Reported sums stolen following email and social-media account hacking reached £6.3m during the 2025/26 financial year, up from £1.2m a year earlier, according to Report Fraud.
The increase represents a 417% rise in the amount reported stolen. The number of hacking reports increased by 34% over the same period, a separate measure that shows losses grew considerably faster than report volumes.
Email and social-media account hacking remains the most frequently reported form of cyber crime to the national service. Compromised gaming, streaming, travel and delivery accounts also appeared in reports during the year.
The attraction for criminals extends beyond the account itself. Taking control of an established email address or social profile gives an attacker access to an identity that colleagues, customers, suppliers or personal contacts may already trust. That can make subsequent requests for credentials, money or altered payment details more convincing.
Report Fraud, which is run by City of London Police, has launched a campaign encouraging wider use of passkeys. Unlike conventional passwords, passkeys use cryptographic credentials stored through a user’s device or credential provider and are designed so they cannot simply be typed into a fraudulent login page.
The National Cyber Security Centre recommends enabling passkeys as a priority on business-critical accounts where the service supports them. Its guidance identifies banking and finance systems, HR and payroll platforms, social media, online storage, company websites and point-of-sale software among the accounts where compromise can expose sensitive information or interrupt operations.
Passkeys are particularly useful against phishing because there is no reusable password for an employee to disclose to a fake site. Where passkeys are not available, the NCSC continues to recommend strong, unique passwords backed by two-step verification.
The control issue reaches well beyond an IT team. Marketing employees and agencies can manage corporate social accounts, finance teams depend on email for supplier correspondence, HR platforms hold employee information and senior executives may have privileged access across several external services. A compromised identity in any of those areas can become a route into a wider fraud attempt.
That risk is already visible in payment diversion. City of London Police said in September that more than £101m had been reported stolen through payment diversion fraud during 2025/26. Such attacks can involve criminals compromising or impersonating an email account and then redirecting a genuine payment to an account they control.
Passkeys cannot remove every route to account takeover. Recovery processes, legacy credentials, unmanaged devices and services without passkey support can all leave weaknesses. Businesses also need controls around account ownership, privileged access and what happens when an employee or supplier relationship ends.
The latest loss figures nevertheless strengthen the case for treating digital identity as part of fraud prevention rather than simply password hygiene. When communications, supplier instructions and financial decisions depend on recognising a trusted account, control of that account can carry direct financial value.





You must be logged in to post a comment.