Skip to Content

Cyber Crime

Cybercrime and Online Fraud: How to Protect Yourself


Fraud and computer misuse are among the most common crimes affecting people in England and Wales.


The latest detailed Crime Survey for England and Wales estimated approximately 4.2 million incidents of fraud and 692,000 incidents of computer misuse in the year ending March 2025.


These are survey estimates rather than the number of crimes reported to the police. The true scale is difficult to establish because many victims do not report what happened.


People may remain silent because they:


  • feel embarrassed;
  • blame themselves;
  • believe the loss is too small;
  • do not know where to report it;
  • think the criminal cannot be identified;
  • fear criticism from employers or relatives; or
  • do not realise that a crime has occurred.

Cybercriminals deliberately exploit trust, urgency, fear and confusion. Becoming a victim does not mean that someone was foolish.


What Is Cybercrime?


Cybercrime is a broad term covering criminal activity involving computers, telephones, online accounts, networks or digital information.


It may include:


  • hacking;
  • phishing;
  • ransomware;
  • malware;
  • account takeover;
  • identity theft;
  • online banking fraud;
  • investment scams;
  • romance fraud;
  • online shopping fraud;
  • data theft;
  • cyberstalking;
  • sextortion; and
  • attacks against businesses or public services.

Some crimes exist only because of technology. In other cases, computers and telephones are simply used to commit traditional offences such as fraud, theft, blackmail or harassment.


What Is Phishing?


Phishing occurs when a criminal uses a fraudulent email, text message, telephone call, social-media message or website to trick someone into revealing information or taking an unsafe action.


The message may appear to come from:


  • a bank;
  • HM Revenue and Customs;
  • a delivery company;
  • the police;
  • a utility provider;
  • a government department;
  • an employer;
  • a solicitor;
  • a friend or relative; or
  • a familiar online service.

The criminal may try to persuade the recipient to:


  • follow a link;
  • open an attachment;
  • enter a password;
  • provide card details;
  • approve a payment;
  • download software;
  • call a fraudulent telephone number; or
  • allow remote access to a device.

Can an Email Address Be Faked?


Yes. The name and address displayed in an email can be disguised or imitated.


A message may appear to come from a genuine organisation even though a criminal sent it.


Fraudsters may also register a domain name that differs from the genuine address by only one letter or symbol.


Do not rely solely on the sender's name, logo, formatting or email address when deciding whether a message is genuine.


Warning Signs of a Phishing Message


Possible warning signs include:


  • unexpected urgency;
  • threats that an account will be closed;
  • requests for passwords or security codes;
  • an unexpected payment request;
  • a link that does not match the organisation's genuine website;
  • poor spelling or unusual wording;
  • an unexpected attachment;
  • a request to keep the transaction secret;
  • a change to familiar bank details; or
  • a message that creates panic, excitement or pressure.

Some fraudulent messages contain perfect spelling and branding. Artificial intelligence and stolen business information can make scams highly convincing.


What Is Smishing?


Smishing is phishing carried out by text message or another mobile-messaging service.


Common examples include messages claiming that:


  • a parcel could not be delivered;
  • a small delivery fee is due;
  • a bank account has been compromised;
  • a tax refund is available;
  • a parking penalty remains unpaid;
  • a family member has lost their telephone; or
  • an account must be verified immediately.

The link may lead to a fraudulent website designed to steal card details, passwords or personal information.


What Is Vishing?


Vishing is phishing conducted by telephone.


The caller may pretend to be from a bank, the police, a technology company or another trusted organisation.


The telephone number displayed on the recipient's screen may be spoofed, meaning it has been manipulated to resemble a genuine number.


A caller may claim that:


  • money must be moved to a safe account;
  • a bank employee is involved in fraud;
  • a payment needs to be cancelled;
  • the victim’s computer is infected;
  • a tax or court payment is overdue; or
  • the victim must assist with a confidential investigation.

