Note: This post uses recent UK sources available now. If a figure may move over time, I have named the date or said so clearly.
AI scams and account takeovers are driving a surge in UK fraud reports
UK fraud reporting is being pushed up by two closely linked trends: criminals are using generative AI to make scams more convincing and easier to scale, while account takeover attacks are rising as attackers target bank, retail and mobile phone accounts. The Home Office’s National Assessment Centre says fraud in the UK has increased, is becoming more tech-enabled, and is being scaled with generative AI and other fraud-enabling tools. (gov.uk)
Separate UK data points in the same direction. Cifas reported more than 444,000 fraud cases in 2025, its highest ever annual total, including more than 78,000 facility, or account, takeover cases. It also said criminals are exploiting AI to improve malicious messages and automate credential attacks. Meanwhile, the government’s call for evidence on unauthorised fraud noted a 469% increase in reports of suspected AI-enabled fraud incidents to Report Fraud from 2023 to 2025. (cifas.org.uk)
What happened
Fraudsters have not needed to invent new crime types to benefit from AI. Instead, they are using it to make old tricks faster, cheaper and harder to spot. According to the Home Office, criminals are using social engineering and generative AI to scale attacks and bypass countermeasures. Cifas also says attackers are using stealthier tactics, such as disabling alerts and gradually changing account details, to avoid detection. (gov.uk)
At the same time, account takeover is becoming more common. Cifas reported that mobile phone products were the most common target, followed by online retail and personal credit cards. It also reported a rise in unauthorised SIM swaps, which can let criminals intercept security codes sent by text message. The government’s call for evidence said SIM-swap attacks rose sharply in 2024 and continued to rise afterwards. (cifas.org.uk)
Why it matters
This matters because account takeover can turn a scam into direct financial loss very quickly. Once criminals control a login, phone number or recovery email, they may be able to reset passwords, change contact details, intercept one-time passcodes and make unauthorised purchases or transfers. The government’s fraud strategy says fraud is a major threat to individuals and businesses, and that the response now needs to focus on disruption, protection and victim support. (gov.uk)
It also matters because AI is lowering the cost of producing realistic scam content. That can include persuasive messages, fake customer service chats, cloned voices, spoofed images and more convincing impersonation attempts. The trend does not mean every scam is AI-generated, but official UK sources say AI is increasingly part of the fraud toolkit. (gov.uk)
Who may be affected
In principle, anyone with an online account can be affected. The risk is often higher for people who use:
- banking apps and online banking
- shopping accounts with saved cards or address details
- mobile phone contracts linked to recovery codes
- email accounts used to reset other passwords
- social media accounts that can be used for impersonation or contact-list scams
Businesses may also be affected. The government says fraud is increasingly international and tech-enabled, while Cifas says account takeover remains a major fraud type across sectors. (gov.uk)
Warning signs to watch for
Warning signs are often subtle. Look out for:
- unexpected text messages or emails asking you to verify a login or approve a password reset
- calls claiming to be from your bank, phone provider or a government body, especially if they create pressure to act immediately
- notifications about logins, device changes or password resets you did not request
- missing security alerts, or settings changed on your account without your knowledge
- messages from friends or contacts that feel out of character, which can indicate a hijacked account
- SIM card problems, such as sudden loss of signal, which can be a sign of a SIM-swap attack
GOV.UK warns people to be suspicious if someone asks for payment into an unknown account, demands secrecy, pushes urgent action, or uses poor-quality websites or messages. (gov.uk)
What you should do now
If you think you may be at risk, act quickly:
- Change your passwords for email, banking and any account that uses the same or similar password.
- Turn on two-factor authentication where it is available, preferably using an authenticator app rather than text messages where possible.
- Check your account recovery details and remove anything you do not recognise, such as unfamiliar phone numbers or email addresses.
- Look for suspicious activity in banking, shopping and phone accounts, including new payees, address changes or device changes.
- Contact your bank or provider using the number on the back of your card or from the official website, not from a message you received.
- Report the fraud to Action Fraud or Report Fraud. GOV.UK says Action Fraud is the UK fraud-reporting and advice centre, and reports are analysed by the National Fraud Intelligence Bureau. The Report Fraud statistics dashboard is updated monthly. (reportfraud.police.uk)
If you are a business or organisation under cyber attack, Report Fraud says to call 0300 123 2040 immediately. (reportfraud.police.uk)
How to stay safer next time
The good news is that a few habits can reduce risk:
- use a unique password for every important account
- store passwords in a reputable password manager
- enable app-based 2FA where possible
- keep your phone number, email and recovery options up to date
- be careful with any message that pushes urgency, secrecy or fear
- never trust a caller just because they know some of your personal details
- avoid clicking login links from emails or texts; open the site or app yourself
- check official GOV.UK guidance and fraud warnings regularly, especially if you manage money or help family members online
For UK visa and government-related contacts, GOV.UK also says official government websites end in .gov.uk, and that you should be wary of poor grammar, fake branding and requests for payment by email or to a personal bank account. (gov.uk)
Why the response is getting stronger, but the threat is still growing
The government’s 2026 to 2029 fraud strategy says the UK is taking a three-part approach: disrupt criminals, safeguard the public and respond better to victims. It includes the new Online Crime Centre, an expanded Stop! Think Fraud campaign and the new Report Fraud service. That is a sign that fraud is being treated as a system-wide problem, not just a consumer issue. (gov.uk)
Even so, the figures suggest the threat is still increasing. Cifas reported record annual fraud cases in 2025, and the government says AI-enabled fraud reports are rising. The exact scale is hard to pin down, because official sources also note that fraud is often under-reported and difficult to measure precisely. (cifas.org.uk)
Key takeaway
AI is making scams more convincing, and account takeover is giving criminals a direct route into people’s money and identity. If you use online banking, email, shopping or a mobile number linked to account recovery, it is worth tightening your security now, not after something goes wrong. (gov.uk)