Cybercrime linked to email and social media hacking netted scammers £6.3m in 2025/6 — a jump from £1.2m the year before — according to the UK’s Report Fraud service, which has launched a public campaign urging internet users to switch to passkeys.
Report Fraud's passkey campaign
The Report Fraud service has begun a public awareness drive that focuses on passkeys as an alternative to passwords. The campaign follows an increase in account-takeover reports and larger sums stolen from victims. Report Fraud framed the issue as personal and cascading: “For most people, being hacked isn't just a cyber issue, it's personal. It can leave victims locked out of important accounts, worried about what information has been accessed, and concerned that criminals may use their identity to target others,” said chief superintendent Amanda Wolf, head of Report Fraud operations. “What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud.”
Scale of 2025/6 account-takeover losses
Report Fraud disclosed that scams tied to email and social media account takeovers produced £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) in the previous year. The number of reports for this type of account takeover rose by a third (34%) over the same period. The service did not provide an exhaustive breakdown of monetisation routes but highlighted the growing financial impact and volume of incidents.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildImpersonation and ticketing scams as primary monetisation tactics
Report Fraud identified impersonation of family and friends as one of the more common fraud techniques using hacked accounts. Impersonation can take various forms; one common tactic is to have the account owner appear to be in urgent trouble and to trick contacts into sending funds. Opportunistic scammers also use hacked accounts for ticketing scams, selling non-existent tickets for sold-out events to desperate buyers. Lloyds Bank warned in November 2024 that 70% of all reported concert ticket scams since August were related to Oasis, with victims losing an average of £346 ($449), rising to £1000 ($1300) for some.
How passkeys work, according to the NCSC
Report Fraud and the National Cyber Security Centre recommend passkeys as a defensive measure. The source explains why passkeys are harder for scammers to exploit: there is no password to guess or steal; the user logs in via a device PIN or biometric like a face scan; passkeys are cryptographically tied to legitimate websites; and even if a website were breached, a hacker would not have access to the user’s private key, which stays on their device. Jonathon Ellison, director for national resilience at the NCSC, argued: “Passkeys are simpler, faster and more secure to use, raising our national resilience against phishing attacks whilst leaving password headaches behind.”
Password knowledge: the NordVPN survey
Complementing the official advice, data from NordVPN published on October 6 shows a mismatch between users’ theoretical knowledge and practical behaviour. Out of 4,896 UK participants, 96% correctly answered the firm’s question on creating a strong password, but only 16% knew how to store one safely (i.e. in a password manager). That gap — high awareness of what a strong password is, low awareness of safe storage — is central to Report Fraud’s argument for moving away from password-centric authentication.
What this means for end users, Lloyds Bank, and scammers
- End users: The campaign urges individuals to adopt passkeys and reduce reliance on passwords and unsafe storage habits. The Report Fraud messaging stresses the personal consequences of a compromised account and the chain effect on friends and family.
- Lloyds Bank and consumer-facing firms: Financial institutions that track scam trends will note the ticketing-scam figures and the losses reported by victims; previous warnings from Lloyds Bank about concert ticket scams underline the continuing financial harm when hacked accounts are monetised.
- Scammers: The Report Fraud and NCSC narrative points to a tactical shift for defenders — hardening authentication with passkeys removes profitable avenues such as account impersonation and resale of non-existent tickets that depend on reusable or phishable credentials.
The combined picture from Report Fraud, the NCSC and the NordVPN survey is straightforward: account takeovers have grown in both frequency and monetary impact, standard password practices remain uneven, and passkeys are being promoted as a practical barrier to the specific scams detailed. Whether the public adopts passkeys at scale — and whether that adoption materially reduces the £6.3m-plus losses recorded in 2025/6 — is the next measurable outcome the authorities are betting on.




