Yes—fraud and cybercrime remain substantially under-reported. But “under-reported” does not mean that officials know the exact hidden total, or that every unreported incident would lead to a prosecution. It means that complaint-based statistics capture only the cases reaching a particular reporting channel.
In England and Wales, the UK government’s latest published measure found that about 12% of estimated fraud and computer-misuse incidents were reported to Action Fraud in the year ending March 2024. The implied 88% gap is a useful warning, not a universal estimate of all incidents that went unreported to every bank, police force, insurer, employer or regulator.
As an Amazon Associate I earn from qualifying purchases.
What “under-reported” actually means
The phrase covers several different gaps:
- Victimisation gap: an incident is experienced but reported nowhere.
- Channel gap: a victim tells a bank, platform, insurer or employer but not police or a national reporting centre.
- Recording gap: an incident is reported but not classified, linked or counted as a criminal offence.
That distinction matters in the UK. Action Fraud is the national reporting centre for fraud and cybercrime, but it is not the only place where an incident may appear in administrative records. The government’s 12% measure is therefore specifically about reporting to Action Fraud—not proof that 88% of incidents were invisible to every organisation.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →The government also cautions that Crime Survey estimates for fraud and computer misuse have known overestimation concerns, and that changes to telephone-based surveying affected comparability during the pandemic period. The safest conclusion is that the gap is large, while its exact size is uncertain. Read the Home Office methodology and performance measure.
#1 Best Overall
The latest numbers measure different things
| Measure | What it tells us | What it does not tell us |
|---|---|---|
| Crime Survey estimates | Estimated victimisation among surveyed households and individuals | The precise number of real incidents or the number reported to every authority |
| Action Fraud records | Reports reaching the UK national reporting centre | The total number of incidents, investigations or convictions |
| Police referrals | Cases passed to territorial police forces for possible further action | How many cases were investigated, charged or prosecuted |
| Bank and payment-provider reports | Fraud detected or reported within financial systems | The full criminal or social impact of the incident |
| FTC and FBI IC3 complaints | US complaints and reported losses submitted to those systems | A national census of all US fraud |
For England and Wales, official crime data for the year ending March 2025 recorded 1,225,778 fraud offences and 55,576 Computer Misuse Act offences. Action Fraud recorded 354,622 offences, while 52,949 unique offences were referred to territorial police forces.
Those figures describe different stages. A report is not automatically a referral; a referral is not an investigation; an investigation is not a charge; and a charge is not a conviction.
Historical figures should not be presented as current
The headline that fraud and cybercrime are “still vastly under-reported” was popularised by a Computer Weekly report published on 4 February 2021. It compared estimates for the 12 months to September 2020 with recorded reports:
Recommended Free Tools
- Estimated fraud: 4.4 million incidents.
- Recorded fraud offences: 730,765.
- Estimated computer-misuse offences: 1.7 million.
- Referrals to the National Fraud Intelligence Bureau: 29,094.
The article calculated that roughly 16.6% of estimated fraud and 1.7% of estimated computer-misuse offences appeared in the relevant reported figures. These numbers are important historical context, but they are not the current UK reporting rate.
Why victims do not report
Shame and self-blame
Romance scams, investment fraud, impersonation scams and business-email compromise can leave victims feeling embarrassed or responsible. Fear of being judged as careless can be enough to suppress a report, particularly when the victim believes friends, colleagues or officials will blame them.
The belief that reporting will not help
Some victims assume that the offender is overseas, the money cannot be recovered or the police will not investigate. That perception may create a feedback loop: fewer reports produce fewer visible leads, which can make official action appear less likely. It is a plausible explanation for non-reporting, not proof that every report receives no attention.
Small, uncertain or attempted losses
A person may ignore a suspicious message when no money was lost, or decide that a small loss is not worth the time. Businesses may treat a minor phishing attempt or malware alert as an IT nuisance rather than a crime.
The UK’s Cyber Security Breaches Survey 2025/2026 found that among organisations that did not report their most disruptive incident externally, 72% of businesses and 73% of charities said it was not significant enough to warrant reporting.
Rank #3
Reporting friction
Victims may be unsure whether to contact their bank, Action Fraud, local police, an insurer, a platform, a regulator or an employer. Multiple routes can cause confusion, duplicate records or incomplete evidence.
Business reputation and legal concerns
Companies may fear reputational damage, customer concern, regulatory scrutiny, litigation or insurance consequences. They may also worry that reporting will expose weak controls. Criminal reporting is separate from mandatory or contractual breach notification: a company may need to notify a regulator or affected customers even if it does not file a police report.
Lost evidence and cross-border complexity
Victims often delete messages, reset devices or close accounts before preserving evidence. Fraud can also span several countries, payment providers and online platforms, making enforcement appear futile even when reports help connect related cases.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Why under-reporting matters
Reports contribute to intelligence about repeat offenders, mule accounts, phone numbers, domains, cryptocurrency addresses and linked victims. A single complaint may not produce an immediate investigation, but it can become significant when combined with other reports.
