UK Sees Staggering 417% Rise in Hacked Account Losses Amid Reporting Overhaul
The UK has reported a dramatic 417% surge in financial losses linked to hacked online accounts, totaling Β£6.3 million in the last financial year. This significant increase, however, largely reflects improved reporting mechanisms following the launch of the new **Report Fraud** service, rather than an equivalent spike in actual incidents. The new platform aims to provide a clearer picture of the nation's pervasive cybercrime challenge.
Reported financial losses stemming from compromised email, social media, and other online accounts in Britain soared by 417% over the past financial year. Despite this alarming figure, authorities attribute much of the increase to changes in how incidents are reported, rather than a fivefold rise in attacks.
In its inaugural annual assessment, published Friday, the **City of London Police** revealed that victims lost Β£6.3 million ($8.5 million) to account hacks in the year ending March 31, a substantial jump from Β£1.2 million ($1.6 million) the previous year. The number of affected victims reporting a financial loss also surged by 929%, from 226 to 2,325.
### The Impact of Improved Reporting
These significant increases coincide with the rollout of **Report Fraud**, the national service that formally launched in January, replacing the much-maligned **Action Fraud** system. Experts widely believed that the shortcomings of **Action Fraud** suppressed the true number of victim-reported cybercrimes.
Indicating the success of the new platform, police noted that 92% of the account-hacking reports involving financial loss were recorded in the second half of the financial year, directly aligning with the **Report Fraud** launch. While this improvement is crucial for data collection, it complicates direct year-on-year comparisons, as more incidents are now being identified and recorded.
Unlike its predecessor, **Report Fraud** is designed to gather more comprehensive information from victims and the private sector. This enhanced data collection enables law enforcement and other agencies to identify crime patterns more effectively, offering a clearer understanding of a problem long considered underreported.
### Broader Anti-Fraud Strategy
This shift in reporting comes as the British government works to overhaul its broader response to fraud. In March, it unveiled a new strategy that places greater responsibility on telecom companies, technology platforms, and financial firms to prevent scams.
Fraud has become the most prevalent crime in England and Wales, accounting for approximately 40% of offenses measured by official surveys. Police estimate that over two-thirds of this fraud is cyber-enabled, meaning technology is used to facilitate or scale the crime, even if the underlying offense isn't a direct hacking incident.
### Cyber-Dependent Crimes on the Rise
**Report Fraud** separately tracks cyber-dependent crimesβoffenses like hacking and malware that are impossible without computer networks. The service received 64,608 reports in this category during 2025-26, a 34% increase. Account hacking was by far the largest component, with 44,355 reports.
Reported losses from these cyber-dependent crimes rose by 90% to Β£14.3 million ($19.3 million), with the average loss per victim increasing from Β£155 ($209) to Β£220 ($309).
It's important to note that the category of cyber-dependent crimes does not encompass the total financial impact of online fraud. Investment scams, payment diversion, online shopping fraud, and bank-account fraud are categorized separately, even when digital tools are central to their execution. Across these broader fraud categories, **Report Fraud** recorded Β£3.2 billion ($4.3 billion) in reported losses during the year, an increase of more than a quarter.
### Overlapping Incidents and Organizational Impact
The assessment highlights that hacking and fraud can be recorded separately even when part of the same incident. For instance, a victim whose email account is compromised and then used to facilitate a scam might report the fraud without knowing their account was initially hacked. In such cases, the financial loss is attributed to the fraud rather than the initial compromise.
Organizations accounted for 2,271 cybercrime reports. Where the organization size was known, small and medium-sized businesses (SMBs) comprised 62% of cases. Police noted that smaller firms often have fewer cybersecurity resources and can also serve as entry points into larger companies through supply chains and other business relationships.
### Ransomware Reporting Challenges
Figures for ransomware were more challenging to interpret. **Report Fraud** received 323 reports during the year, a 25% decrease from 430. However, police cautioned that ransomware attacks are reported through various channels, suggesting the decline might indicate underreporting rather than a genuine reduction in attacks.
Proposals in Britain to introduce mandatory reporting of ransomware attacks and payments are currently stalled following a government consultation last year. This consultation followed a series of high-profile ransomware incidents that impacted the country, including attacks that led to empty grocery store shelves and one that tragically contributed to a hospital patient's death in London.
Separate data from the **Information Commissionerβs Office (ICO)** recorded 452 ransomware-related data breaches between the second and fourth quarters of 2025. While these datasets stem from the same criminal activity, they measure different aspects (ICO records data protection breaches, while **Report Fraud** records crime reports), further complicating direct comparisons.
In 2023, British authorities, including the **National Cyber Security Centre (NCSC)**, expressed increasing concern that ransomware victims were keeping incidents secret. The NCSC warned that "If attacks are covered up, the criminals enjoy greater success and more attacks take place."