Skip to content

Social Media Scamming: UK Statistics, Warning Signs and Recovery

Updated on:
Updated by: Ciaran Connolly
Reviewed byAsmaa Alhashimy

Social media scamming cost UK businesses and consumers £1.28 billion in payment fraud last year, and two thirds of the cases that led to those losses started on an online platform rather than in an inbox or on a phone call. That single figure explains why social media scams have moved from a consumer nuisance to a live operational risk for small and medium businesses across Northern Ireland, Ireland and the UK.

Social media scamming now sits alongside invoice fraud and ransomware as a standing business risk rather than a personal one. The statistics below are drawn from UK Finance and the UK Government’s own annual cyber survey, not from vendor marketing. They matter because the pattern they describe is specific: fraudsters are no longer breaking into systems, they are talking their way past people. This guide covers what the numbers show, which types of social media scamming are hitting UK SMEs hardest right now, how to spot them, what to do in the first 24 hours, and where to report fraud since the national reporting service changed in December 2025.

Social Media Scamming Statistics: What the UK Data Shows

The most reliable UK figures come from two annual sources. UK Finance publishes payment fraud data reported by banks. The Department for Science, Innovation and Technology publishes the Cyber Security Breaches Survey, an official statistic based on a random probability survey of more than 2,000 UK businesses. Read together, they describe both the money lost to social media scamming and the entry point used to start it.

How Much UK Fraud Now Starts on a Social Platform

UK Finance’s Annual Fraud Report 2026 recorded £1.28 billion stolen through payment fraud in 2025, a 4% rise on the previous year, across more than four million confirmed cases. Authorised push payment losses, where the victim is manipulated into sending the money themselves, rose 19% to £576.4 million. Of that total, £75.6 million was lost by businesses rather than individuals.

The origin data is the part that matters most for anyone running a business page, because it shows how much of this activity begins as social media scamming rather than as a phone call or a hacked server. Around 66% of authorised push payment cases started online, accounting for 32% of the money lost, with a further 17% beginning through telecoms channels. Purchase scams made up 71% of all cases, with losses up 20% to £118.1 million.

Investment fraud, much of it seeded through fraudulent advertising on social platforms, produced the single largest share of losses at £221.5 million, up 40% in a year. Very little of that spending was stopped at the platform level, which is why social media fraud continues to convert at the rate it does.

What the Government’s Cyber Survey Adds

The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses identified a cyber security breach or attack in the previous 12 months, roughly 612,000 organisations. Phishing was the most common type by a wide margin at 38%, and among businesses that were breached, 69% rated phishing as the most disruptive incident they faced. More telling still, the share of breached businesses that experienced phishing and nothing else rose from 45% to 51%.

Two figures from that survey explain why scams on social media keep working on smaller firms. Only 19% of UK businesses ran any staff training or awareness activity on cyber security in the year, falling to 14% among micro businesses. And only 47% had two-factor authentication in place across networks and applications. The attack surface for social media scamming is human, and most small firms have not addressed it.

MetricFigureSource
UK payment fraud losses, 2025£1.28 billionUK Finance, Annual Fraud Report 2026
Business share of APP fraud losses£75.6 millionUK Finance, 2026
APP fraud cases originating online66%UK Finance, 2026
Investment fraud losses (largest category)£221.5 million, up 40%UK Finance, 2026
UK businesses reporting a breach or attack43% (approx. 612,000)Cyber Security Breaches Survey 2025/2026
Businesses experiencing phishing38%CSBS 2025/2026
Businesses providing staff cyber training19%CSBS 2025/2026
Businesses with two-factor authentication47%CSBS 2025/2026
Businesses hit by cyber-facilitated fraud3% (approx. 43,000)CSBS 2025/2026

Averaged out, that works out at roughly eight fraud cases every minute across the UK, or about 11,000 a day. Most of those cases involve individual consumers, but the business share is substantial and rising, and the account most often used as the way in is a social one. Social media scamming works at that volume because it costs a criminal almost nothing to attempt. Anyone who wants the account-level picture will find more detail in the data on social media hacking statistics, which covers how takeovers actually happen once a scammer has a foothold.