A bank or police officer will not ask you to transfer money to a "safe account" or hand over cash, cards or security codes.


Technical Support Scams


A common scam begins with a telephone call or pop-up message claiming that the victim's computer has a virus or security problem.


The criminal may pretend to represent Microsoft, Apple, an internet provider or a security company.


They may ask the victim to:


  • install remote-access software;
  • visit a particular website;
  • read out information shown on the screen;
  • log into online banking;
  • pay for unnecessary repairs; or
  • provide passwords and card details.

Once remote access is granted, the criminal may view files, steal information, install malware or operate the victim's online banking.


End the call. Do not follow instructions or install software.


What Is Malware?


Malware means malicious software designed to damage, disrupt, monitor or gain unauthorised access to a device or network.


Malware may be installed through:


  • a fraudulent attachment;
  • an unsafe download;
  • a fake software update;
  • a compromised website;
  • an infected storage device;
  • pirated software;
  • a malicious mobile application; or
  • remote access given to a criminal.

Types of malware include viruses, spyware, keyloggers, trojans and ransomware.


What Is a Keylogger?


A keylogger records information entered through a keyboard or device.


It may capture:


  • passwords;
  • banking details;
  • private messages;
  • email addresses;
  • searches;
  • documents; and
  • other sensitive information.

Keylogging may be carried out through malicious software or, less commonly, through a physical device connected to a computer.


Spyware and Screen Monitoring


Spyware may allow a criminal to monitor activity without the user's knowledge.


Depending on the software and permissions obtained, it may:


  • take screenshots;
  • record browsing activity;
  • read messages;
  • access photographs;
  • track location;
  • activate a microphone;
  • access a camera; or
  • collect account credentials.

Monitoring software can also be used as part of domestic abuse, stalking or workplace misconduct.


Webcam and Intimate-Image Blackmail


A criminal may obtain intimate images or recordings by hacking a device, using a false online identity or persuading the victim to participate in a video call.


The criminal may then threaten to send the material to relatives, friends, colleagues or social-media contacts unless money is paid.


This is commonly known as sextortion.


Do not assume that paying will end the threats. Further demands frequently follow.


Preserve the evidence, stop communicating where safe, report the account, and contact the police.


What Is Ransomware?


Ransomware is malware that prevents access to a device or data, commonly by encrypting files.


The criminal then demands payment, often in cryptocurrency, in return for restoring access.


Some attackers also steal information and threaten to publish it.


Paying a ransom does not guarantee that:


  • files will be restored;
  • stolen data will be deleted;
  • the criminal will not demand more money;
  • the system is free from malware; or
  • the victim will not be attacked again.

Affected organisations should obtain specialist cyber-security and legal advice immediately.


Account Takeover


Account takeover occurs when a criminal gains access to an email, banking, social media, shopping or other online account.


This may happen through:


  • a stolen password;
  • phishing;
  • malware;
  • a leaked database;
  • password reuse;
  • the interception of security codes;
  • social engineering; or
  • unauthorised access to a telephone number.

Once inside an account, the criminal may change the password, impersonate the owner, steal information or target the victim's contacts.


Email Account Takeover


An email account is particularly valuable because it can be used to reset passwords for many other services.


A criminal with access to email may:


  • read private correspondence;
  • identify upcoming payments;
  • intercept invoices;
  • reset banking or social-media passwords;
  • impersonate the account holder;
  • send scams to contacts; and
  • delete security warnings.

Email accounts should use a strong, unique password and two-step verification.


Business Email Compromise


Business email compromise occurs where criminals impersonate a senior employee, supplier, solicitor, client or other trusted contact to redirect a payment.


The criminal may compromise a genuine email account or create a similar-looking address.


Typical examples include:


  • changing the bank details on an invoice;
  • requesting an urgent confidential payment;
  • intercepting conveyancing correspondence;
  • redirecting wages;
  • requesting gift cards; or
  • impersonating a director or senior manager.

