P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Passkeys urged after a 417% rise in reported losses that Report Fraud's own assessment links to its new service

Report Fraud launched a passkey campaign on 5 October on a 417 per cent rise in reported hacked-account losses, to £6.3m. Its own assessment says victims reporting a loss rose from 226 to 2,325, and that the timing is likely due to its new service.

By Parminder Kumar Sharma · · 18 min read

A smartphone lying on a dark desk, its screen showing a blank sign-in page drawn as empty rounded pills, with a cyan outline of a key and a small empty padlock. Nothing carries any lettering of its own.

£6.3m from £1.2m is 5.25 times. Victims reporting a loss rose 10.3 times

On 5 October 2026 Report Fraud, the City of London Police service that replaced Action Fraud, launched a public campaign urging people to switch to passkeys. Its headline number is that reported stolen sums from email and social media hacking rose to £6.3 million in 2025/26, from £1.2 million in 2024/25, which the release also gives as 417 per cent, with the number of reports up by a third (34 per cent). On the rounded pounds that is 5.25 times. The published 417 per cent implies 5.17 times, and the gap is rounding. With reports up 34 per cent, reported losses per report rose by about 3.9 times (derived).

The sharper number is in the service's own Annual Assessment, published on 4 September, and not in the campaign release. The number of victims reporting a loss in this category rose from 226 to 2,325, which is 10.3 times or 929 per cent. Unique victims rose 27 per cent, to 25,991. Dividing the totals by those victim counts, which is our arithmetic and not a published figure, the average reported loss per victim who reported one fell from about £5,300 to about £2,700. The total rose because far more reports carried a recorded loss, not because each loss was bigger.

The assessment says why it thinks that happened. 92 per cent of the reports with a loss, and 81 per cent of the loss total, fell in the second half of the year. That "directly coincides with the change to Report Fraud and is therefore likely due to the new Report Fraud service".

What that does not establish.

  • It does not establish that attacks did not rise. The assessment records 44,355 reports, up 34 per cent, and 25,991 unique victims, up 27 per cent, and offers criminal use of AI and Online Safety Act duties as factors behind the victim rise, with no measurement of either. A better recording system and a real increase can both be true. The published figures cannot separate them.
  • It does not establish the size of the harm. Report Fraud counts what victims choose to report, unverified, for England, Wales and Northern Ireland, with cryptocurrency losses excluded, and says hacking is often left out of a report when the fraud that follows is reported.
  • It does not establish that passkeys would have stopped any of it. Neither document says how these accounts were taken.
  • It does not establish a link between the rise and the campaign. The assessment's own campaign calendar already lists "Social Media & Email Hacking" under October to December 2026.
Four pairs of bars, each pair drawn to scale, for 2024/25 and 2025/26 in Report Fraud's hacked-account category. Reported loss: 1.2 million pounds then 6.3 million, up 5.25 times on rounded figures. Reports: about 33,100 then 44,355, up 34 per cent. Victims reporting a loss: 226 then 2,325, up 10.3 times. Average loss per victim reporting a loss: about 5,310 pounds then about 2,710 pounds, roughly halved.
Report Fraud press release of 5 October 2026 and Annual Assessment FY2025-26 (pages 14 and 23), read on 6 October 2026. Dashed outlines are our arithmetic from the published figures.

The arithmetic, and what each figure is

Report Fraud publishes the totals and the percentages. The multiples and the averages below are ours, computed from them, and each carries its rounding.

Published and derived figures, from the press release of 5 October 2026 and the Annual Assessment FY2025-26 (pages 14, 23 and 25)

  1. Figure
    Loss multiple
    Arithmetic
    £6.3m / £1.2m = 5.25. The published 417% means 5.17
    Status
    Derived from rounded pounds. 417% is Report Fraud's own
  2. Figure
    Reports in 2024/25
    Arithmetic
    44,355 / 1.34 = about 33,100
    Status
    Derived from a rounded 34%. The earlier count is not printed in the text read
  3. Figure
    Loss per report
    Arithmetic
    £6.3m / 44,355 = about £142. £1.2m / 33,100 = about £36. Ratio 3.9
    Status
    Derived
  4. Figure
    Victims reporting a loss
    Arithmetic
    2,325 / 226 = 10.29, so +929%
    Status
    929% published. The multiple is derived
  5. Figure
    Average per such victim
    Arithmetic
    £6.3m / 2,325 = about £2,710. £1.2m / 226 = about £5,310. Down 49%
    Status
    Derived. Holds across rounding: about £2,690 to £2,730 against £5,090 to £5,530
  6. Figure
    Unique victims in 2024/25
    Arithmetic
    25,991 / 1.27 = about 20,465
    Status
    Derived from a rounded 27%
  7. Figure
    Share of victims with a loss
    Arithmetic
    226 / 20,465 = about 1.1%. 2,325 / 25,991 = about 8.9%
    Status
    Derived, approximate
  8. Figure
    Where the year's loss fell
    Arithmetic
    81% of £6.3m = about £5.1m in the second half. 19% = about £1.2m in the first
    Status
    Derived from published shares. The split date is not given
  9. Figure
    The rest of the category
    Arithmetic
    Social media slice: 9,846, down 18%, so about 12,000 before. The remainder: 34,509 now against about 21,100, up roughly 64%
    Status
    Derived. Assumes the earlier keyword count used the same method

Two of these pull in different directions, and that is the point. The first half-year alone, about £1.2 million by this arithmetic, matches the whole of 2024/25, so a real rise is not excluded. And an average loss that roughly halved fits a collection system that is now catching smaller losses it used to miss. That second reading is inference, not a finding. Report Fraud's own word is "likely". The arithmetic is consistent with it and does not prove it.

The service went live on 4 December 2025. From that day to 31 March 2026 is 118 days, 32 per cent of a 365 day year. The assessment calls the later period the "second half" and does not give its start date, so we cannot say how much of the loss-bearing reporting sits on either side of the switch.

Two documents from one organisation

The campaign release and the assessment come from the same service, and they tell different parts of the story. The release's body speaks of "Reported stolen sums", and its headline says sums stolen rose by more than 400 per cent. It does not carry the assessment's attribution of the timing to the new service, the 226 to 2,325 victim count, or the fall in social media hacking. The assessment records 9,846 social media hacking reports, down 18 per cent, and two popular platforms down 60 and 47 per cent, where it says improved platform security is a "realistic possibility". The Infosecurity Magazine write-up of 6 October, a secondary source, repeated "a major increase in sums stolen".

We do not read that as concealment. A press release is written to move people to act, an assessment is written to say what the data support, and Report Fraud is both the collector of the data and the author of the campaign. A reader who stops at the release gets the 417 per cent without its footnote.

The release also carries statements from Google Cloud and Meta, whose services host the kind of accounts being taken over and which both speak up for passkeys. Google, Apple, Microsoft and the FIDO Alliance all promote them in the pages cited here. None of that makes the advice wrong. It is the reason the vendor statements are not evidence about the rise in losses.

Stated and not stated

What the Report Fraud release (5 October) and Annual Assessment (4 September 2026) state, and what they leave out. Read 6 October 2026

  1. Question
    How big is the loss?
    Stated
    £6.3m reported in 2025/26, up 417%. Victim-reported, unverified, England, Wales and Northern Ireland, cryptocurrency excluded
    Not stated
    The total loss. Losses booked under the fraud that followed a hack, which the assessment says often go unlinked
  2. Question
    Why did it rise?
    Stated
    The loss-bearing reports are concentrated in the second half and this is "likely due to the new Report Fraud service". AI and Online Safety Act duties named as factors for victims
    Not stated
    How much of the rise is real. The date of the split. Any measurement of the AI or Online Safety Act effect
  3. Question
    How many people?
    Stated
    25,991 unique victims, up 27%. 2,325 reported a loss, up from 226 (+929%). 44,355 reports, up 34%
    Not stated
    The earlier-year report count, which we derive as about 33,100
  4. Question
    How were accounts taken?
    Stated
    Reporting does not consistently capture the pathway. From December 2025 to March 2026, 38% (5,492) of reports carried a yes to "Was your email account hacked?"
    Not stated
    Any split by phished password, reused password, recovery abuse, SIM swap, session theft or support-desk fraud
  5. Question
    Would passkeys have helped?
    Stated
    NCSC: resistant to guessing, phishing and credential stuffing. Assessment: wider adoption "likely to reduce" credential attacks, but compromise "is not limited to credential theft"
    Not stated
    A count of reports where a passkey would have stopped the takeover
  6. Question
    Did the campaign cause anything?
    Stated
    Launched 5 October 2026. Listed in the assessment's calendar for October to December 2026
    Not stated
    Any effect, and any link between the rise and the campaign

How these accounts were taken is not in the data

The assessment is plain about it. Reporting in this category "does not consistently capture information related to online account compromise pathways", and victims "may be unaware of the exact method", especially where it is malware or session hijacking. What victims can report are symptoms: recovery notifications, suspicious logins, loss of access, and weaknesses of their own such as password reuse or no two-step verification. From December 2025 the website asks "Was your email account hacked?" before the report. That counts a symptom, not a route.

What exists comes from outside Report Fraud. The NCSC's paper on credentials cites Microsoft's Digital Defense Report 2025 for how often each technique appears among attacks on Microsoft's identity systems: password brute force and credential stuffing together 97 per cent, infostealers 2.4 per cent, adversary-in-the-middle phishing 0.24 per cent. Those are attempts at one vendor's systems, not UK victims' reports, and the NCSC itself says adversary-in-the-middle phishing remains a concern despite its low share. It also states that abuse of legitimate credentials "is responsible for the majority of cyber harms to individuals". So passkeys are aimed at the most common attacks the NCSC can cite. The UK report data cannot say how many of the 2,325 victims would have been spared.

Where Report Fraud has named a mechanism, it is reuse. Its June release on retailer accounts says criminals use login details from data breaches, helped by reused passwords, then collect goods in store. What the hacked accounts are used for, in the campaign release, is impersonation: "one of the most common themes" is compromised accounts used to pose as family and friends, and some to offer fake tickets. No count is given for either.

A passkey is a key for one door

A passkey is, in the FIDO Alliance's words, an authentication credential based on FIDO standards, stored on a phone, a computer or a hardware security key, and tied to a user's account on a website or app. Microsoft's help page says it is tied to the domain it was created for, so a lookalike page is never offered it. The NCSC's paper scores FIDO2 credentials "never vulnerable" to credential harvesting, credential stuffing and adversary-in-the-middle phishing, and says passkeys are as secure as or more secure than traditional multi-factor authentication at every stage. That is good news and the site says so plainly.

The friendly name is the trap. "Passkey" reads as a stronger password. It is not a password at all. It is a credential bound to a device and a site, or held in a cloud account that syncs it, and that moves where the weakness sits. "Switch to passkeys" is advice about one door. The account has others: the older sign-in that stays beside the passkey, the recovery route, the session already on the device, and the cloud account that holds the keys.

A list of seven routes into a hacked account with what a passkey does to each. Closed by a passkey: lookalike-site phishing, and reused or stuffed passwords. Open, untouched: a password kept as a fallback sign-in, and account recovery by email link, SMS or support desk. Depends on setup: a stolen session or infostealer, the cloud account that syncs the keys, and a passkey the attacker registers after a takeover.
Drawn from the NCSC paper on traditional and FIDO2 credentials (published 23 April 2026, modified 31 July 2026), Google's passkey help pages and Report Fraud's glossary, read on 6 October 2026.

Each platform's own pages show the same shape. The table treats the three alike, and quotes only where the wording matters.

What each platform's own help pages say about a passkey and about recovery. Read 6 October 2026

  1. Platform
    Google
    With a passkey added
    Adding a passkey "doesn't change or remove any authentication or recovery factors" already on the account. The passkey skips the second step of 2-Step Verification
    If the device or account is lost
    Fall back to a password and traditional 2-Step Verification, or Google's recovery flow. Google encourages adding an email address and phone number
  2. Platform
    Apple
    With a passkey added
    Passkeys sync through iCloud Keychain, which requires two-factor authentication on the Apple Account
    If the device or account is lost
    Keychain recovery needs the account password, a text to the registered phone number and the device passcode. An optional recovery contact. Account recovery can take days
  3. Platform
    Microsoft
    With a passkey added
    A passkey can sit in a synced credential manager or on one device or key. SMS is being phased out for personal account sign-in and recovery
    If the device or account is lost
    A device-bound passkey is lost with the device unless another recovery method exists. Verified email and a passkey are the stated route. Support agents cannot send reset links

The NCSC wrote the condition down. Its paper says attackers target account recovery for both kinds of account because "the recovery process can often be weaker than the authentication to the account". Recovery by an emailed link reduces the service to the security of the email account, and where the flow requires it, criminals pay for SIM swaps. It says users are "unlikely to see the full benefits" of FIDO2 until traditional multi-factor authentication is removed as an option, expects attackers to downgrade to it, and expects them to register passkeys of their own to keep access after a takeover. It recommends that the account which syncs the keys is itself protected by phishing-resistant sign-in and has a secure recovery option.

The campaign release sends people who have been hacked to the NCSC's guide to recovering a hacked account. The page footer reads "Reviewed 24 August 2022", its page metadata gives 8 December 2025, and its steps never mention passkeys. Step five describes 2-step verification by a code "often sent by SMS or email". That is guidance written before the push, not an error, but it is the page a victim lands on.

The long version of this argument, for one government service, is in the GOV.UK One Login passkeys briefing. The case where the route went round the login altogether, through a support desk, is in the Microsoft X account briefing.

Who is in these numbers

In this category 94 per cent of victims are individuals and 4 per cent are organisations. Organisations filed 2,271 cyber crime reports in all, and 1,250 of them, 55 per cent, were hacked social media and email accounts. Where size was known, small and medium-sized businesses were 62 per cent, and the smallest, 0 to 49 employees, were 45 per cent of all organisational reports. Phishing and social engineering were the most commonly reported vectors, and the assessment recommends passkeys "throughout their organisation and supply chain where possible". The text we read gives no figure for charities as a group.

Three scope points matter for a UK reader. The assessment excludes Scotland, where cyber crime goes to Police Scotland on 101, although the release calls this the most reported cyber crime "in the UK". The loss figure excludes cryptocurrency, so by our reading a hijacked brand account used to push a token, as in the Microsoft X account case, would not appear in the £6.3 million. And UK Finance's Annual Fraud Report 2026, published 12 June 2026, counts bank and card fraud reported by its members for calendar 2025, almost £1.3 billion in all. It is a different dataset and its figures are not combined with Report Fraud's here.

What to do, in order

The order is our judgement, drawn from the NCSC, the platform pages and the assessment. It starts with email because the NCSC says a criminal who controls your email can reset the passwords on your other accounts. Email is the recovery path to everything else.

Take this with you

For individuals, small businesses and charities

  • Put a passkey or a hardware security key on your email account first. Every other account can be reset through it.
  • Check the recovery methods on that account and on any account tied to a phone number: recovery email, recovery phone, trusted contacts. Delete any you no longer control, and protect the recovery address as strongly as the account.
  • Where a service lets you, stop SMS being the only fallback. Add an authenticator app, a second passkey or a security key. The NCSC lists message-based methods last for organisations, and Microsoft is phasing SMS out for personal accounts. Where SMS is all that is on offer, keep it rather than nothing.
  • For accounts that cannot use passkeys, use a password manager to make a unique password for each, and turn on 2-step verification. That is the NCSC's own advice and the campaign release repeats it.
  • Look at what else can already open the account: signed-in sessions, forwarding rules on email, connected apps, registered passkeys and trusted devices. End the ones you do not recognise.
  • List the accounts that can take payments or reach your customers: shop and marketplace logins, ticketing, donation pages, the domain registrar, brand and social accounts. Secure those straight after email.
  • Agree a second channel with family, staff and colleagues. A message asking for money, from a known account, is checked by a call or in person. The release gives the same advice.

Take this with you

For organisations with staff and customers

  • Enrol staff in passkeys or FIDO2 security keys for email, single sign-on and finance systems. Then set a date to switch off password and code sign-in for those accounts, because the NCSC says the full benefit arrives only when the traditional route is removed.
  • If you hold customer accounts, offer passkey sign-in, and design recovery before you launch it. No recovery on an SMS code alone for high-value actions, a notice to the customer when a passkey is added or recovery is used, and a delay or extra check before an email, phone or payout detail changes.
  • Train help desks on recovery fraud. No change of email address, phone number or sign-in method on an inbound call without a check that a hacked mailbox could not pass. Log every such change and review them.
  • Remove the gaps the NCSC names in its corporate guidance: legacy protocols that accept a password alone, and accounts excluded from strong sign-in because a user found it a nuisance.
  • Report a compromised account to Report Fraud on 0300 123 2040 or at reportfraud.police.uk, in Scotland to Police Scotland on 101, and say the account was hacked. The assessment says hacking is often left out when the fraud that followed is the thing reported.

What we could not verify

  • The interactive statistics dashboard, which holds 13 months of data by force area, was not read. The assessment warns that its figures "may differ" in later requests.
  • The date that divides the two halves of 2025/26 is not given. The assessment text does not spell out the financial year dates either. We read it as the usual 1 April 2025 to 31 March 2026, which The Record also states.
  • The earlier-year report and victim counts are derived from rounded percentages. The figures used here agree across pages 14, 23 and 25 and with the release. This is a first version, and two of its organisation loss totals differ by page, £2.5 million on page 14 and £2.3 million on page 26.
  • The release gives impersonation and fake tickets as themes with no counts, and the assessment text has no ticket section.
  • We read the Report Fraud copy of the release, not the City of London Police news page. Google, Apple and Microsoft help pages can change, and Microsoft's SMS page shows no date in the text read.
  • Get Safe Online and Cyber Aware materials were not used.

The question this leaves

Report Fraud's data can say that more victims reported a loss. It cannot say through which door. A passkey is the right advice for the door the NCSC can show is most attacked, and the assessment's own caveat is that account compromise is not limited to credential theft.

So here is the question the figures cannot answer for you. If every passkey you issue works perfectly tomorrow, how many of your accounts can still be opened with a code sent to an inbox or a phone number, by whoever can reach that inbox, that number or your help desk?

Key facts

Sources

  1. PrimaryThe campaign release of 5 October 2026 (page updated 6 October), read in full in a browser: the 417 per cent, 34 per cent, the advice, the quoted statements and the NCSC recovery linkReport Fraud (City of London Police)accessed 2026-10-06
  2. PrimaryReport Fraud Annual Assessment FY2025-26, version 1, September 2026, 60 pages read in a browser: NFIB52C definition, 44,355 reports, 25,991 victims, 226 to 2,325 victims with a loss, second-half concentration, pathways caveat, methodologyReport Fraud (City of London Police)accessed 2026-10-06
  3. PrimaryThe assessment's landing page, which links the PDFReport Fraud (City of London Police)accessed 2026-10-06
  4. PrimaryThe 4 September 2026 release announcing the first Annual Assessment, used for its publication dateReport Fraud (City of London Police)accessed 2026-10-06
  5. PrimaryThe service-launch notice: Report Fraud replaced Action Fraud from 4 December 2025 in England, Wales and Northern IrelandReport Fraud (City of London Police)accessed 2026-10-06
  6. PrimaryJune 2026 release on retailer account takeover: breached logins, password reuse and click and collectReport Fraud (City of London Police)accessed 2026-10-06
  7. PrimaryThe statistics page: interactive dashboards updated monthly with a 13 month window, described and not readReport Fraud (City of London Police)accessed 2026-10-06
  8. PrimaryComparing the security properties of traditional user credentials and FIDO2 credentials for personal use, published 23 April 2026, modified 31 July 2026: attack table, recovery, sync fabric, downgrade and attacker-registered passkeysNational Cyber Security Centreaccessed 2026-10-06
  9. PrimaryPasskeys: what you need to know, the NCSC's recommendation and plain-language descriptionNational Cyber Security Centreaccessed 2026-10-06
  10. PrimaryRecovering a hacked account, the guide the release links to: steps, 2-step verification by SMS or email, no passkey stepNational Cyber Security Centreaccessed 2026-10-06
  11. PrimaryUse a strong and separate password for your email: what a criminal can do with a controlled mailboxNational Cyber Security Centreaccessed 2026-10-06
  12. PrimaryManaging your passwords, updated 21 May 2026: password managers, 2-step verification first, and passkeys as the first choiceNational Cyber Security Centreaccessed 2026-10-06
  13. PrimaryRecommended types of MFA for corporate services: FIDO2 first, message-based methods lastNational Cyber Security Centreaccessed 2026-10-06
  14. PrimaryAvoiding MFA anti-patterns: legacy protocols that accept a password alone, and accounts excluded from strong sign-inNational Cyber Security Centreaccessed 2026-10-06
  15. PrimaryWhat a passkey is: a FIDO credential tied to an account, synced or device-boundFIDO Allianceaccessed 2026-10-06
  16. PrimarySign in with a passkey instead of a password: existing factors unchanged, the second step skipped, the 7 day wait and suspicious passkey handlingGoogleaccessed 2026-10-06
  17. PrimaryPasskey safety centre FAQ: fall back to legacy options, recovery flow, add email and phoneGoogleaccessed 2026-10-06
  18. PrimaryAbout the security of passkeys: iCloud Keychain, two-factor requirement, keychain recovery by text and passcode, recovery contactAppleaccessed 2026-10-06
  19. PrimaryWhat to expect during account recovery: the waiting periodAppleaccessed 2026-10-06
  20. PrimaryWhat are passkeys and why they matter: domain binding, synced and device-bound passkeysMicrosoftaccessed 2026-10-06
  21. PrimaryMicrosoft to stop sending SMS codes for personal accounts: SMS phased out for sign-in and recoveryMicrosoftaccessed 2026-10-06
  22. PrimaryAnnual Fraud Report 2026 press release, 12 June 2026: bank-reported fraud for 2025, a different dataset, context onlyUK Financeaccessed 2026-10-06
  23. Reported byNews report of 6 October 2026 that pointed to the storyInfosecurity Magazineaccessed 2026-10-06
  24. Reported byNews report of 4 September 2026 on the same figures, used as a pointer for the financial year endThe Recordaccessed 2026-10-06

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.