What Changed: AI, Cloned Voices and Deepfake Video

The advice most UK businesses absorbed a decade ago was to look for bad spelling, odd grammar and low-resolution logos. That advice is now actively dangerous, because it teaches people to trust anything that looks polished, and modern social media scamming is polished by default. Generative tools have removed every cue that used to separate a scam message from a real one.

The Arup Case and What It Proved

In January 2024, an employee in the Hong Kong office of Arup, the London-based engineering firm behind the Sydney Opera House, was invited to a video conference with people who appeared to be the company’s UK chief financial officer and several colleagues. Every participant was AI-generated. The employee made 15 transfers totalling HK$200 million, roughly £20 million. Arup later confirmed publicly that fake voices and images had been used. The staff member had initially been suspicious of the email that prompted the call, and dropped that suspicion after seeing faces and hearing voices he recognised.

The lesson for an SME is not that deepfakes will target a five-person firm in Ballymena with a £20 million ask. It is that video and voice are no longer proof of identity, that the most expensive social media scams now begin with a message rather than a breach, and any payment or access request that arrives through a social channel needs verification through a different channel entirely. A callback to a number you already had, not a number supplied in the message.

Why Detection Advice Has Shifted

Real-time deepfakes still carry tells, though they are getting subtler: latency between lip movement and audio, unnatural blink rates, edges that blur when a hand passes in front of the face, and a reluctance to turn the head fully in profile. Asking someone on a suspicious call to turn side-on or pass a hand across their face remains a practical live test.

Those tells will not last. The durable defence against AI-assisted social media scamming is procedural rather than perceptual, which is why payment authorisation processes matter more than staff getting better at spotting fakes.

“Social media security is no longer an IT conversation,” says Ciaran Connolly, founder of ProfileTree, Belfast’s web design and digital marketing agency. “For SMEs, the Facebook Business Manager holds the keys to everything: ad budget, customer data, and often the primary channel for customer service. Protecting it should be treated as seriously as protecting your bank account.”

The same government survey found that of the 31% of UK businesses using or considering AI, only 24% had any practice in place to manage the cyber risks that come with it. Adoption is running well ahead of readiness on both sides of the fence, and social media scams are where that gap shows up first.

The Types of Social Media Scamming Targeting UK Businesses

Consumer-facing coverage of scams on social media tends to focus on romance fraud and fake marketplace listings. Those exist, but the forms of social media scamming aimed at businesses look different, and understanding which platform carries which risk is the starting point for any defence worth having.

Meta Business Suite and Ad Account Hijacking

This remains the most damaging form of social media scamming affecting UK SMEs, and it is still poorly understood by most owners. The attack usually opens with a message to the business Facebook page or to an admin’s personal account, apparently from Meta support, a large client or a business partner, carrying a link or attachment.

Opening the link steals a session token from the browser. A session token is not a password. It authenticates the attacker as you without them ever knowing your credentials, which is why two-factor authentication does not stop this particular attack: the login process is bypassed entirely.

This is the variety of social media fraud that does the most financial damage in the shortest time. Once inside, attackers add themselves as admins, remove the legitimate ones, and start running ads. Businesses have reported thousands of pounds of fraudulent ad spend within hours. Meta’s support response time for a small business in this position is measured in days, by which point the budget is gone.

Prevention comes down to limiting admin access, using dedicated business email addresses for account management rather than personal ones, and reviewing active sessions in Meta Business Suite on a schedule. Any session from an unrecognised device or location should be ended immediately.

LinkedIn Impersonation and Recruitment Fraud

Social media impersonation scams on LinkedIn have increased sharply, and they are among the hardest forms of social media scamming to shut down quickly. The common pattern involves a fake profile cloning a senior member of your team, usually the MD or finance director, then approaching suppliers, clients or job candidates from that profile.

