top of page

Social Media, Email and WhatsApp compromise cost businesses £3.8m in last 12 months

Updated: Apr 17, 2023

Unsecured social media and email accounts with organisations, such as limited companies, sole traders and charities, reported losing £3.8 million to these crimes to hackers between February 2020 and February 2021.


The Cyber Resilience Centre for the South East wants to reaffirm the message for you to secure your social media and email accounts. Criminals managed to compromise more than 15,000 accounts in the past year.


The national reporting centre for fraud and cybercrime, Action Fraud received 15,214 reports of email and social media hacking between February 2020 and February 2021 – with 88 per cent of victims being individuals who had their personal accounts compromised by criminals. 23% of victims were aged between 20 and 29.

For organisations, such as limited companies, sole traders and charities, there were significantly fewer reports (1,741 reports of hacking), they reported loses of £3.8 million to these crimes compared to the £283,500 lost by individual victims.

How do cyber criminals exploit WhatsApp?


If you add a new device to a WhatsApp account, it requires a code that is sent to the WhatsApp account associated with the original phone number. However, it is becoming apparent that offenders are commonly using social engineering methods to obtain this code and add their own device.


When your social media or email accounts are compromised the loss isn’t just financial. Research conducted by the NFIB found that victims said having their account compromised has a significant or severe emotional impact, as intimate photos and private details can be exposed. How can I protect myself and my business and keep my accounts secure?

  • When did you last update your password? Make sure you are using a strong and separate password to protect your email - Don't use the same password on multiple accounts! Make sure that you're protecting your other important accounts, such as banking or social media.

  • Always enable two-step verification (2SV). It really simple to set up and will help you to stop hackers from getting into your online accounts, even if they find your password.

  • Be wary of messages which ask for your login details or authentication codes. Despite some messages appearing genuine or claiming to be from someone you know.

  • Use online support or help pages. If you can't access your account, you'll often find information about how to recover your account.

  • Always report suspicious emails you have received. Please forward scam emails to report@phishing.gov.uk. and suspicious texts you have received but not acted upon to 7726.

What can I do if my account has been compromised? If you lose access to your account or a hacker has taken control, please follow the NCSC’s guidance on how to recover a compromised account. If you receive a demand for money, do not pay the suspect so you can regain access to your account. It’s likely that the suspect will demand more money instead of giving you control of your account back. If you have paid any money, contact your bank immediately and report it to Action Fraud online or call 0300 123 2040 as soon as possible. Other ongoing scams to watch out for include; Fake Netflix emails, Post Office Scams & COVID-19 vaccine appointments.

bottom of page