Police Urge Passkey Use After Surge in Cybercrime Profits

Written by

The UK’s Report Fraud service has launched a new public awareness campaign urging internet users to switch to passkeys, after revealing a major increase in sums stolen from victims.

The fraud reporting service said that cybercrime linked to email and social media hacking netted scammers £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) the year previously.

The number of reports for this type of account takeover increased by a third (34%) over the same period.

Report Fraud didn’t go into much detail about the tactics cybercriminals use to monetize their access to victims’ accounts, aside from claiming that one of the most common is impersonating family and friends.

Read more on account takeover: FBI Warns of $262m Losses from Account Takeover Fraud in 2025.

Impersonation can come in various forms, but one of the most popular techniques to trick victims into sending funds is to impersonate the account owner and pretend to be in trouble.

Ticketing scams are also money-spinners for opportunistic scammers. They use hacked accounts to sell non-existent tickets for sold-out shows to desperate gig-goers.

Lloyds Bank warned in November 2024 that 70% of all reported concert ticket scams since August were related to Oasis, with victims losing an average of £346 ($449), rising to £1000 ($1300) for some.

"For most people, being hacked isn't just a cyber issue, it's personal. It can leave victims locked out of important accounts, worried about what information has been accessed, and concerned that criminals may use their identity to target others,” said chief superintendent Amanda Wolf, head of Report Fraud operations.

"What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud.

Experts Recommend Passkeys

For this reason, Report Fraud is urging internet users to protect their accounts with passkeys.

These are much harder for scammers to crack as there’s no password to guess or steal: the user logs in via a device PIN or biometric like a face scan.

They are cryptographically tied to legitimate websites, and even if the latter were breached, the hacker wouldn’t have access to the user’s private key, which stays on their device.

“Passkeys are simpler, faster and more secure to use, raising our national resilience against phishing attacks whilst leaving password headaches behind,” argued Jonathon Ellison, director for national resilience at the National Cyber Security Centre (NCSC).

The news comes as new data from NordVPN highlights that consumers are still getting password best practices wrong.

Out of 4896 UK participants in a survey published on October 6, 96% correctly answered the firm’s question on creating a strong password, but only 16% knew how to store one safely (i.e. in a password manager).

What’s Hot on Infosecurity Magazine?