The amount stolen through email and social media hacking in the UK surged to £6.3 million during the 2025-26 financial year, marking a more than fivefold increase compared to £1.2 million reported the previous year. This rise comes amid a broader surge in cybercrime, with hacking of email accounts remaining the most commonly reported type in the country and victim numbers climbing by 34%.
The increase in cyber fraud has prompted authorities to launch a public awareness campaign during Cybersecurity Awareness Month aimed at urging consumers to better protect their online accounts. Report Fraud, a national anti-fraud organisation, emphasised the importance of adopting stronger security measures such as passkeys and two-step verification to help prevent unauthorised access.
Hacking, which involves criminals breaching email, social media, or other digital accounts, is often used as a means to impersonate victims. Fraudsters exploit these compromised accounts to deceive family and friends into sending money or purchasing fraudulent offers like fake tickets. One recurring pattern noted by authorities is the use of stolen accounts to target the victim’s personal network, increasing the scope and impact of the fraud.
Chief Superintendent Amanda Wolf, head of operations at Report Fraud, highlighted the personal toll of such attacks, pointing out that hacking can leave individuals locked out of vital accounts while raising concerns about sensitive information being accessed or misused. She noted that fraudulent activity stemming from one compromised account can quickly expand to affect loved ones and colleagues, exploiting trust to carry out further scams.
Wolf urged the public to take proactive steps to safeguard their online presence, specifically recommending the widespread adoption of passkeys and enabling two-factor authentication. These security measures create additional barriers for criminals trying to gain account access, significantly reducing vulnerability.
Jonathon Ellison, director for national resilience at the National Cyber Security Centre, echoed these recommendations, underscoring that many individual cyber incidents start with attempts to steal login credentials. Ellison encouraged users to choose passkeys wherever possible, calling them more secure, quicker, and easier alternatives to traditional passwords. He also stressed the role of these technologies in enhancing the country’s overall resilience to phishing and other cyber threats, helping individuals avoid the difficulties often associated with managing passwords.
The recent spike in online account hacking highlights the growing challenges in digital security and underscores the need for users to remain vigilant and employ robust protections to safeguard their personal information.
