Criminal account takeover — where hackers seize someone's email or social media, then impersonate them to defraud their friends and family — has surged from £1.2m in reported UK losses in 2024-25 to £6.3m in 2025-26, a rise exceeding 400%. The data comes from Report Fraud, the City of London police service responsible for economic crime. True losses are certainly higher: many victims never report, often out of embarrassment or because individual amounts seem too small to bother. The mechanism is brutally simple and brutally effective. Hackers compromise a person's Instagram, WhatsApp, or email, then exploit the trust graph attached to that identity. Sold-out gig tickets are a favourite lure — one victim's hijacked Instagram was used to sell fake Oasis tickets, extracting £1,400 from her own friends. The impersonation was so convincing that targets genuinely believed they were speaking to her. The 'Hi mum' variant works the same trust channel through different bait: a text from someone claiming to be your child in an emergency, urgently needing cash. Santander data shows fraudsters posing as sons extracted the most money, followed by daughters. What makes this category of fraud structurally different from phishing or romance scams is that the attack surface is not the victim's credulity about strangers — it is the victim's rational trust in people they actually know. Every compromised account becomes an amplifier: one breach yields access to an entire social graph of potential secondary victims. Ch Supt Amanda Wolf of Report Fraud described the cascade: what starts with one compromised account 'can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud.' The extraction pattern is clear: criminals capture the value embedded in personal relationships, platform companies bear zero cost, and individual users absorb both the financial loss and the social damage. Instagram, WhatsApp, and email providers profit from engagement and network density — the very properties that make these attacks scale — while investing minimally in authentication infrastructure that would prevent them. Password-based authentication remains the default across most services, despite being the known weak link. Report Fraud is now urging adoption of passkeys — device-bound, biometric authentication that cannot be phished or stolen like passwords. The technology exists and works. The obstacle is not technical but structural: platforms have little incentive to force migration from passwords when the cost of account compromise is externalized entirely to users and their social networks. The £6.3m figure, already an undercount, represents a tax on trust that the people who built the trust infrastructure do not pay. The 425% year-on-year surge is not a blip. It reflects criminals discovering a high-yield, low-risk attack vector and industrializing it. Until platform liability changes or passkey adoption reaches critical mass, the economics favour the attackers. The people paying the price are not careless or gullible — they are trusting the people they know, which is exactly what social platforms were designed to encourage.