More than 78,000 UK account takeover cases were reported to the National Fraud Database in 2025, according to Cifas’ Fraudscape 2026 report. The figure is serious, but it needs careful wording: it covers “facility” or account takeovers across sectors, not just banking apps. Cifas says mobile phone products dominated, followed by online retail and personal credit cards.
Even so, the warning matters for anyone who uses mobile banking. UK Finance separately reported that unauthorised mobile banking fraud reached 35,661 cases and £43.0 million in gross losses in the first half of 2025, the highest first-half total it has recorded for this fraud type since it began collecting the data in 2015.
What happened?
Cifas reported 444,993 fraud-risk cases to the National Fraud Database in 2025, a record level and a 6% rise on 2024. Within that, 78,387 were account takeover cases, making up 18% of all filings.
An account takeover happens when a criminal gains control of a real account and uses it as if they were the genuine customer. Report Fraud, the UK fraud reporting service, says this can affect bank, credit card, email and other service accounts, and that online banking takeovers are usually linked to phishing, spyware or malware.
Cifas also warned that criminals are using AI and generative technologies to create more convincing impersonations, fake documents and synthetic identities at speed. It said criminals are also using AI to improve malicious messages and automate credential attacks, while using stealthier tactics such as disabling alerts or gradually changing account details.
Why this matters for your banking app
Your banking app is protected by strong security, but criminals often try to get around that security by targeting you, your phone number, your email account or your login details.
For example, a scammer may:
- send a fake text or email that looks like it comes from your bank;
- phone you pretending to be from a bank fraud team, HMRC, the police or another trusted organisation;
- trick you into sharing a one-time passcode, card reader code or app approval;
- take over your email account and use password reset links;
- try a SIM swap so your calls or texts go to a device they control;
- use stolen passwords from data breaches on other websites.
The Financial Conduct Authority says banking scams can involve phishing emails and texts, fake websites, number spoofing and calls that use scare tactics to get people to act quickly. It also says banks will not email or text you asking for personal information or account details.
Who may be affected?
Anyone with online banking, a banking app, email, a mobile phone contract or online shopping accounts could be targeted. You do not need to be wealthy or technically inexperienced to be at risk.
You may be more exposed if:
- you reuse the same password across different sites;
- your email account does not have two-step verification turned on;
- your phone number is used to receive banking security codes;
- you often respond quickly to texts, calls or emails while busy;
- you have recently received breach notifications from companies you use;
- you post a lot of personal information publicly on social media.
This is not about blaming victims. Modern scams are designed to look ordinary, urgent and believable. AI can make messages sound more natural and can help criminals personalise attacks.
Warning signs of an account takeover attempt
Stop and check carefully if you notice any of the following:
- A one-time passcode you did not request. This may mean someone is trying to log in or reset your password.
- A call claiming your account is at risk. Scammers often create panic and tell you to move money or approve a transaction.
- Your phone suddenly shows “No Service”. This can happen for innocent reasons, but it can also be a warning sign of a SIM swap.
- Bank alerts stop arriving. Cifas has warned that criminals may disable alerts to avoid detection.
- New payees, changed contact details or unfamiliar transactions. Check your app and statements regularly.
- Emails about password resets or new device logins. Treat these as urgent if you did not make the change.
- Pressure to install remote access software. A genuine bank will not need to take control of your phone or computer.
- Requests for your PIN, password or full banking details. The FCA has warned that fraudsters impersonating trusted bodies try to obtain PINs and passwords, and says sensitive banking information should not be handed over.
What to do now if you think someone is trying to get in
If you are worried, act quickly but calmly.
- Do not approve any login, payment or security request unless you started it yourself.
- Hang up if you are on a suspicious call. Wait a few minutes, then call your bank using the number on your card, statement or the bank’s official website.
- Use a different phone if possible if you think the call may still be connected.
- Open your banking app directly rather than using a link in a text or email.
- Change your banking, email and mobile account passwords from a device you trust.
- Check your recent payments, new payees, standing orders and personal details in your banking app.
