A sharp rise in losses linked to hacked email and social media accounts has prompted the UK’s Report Fraud service to launch a public campaign encouraging users to switch to passkeys.
The service said cybercrime linked to email and social media hacking generated £6.3 million ($8.3 million) in stolen funds in 2025/26, compared with £1.2 million ($1.6 million) the previous year. Reports of this type of account takeover also increased by 34% during the same period.
Report Fraud did not provide detailed information on how criminals monetise access to compromised accounts. However, impersonating family members and friends remains one of the common methods. In many cases, criminals pose as the account owner and claim to be in trouble to persuade contacts to send money.
Hacked accounts are also used in ticket scams, where criminals offer fake tickets for sold-out events. In November 2024, Lloyds Bank said 70% of reported concert ticket scams since August were linked to Oasis. Victims lost an average of £346 ($449), with some losing as much as £1,000 ($1,300).
“For most people, being hacked isn’t just a cyber issue, it’s personal. It can leave victims locked out of important accounts, worried about what information has been accessed, and concerned that criminals may use their identity to target others,” said chief superintendent Amanda Wolf, head of Report Fraud operations.
“What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud.
Report Fraud is therefore recommending passkeys as an added layer of account protection. Passkeys do not rely on passwords that can be guessed or stolen. Users authenticate through a device PIN or biometric method such as facial recognition.
Passkeys are cryptographically linked to legitimate websites. Even if a website is breached, attackers cannot access the user’s private key stored on the device.
“Passkeys are simpler, faster and more secure to use, raising our national resilience against phishing attacks whilst leaving password headaches behind,” said Jonathon Ellison, director for national resilience at the National Cyber Security Centre (NCSC).
New survey data also shows gaps in password security. Among 4,896 UK participants surveyed on October 6, 96% correctly identified how to create a strong password, but only 16% knew how to store one safely using a password manager.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


