UK Account Hijacking Fraud Up 400% as Scammers Sell Fake Tickets Through Victims' Own Profiles

Criminals are breaking into people's email and social media accounts to impersonate them, then selling counterfeit concert tickets to the victim's own friends. The UK's cybersecurity authority says one fix is already in most people's pockets.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 3 min read
Illustration: A smartphone screen glowing in a darkened room shows a social media profile page with a notification badge
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Losses from account-impersonation fraud in the UK rose by more than 400% in a single year, according to official UK data reported by The Guardian.
  • Criminals break into email and social media accounts, then pose as the account owner to sell fake tickets for sold-out events to the victim's contacts.
  • The UK National Cyber Security Centre (NCSC) now actively recommends passkeys over passwords wherever they are available.
  • Passkeys, built on the FIDO2 open standard, cannot be intercepted or stolen the way passwords can, making them resistant to the phishing attacks that typically start this kind of fraud.

The scam is straightforward and brutal. Criminals break into someone's email or social media account, look at who they know, and then pretend to be that person to sell fake tickets for sold-out gigs to the victim's own friends and family. Because the message comes from a trusted account, people pay without a second thought.

Official UK figures, first reported by The Guardian, show money stolen through account-impersonation fraud climbed by more than 400% in a year. That is not a marginal creep. It is a category of crime that has multiplied roughly five times over in twelve months.

How do criminals get into these accounts in the first place?

Most start with phishing: fake emails or messages designed to trick someone into typing their password into a site that looks legitimate but isn't. Once captured, the account is theirs.

The NCSC is blunt about why passwords are the weak link. They can be guessed, reused across dozens of sites, or leaked in data breaches. Traditional two-step verification, where a site sends a code by text message, helps, but codes can also be intercepted by a convincing enough scammer.

What is a passkey and why does it matter here?

A passkey replaces the password entirely. Your phone or computer generates a unique cryptographic key, a pair of long mathematically linked codes, stored securely on your device. To authenticate, the device checks your face or fingerprint. The NCSC explains on its official passkeys page that passkeys are built on the FIDO2 open standard and are a full replacement for passwords, not an add-on.

Critically, a passkey never travels across the internet in a form that can be stolen. There is no password for a phishing site to capture, which removes the most common entry point for account-hijacking fraud. That said, our 4 September story "Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them" found that attackers don't need to break the cryptography: they walk around it, targeting the humans and processes that manage passkey setup instead.

Passkeys are already available on major platforms: Google and Apple accounts support them, as do a growing number of banks and retailers.

What should people actually do?

Check whether the services you use most, especially email and social media, offer passkeys and switch to them. Setup usually takes under two minutes.

For accounts that don't yet support passkeys, use a password manager to generate a unique, strong password, and turn on two-step verification using an authenticator app rather than a text message where possible.

Anyone contacting you out of the blue to sell tickets deserves a quick phone call to confirm it's really them. An account that's been taken over looks identical to the real one.

Should you worry?

The 400% figure looks like a rounding error until you read what sits behind it: real people, sold-out shows, and trust weaponised against friends. The technical fix exists and adoption is the only thing lagging. Passkeys aren't perfect, but they close the door phishing currently walks straight through.

© 2026 Threat Vectr