On 10th March, the UK Government launched The UK Fraud Strategy 2026 – 2029. The goal is to ensure the UK is “the hardest place in the world for fraudsters to operate.”
It’s the most comprehensive fraud document the country has ever produced. It correctly identifies the scale of the threat, recognises cross-border criminal networks and introduces structurally sound initiatives.
Recently social media has been awash with nostalgic images and videos from 2016 – sadly that’s also where this strategy belongs. Despite being a competent and well-structured plan of action, it’s a response to problems that existed a decade ago.
The strategy is better than what’s come before, but frustratingly, it’s just not a good enough blueprint to shift the trajectory and effectively tackle fraud and economic crime in the UK.
Nearly half of UK crime is fraud-related

All figures derived from the Fraud Strategy 2026-2029 and underlying government datasets (CSEW, MOJ Criminal Justice Statistics) unless otherwise noted. Percentages and caveats represent RedCompass Labs analysis.
The UK government strategy is designed to introduce a system-wide approach to fraud prevention, disruption and victim support. It’s not difficult to see why; 45% of all crimes in the UK are fraud related, at an annual cost of at least £14.4bn.
However, that figure only captures reported, measurable losses. In reality, this is only the tip of the tip of the iceberg. The true exposure, including unreported fraud, secondary economic damage and the UK’s share of the global scam compound economy, is substantially higher.
On the surface, the UK government’s commitment to the problem appears substantial;
- £250m+ investment allocated to implementing the strategy over 3 years
- A new body, the Online Crime Centre (OCC) established, at a cost of £31m
- Cross-government and public-private collaboration, including government departments, law enforcement, banks and tech platforms
Unfortunately, this doesn’t go anywhere near far enough.
The investment is disproportionately small, and the timeline for platform accountability is dangerously slow. The strategy’s own data demonstrates the need for a far more aggressive response.
What the UK Fraud Strategy gets right
Despite the significant issues with the UK government’s latest fraud initiative, there are some positives which can be built on:
-
The Online Crime Centre model (not the body)
Putting public and private sector bodies in the same location, sharing data and collaborating in real-time is the correct operational architecture for disruption.
-
Acknowledging the international dimension
Identifying overseas fraud operations (AKA scam compounds), sanctioning criminal organisations like the Prince Group and bilateral MoUs (Memorandums of Understanding) with other countries to cooperate on fraud. There’s also a commitment to work through INTERPOL to create a Global Fraud Taskforce by 2029.
-
Convergence crime is partially recognised
The strategy acknowledges that cyber fraud operations are poly-criminal, intertwined with trafficking, money laundering, corruption, and organised crime. This is a step forward from the previous UK fraud policy.
-
Sanctions as a disruption tool
Using asset freezes and travel bans against scam compound operators is meaningful progress and should be expanded aggressively.
6 areas where the UK Fraud Strategy falls short
-
Institutional fragmentation
In recent months, the Online Crime Centre (OCC), National Fraud Squad and National Police Service (absorbing the National Crime Agency) have all been launched or announced. This adds more agencies to the 50+ bodies that already exist to tackle fraud and economic crime in the UK.
The result? Even more bureaucratic layers added to an already fragmented ecosystem. The proliferation of counter-fraud agencies creates a system of bodies all pulling in different directions that actually harms the UK’s ability to stop fraud at the speed it occurs.
The current setup creates boundary disputes, data-sharing negotiations, and competing reporting lines. The administrative overhead alone consumes resources that should be directed at criminals.
The question is not whether the OCC’s function is sound (it is), but why it must be a new body when the NECC, the NFS, and multiple existing structures already occupy this space.
A scam compound has a flatter, more integrated organisational structure than the UK’s counter-fraud system.
A single criminal operation handles recruitment, exploitation, fraud execution, cash-out, and laundering as a single vertically integrated business and outsourced services (laundering and criminal SaaS).
The UK’s response involves 50+ organisations, each with its own budget, minister, KPIs, and definition of the problem. A more streamlined and effective solution is needed.
-
Tech platform accountability: too slow, too soft
70% of APP (Authorised Push Payments) fraud – where a criminal deceives someone into transferring money into their account – originates on social media.
The Online Safety Act’s fraudulent advertising duties will not come into force until 2027 while Ofcom (the UK’s independent communications regulator) will only consult on the detail around summer 2026. On top of this, the programmatic advertising system largely falls outside the act’s scope.
The response to this gap is a voluntary industry partnership reporting back in early 2027, with a conditional threat of legislation.
Frustratingly, under the new strategy, platforms that profit from fraud-enabling content face no meaningful financial consequences under this strategy for at least another 18 months.
