Financial cybercrime cost UK bank customers £1.28 billion in 2025 alone, and the criminals behind it are shifting tactics faster than most people realise. Financial cybercrime encompasses every form of digital fraud targeting your bank account, savings, or payment details, from a scam text that appears to be from your bank to a fraudster posing as a builder who needs an urgent deposit. This guide sets out the latest UK statistics on financial cybercrime, the new rules that determine whether you get your money back, and the practical steps to take if it happens to you.

Unlike a stolen wallet, financial cybercrime often leaves no obvious sign until the money is already gone. That makes understanding your rights before an incident happens far more useful than reading about them for the first time afterwards.

The Current State of Financial Cybercrime in the UK

Financial cybercrime in the UK is not shrinking. UK Finance’s Annual Fraud Report 2026 recorded more than four million confirmed fraud cases in 2025, a rise of eleven per cent on the year before, with total losses of £1.28 billion. On average, eight people were defrauded every minute in 2025, losing close to £2,500 between them in that same minute.

Authorised Push Payment Fraud: The Biggest Threat

Authorised push payment fraud, in which a victim is tricked into sending money to a fraudster rather than having it stolen without their knowledge, is the fastest-growing part of the UK’s financial cybercrime problem. Losses rose 19 per cent in 2025 to £576.4 million, even as unauthorised fraud, such as stolen card details used without the victim’s knowledge, fell 5 per cent to £703.4 million.

Purchase scams, in which the victim pays for goods or services that never arrive, accounted for 71 per cent of all authorised push payment cases. Investment scams caused the most damage per case, with losses up 40 per cent to £221.5 million, and romance fraud losses rose 23 per cent to £39.2 million.

Two-thirds of these cases started on online platforms such as social media and marketplaces, with a further 17 per cent beginning through a phone call or text message. Our guide to phishing attack trends and statistics covers the messaging tactics criminals use to make first contact.

Investment Scams and the Rise of AI Voice Cloning

Investment fraud is now the single most damaging category of financial cybercrime by value, and criminals are increasingly using artificial intelligence to make their approaches convincing. AI-generated voice cloning is being used to impersonate a relative, a colleague, or a bank’s own fraud team, and to ask the victim to move money urgently to a “safe account.” No genuine bank or family member will ever ask you to transfer money to protect it. Treating any request like that as a reason to hang up and call the person back on a known number, rather than a number given during the call, remains the single most effective defence.

Card Fraud and Account Takeover

Authorised push payment scams get most of the attention, but unauthorised financial cybercrime, where a criminal uses your card or account without your knowledge or consent, still accounts for the larger share of total losses. Remote purchase card fraud, where stolen card details are used to buy goods online without the physical card present, rose 3 per cent in 2025 to £423.5 million, with case numbers up 13 per cent to 3.2 million. Lost and stolen card fraud fell slightly to £109.8 million, while contactless fraud rose 8 per cent to £46.8 million as more everyday spending moved to tap-and-go payments.

Account takeover, where a criminal gains enough personal information to log into an existing account and change its details, remains a particular concern because it often goes unnoticed until a statement arrives. Enabling two-factor authentication on banking and email accounts and using a unique password for each closes off the two most common routes in. Our guide to creating strong passwords sets out how to do this without resorting to easily guessed variations.

The PSR’s Mandatory Reimbursement Rules

Since October 2024, most victims of authorised push payment fraud have had a legal right to reimbursement rather than relying on their bank’s goodwill. The rules are more specific than many people realise, and knowing the details matters if you ever need to make a claim.

Who Is Covered and What Is Excluded

The Payment Systems Regulator’s reimbursement requirement applies to consumers, micro-enterprises and charities who lose money to authorised push payment fraud sent through Faster Payments or CHAPS within the UK. It does not cover international transfers, cash payments, card fraud, or losses arising from a genuine but disputed commercial transaction rather than a scam. The sending bank and the receiving bank split the cost of reimbursement equally between them, which was designed deliberately to give both sides a financial reason to invest in fraud detection rather than leaving the sending bank to carry the loss alone.

The £85,000 Reimbursement Limit and the Consumer Standard of Caution

Reimbursement under the scheme is capped at £85,000 per claim. This figure was set after the regulator originally proposed a much higher limit of £415,000, then lowered it following industry consultation, deliberately aligning it with the existing compensation limit under the Financial Services Compensation Scheme so it would be a figure consumers already recognised. The regulator’s own data shows this limit still covers 99.8 per cent of cases by volume and around 90 per cent of the total money lost.