Any request to change payment details should be checked using a trusted telephone number already held on file.


Authorised Push Payment Fraud


Authorised Push Payment fraud occurs where a victim is deceived into instructing their bank to transfer money to a criminal-controlled account.


It may involve:


  • purchase scams;
  • investment fraud;
  • romance fraud;
  • invoice fraud;
  • impersonation scams;
  • property transaction fraud; or
  • false police or bank calls.

Qualifying payments made through Faster Payments or CHAPS may fall within the mandatory reimbursement framework introduced in October 2024.


Anyone who has transferred money should contact their bank immediately.


Identity Theft


Identity theft involves obtaining and using another person's information without permission.


Stolen details may be used to:


  • open bank accounts;
  • apply for loans or credit cards;
  • take over telephone contracts;
  • purchase goods;
  • access benefits or tax accounts;
  • create false online profiles; or
  • commit fraud in the victim’s name.

Victims should check bank statements, credit reports and official accounts for unfamiliar activity.


Password Security


Use a different password for each important account.


If one service suffers a data breach, criminals may test the stolen password against banking, email, shopping and social-media accounts.


A strong password should be:


  • long enough to resist guessing;
  • unique to the account;
  • difficult to associate with the user; and
  • stored securely.

A password manager can create and store unique passwords so that the user does not have to remember each one.


Use Two-Step Verification


Two-step verification adds an additional security check when an account is accessed.


This may involve:


  • an authentication application;
  • a security key;
  • a passkey;
  • a code sent to a device; or
  • biometric confirmation.

It can prevent many account takeovers even where a password has been stolen.


Two-step verification should be enabled on email, banking, social media, cloud storage and other important accounts.


Keep Devices Updated


Software updates frequently contain security fixes for newly discovered weaknesses.


Enable automatic updates for:


  • computers;
  • telephones;
  • tablets;
  • internet browsers;
  • applications;
  • routers;
  • smart televisions; and
  • other internet-connected devices.

Devices and software that are no longer supported should be replaced or isolated where possible.


Antivirus and Built-In Security


Modern operating systems normally contain built-in security tools, including firewalls and malware protection.


These protections should be enabled and kept updated.


Additional commercial antivirus software may be useful in some circumstances, but no security product can protect against every scam.


Security software cannot prevent a user from deliberately approving a fraudulent transfer or giving a criminal remote access.


Back Up Important Information


Regular backups can reduce the damage caused by ransomware, equipment failure, theft or accidental deletion.


Important files may be backed up to:


  • a reputable cloud service;
  • an external storage device; or
  • both.

A backup should not remain permanently connected to a device if ransomware could encrypt it along with the original files.


Online backup accounts should be protected with a unique password and two-step verification.


Be Careful With Links and Attachments


Do not open an unexpected attachment or follow an unfamiliar link merely because the message appears to come from someone you know.


Their account may have been compromised.


Where a message appears to come from a bank or service provider:


  • do not use the link in the message;
  • open the organisation’s official application; or
  • enter the known website address yourself.

Contact the sender through a separate trusted method if the request is unusual.


Banks and Security Information


A genuine bank may contact a customer to discuss suspicious activity, but it will not ask the customer to:


  • disclose a full password;
  • provide a PIN;
  • read out a complete security code;
  • move money to a safe account;
  • allow remote access to a device;
  • hand over a bank card to a courier; or
  • conceal the transaction from branch staff.

End the call and contact the bank using the number printed on the card or another independently verified number.


What Should You Do After Clicking a Suspicious Link?


If no information was entered and nothing was downloaded, close the page and run an appropriate security check.


If you entered a password:


  • change it immediately;
  • change it anywhere else it was reused;
  • enable two-step verification;
  • sign out other active sessions; and
  • check the account for altered security details.

If bank or card details were provided, contact the financial institution immediately.


If software was installed or remote access was granted, disconnect the device from the internet and obtain specialist assistance.


What Should You Do if Your Computer Is Locked?


Do not telephone or pay the person identified in a pop-up message.


A frozen screen may be caused by:


  • a fraudulent browser message;
  • malware;
  • ransomware;
  • a technical failure; or
  • a fake security warning.

Disconnect the device from the internet and seek help from a reputable computer professional or the device provider.


Do not give an unknown caller remote access to investigate the problem.


What Should You Do if Money Has Been Stolen?


Contact your bank or payment provider immediately using a trusted number.


Ask it to:


  • stop any payment that has not completed;
  • contact the receiving bank;
  • secure the account;
  • cancel compromised cards;
  • investigate unauthorised transactions;
  • consider reimbursement rights; and
  • record any relevant vulnerability.

Speed can make a significant difference to the chance of recovering money.


Preserving Evidence


Keep copies of relevant:


  • emails;
  • text messages;
  • telephone numbers;
  • usernames;
  • web addresses;
  • screenshots;
  • bank records;
  • receipts;
  • cryptocurrency wallet details;
  • remote-access software names; and
  • dates and times.

Do not delete or edit material that may assist an investigation.


Reporting Suspicious Emails and Messages


A suspicious email can be forwarded to the National Cyber Security Centre at report@phishing.gov.uk.


Suspicious text messages can usually be forwarded free of charge to 7726.


Suspicious websites can also be reported through the National Cyber Security Centre.


These services can be used even where no money was lost.


Reporting Fraud or Cybercrime


Report Fraud is the national service for reporting fraud and cybercrime in England, Wales and Northern Ireland.


A report can be made online or by calling 0300 123 2040.


In Scotland, fraud and cybercrime should normally be reported to Police Scotland by calling 101.


Call 999 where:


  • someone is in immediate danger;
  • a crime is taking place;
  • the offender is nearby;
  • there is a threat of violence; or
  • an urgent police response is required.

Businesses Under Cyberattack


A business, charity or organisation experiencing an active cyberattack should contact Report Fraud promptly and obtain specialist technical assistance.


The organisation may also need to consider:


  • isolating affected systems;
  • activating its incident-response plan;
  • preserving logs and evidence;
  • informing its insurer;
  • obtaining legal advice;
  • contacting the Information Commissioner’s Office;
  • notifying affected customers;
  • meeting contractual reporting duties; and
  • considering whether regulators must be informed.

Notification deadlines can be short, particularly where personal information has been compromised.


Personal Data Breaches


A cyberattack involving personal data may create duties under UK data-protection law.


An organisation may need to notify the Information Commissioner's Office where the breach is likely to create a risk to people's rights and freedoms.


Where the risk is high, affected individuals may also need to be informed without undue delay.


Failure to investigate or report an applicable breach can result in regulatory action.


Cybercrime Offences


The Computer Misuse Act 1990 contains offences including:


  • unauthorised access to computer material;
  • unauthorised access with intent to commit or facilitate further offences;
  • unauthorised acts intended to impair the operation of a computer;
  • unauthorised acts causing or risking serious damage; and
  • making, supplying or obtaining articles for use in computer-misuse offences.

Related conduct may also amount to fraud, blackmail, theft, stalking, harassment, data-protection offences or money laundering.


Recovery Scams


Victims may later be contacted by someone claiming that they can recover lost money or data.


The caller may pretend to be:


  • a solicitor;
  • a police officer;
  • a government investigator;
  • a bank employee;
  • a cryptocurrency specialist; or
  • a cyber-recovery company.

They may request an advance fee, access to the victim's device or further banking information.


Never pay an unsolicited person to recover money without independently verifying their identity and regulatory status.


Helping Older or Less Confident Internet Users


Cybersecurity does not need to be technically complicated.


