Skip to content

Security1 publisher2 min readPublished

UK police push passkeys as account-takeover losses climb to £6.3m

The UK's Report Fraud service is urging the public onto passkeys after email and social media takeover losses rose to £6.3m in 2025/6 from £1.2m. The NCSC is backing the switch as a defence against phishing.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Reports of email and social media account takeover rose 34% over the same year, a much slower climb than the money lost.
  • Report Fraud named impersonation of family and friends as one of the most common ways criminals cash in on a hijacked account.
  • Criminals also use hacked accounts to sell tickets that do not exist for sold-out shows.
  • Passkeys are tied to the legitimate website, and the private key stays on the user's device even if that website is breached.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Security teams moving staff and customer logins to passkeys can now cite a police-led public campaign and the NCSC making the same recommendation for personal accounts.
  • exposure Wolf counts colleagues among the people one hijacked account can reach, so staff personal email and social accounts are a route into the workplace that employers do not secure.
  • constraint The release, as reported, does not say how the accounts were first compromised, so it cannot show what share of the £6.3m passkeys would have stopped.

More takeovers are being reported, and each one is producing much more money. Losses grew 5.25 times while reports grew 34% [13][3]. Each report in 2025/6 therefore carried about 3.9 times the loss of a report a year earlier [14]. The ratio is per report, not per victim.

The money comes from the trust attached to the account. In one popular version, the criminal poses as the account owner and pretends to be in trouble so the victim sends funds [5]. "What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud," said Chief Superintendent Amanda Wolf, head of Report Fraud operations [8].

The Lloyds Bank figure quoted alongside the Report Fraud data measures something else. In November 2024 the bank said 70% of concert ticket scams reported since August involved Oasis, with victims losing £346 on average and up to £1,000 in some cases [7]. That covers concert ticket fraud in general. It does not size the account-takeover problem.

Passkeys deal with the takeover itself. There is no password for a criminal to guess or steal, and the passkey is cryptographically tied to the legitimate website [9][10]. The NCSC puts its case in terms of phishing. "Passkeys are simpler, faster and more secure to use, raising our national resilience against phishing attacks whilst leaving password headaches behind," said Jonathon Ellison, director for national resilience at the National Cyber Security Centre [11].

The data on password habits comes from a vendor. A NordVPN survey of 4,896 UK participants, published on October 6, found 96% answered its question on creating a strong password correctly, but only 16% knew to store one in a password manager [12].

What to watch

  • Whether Report Fraud publishes how the accounts were first taken (phishing, password reuse or another route), which would show how much of the £6.3m passkeys address.
  • Whether next year's figures show loss per report still rising after the passkey campaign has run.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories