City of London Police said romance fraudsters stole £102 million from UK victims in 2025 across 10,784 reports filed through the Report Fraud service, a 29 percent increase year over year. Average losses were about £9,500 per victim, with some cases reaching £1 million, as offenders built emotional trust over time before requesting money for fabricated travel, medical, or other urgent expenses.
Older adults were hit hardest financially, with nearly half of total losses borne by people aged 55 to 74. Men submitted the highest number of reports, while women suffered the greatest monetary losses. Authorities warned that romance fraud causes both financial and emotional harm and noted that, while the crime remains smaller in the UK than categories such as banking, investment, and online shopping fraud, comparable losses in the United States were far higher, with the FBI IC3 estimating $929.4 million lost to romance scams in 2025.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
ShinyHunters set a May 6 deadline for Cushman & Wakefield to make contact in order to prevent publication of the allegedly stolen data. The ultimatum followed the group's claim that it had exfiltrated more than 500,000 Salesforce records.
City of London Police publicly reported that romance fraud cost UK victims £102 million in 2025 and highlighted the emotional and financial harm caused by offenders who build trust before requesting money. The announcement also noted average losses of about £9,500 per victim, with some cases reaching £1 million.
Cushman & Wakefield confirmed a limited data security incident caused by vishing and said it had activated incident response protocols, contained unauthorized activity, and engaged third-party experts. The company said systems and operations continued to run normally while the investigation proceeded.
The Qilin ransomware group added Cushman & Wakefield to its leak site on May 4, claiming responsibility for an attack but not describing its intrusion method. Reporting noted there was no known link proving coordination with ShinyHunters.
ShinyHunters told The Register it attacked Cushman & Wakefield on May 1 and claimed to have stolen more than 500,000 Salesforce records containing personally identifiable information and internal corporate data. The claim was presented as part of a broader campaign linked to Salesforce-focused intrusions.
City of London Police said romance fraudsters stole £102 million from UK victims during 2025, based on 10,784 reports submitted through the Report Fraud service. The force said reports were up 29 percent year over year, with older victims disproportionately affected.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cityoflondon.police.uk
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.