Family members and trusted friends can help by:


  • installing updates;
  • enabling two-step verification;
  • setting up a password manager;
  • reviewing privacy settings;
  • explaining common scams;
  • checking unusual payment requests; and
  • identifying a reputable source of technical support.

Support should be offered without ridicule or blame. Criminals succeed by manipulating people, not merely by exploiting technical weaknesses.


Basic Cybersecurity Checklist


  • Use a unique password for every important account.
  • Enable two-step verification.
  • Keep devices and applications updated.
  • Back up important files.
  • Do not disclose passwords, PINs or security codes.
  • Do not move money to a so-called safe account.
  • Check payment-detail changes independently.
  • Do not grant remote access to an unexpected caller.
  • Pause before responding to urgent messages.
  • Contact your bank immediately if money has been transferred.

How a Solicitor Can Help


A solicitor may assist where cybercrime involves:


  • substantial financial loss;
  • a disputed bank reimbursement claim;
  • identity theft;
  • data protection;
  • business interruption;
  • ransomware;
  • blackmail;
  • defamation;
  • cyberstalking;
  • an urgent injunction;
  • asset tracing;
  • an allegation under the Computer Misuse Act; or
  • a regulatory investigation.

Finding a Cybercrime or Fraud Solicitor


Cybercrime can cause financial loss, reputational harm and serious emotional distress. Report the matter promptly, preserve the evidence and secure any affected accounts or devices.


Use the search facility at the top of this page to find a solicitor experienced in cybercrime, fraud, banking disputes, data protection or technology law.


Disclaimer


Solicitors.com is not a firm of solicitors. This article provides general information about cybercrime and online security in the United Kingdom and does not constitute legal, financial or technical advice. Reporting procedures and legal rights will depend on the circumstances and the part of the UK involved.


Feedback


If you believe this page contains an error or requires updating, please get in touch with us. We welcome amendments that help keep our legal information accurate and useful.


Image Description
related news
recent articles
Double Jeopardy Law

What is Double Jeopardy? and is it still Law in the UK?..

link

Fraud Solicitors | Solicitors.com

Fraud Solicitors. Fraud could be described as a deception in order to secure unfair or unlawful gain, usually monetary...

Reporting a Crime.

If the crime is ongoing call 999, you should not put yours or anyone else’s safety at risk by taking action yourself...

Finders Keepers | Finders Law

Finders Keepers | Finders Law
Ever since the phrase came into being in the early nineteenth century, documented as no halfers-findee, lossee seekee, which sou..

What is a Section 60 notice?

Over 2000 section 60 notices have been issued in London last year..

link

Neighbour Disputes | Nuisance Neighbours

Unfortunately, not everyone is respectful in life, most of the time we just move on and keep our opinion to ourselves, but when that comes to where we live you..

Computer & IT Law

Computer and IT Law.
Computer Law is concerned with controlling and securing information stored on and transmitted between computers. Computer networks contain..

Criminal Law

..

Stop and Search Laws to be changed?

Police Chiefs are calling for a change in the 'stop and search' l..

link

Speeding motoring offences

Speeding motoring offences
Over 100,000 motorists are caught speeding each year, many have attended speed awareness courses, many were fined and received point..

Double Jeopardy Law

What is Double Jeopardy? and is it still Law in the UK?..

Children and the Law Consensual Sex

Children and the Law Consensual Sex
To consent is to agree to something, so when you are talking about the age of consent it is the age at which that law state..

Image Description
Is there anything wrong with this page? - any amendments will receive accreditation - email us

Solicitors.com are not a firm of solicitors, and any content on the site should not be used in substitute for obtaining Legal advice from a solicitor regulated in the UK, Solicitors.com recommends that you contact a firm of solicitors to discuss your individual legal requirement. Whilst we strive to bring you accurate up to date content, all content on this site is not legal advice and is not guaranteed to be correct. Use of this site does not create a client relationship.

Information by area of law
Back to top