Report Fraud Annual Assessment 2026: What SMEs Should Know

Investors were told they could buy fine wine, leave it securely stored and sell it later at a profit. If they preferred, the bottles could be delivered to their home.

Some had responded to social media adverts. Others had been contacted directly. A broker explained the arrangement, and money changed hands.

Then the problems began. Brokers became unreachable. Investors were told their wine was missing or inaccessible, or that the company had ceased trading. Some later heard from law enforcement that the operation was under investigation.

The first Report Fraud Annual Assessment identifies 401 reports linked to this unnamed wine investment company, with £23 million in reported losses. The average loss per victim was £62,093.

The case illustrates a pattern that runs through the assessment. Modern fraud often succeeds by resembling ordinary life and business: an investment held in storage, an invoice from a supplier, a message from a colleague or an endorsement from a familiar public figure. Technology helps criminals create that appearance at greater speed and scale.

The first Report Fraud Annual Assessment from a new national service

Published on 3 September 2026, this is the first annual assessment from Report Fraud, the national service that replaced Action Fraud across England, Wales and Northern Ireland on 4 December 2025. Its full public launch followed in January 2026.

Report Fraud brought cyber crime and fraud reporting, triage and intelligence into one system. It was designed to give victims a clearer route into policing and to produce better information for investigators, government and industry. The annual assessment is the first substantial view of what that new intelligence picture can reveal.

It covers reports made during the 2025/26 financial year, including data from victims, businesses and partner organisations. The report also draws in Cifas (Credit Industry Fraud Avoidance System) crime reports and uses revised questions intended to record offences more consistently.

That makes it an important starting point, although not yet a clean annual benchmark. Report Fraud launched part-way through the year, and changes to data sources and reporting methods affect comparisons with 2024/25.

The headline figures show why that qualification matters. Report Fraud recorded 503,288 fraud reports, a 50% annual increase. Most of that rise came from the inclusion of Cifas data. Excluding Cifas, reports increased by 6%, from 336,207 to 356,073.

Reported fraud losses still rose by 26% to £3.2 billion. Cifas reports contained no loss figures, so the additional data source does not explain that increase. These remain self-reported losses, however, and the assessment excludes cryptocurrency losses from its financial totals.

The figures are best read as an emerging national picture, grounded in real reports but shaped by what victims recognise, record and choose to report.

Fraud increasingly creates a reason to trust

Investment fraud accounted for 36,464 reports and £911 million in reported losses. Report volumes rose by 37% and losses by 20%, while the average loss fell by 13% to £28,188. The report reads this as a move towards more incidents with lower individual losses, although it also notes that greater awareness of reporting channels and the launch of Report Fraud may have contributed to the rise in volumes.

The wine case shows why some investment fraud can remain hidden. Storage and delayed returns were part of the proposition, so the absence of a physical asset or immediate payment did not initially look unusual. The structure of the investment gave the fraud time to continue.

Other scams create trust in different ways. Romance fraud reports rose by 26% to 11,980, with losses reaching £121.1 million.

In some cases, criminals combined a supposed relationship with a fraudulent investment. There were 423 reports of this hybrid romance and investment fraud. An emotional relationship becomes the route through which the investment is introduced.

Artificial intelligence can make the supporting evidence more convincing. In 956 reports, the victim identified suspected AI use, a 395% increase on the 193 reports of the previous year. Reported losses associated with these cases rose from £1.2 million to £9.6 million.

Investment fraud made up 37% of these AI-related reports. Methods included generated videos of celebrities and public figures apparently endorsing investments, manipulated images, cloned voices and real-time video impersonation. The report is careful about what these figures prove: victims may fail to recognise AI, while greater public awareness may itself increase reporting. The true prevalence remains unknown.

AI is helping criminals produce believable identities, conversations and evidence for established forms of fraud. The National Assessment Centre reached a similar conclusion in March 2026, finding that criminals were using generative AI to enhance and scale existing threats.

A trusted account can be more useful than a fake one

The same pattern appears in fraud against businesses. Taking control of a real account gives a criminal an identity that colleagues, customers and suppliers already trust.

Report Fraud received 2,271 cyber-crime reports from organisations. Hacking of email, social media and other online accounts made up 55% of them. Phishing and social engineering were the most commonly reported routes into organisations.

Access to a supplier's email account can give a criminal an existing email history, names, writing styles and the timing of an expected payment. A request to change bank details then arrives inside a real conversation rather than as an obvious approach from a stranger.

Payment diversion fraud accounted for 3,657 reports, with losses of £101 million. Invoice fraud was its largest subcategory. The assessment also found attempts to change the destination accounts used by hotel, restaurant and ordering platforms in order to divert payments.

There are some signs of progress. Payment diversion losses fell by 24%, despite a 3% rise in reports. UK Finance's separate banking data also found that invoice and mandate, CEO and impersonation scams had fallen to multi-year lows. At the same time, losses from purchase, investment, romance and advance fee scams reached record levels.

That pattern is consistent with controls that check where money is going taking effect, although neither report attributes the change to them. Those controls matter less when the recipient is correctly identified but the underlying product, investment or relationship is false.

Account protection needs payment controls

SMEs accounted for 62% of organisational cyber-crime reports, and organisation size was recorded in 69% of reports. The smallest organisations, with fewer than 50 employees, accounted for 45%. The report also notes that SMEs make up 99% of UK organisations, so the data does not show that they are being attacked out of proportion to their presence in the economy.

It does show that the threat reaches ordinary businesses. Smaller firms often depend on a limited number of people to manage email, suppliers, payments and IT. A compromised account or convincing request can cross several of those functions at once.

The assessment recommends Cyber Essentials for SMEs. Its five technical controls cover secure configuration, software updates, user access, malware protection and firewalls, reducing common routes into business systems.

The report also recommends passkeys, which resist phishing because there is no password for a user to reveal. Where passkeys are unavailable, the NCSC advises strong passwords and two-step verification.

Those technical measures need matching business controls. Changes to supplier or customer payment details should be checked through contact information already held, independently of the request. Unusual transactions should receive a meaningful second approval. Staff should be able to pause a payment without being blamed for slowing the business down.

The wine investors were given an asset, a broker and a plausible reason to wait. Each element supported the others. Businesses encounter similar chains of trust every day, usually for entirely legitimate reasons.

The practical response is to protect the accounts through which trust is communicated, then verify the evidence before money or access changes hands. As fraud becomes better at looking ordinary, that independent check becomes one of the few signals a criminal cannot manufacture alone.

A strong first Report Fraud Annual Assessment

This first Annual Assessment deserves credit. It turns hundreds of thousands of individual reports into a coherent national picture, combines the figures with revealing case studies and is candid about the limits of the data. That is a valuable contribution during the transition from Action Fraud to a new reporting and intelligence service.

The next edition should be even more revealing. It will cover a full year of Report Fraud, allow cleaner comparisons and begin to show whether better intelligence is leading to earlier intervention and less harm.

Fraud succeeds by hiding inside ordinary transactions, conversations and relationships. This report starts to make those patterns visible. The next will show whether that clearer view is helping us stop them.

If you support small businesses and want to talk through how Cyber Essentials fits into that work, you can book a call with a CyberSmart advisor. For more analysis like this, subscribe to CyberSmart's LinkedIn newsletter.

Sources