Skip to main content
Mallory
Back to stories
identity-impersonation-fraud

UK Romance Fraud Losses Hit £102M as Reports Surge

Updated 12d agoFirst seen May 5, 20264 sources

City of London Police said romance fraudsters stole £102 million from UK victims in 2025 across 10,784 reports filed through the Report Fraud service, a 29 percent increase year over year. Average losses were about £9,500 per victim, with some cases reaching £1 million, as offenders built emotional trust over time before requesting money for fabricated travel, medical, or other urgent expenses.

Older adults were hit hardest financially, with nearly half of total losses borne by people aged 55 to 74. Men submitted the highest number of reports, while women suffered the greatest monetary losses. Authorities warned that romance fraud causes both financial and emotional harm and noted that, while the crime remains smaller in the UK than categories such as banking, investment, and online shopping fraud, comparable losses in the United States were far higher, with the FBI IC3 estimating $929.4 million lost to romance scams in 2025.

Share:
UK Romance Fraud Losses Hit £102M as Reports Surge
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the earliest known activity through the most recent confirmed update.

6 EVENTS
Dec 31, 20255mo ago

UK romance fraud losses reach £102 million in 2025

City of London Police said romance fraudsters stole £102 million from UK victims during 2025, based on 10,784 reports submitted through the Report Fraud service. The force said reports were up 29 percent year over year, with older victims disproportionately affected.

May 1, 202617d ago

ShinyHunters claims attack on Cushman & Wakefield

ShinyHunters told The Register it attacked Cushman & Wakefield on May 1 and claimed to have stolen more than 500,000 Salesforce records containing personally identifiable information and internal corporate data. The claim was presented as part of a broader campaign linked to Salesforce-focused intrusions.

May 4, 202614d ago

Qilin lists Cushman & Wakefield on its leak site

The Qilin ransomware group added Cushman & Wakefield to its leak site on May 4, claiming responsibility for an attack but not describing its intrusion method. Reporting noted there was no known link proving coordination with ShinyHunters.

May 5, 202613d ago

Cushman & Wakefield confirms vishing-related security incident

Cushman & Wakefield confirmed a limited data security incident caused by vishing and said it had activated incident response protocols, contained unauthorized activity, and engaged third-party experts. The company said systems and operations continued to run normally while the investigation proceeded.

City of London Police publishes 2025 romance fraud figures

City of London Police publicly reported that romance fraud cost UK victims £102 million in 2025 and highlighted the emotional and financial harm caused by offenders who build trust before requesting money. The announcement also noted average losses of about £9,500 per victim, with some cases reaching £1 million.

May 6, 202612d ago

ShinyHunters sets May 6 deadline for Cushman & Wakefield contact

ShinyHunters set a May 6 deadline for Cushman & Wakefield to make contact in order to prevent publication of the allegedly stolen data. The ultimatum followed the group's claim that it had exfiltrated more than 500,000 Salesforce records.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.