Police across the UK are urging residents to move away from passwords and adopt passkeys after a sharp spike in profits from hacked email and social media accounts.[1][2][15] The national Report Fraud service says financial losses linked to account takeover on those platforms soared 417% in financial year 2025/26, climbing from about £1.2 million to £6.3 million.[2][15] Officials timed the warning to coincide with Cybersecurity Awareness Month, framing passkeys and two-step verification as essential protections against a rising tide of online crime.[1][2][15]
Alongside the jump in stolen sums, Report Fraud recorded a 34% year-on-year increase in the number of email and social media hacking reports, underscoring how widely criminals are abusing compromised accounts.[1][15] Police in Northern Ireland alone logged around 560 such incidents in the last financial year, with victims often seeing their profiles hijacked to run scams, solicit money or harvest further personal data from contacts.[2] Investigators say many of these account takeovers begin with basic credential theft—passwords reused across services, phished one-time codes or login details stolen from already-compromised devices.[1][2][6]
Recent industry and government data show that the UK figures are part of a broader surge in account takeover fraud worldwide.[3][7][13] Javelin Strategy & Research’s 2026 Identity Fraud Study estimates that six million U.S. consumers had an existing account hijacked in 2025, up 18% from 5.1 million the year before.[3][12] One widely cited study puts U.S. account takeover losses at more than $15.6 billion in 2024, while suspicious activity reports involving ATO filed to the Financial Crimes Enforcement Network rose over 36% year-on-year.[4][13] Other analyses suggest account takeover is now the costliest fraud category globally, with losses exceeding $15 billion and victim counts continuing to climb.[3][7][11]
In its most recent annual report, the FBI’s Internet Crime Complaint Center highlighted account takeover as an emerging category of complaints, logging thousands of cases and hundreds of millions of dollars in reported losses.[8][10] Separate analyses from security vendors suggest that ATO attacks increased roughly 24% year-on-year in 2024 and that a large majority of organizations experienced at least one incident, with some suffering dozens of separate takeovers.[6][11] Criminals typically gain access by stealing or guessing passwords, reusing credentials leaked in other breaches, or tricking victims into handing over login codes through phishing and social engineering campaigns.[6][11] Once inside, they can reset recovery information, lock out the legitimate user and quickly monetize the access through direct theft, impersonation or the sale of the compromised account.[3][6][14]
Police and fraud specialists argue that passkeys directly blunt many of those techniques because they replace reusable passwords with cryptographic credentials bound to a device and verified through a PIN or biometric check such as a fingerprint or face scan.[1][15] Unlike passwords, passkeys are resistant to guessing, credential stuffing and many phishing attacks, since there is no static secret for scammers to steal or reuse on other sites.[1][15] UK officers involved in the Report Fraud campaign describe passkeys as significantly harder for criminals to crack than traditional logins, noting that they can also be easier for the public to use once enabled.[1][2][15]
Authorities are urging the public to enable passkeys wherever major services support them, including email providers, social media platforms and financial apps, and to turn on two-step or multi-factor verification as an additional backstop.[1][2][15] Where passkeys are not yet available, users are being advised to rely on strong, unique passwords managed by reputable password managers and to stay alert to unsolicited messages that attempt to harvest login details or one-time codes.[2][5][11] Given the steep rise in losses and the relative ease of enabling stronger authentication, law enforcement’s message is that small changes in how people sign in can significantly reduce the profits cybercriminals are currently extracting from hacked accounts.[1][2][15]
References
- Police Urge Passkey Use After Surge in Cybercrime Profits
- Passkeys Urged As Hacked Account Losses Jump 417%
- Account Takeover Is the Costliest Fraud Type, With 6 …
- Identity Fraud, Scams Cost Americans Billions in 2024 – AARP
- Inside the Fraud Threat: What Every Leader Should Know – LOMA
- Cybersecurity Industry Statistics: ATO, Ransomware …
- Identity Theft Statistics 2026: Key Fraud Data and Trends
- FBI IC3 Report: Losses Hit $20.9 Billion Due to ATO, Phishing, Fraud
- 1 2025 IC3 ANNUAL REPORT
- 30 Alarming account takeover fraud statistics you can’t …
- 2026 Identity Fraud Study: The Illusion of Progress
- Account Takeover Fraud: A Persistent Threat
- Account Takeover Statistics 2026: Why Ecommerce and Media …
- Bombshell report shows 34% increase in email hacking with £6.3m lost