Banks can apply an excess of up to £100 per claim, though this cannot be charged to a customer classed as vulnerable, and can refuse a claim entirely if the customer is judged to have shown gross negligence under what is called the consumer standard of caution, for example, ignoring a clear, specific warning from their bank about a scam in progress. Claims must be reported within 13 months of the final payment, and a bank has five working days to reimburse a victim, or up to 35 working days if it needs more information first.

In 2025, banks reimbursed £354.3 million to authorised push payment victims, around 61 per cent of total losses under the scheme. Losses above £85,000 are not left without any recourse. They can still be pursued through a complaint to the bank and, if unresolved, escalated to the Financial Ombudsman Service, which has the power to award compensation of up to £430,000 per complaint.

Consumer Protection Across the UK and Ireland

Financial Cybercrime, consumer protection

Financial cybercrime protection is not uniform across the UK and Ireland, and the differences matter if you live near a border or bank with an institution based in another jurisdiction.

England, Wales and Scotland: The Financial Ombudsman Service

Across Great Britain, the Financial Ombudsman Service is the independent body that reviews a complaint if you are not satisfied with your bank’s decision on a reimbursement claim. It is free to use, does not require a solicitor, and reaches decisions based on what it considers fair and reasonable, given the full circumstances of the case, rather than following a rigid checklist. Reports of suspected fraud should still go to Action Fraud in the first instance, as it is the UK’s central reporting body that identifies patterns across multiple victims.

Northern Ireland: Same UK Protections, Different Reporting Route

Northern Ireland falls under the same UK GDPR, PSR reimbursement rules and Financial Ombudsman Service as the rest of the UK, so the underlying financial cybercrime protections are identical. The practical difference is local policing: alongside reporting to Action Fraud, victims in Northern Ireland can also involve the Police Service of Northern Ireland’s economic crime unit, particularly where an incident is linked to organised crime operating across the Irish border.

Republic of Ireland: A Different System Altogether

The Republic of Ireland sits outside the UK’s regulatory framework entirely, so the PSR’s mandatory reimbursement scheme does not apply there. Payment fraud is regulated by the Central Bank of Ireland; complaints go to the Financial Services and Pensions Ombudsman rather than the Financial Ombudsman Service; and suspected fraud is reported to An Garda Síochána, typically through the Garda National Economic Crime Bureau for larger or more complex cases.

The EU’s own equivalent reimbursement framework, part of the incoming PSD3 and Payment Services Regulation package, is expected to introduce protections modelled on the UK’s approach, but it remains in the legislative process and is not likely to be operational before 2027, so Irish consumers currently have no direct equivalent to the UK’s mandatory reimbursement right.

Protecting Yourself Before Financial Cybercrime Happens

Prevention is worth far more than any reimbursement claim, since even a successful claim rarely covers the time, stress and disruption of dealing with fraud after the fact.

Recognising the Warning Signs

Most financial cybercrime relies on urgency and a plausible story rather than technical sophistication. A request to move money quickly, to a new or unfamiliar account, that discourages you from checking with anyone else first, is the pattern behind almost every authorised push payment scam, whatever story sits around it. Genuine banks, HMRC and the police will never ask you to transfer money to a “safe account,” and a caller who becomes impatient or hostile when you say you want to check independently is close to certainly a fraudster. Our guide to what cyber fraud is covers the wider range of tactics behind these approaches, beyond banking specifically.

What Banks Are Doing on Their Side

Banks are not passive in this. Confirmation of Payee, which checks that the name on a payment matches the account it is going to, is now standard across the UK’s largest banking groups, and most banks now use behavioural monitoring to flag payments that look out of character for a customer before they are sent. For a closer look at how banks themselves defend against financial cybercrime, our guide to cybersecurity in the banking sector covers the institutional side of this in more depth. None of this removes the need for personal vigilance, since the fastest-growing scams are specifically designed to get a victim to bypass their bank’s own warnings.

How to Recover Money After a Banking Cyber-Attack

What you do in the first hour after realising you have been targeted by financial cybercrime has a real effect on whether the money can be recovered at all.