A second variant targets candidates directly. A fake recruiter using your brand name makes a credible job offer, then requests personal documents or bank details for payroll setup, or sends a malware-carrying file dressed up as an employment contract. The damage runs in two directions: the candidate loses money or data, and your business absorbs the reputational hit for something it did not do.

WhatsApp Business Phishing

WhatsApp Business is used heavily by SMEs across the UK and Ireland for customer contact, and it has become a standing target for social media scamming. The most common approach is the urgent invoice pivot: a message from what appears to be a known supplier or colleague asking for payment to a new account number, sent from a cloned or compromised account.

A separate variant goes after the account itself. A caller claiming to be WhatsApp support asks the owner to read out the six-digit verification code sent by text, then uses it to take the account over. No legitimate platform will ever ask for that code. If your team relies on the platform for customer messaging, the security settings in the WhatsApp Business features are worth reviewing alongside your wider account access policy.

TikTok Shop, Affiliate Fraud and Brand Abuse

This is one of the least covered areas in UK business security guidance, and one where social media scams often go unrecognised for months. SMEs selling through TikTok Shop are approached by fake influencer accounts offering product promotion. After receiving free stock or an upfront content payment, the account disappears.

More sophisticated variants involve affiliate fraud, where criminals manipulate tracking systems to generate commissions on sales they never influenced. Because the loss shows up as a marketing cost rather than a theft, brand owners often absorb it for months without recognising it as fraud at all. Reconciling affiliate commissions against actual referral traffic is the only reliable way to catch it.

Link-in-bio tools sit in an awkward gap. Customers trust the link because it appears on your verified profile, but the destination is controlled by a third-party account that may have weaker protection than the social account itself. Two forms of social media scamming follow from that gap. A compromised Linktree or similar account lets an attacker silently redirect your traffic to a phishing page or fake shop while your profile still looks untouched. Separately, fraudsters build cloned bio pages using your brand name and logo, then push them through paid promotion.

Check your own link-in-bio destinations monthly, protect that account with the same rigour as the social account it serves, and search your brand name periodically to find clones.

Marketplace and Purchase Scams

Purchase scams account for 71% of all authorised push payment cases in the UK. For businesses, exposure to these social media scams runs both ways: staff buying equipment through Marketplace listings that never arrive, and criminals using your business name and photographs to sell goods they do not have. The second is more damaging, because the buyers who lose money will look for you, not the scammer.

Warning Signs: How to Spot Social Media Scams Before They Land

Most business-focused scams on social media share a small set of characteristics, and once a team can name them, the hit rate drops sharply. Recognising social media scamming early is cheaper than recovering from it by an order of magnitude.

Verifying Emails That Claim to Come From Meta

One of the most common questions from business owners is whether security@facebookmail.com is genuine. It is. The facebookmail.com domain is Meta’s legitimate sending address for account notifications, security alerts and password reset codes, which is precisely why fraudsters spoof the display name to imitate it.

Two checks settle it. First, look at the actual sending domain rather than the display name, since genuine messages come from facebookmail.com or meta.com. Second, and more reliably, open Facebook directly, go to Settings, then Password and Security, then “See recent emails from Meta”. Any genuine email will be listed there. Anything that is not listed is fake, however convincing it looks. Meta will never ask for your password, your verification code, or access to your screen.

Red Flags in Direct Messages

Urgency is the constant across almost every form of social media scamming. A policy violation that must be appealed within 24 hours, an ad account about to be suspended, a payment that has to move today. Genuine platform enforcement does not arrive by direct message with a countdown attached.

Look also for requests that move you off-platform to complete a form, links where the visible text does not match the destination, verification codes requested by anyone at all, and unexpected file attachments described as invoices, contracts or briefs. A supplier changing bank details is always worth a phone call to a number you already hold.

The Business Impact Beyond the Immediate Loss

The money lost to social media scamming is the visible part. Businesses that lose access to a Facebook or Instagram account also lose historical ad data, audience targeting, and years of customer message history. Rebuilding all of that costs time and budget that the fraud figures never capture.