Rank #4
Under-reporting also affects public policy. If incidents never enter official data, governments may underestimate the resources needed for enforcement, the harm to vulnerable people and the need for prevention campaigns or platform and payment-system regulation.
Businesses that rely only on police or regulator statistics may misjudge their exposure. Administrative data reflects not only offending, but also how easily victims detect incidents, how willing they are to report and how agencies record them.
It is also reasonable to infer that low reporting can reduce the apparent risk faced by criminals. That is an inference from the reporting gap, not a directly measured claim that every offender changes behaviour because of it.
What happens after a report?
- Initial complaint: the agency or provider records the allegation and available details.
- Evidence review: transaction data, messages, account information and technical evidence may be assessed.
- Categorisation and linkage: the incident may be matched with related reports or infrastructure.
- Referral or intelligence use: some cases are passed to another agency or retained for intelligence.
- Possible investigation: priority depends on evidence, threat, jurisdiction, harm and available resources.
- Possible recovery, charge or no further action: outcomes vary and may not be communicated in detail.
A report may be logged without an immediate investigator, passed to another organisation or used for intelligence without visible feedback. That does not necessarily mean it was useless. Equally, reporting does not guarantee recovery, prosecution or even confirmation that a criminal offence occurred.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to report effectively
If you are in England, Wales or Northern Ireland
- Contact your bank, card issuer or payment provider immediately if money or payment credentials are involved.
- Report fraud and cybercrime through Action Fraud.
- Contact police directly if there is immediate danger, a suspect is present or urgent intervention is needed.
- Preserve screenshots, emails, messages, phone numbers, URLs, transaction records, wallet addresses and relevant device information.
If you are in the United States
- Report internet crime to the FBI Internet Crime Complaint Center.
- Report consumer fraud through the Federal Trade Commission’s ReportFraud service.
- Contact your bank, card issuer, payment service or cryptocurrency provider immediately.
- Contact local law enforcement for threats, physical danger, ongoing extortion or another urgent situation.
Report attempted scams as well as confirmed losses. Pattern information can matter even when no money was transferred. Do not delay reporting while trying to assemble perfect evidence—submit the initial report promptly and add supporting material later.
For businesses
- Contain the incident without destroying evidence.
- Bring in security, IT, legal and executive decision-makers.
- Notify insurers and relevant service providers.
- Assess regulatory, contractual and customer-notification duties.
- Report through the appropriate law-enforcement or national cybercrime channel.
- Preserve logs, email headers, authentication records, endpoint images and payment instructions.
- Reset credentials and revoke tokens as part of a documented response plan.
Notification requirements depend on jurisdiction, sector, contract, data type and the facts of the incident. A business should obtain appropriate legal and technical advice rather than assume one reporting rule applies everywhere.
Why the statistics disagree
- Fraud is not one crime: payment fraud, identity theft, romance scams, procurement fraud and business-email compromise may be recorded differently.
- Cybercrime is a broad label: ransomware, account takeover, unauthorised access, malware and cyber-enabled fraud do not necessarily belong to one count.
- Records can overlap: a victim, bank, employer and police force may each record the same incident.
- One report can contain several offences: systems may split or group them differently.
- Surveys contain error: respondents may forget incidents or classify them incorrectly.
- Reported loss is not total harm: remediation, business interruption, emotional distress and lost time may be omitted.
- A complaint is an allegation: it is not proof that an offence occurred.
US figures illustrate the same limitation. The FTC says consumers reported approximately $16 billion in fraud losses during 2025, while the FBI’s IC3 recorded 452,868 cyber-enabled fraud complaints and $17.697 billion in reported losses. The FTC and IC3 systems have different populations and definitions, so their totals should not simply be added together. See the FTC data and the FBI IC3 annual report.
The accountability question
The reporting gap raises a question beyond victim behaviour: are banks, platforms, governments and law-enforcement agencies making reporting easy enough, and making reports useful enough for victims to continue using the system?
The Home Office’s Fraud in the Digital Age review, published on 14 July 2026, examines barriers to investigating and prosecuting fraud against individuals and businesses. The policy challenge is not simply to persuade more people to report. It is also to improve evidence sharing, cross-border cooperation, payment intervention, feedback and the visibility of outcomes.
The bottom line
Official fraud and cybercrime figures are best treated as a lower bound on known harm, not a complete count of offending. The UK’s latest measure indicates that only around 12% of estimated incidents reached Action Fraud in the year ending March 2024, but that figure cannot be converted into a universal “88% of all cybercrime” statistic.
Reporting cannot guarantee that money will be recovered or that an offender will be prosecuted. Not reporting, however, means the incident is less likely to enter official intelligence, be linked to other cases or inform prevention. Report quickly, preserve evidence and use the relevant financial and official channels together.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