The First Hour: Containing the Damage

Call your bank’s fraud line immediately, using the number on the back of your card or its official website rather than any number given to you during the incident itself, since fraudsters frequently spoof bank numbers. Ask the bank to freeze the receiving account if you have the details, since payments can sometimes still be recalled if reported within minutes rather than hours. Report the incident to Action Fraud, or to the Police Service of Northern Ireland or An Garda Síochána, depending on where you are based, and change the passwords on your online banking and email accounts straight away in case the fraudster gained access to more than just the payment itself.

Escalating to the Financial Ombudsman Service

If your bank declines your reimbursement claim, ask for its final written response letter, as you will need it to escalate the complaint. You then have six months from the date of that letter to refer the case to the Financial Ombudsman Service, which will review the bank’s decision independently and can overturn it if it finds the bank did not apply the rules correctly or acted unfairly.

There is no cost to the customer for using the service, and you do not need a solicitor to submit a case. However, keeping a clear timeline of events, screenshots of any messages from the fraudster, and copies of everything sent to the bank makes for a stronger case than a verbal account alone. The Ombudsman typically takes several months to reach a final decision in more complex financial cybercrime cases, so patience and persistence are often needed.

What to Do if Your Bank Refuses a Refund

A bank refusing a claim on the grounds of gross negligence must be able to show real evidence for that decision, not simply assert it. If you believe you followed reasonable care and were still refused, keep every piece of correspondence with the bank and the fraudster, including screenshots of messages, and put your case to the Ombudsman in writing rather than accepting the refusal as final. Our guide to preventing a data breach also covers the wider steps to take if the fraud involved a compromise of your personal data rather than a one-off scam payment.

The Future of Banking Security

Financial cybercrime and the defences against it are both moving quickly, and two changes in particular are likely to shape UK banking security over the next few years.

AI-Driven Fraud Detection

Banks are increasingly using machine learning models to flag unusual payment patterns in real time, comparing a transaction against a customer’s normal behaviour rather than relying on fixed rules alone. A payment that matches your usual spending pattern in size, timing and destination is far less likely to trigger a hold than one that breaks from it sharply, which is why banks sometimes intervene with a warning or a temporary delay on a payment that looks entirely normal to the customer making it but unusual against their own history.

This cuts both ways: the same technology that helps banks spot fraud faster is also being used by criminals to write more convincing scam messages and clone voices, so the contest between detection and deception is likely to keep accelerating rather than settling down.

Biometric Authentication and the Decline of SMS Codes

Fingerprint and facial recognition are gradually replacing SMS one-time passcodes for approving payments, since text messages can be intercepted via SIM-swapping attacks in ways that fingerprints cannot be. Expect more banks to push customers towards biometric approval within their banking apps over the coming years, alongside wider adoption of passkeys in place of passwords for logging in. Our guide to secure online transactions covers the wider authentication changes affecting online payments more generally.

FAQs

What counts as financial cybercrime?

Financial cybercrime encompasses any digital fraud aimed at stealing money or financial information, including authorised push payment scams, unauthorised card fraud, phishing targeting banking details, and investment or romance fraud that leads to a bank transfer.

Can I get my money back if I authorised the payment myself?

Often yes. Since October 2024, most UK victims of authorised push payment fraud have a legal right to reimbursement from their bank, subject to the £85,000 cap and the consumer standard of caution.

What is the maximum amount a UK bank must refund for authorised push payment fraud?

£85,000 per claim under the PSR’s mandatory reimbursement rules. Losses above that figure can still be pursued directly with the bank or via the Financial Ombudsman Service.

Who do I report financial cybercrime to in Northern Ireland?

Action Fraud, the same as the rest of the UK, alongside the Police Service of Northern Ireland’s economic crime unit, for cases with a cross-border dimension.

Does the Financial Ombudsman Service always side with the bank?

No. It is independent of both banks and consumers and decides each case on what it considers fair and reasonable, which can and does result in decisions against banks where a reimbursement claim was wrongly refused.

How long does a bank have to respond to a fraud claim?

Five working days under the PSR rules, extendable to 35 working days if the bank genuinely needs more information from the customer to reach a decision.

Is financial cybercrime covered by my home insurance?

Rarely for the loss itself, though some UK home insurance and bank account packages include identity theft assistance. Check your policy documents, since cover varies significantly between providers and is not something to assume you have.