A Sharp Spike in Identity-Based Fraud
Official figures released by the City of London police's Report Fraud service — the unit holding national responsibility for economic crime in the United Kingdom — reveal a dramatic escalation in losses tied to email and social media account takeovers. The reported value of stolen funds climbed to £6.3 million during the 2025-26 financial year, compared with just £1.2 million in the preceding 2024-25 period, representing a year-on-year increase of more than 400 percent.
Authorities caution that the headline number almost certainly understates the true scale of the problem. A significant proportion of victims choose not to file a report, frequently citing embarrassment over the breach or the perception that the individual sum taken was too small to warrant a police complaint. The actual financial damage to households across the country is therefore likely well above the £6.3 million figure.
The Tactics: Fake Tickets and Fabricated Emergencies
The most common exploitation pattern involves criminals gaining access to a victim's social media profile and then using that stolen identity to peddle counterfeit event tickets — often for sold-out concerts or high-demand gigs — directly to the victim's own friends, family members, and followers. Because the message appears to come from a known and trusted contact, recipients rarely question the legitimacy of the offer before paying.
A second widespread vector is what fraud investigators have labelled the "Hi mum" scam. In this scheme, a criminal sends a WhatsApp message or text pretending to be the victim's child or another close relative, claiming an urgent emergency situation that requires immediate cash transfer. The emotional pressure of a perceived family crisis is designed to short-circuit the recipient's usual caution.
Banking data from Santander indicates that impersonating a son is the single most effective pretext for extracting money from a parent, with impersonation of a daughter close behind. The familiarity and emotional weight of a parent-child relationship make these messages particularly persuasive, even when the sender is a complete stranger.
A Real-World Case That Illustrates the Risk
The Guardian previously profiled a music enthusiast whose Instagram account was compromised by hackers. The intruders used her online identity to advertise tickets to an Oasis concert, successfully defrauding her friends out of £1,400. The victim described how convincing the impersonation was: her friends and family members genuinely believed they were communicating with her throughout the exchange, and only later realised the messages had originated from a criminal's device. The case underscores how quickly a single breached account can be weaponised against the people who trust the account holder most.
Official Warnings and the Push for Passkeys
Ch Supt Amanda Wolf, who heads Report Fraud operations, stressed that for most people the consequences of a hack extend well beyond a technical inconvenience. "It can leave victims locked out of important accounts, worried about what information has been accessed, and concerned that criminals may use their identity to target others," she told the Guardian. She warned that what begins as one compromised login "can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud."
In response to the surging losses, Report Fraud is rolling out a public awareness campaign centred on a single, concrete step: switching to passkeys wherever a platform offers them. A passkey authenticates a user through their personal device and biometric data rather than a stored password, meaning there is no shared secret for an attacker to steal or phish. The service is urging every user to audit their online accounts, enable multi-factor authentication, and migrate to passkey-based login as soon as the option is available to reduce the chance that a hijacked identity can be used to defraud the people they know best.