Security News

UK Police Push Passkeys as Account Takeover Losses Jump More Than Fivefold

Infosecurity Magazine · 6 Oct 2026
Key Takeaway Turn on passkeys for your business email and social media accounts wherever they are offered, and warn staff that urgent money requests from a contact's account may be a hacker posing as them.

The UK's Report Fraud service has launched a public awareness campaign encouraging people to switch to passkeys. It follows a sharp rise in money stolen through hacked email and social media accounts. The service says this type of cybercrime netted scammers £6.3m ($8.3m) in 2025/6, up from £1.2m ($1.6m) the year before. Reports of this kind of account takeover rose by a third (34%) over the same period.

Report Fraud gave little detail on how criminals turn stolen access into cash, but said impersonating family and friends is one of the most common methods. A typical approach is to pose as the account owner and claim to be in trouble so that contacts send money. Hacked accounts are also used to sell non-existent tickets for sold-out shows. Lloyds Bank previously reported that 70% of concert ticket scams logged between August and November 2024 related to Oasis, with average losses of £346 ($449).

Chief superintendent Amanda Wolf, head of Report Fraud operations, said a hack is personal for most victims, and that one compromised account can quickly affect family, friends and colleagues. Passkeys are harder for scammers to defeat because there is no password to guess or steal. Users log in with a device PIN or a biometric such as a face scan. Passkeys are cryptographically tied to legitimate websites, and the private key stays on the user's device, so a breach of a website would not give a hacker that key.

passkeys account takeover fraud impersonation scams authentication

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.