss was small [3]. The published figures do not split business victims from personal ones, or say whether reporting habits changed between the two years.

The fraud works by borrowing a relationship. In a case the Guardian reported earlier, hackers took over a music fan's Instagram account, advertised tickets to an Oasis gig in her name and took 1,400 pounds from her friends [5]. She said they "impersonated her so well that her friends and family genuinely thought they were speaking to her" [6]. The money came from people who were paying someone they believed they knew.

A finance director could fairly say that 6.3 million pounds across the whole country is a small number, and that an employee's Instagram account is the employee's problem. The first point holds on these figures. The second is harder to sustain given how Ch Supt Amanda Wolf, head of Report Fraud operations, describes the spread [10]. She said what starts with one compromised account "can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud" [9]. I think that supports adding account takeover to staff awareness training. On this data it does not support a large new security budget line, because the figures count reported losses from people's own accounts [1].

Sequencing is the practical question for this quarter. Two annual figures show a jump; a third year would show whether it is a trend [1]. Moving company accounts to passkeys deals with the logins an employer controls [12]. Staff's personal email and social media accounts stay outside that control. The impersonation that runs through them is handled by teaching people to check an unexpected request from a familiar name, and that work continues after any login change is finished.

What to watch

  • Report Fraud's figures for 2026-27, which would show whether the jump from 1.2 million to 6.3 million pounds continues from the higher base.
  • Any split of account-takeover losses between business and personal victims, from Report Fraud or from banks such as Santander.
  • Evidence of passkey take-up after the Report Fraud campaign, and whether reported losses move with it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories