A new warning has been issued after £6.3 million was reported lost through hacked email and social media accounts in 2025/26.
Report Fraud has launched a new awareness campaign on 5 October, warning that criminals are taking control of genuine accounts and then using them to target the account owner’s friends and family.
This can include asking contacts for money, pretending to need financial help or advertising fake event tickets.
The important warning is that a message can come from the genuine Facebook, Instagram or email account of someone you know and still be a scam.
Update, 5 October 2026: This article has been updated with exact figures and additional information supplied directly to Skint Dad by Report Fraud.

Reported losses have risen sharply
Report Fraud says reported financial losses linked to its “hacking – social media and email” category reached £6.3 million during the 2025/26 financial year.
In response to questions from Skint Dad, Report Fraud confirmed the exact figure was £6,267,119, up from £1,212,299.60 in 2024/25 — a 417% increase.
It also confirmed that 44,355 reports were received during 2025/26, up from 33,077 the year before, an increase of 34%.
The category includes unauthorised access to social media, email and other online accounts.
The figures are based on reports made to Report Fraud and do not mean that the number of actual hacking incidents increased by 417%.
There is an important reason to be cautious with the huge 417% increase. Report Fraud says 92% of reports involving a financial loss, and 81% of the money reported lost, were recorded in the second half of the year.
This coincided with the change to the new Report Fraud service, which the assessment says is likely to have affected the figures.
Skint Dad asked Report Fraud whether it could say how much of the £6.3 million was lost by friends, family or other contacts after criminals took over somebody else’s account.
Report Fraud said it does not hold that level of detail because its data is based on information submitted through its self-reporting system.
It also could not provide a breakdown showing whether fake ticket sales, requests for money or another type of scam accounted for the largest losses.
The £6.3 million figure was included in Report Fraud’s annual assessment released in September.
The new development on 5 October is the launch of an awareness campaign urging people to protect their accounts and be cautious about messages coming from hacked accounts.
Why a message from a real friend can still be a scam
One of the common patterns identified by Report Fraud involves criminals getting access to somebody’s genuine account.
Once inside, they can message the person’s real friends, relatives and other contacts.
That can make the scam much harder to spot.
Instead of receiving a message from an obviously fake profile, it could appear in the same account or conversation you have used to speak to that person before.
A criminal might then claim they urgently need money, ask for financial help or offer tickets for an event.
Report Fraud says people should not automatically trust that somebody is who they appear to be simply because a message has arrived through their social media or email account.
Instead, contact the person another way.
Phone them using a number you already have, send them a text message or speak to them in person.
This is particularly worth remembering if you suddenly receive a message that appears to be from your son, daughter, another relative or a close friend asking for money.
Another safeguard is to agree a family safe word for unexpected requests for money. Agree it in person or by phone rather than sharing it in your normal message history, where somebody who gains access to an account could potentially see it.
How can a genuine account be taken over?
Criminals can get access to accounts in different ways.
One way this can happen is phishing, where someone is tricked into entering their login details into a fake website.
Reusing the same password across several accounts can cause problems too. If a criminal gets hold of that password, they can try it on other services.
Email accounts are particularly important to protect because they are often used to reset passwords for other accounts.
This means one compromised account can sometimes give criminals opportunities to target others.
Five checks before sending money or paying for tickets
If a friend or family member suddenly contacts you asking for money, take a couple of minutes to check the request before paying.
- Don’t send money immediately. Give yourself time to check who you are really speaking to.
- Contact the person another way. Call a number you already have rather than relying on contact details in the message.
- If they’re offering tickets, speak to them directly and confirm they are genuinely selling them.
- Ask yourself whether the request sounds normal for that person. Sudden urgency or unusual payment instructions should make you stop and check.
- If you cannot confirm the request independently, don’t send the money.
The important point is that seeing your friend’s name, profile picture and genuine account is no longer enough on its own to prove that you are speaking to them.
What is a passkey?
As part of the new campaign, Report Fraud is encouraging people to use passkeys where they are available.
A passkey is a secure way of signing into an account without typing in a traditional password.
You normally approve the login using the security already built into your phone, tablet or computer, such as your fingerprint, face recognition or device PIN.
The National Cyber Security Centre recommends using passkeys where they are available.
One advantage is that there isn’t a normal password that you can accidentally type into a fake login page and hand to a criminal.
What is two-step verification?
If an account does not offer passkeys, official advice is to use a strong, unique password and switch on two-step verification, often shortened to 2SV.
You may also see it called two-factor authentication or 2FA.
It means there is an extra check when someone tries to sign into your account.
For example, you might need to enter a code or approve the login using another device.
So even if somebody gets hold of your password, they still have another security step to get through.
What should you do if your account has already been hacked?
Start by going directly to the official website or app for the account that has been hacked and look for its account recovery or support section.
The National Cyber Security Centre recommends several other steps.
Check your email filters and forwarding rules for anything you did not set up yourself. Criminals can add forwarding rules so copies of your emails are sent to them.
Change the password for the hacked account and change it anywhere else you have used the same password.
Log all devices and apps out of the account so somebody who was already signed in cannot simply stay connected.
Then switch on extra security, such as a passkey or two-step verification, where it is available.
Tell your friends, family or followers that the account was hacked and ask them to treat recent messages from it with caution.
You should also check your bank statements and online shopping accounts for payments or purchases you don’t recognise.
What if you’ve already sent money?
Contact your bank straight away if you’ve sent money to a scammer or shared banking information.
People in England, Wales and Northern Ireland can report fraud and cyber crime to Report Fraud.
People in Scotland should report fraud to Police Scotland by calling 101.
Suspicious emails can also be forwarded to the National Cyber Security Centre at report@phishing.gov.uk.
Suspicious text messages can be forwarded free of charge to 7726.
The simplest rule is to check before you pay.
Even when the message appears to come from the genuine account of somebody you know.
Add Skint Dad as one of your preferred sources.
Saved a few quid with our tips?
If Skint Dad has helped you spend less or feel more in control of your money,
you can support the site with a small contribution.
