The Headline Number
In its first annual assessment published under a new reporting framework, the City of London Police revealed on September 4, 2026 that UK victims reported losing £6.3 million ($8.5 million) to account-hacking attacks in the year ending March 31, 2026 — up from £1.2 million ($1.6 million) the year before, a roughly 417% jump. The number of victims rose even more sharply, from 226 to 2,325 — a 929% increase — while the average loss per victim rose from £155 to £220.
The Real Driver: A New Reporting Platform, Not a New Crime Wave
Police were explicit that the headline figures don't reflect a genuine fivefold surge in attacks. Instead, they attribute most of the jump to changes in how incidents are reported. The UK's long-criticized Action Fraud platform was replaced by the new Report Fraud system in January 2026, and the timing lines up directly with the data: 92% of account-hacking reports involving a financial loss were recorded in the second half of the financial year — the half that followed the platform switch.
In other words, the new system appears to be surfacing incidents that victims previously never reported at all, rather than capturing a genuine spike in criminal activity.
By the Numbers
| Metric | Year Ending March 2025 | Year Ending March 2026 |
|---|---|---|
| Reported losses | £1.2 million | £6.3 million |
| Victims | 226 | 2,325 |
| Average loss per victim | £155 | £220 |
Broader cyber-dependent crime context (year ending March 2026):
- 64,608 total reports of cyber-dependent crime, a 34% year-over-year increase
- 44,355 of those reports specifically involved account hacking
- Fraud now accounts for roughly 40% of all recorded crime in England and Wales
- Police estimate more than two-thirds of that fraud has a cyber-enabled element
Why Police Are Cautious About the Comparison
The City of London Police explicitly warned against treating these year-over-year figures as a clean measure of how much account-hacking activity actually changed. Improved identification and recording processes — a friendlier reporting platform, better categorization, and reduced friction for victims — can drive large apparent increases in reported crime without a proportional increase in underlying offending. The force framed this report as a baseline for future comparisons rather than a definitive trend line.
Why This Matters
This is a useful case study in reading crime statistics carefully: a fivefold jump in reported losses sounds alarming in isolation, but the underlying driver here is a reporting-infrastructure change, not a validated escalation in attacker activity. That said, the absolute scale — over 44,000 account-hacking reports and fraud comprising roughly 40% of all recorded crime — still represents a substantial and likely under-reported problem, since even the "improved" figures are widely assumed to capture only a fraction of actual incidents.
Recommended Actions
- Don't over-index on single-year percentage changes in fraud/cybercrime statistics without checking for reporting-methodology changes first.
- Encourage victims to report account-takeover incidents through the new Report Fraud platform — better data quality benefits everyone's threat modeling, including yours.
- Treat account-hacking as a high-volume, low-average-loss crime (£220 average) — appropriate for automated credential-stuffing style defenses (MFA, breach-password screening) rather than assuming high-value targeted attacks.
- Reassess fraud-loss baselines used in risk models or insurance discussions in light of the platform transition, to avoid drawing false conclusions from pre/post comparisons.