Reach degradation is the second cost. Accounts used to run fraudulent advertising, or reported by users who received scam messages from them, often see organic reach suppressed even after recovery. Platform support teams rarely acknowledge it, but the pattern is familiar to agencies handling recovery work after social media fraud.

Then there is trust. Where a brand has been impersonated, the damage outlasts the removal of the fake account, because customers who saw it may never learn it was fraudulent. The government survey recorded a rise in businesses reporting reputational damage from a breach, from 1% to 3% year on year. That is a small percentage of a very large number, and the data on online reputation management shows how long negative associations persist once they attach to a brand name.

There is a compliance dimension too. If customer phone numbers, email addresses or order details were exposed through a compromised page inbox, that may qualify as a personal data breach requiring notification to the Information Commissioner’s Office within 72 hours. Businesses handling customer data through social channels should treat breach notification as part of staff onboarding rather than a separate compliance exercise, and GDPR training for your team covers the reporting timelines that apply.

The Five-Point SME Social Media Security Framework

Social media scamming aimed at UK businesses is largely preventable. These five steps remove most of the exposure, and none of them require a security budget.

1. Audit your admin access. Review who holds admin or editor rights on every business account. Remove anyone who has left. Never add personal accounts as admins, and use dedicated business email addresses for all platform accounts.

2. Turn on two-factor authentication everywhere. It will not stop session token theft, but it blocks the majority of credential-based attacks. Use an authenticator app rather than SMS where the platform supports it, and passkeys where they are offered.

3. Train the team. Human error is the entry point in most social media scams. Staff need to recognise a suspicious link, know how to verify an unexpected request through a second channel, and know who to tell internally. With only 19% of UK businesses running any cyber training at all, this is the step that separates the prepared from the exposed. ProfileTree’s digital training covers social media security as part of broader digital skills work with SME teams across Northern Ireland, Ireland and the UK.

4. Separate personal and business browsing. Admins should manage business accounts from dedicated devices or browser profiles. Mixing personal browsing with business account management is how session tokens get stolen.

5. Run a monthly access review. Check active sessions in Meta Business Suite, LinkedIn and every other platform where the business holds an account. Terminate anything from an unfamiliar device or location.

Most guidance on social media scams stops at “do not click”, which is no help to the person who already did. If you clicked a link on social media but entered no credentials, the risk is real but manageable, and the steps are specific.

Start by closing the tab and disconnecting the device from the network if the page attempted a download. Clear cookies and site data for the affected browser profile, because a session token can be lifted from an existing cookie without any credentials being typed.

Next, check connected apps rather than passwords. In Facebook, Instagram, LinkedIn and Google, review the list of third-party apps with account access and revoke anything unrecognised. Malicious pages frequently request permissions rather than passwords, and this is the step most people skip.

Then end all active sessions on the platform and log back in, which invalidates any token that was stolen. Change the password on the email account tied to your social accounts, since password reset links sent there are the most valuable thing an attacker can hold. Run a malware scan on the device, and check browser extensions for anything installed recently that you did not add.

Finally, watch the account for changed admin permissions, new ad campaigns, or messages sent from your account that you did not write. If any of those appear, treat it as a live compromise and move to the recovery steps below. Treat the device and the account as two separate clean-up jobs, because clearing one does not clear the other.

Reporting Social Media Scamming in the UK and Ireland

This is where most existing guidance on social media scamming is now out of date, and it matters because a report filed to the wrong body may not reach an investigator at all.

England, Wales and Northern Ireland

Action Fraud no longer exists. On 4 December 2025 it was replaced by Report Fraud, a new service run by the City of London Police, with a full public launch in January 2026. Report Fraud covers England, Wales and Northern Ireland. Reports are made online at reportfraud.police.uk or by phone on 0300 123 2040, the same number used previously. The old Action Fraud web address redirects to the new service.

Businesses in Northern Ireland should note that this national route does cover them, contrary to a lot of older advice still circulating. The exception is a “call for service”, where you contact the Police Service of Northern Ireland directly on 101: use that when a fraud is happening now or happened within 24 hours, when you know the suspect and they live in Northern Ireland, when the victim is vulnerable, or when police need to act quickly to preserve evidence or stop money moving.

Scotland

Scotland sits outside the Report Fraud service. Businesses and individuals should contact Police Scotland on 101, or 999 in an emergency.

Republic of Ireland

Cross-border businesses trading into the Republic need a separate route. Fraud is reported in the first instance to your local Garda station. Serious or complex cases are passed to the Garda National Economic Crime Bureau, and the Garda Cyber Crime Bureau can be contacted on 01 666 3708. There is no single online national reporting portal equivalent to Report Fraud.

Where you areReport toContact
England and WalesReport Fraud (City of London Police)reportfraud.police.uk or 0300 123 2040
Northern IrelandReport Fraud, or PSNI for a call for servicereportfraud.police.uk or 101 for PSNI
ScotlandPolice Scotland101, or 999 in an emergency
Republic of IrelandLocal Garda station / Garda National Economic Crime BureauLocal station; Garda Cyber Crime Bureau 01 666 3708
Data breach (UK)Information Commissioner’s OfficeWithin 72 hours of becoming aware

Whichever jurisdiction applies, report the social media scam to the platform as well, and contact your bank first if money has moved. Banks can often stop or recall a transfer if they are told quickly, and speed matters more than paperwork in the first hour.

The First 24 Hours: What to Do After a Social Media Scam

If a social media scam lands, the first day is when you have the most control over the outcome.

Contact the bank immediately where any payment has been taken or where card details are attached to a compromised ad account. UK protections around unauthorised electronic transactions are stronger than many owners realise, and banks reimbursed £354.3 million to authorised push payment victims in 2025, around 61% of losses.

Report the compromise to the platform itself, since platforms act on volume of reports when deciding which social media scams to investigate. For Meta, use the compromised account tool at facebook.com/hacked. For LinkedIn, use the Help Centre account recovery flow. Document every step, with screenshots and timestamps, because identity verification requests often follow.

Change passwords across all connected accounts, starting with the email addresses used to manage the social accounts. If that email was accessed, every reset link sent to it is in the attacker’s hands.

Tell customers if there is any chance that messages sent from your account during the compromise directed them to fraudulent payment details or content. A short, clear statement through your website, email list or another channel does more for trust than silence does.

File the report with the correct body for your jurisdiction and keep the reference number. Insurers and banks will both ask for it.

Getting Ahead of It

Social media scamming is not going to slow down, and the tools available to fraudsters improve every year. The businesses that come through these incidents with the least damage are the ones that had access controls, verification habits and a reporting plan in place before anything went wrong.

If you want help protecting and rebuilding your business’s online presence, from account security and social media management through to staff training, talk to the ProfileTree team in Belfast.

Frequently Asked Questions

Is security@facebookmail.com a legitimate email address? 

Yes. facebookmail.com is Meta’s genuine sending domain for security alerts and account notifications, which is why scammers imitate it. Confirm any message by opening Facebook directly and checking Settings, then Password and Security, then “See recent emails from Meta”. Genuine messages appear in that list.

What should I do if I clicked a scam link but didn’t enter any details? 

Clear cookies and site data for that browser profile, revoke unrecognised third-party app permissions on your social accounts, end all active sessions and log back in, change your email password, and run a malware scan. Session tokens can be stolen without you typing anything.

How many people get scammed a day in the UK? 

UK Finance recorded more than four million confirmed fraud cases in 2025, averaging roughly eight cases every minute, or about 11,000 a day. That covers all payment fraud, and social media scamming accounts for a growing share of it: around 66% of authorised push payment cases began online.

Can my bank recover money taken through fraudulent social media ads? 

Often, yes. If a fraudster used your connected card without authorisation, it is classed as an unauthorised transaction and banks are generally required to refund it. If you were tricked into approving the payment, reimbursement rules for authorised push payment fraud may still apply. Contact your bank immediately.

How do I report social media scamming in Northern Ireland? 

Use Report Fraud at reportfraud.police.uk or 0300 123 2040, which covers Northern Ireland alongside England and Wales. Contact the PSNI on 101 instead if the fraud is ongoing, happened in the last 24 hours, the suspect lives locally, or the victim is vulnerable.

Does two-factor authentication stop all social media scams? 

No. It blocks credential-based attacks where someone tries to log in with your username and password, but it does not stop the session token theft used in the most damaging social media scamming cases, where the login process is bypassed. Use two-factor authentication and review active sessions regularly.

How do I know if a video call is a deepfake? 

Watch for lag between lip movement and sound, unnatural blinking, and blurring when a hand crosses the face. Ask the person to turn side-on or move a hand past their face. Treat any payment request made on a video call as unverified until confirmed on a number you already hold.

Are Linktree and link-in-bio scams a risk for businesses? 

Yes, in two ways. A compromised link-in-bio account lets an attacker redirect your audience to a phishing page while your profile looks normal, and fraudsters also build cloned bio pages using your brand name. Check your destinations monthly and secure that account properly.

Leave a comment

Your email address will not be published.Required fields are marked *

Web Design

Web Design

We design stunning, user focused websites that present your brand beautifully and convert visitors into customers.

Web Development

Web Development

We use the latest development tools to build websites that are optimised for peak performance at all times.

Website Management

Website Hosting

We manage everything from site updates and reports to hosting, allowing you to focus on running your business.

Search Engine Optimisation

Search Engine Optimisation

Using the latest SEO techniques, we help your brand get found for the right terms and by the right people.

Digital Marketing Strategy

Digital Marketing Strategy

Navigate the digital landscape with a marketing strategy. Our team crafts comprehensive plans that resonate with your target audience, drive engagement, and boost conversions.

Digital Marketing Training

Digital Marketing Training

Elevate your digital proficiency. Our in-depth training sessions equip your business with cutting-edge digital marketing techniques to outperform competitors and thrive online.

Social Media Strategy

Social Media Strategy

Captivate and grow your social following. We create tailored social media strategies that ignite engagement, amplify your brand's online presence, and foster lasting connections.

Email Marketing Solutions

Email Marketing Solutions

Harness the power of your mailing list. Our precision-targeted email marketing campaigns are engineered to nurture relationships and drive tangible business outcomes.

Content Marketing Services

Content Marketing Services

Elevate your brand with our content marketing mastery. From thought-provoking blogs to eye-catching infographics, we craft content that captivates, informs, and converts your ideal audience.

Video Production

Video Production

Capture your audience with compelling video content. Our production team creates visual stories that engage, inform, and leave a lasting impression.

Brand Storytelling

Brand Storytelling

Bring your brand's story to life with authenticity. We craft compelling narratives that strike a chord with your audience, forging a powerful emotional bond with your brand.

Content Strategy Development

Content Strategy Development

Strategic content that drives action. We develop content strategies that align with your business goals, ensuring every piece of content counts.

AI Training

AI Training

Empower your business with AI expertise. Our tailored training demystifies AI, equipping your team with the knowledge to leverage its potential for growth and innovation.

AI Chatbots

AI Chatbots

Transform customer service with AI chatbots. We develop sophisticated chatbots that elevate user experience, streamline interactions, and deliver unparalleled efficiency.

AI Marketing

AI Marketing

Transform your reach with AI-driven marketing. Harness data-driven insights for laser-targeted campaigns that captivate, engage, and convert your audience.

AI Tools for Business

AI Tools for Business

Optimise your operations with cutting-edge AI tools. We integrate intelligent solutions that streamline processes, enhance efficiency, and support data-driven decision-making.

Join Our Mailing List

Grow your business with expert web design, AI strategies and digital marketing tips straight to your inbox. Subscribe to our newsletter.