- Contact your mobile network if your SIM stops working unexpectedly or you receive messages about a PAC, SIM change or account update you did not request.
- Forward suspicious emails to report@phishing.gov.uk and suspicious texts to 7726. GOV.UK says forwarding texts to 7726 is free and reports the message to your mobile provider.
If money has already gone
Contact your bank or payment provider immediately. Use the official number on your card, statement or app. Ask them to freeze affected cards, block unauthorised access and attempt to recover funds.
If you are in England or Wales and you have lost money or been hacked because of an online scam or fraud, GOV.UK says you can report it to Report Fraud online or by calling 0300 123 2040. If you are in Scotland, report it to Police Scotland.
It is also important to understand the difference between two common situations:
- Unauthorised fraud: someone accessed your account or card without your permission.
- Authorised push payment fraud: you were tricked into sending money yourself to a scam account.
For eligible authorised push payment scams made by UK bank transfer through Faster Payments or CHAPS on or after 7 October 2024, the FCA says payment service providers must usually reimburse up to £85,000 within 5 working days, though some cases can take up to 35 working days and a provider may apply a £100 excess. (fca.org.uk)
The Payment Systems Regulator says these APP protections apply to UK bank transfers and are different from protections for unauthorised fraud, card, cash and cheque payments. If you are unhappy with your bank’s response, you may be able to complain and then take the case to the Financial Ombudsman Service.
How to make your banking app harder to break into
These steps will not remove all risk, but they make account takeover much harder.
- Turn on two-step verification for important accounts. The NCSC says 2-step verification helps keep criminals out even if they know your password, and recommends using it on important accounts such as email, banking, social media and online shopping.
- Secure your email first. Your email account is often the route to password resets for banking, shopping and social media accounts.
- Use unique passwords. Do not reuse your banking or email password anywhere else.
- Use a password manager. The NCSC says password managers can store unique passwords safely, generate strong passwords and help protect against phishing because autofill works only on the correct website.
- Keep your phone and apps updated. Install updates for your phone, browser and banking app promptly.
- Turn on bank notifications. Enable alerts for logins, payments, new payees and card use where your bank offers them.
- Reduce payment limits if you do not need high limits. Many banking apps let you lower transfer or card limits.
- Review trusted devices. Remove any phone, tablet or browser you no longer use.
- Do not share one-time passcodes. A code is often the final key a criminal needs.
- Be careful with public information. Details such as your date of birth, pet names, school, workplace or family names can help criminals answer security questions or personalise scams.
How to handle suspicious calls safely
If someone calls claiming to be from your bank, the police, HMRC, the FCA or a fraud team, you are allowed to stop the conversation. A genuine organisation will not object to you checking independently.
- Do not rely on caller ID. Numbers can be spoofed.
- Do not call back using a number given during the call.
- Use the number on your bank card, statement or official website.
- Do not move money to a “safe account”. This is a common scam phrase.
- Do not give remote access to your phone or computer.
- Do not reveal your PIN, password, memorable information or one-time passcodes.
The FCA advises people to hang up on suspicious calls and return the call using contact details from a trusted source such as a bank statement or the FCA Firm Checker, rather than details supplied in the message or call.
What is uncertain?
The 78,387 figure is a verified Cifas figure for account takeover cases reported to the National Fraud Database in 2025. However, it should not be read as “78,387 UK banking app takeovers”. Cifas’ public summary says mobile phone products dominated, with online retail and personal credit cards also major categories.
It is also difficult to know exactly how many individual scams used AI. Cifas says AI is accelerating and improving fraud tactics, but not every account takeover will involve AI. The safer assumption is that scam messages and impersonation attempts may now look and sound more convincing than older, more obvious scams.
Key takeaway
Account takeover is rising, and AI is helping scammers make phishing, impersonation and credential attacks more believable. The most useful steps are still practical: secure your email, use unique passwords, turn on two-step verification, never share passcodes, and contact your bank immediately through official channels if anything feels wrong.