The UK's national fraud and cyber crime reporting service has started a campaign telling the public to switch to passkeys, after money stolen through hacked email and social media accounts rose more than fivefold in a year. Report Fraud, which is run by the City of London Police, launched the campaign on 5 October 2026 as part of Cybersecurity Awareness Month, with backing from the National Cyber Security Centre (NCSC), Google and Meta.
What Report Fraud found
According to Report Fraud's announcement, reported losses from email and social media account hacking reached £6.3 million in the 2025/26 financial year, up from £1.2 million in 2024/25. That is a rise of 417 per cent. The number of reports of this crime grew by 34 per cent over the same period, and Report Fraud says this type of hacking "remains the most reported form of cyber crime in the UK."
Report Fraud says the most common pattern is a hacked account being used to impersonate the owner and ask family and friends for money or offer them fake tickets. It also found gaming, streaming, travel and online delivery accounts among those taken over.
Chief Superintendent Amanda Wolf, Head of Report Fraud Operations, said: "For most people, being hacked isn't just a cyber issue, it's personal." She added that "switching to passkeys and enabling two-step verification adds a strong extra layer of security and makes it much harder for criminals to gain access to your accounts."
Why the police are pointing to passkeys
A passkey replaces a password with a cryptographic key stored on your phone, computer or a hardware security key, unlocked with a fingerprint, face scan or device PIN. The FIDO Alliance, the industry group behind the standard, describes passkeys as "phishing-resistant" with "no shared secrets", which means there is no password for a fake login page to capture.
The NCSC's Director for National Resilience, Jonathon Ellison, said in the same press release: "We know that most cyber harm to individuals starts with criminals attempting to steal login details, which is why we strongly encourage users to choose passkeys where they are available across digital services and use two-step verification where they aren't." Meta's Global Head of Counter Fraud, Nathaniel Gleicher, said passkeys "are resistant to guessing or theft by criminals, or exploit via malicious websites or scam links."
Where password managers fit
The campaign does not tell people to abandon password managers. Report Fraud's own advice has three steps:
- "Use passkeys wherever they are available."
- "Where passkeys are unavailable, use strong passwords, for example generated by a password manager."
- Turn on two-step verification where you can.
Password managers are also one of the places passkeys are kept. The FIDO Alliance explains that a passkey provider creates and manages a person's passkeys, and that this can be the credential manager built into an operating system or a third-party app. Passkeys can be synced across a person's devices through that provider, or bound to a single device. In practice, that means the choice of password manager now also decides where your passkeys live and which devices they work on.
What to do now
- Start with your email account. It is usually the key to resetting every other account, and Report Fraud's figures show email and social media are where the losses are. Check its security settings for a passkey option.
- Add passkeys to social media accounts that offer them, then to shopping, streaming and gaming accounts.
- Use a password manager for the rest. Report Fraud recommends strong passwords generated by one wherever a passkey is not offered.
- Turn on two-step verification on any important account that does not support passkeys.
- Check a surprising message from a friend by phone, text or in person before sending money. Report Fraud says not to "automatically trust that person is who you think they are."
- Review privacy settings so that personal details such as birthdays, family names and pet names are not visible to strangers. Report Fraud says fraudsters use them to build a picture of their target.
If an account has already been taken over, the NCSC's recovery guide sets out the steps: contact the account provider, check your email for forwarding rules and filters an attacker may have added, change passwords, log all devices out, set up two-step verification, update your devices, warn your contacts, check bank statements and report it. In the UK, hacking can be reported to Report Fraud at reportfraud.police.uk or on 0300 123 2040; people in Scotland should call Police Scotland on 101.
What it means if you are choosing a password manager
If you are comparing password managers, check whether each one can store and sync passkeys on every device and browser you use, not just passwords. It is also worth checking how you would move your passkeys if you later switch provider, and how you would get back in if you lost your phone. These details vary between apps and between operating systems, so check each provider's current help pages before committing.
What is still unknown
- How much of the rise reflects more crime and how much reflects more people reporting it. Report Fraud gives the totals but does not separate the two.
- What share of the hacked accounts already had two-step verification switched on. The announcement does not say.
- How long the campaign will run and what materials it will include beyond the launch. Report Fraud has not published a schedule.
- The figures cover reports made to Report Fraud, so they do not include losses that were never reported. Infosecurity Magazine, which covered the launch, notes the campaign alongside other UK scam warnings but gives no wider total.