October 5, 2026

Hijacked Social Media Accounts: Why Account Takeover Makes Impersonation Fraud More Convincing

Hijacked Social Media Accounts: Why Account Takeover Makes Impersonation Fraud More Convincing

Reported losses linked to hacked email and social media accounts have risen sharply in the UK, highlighting a particularly effective form of online fraud: criminals using genuine accounts to exploit existing relationships of trust.

Figures published by Report Fraud on 5 October 2026 show that reported stolen sums associated with email and social media account hacking reached £6.3 million during the 2025/26 financial year, compared with £1.2 million the year before, an increase of 417%.

The number of reports also increased by 34%.

One of the most common themes identified was the use of compromised accounts to impersonate friends and family. Once access has been obtained, criminals can approach people who already know and trust the genuine account holder, requesting money, advertising non-existent tickets or creating other convincing reasons for payment.

This makes account takeover different from many conventional impersonation scams.

Why a Genuine Account Can Make Fraud More Convincing

Many online scams depend on persuading someone that a message comes from a person or organisation they trust.

Sometimes that identity is fabricated. A criminal might create a copy of a social media profile, spoof an email address or use a similar-looking domain.

Account takeover removes part of that challenge.

If a criminal gains access to a genuine email or social media account, messages may arrive through the same profile, address or conversation that the recipient has used previously.

The recipient may see:

  • A familiar name and profile.
  • Genuine photographs and historic posts.
  • Previous conversations.
  • Shared contacts.
  • Existing message history.
  • A communication arriving through the expected channel.

The fraudster is effectively stepping into an established digital identity rather than creating a new one from scratch.

That existing trust can make unusual requests appear considerably more credible.

From Account Hacking to Impersonation Fraud

Gaining access to an account may only be the first stage.

Once inside, a criminal may be able to review information that helps make subsequent approaches more believable.

Depending on the account and level of access, this could include information about relationships, events, travel, work, purchases or previous conversations.

The attacker may then contact people within the victim's network.

Report Fraud has highlighted examples involving compromised accounts being used to offer fake event tickets or ask friends and relatives for money.

The important feature is not simply that somebody has been impersonated. It is that the fraud is being conducted from an account that the recipient may already regard as authentic.

This can also create a chain of victims. The original account holder suffers the compromise, while friends, relatives, colleagues or customers may subsequently lose money because they trusted communications sent through that account.

Account Takeover Is Not the Same as Spoofing

It is important to distinguish genuine account compromise from other forms of online impersonation.

Email spoofing, for example, can make a message appear to originate from another email address without the criminal necessarily accessing the genuine account.

Similarly, a fraudulent social media profile can copy a person's name, photographs and other information while remaining entirely separate from the real profile.

In an account takeover, an unauthorised person has obtained access to the genuine account.

That distinction matters when determining what has happened and how an incident should be investigated.

Conflict International has previously examined this distinction in Hacked or Spoofed? When an Email Appears to Have Been Sent From Your Own Address.

What Should Be Preserved After an Account Takeover?

Where an account has been compromised and used for fraud, the immediate priority will usually be securing access and preventing further misuse.

However, relevant evidence can easily be lost during the recovery process.

Depending on the circumstances, useful material may include:

  • Suspicious messages sent from the account.
  • Messages received from people approached by the fraudster.
  • Login and authentication records.
  • Security alerts and password-reset notifications.
  • Details of unfamiliar devices or active sessions.
  • Changes to recovery email addresses or telephone numbers.
  • Connected applications.
  • Payment details supplied by the offender.
  • Transaction records where money has been transferred.
  • Screenshots of fraudulent activity.
  • Original emails and associated technical information.

Where possible, evidence should be preserved before messages, sessions or other potentially useful information are deleted.

Screenshots can help demonstrate what appeared on screen, but they may not contain all of the technical information available from the underlying account or original communication.

When an Account Compromise Requires Investigation

Not every compromised account will require a detailed investigation.

In straightforward cases, securing the account, changing credentials and reviewing security settings may be sufficient.

Other incidents can be more complex.

For example, questions may arise over:

  • How the account was accessed.
  • When unauthorised access began.
  • Whether other accounts or devices were affected.
  • What information the attacker was able to view.
  • Whether messages were sent, deleted or altered.
  • Whether the attacker used information from the account to target other people.
  • Whether payments were made as a result.
  • Whether personal or commercially sensitive information was taken.
  • Whether the incident forms part of a wider fraud.

For a business, account compromise can also overlap with payment diversion, business email compromise, data exposure or attempts to impersonate senior personnel.

Establishing the sequence of events can therefore be important both for containing the immediate incident and understanding the wider exposure.

Preventing Account Takeover

Report Fraud's current campaign encourages users to strengthen the security of online accounts, including through the use of passkeys.

Other appropriate measures may include enabling multi-factor authentication, using strong and unique credentials, reviewing account recovery options and monitoring security notifications.

Users should also treat unexpected requests for money or sensitive information carefully, even when they appear to come from somebody they know.

Where a request is unusual, urgent or involves payment, independently confirming it through another trusted means of communication can help identify impersonation before money is transferred.

The central lesson is increasingly important: a message arriving from a genuine account does not necessarily mean that the genuine account holder sent it.

Responding to Account Compromise and Cyber Fraud

The latest figures demonstrate how compromised accounts can become more than an information-security issue.

Once a criminal takes control of an established digital identity, the relationships and trust attached to that identity can themselves become valuable tools for fraud.

Understanding whether an account has genuinely been compromised, what activity took place and what information may have been exposed can therefore form an important part of the response.

Conflict International provides Cyber Security and Incident Response Services to businesses, organisations and legal teams dealing with account compromise, cyber fraud, data exposure and related digital incidents.

Where appropriate, this can include reviewing suspicious authentication activity, identifying affected accounts and systems, preserving relevant digital evidence and supporting the investigation of fraudulent activity connected with the incident.

If you are dealing with suspected account compromise, impersonation or related cyber fraud, contact Conflict International to discuss the circumstances in confidence.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a brief background to your case and the reasons for initiating an investigation.

What is your required outcome? (e.g. Asset Identification, Litigation Support, Due Diligence, or Risk Mitigation).

Please define your relationship to the person or entity of interest (e.g. Legal Counsel, Business Partner, Family Member, or Victim of Fraud).

Please list any specific details you currently possess, such as names, addresses, or any other known details which may assist.

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite