A national account-security campaign has launched, urging people to use passkeys where they are offered, after reported losses linked to hacked email and social-media accounts reached £6.3m in the 2025-26 financial year.
The total compares with £1.2m in 2024-25: a substantial increase in the rounded reported totals. The campaign, launched on 5 October during Cybersecurity Awareness Month, focuses on the way a compromised account can be turned into a route to defraud other people. Criminals may take over an email or social-media profile, impersonate its owner and exploit the trust of friends, relatives or colleagues.
That can include offering non-existent tickets to popular events, sending urgent requests for money or using details visible on an account to make an approach look convincing. The initial account holder may be locked out, but the potential harm can spread well beyond that person’s inbox or profile.
Why the headline figure needs care
The £6.3m is the amount reported as stolen, not an estimate of every loss suffered across the UK. Many people do not report fraud, especially where the individual loss is small or they feel embarrassed. It therefore cannot be treated as a complete measure of the scale of account hijacking.
Nor does the year-on-year increase, by itself, prove that offending rose by the same proportion. A newer national reporting service was introduced during the period, and more detailed recording brought more cases into view. Most reports involving a financial loss were logged in the latter half of the financial year, when the new system was operating. The campaign is consequently a response both to a serious reported harm and to a clearer picture of it.
Account hacking remains the largest reported type of cybercrime. It can involve email, social-media, gaming, streaming, travel or delivery accounts. In a takeover, the attacker’s objective may be access to private information, a ready-made identity to imitate, or a way to contact people who already trust the account owner.
Why passkeys are being promoted
A passkey is a sign-in method held securely on a device. Instead of entering a reusable password into a website, a person confirms access using the device’s usual unlock method, such as a fingerprint, face check or device PIN. This can make credential-theft scams harder to use, particularly where a fake sign-in page is designed to capture a password.
Passkeys are not available on every service, so they should be part of a wider approach rather than a reason to relax other checks. Where they are not offered, people should use a strong, unique password for each account, ideally created and stored by a password manager, and turn on two-step verification where possible. Reusing a password across accounts gives a criminal who obtains it more than one possible way in.
Steps worth taking now
- Check the security settings on your main email account first, since it is often used to reset access elsewhere.
- Enable passkeys on services that support them and remove old or unfamiliar sign-in methods and devices.
- Use two-step verification as an additional safeguard when a passkey is unavailable.
- Review social-media privacy settings and limit personal details that could help somebody imitate you or answer account-recovery questions.
- Before sending money or buying tickets after a message from someone you know, contact them through a separate, trusted route to confirm it is really them.
Anyone who suspects an account has been compromised should act quickly: secure the associated email account, change any exposed password, review active sessions and warn contacts that unexpected messages may not be genuine. A report can also help identify patterns and protect other people from the same tactic.
The new campaign’s central message is straightforward: account security is not only about protecting a profile. It is also about protecting the people who may trust a message sent in that person’s name.