Voluntary charters have been tried before and they have not worked.
Until platforms face direct financial liability for fraud originating on their services, their investment in prevention will remain a fraction of what is needed
-
Convergence acknowledged, not operationalised
The strategy mentions human trafficking and forced labour in the context of overseas scam compounds. But it falls short in creating tangible actions that can help to tackle them;
- No dedicated workstream on the intersection of fraud, trafficking, modern slavery, and organised crime as it manifests in financial data
- No requirement for convergence-crime indicator development
- No mandate for financial institutions to screen for cross-crime typologies
- No reference to the kind of red-flag frameworks and investigation guides that would enable financial institutions to detect these converging threats in transaction monitoring
The convergence is treated as context, not as an operational requirement
-
A performative AI response
The strategy states the government is “working to improve the security of AI models.” This is meaningless in operational terms.
- Face-swap tools, voice cloning services, and GenAI-powered scam scripts are sold as packaged criminal SaaS on Telegram and dark web marketplaces.
- AI-generated content for sextortion is a growing threat but is entirely absent from the strategy.
- The government’s Deepfake Detection Challenge is a one-off event, not a sustained capability.
- The velocity gap between criminal AI adoption and government AI response is measured in years, not months.
The strategy is written by people who see fraud only as a financial crime without understanding the full spectrum of what the available tools enable criminals to do
-
Prevention is an afterthought
The strategy’s prevention approach amounts to a public awareness campaign (Stop! Think Fraud) combined with school resources and PROTECT network volunteers. Meanwhile, they’re up against industrialised, AI-powered, globally coordinated fraud operations generating trillions of dollars.
Prevention should be the dominant investment. What’s needed is mandatory, context-sensitive warnings at the point of transaction across every banking app, social media platform, and telecoms interaction. Tech and telecoms firms should be required to bombard users with scam awareness at a scale proportionate to the threat.
Investment in prevention is not happening and not proposed in the strategy
-
Inadequate asset recovery and money laundering measures
Money mule networks are the operational backbone of fraud cash-out, where criminals convert stolen funds into untraceable cash or cryptocurrency. The strategy’s response? The FCA will “analyse cashing-out methods.”
This is research, not intervention. Asset recovery remains a downstream law enforcement activity and what’s needed is a dedicated, resourced, real-time capability. It takes months or years under the legal framework for international recovery, meanwhile funds are moving through crypto rails in minutes.
The gap is structural and the strategy does not close it
The proportional response the UK needs
The following is not theoretical. It is what a government treating this as a national security crisis, as its own data describes, would do.
-
Consolidation not proliferation
Absorb external bodies and their functions – the OCC, NFS (National Fraud Squad) and relevant City of London Police specialist units – into the NECC (National Economic Crime Centre), and give it statutory independence, expanded authority and a single consolidated budget.
This creates one body, one leader, one budget and one line of accountability to parliament. Nobody needs to lose their job, but the government needs to reshape the system for the threat as it exists in 2026.
-
Mandatory platform obligations with financial teeth
Social media platforms above a defined user threshold should be required to implement real-time fraud content detection and removal with mandatory response times. Failure to do so triggers escalating penalties as a percentage of UK revenue.
These platforms should also pay back a portion of fraud losses that matches the level of fraud originating on their sites. Laws requiring platforms to crack down on fraudulent advertising already exist but haven’t been enforced — that needs to happen now.
-
Treat this as a national security emergency
Fraud isn’t just a financial crime; it’s a threat to national security.
Putting the response under National Security Council oversight, deploying intelligence resources at scale and using Treasury-level financial warfare tools against criminal financial infrastructure would apply the necessary urgency and authority structure akin to counter-terrorism powers.
-
Offensive cyber against criminal infrastructure
Law enforcement needs a mandate to continuously target and dismantle criminal SaaS (software as a service) platforms, dark web fraud marketplaces and the crypto rails that move stolen funds. This can’t just be in one-off operations, but as an ongoing campaign focused on the continuous degradation of the criminals’ business model.
-
Prevention at the scale of the threat
Banks, social media platforms and telecoms companies need to display meaningful fraud warnings at the moment they matter most – when a transaction is actually happening.
Platforms that profit from the engagement that enables fraud should also be required to invest in scam awareness at a scale proportionate to the revenue.
-
Real-time asset recovery as a core function
The UK needs a dedicated unit – working with specialist crypto analytics firms – with the legal powers to trace, freeze and recover funds stolen across jurisdictions in real-time.
That would mean striking bilateral treaties with other countries to fast-track legal cooperation that enables asset recovery.
-
Convergence crime detection as a regulatory expectation
Financial institutions need to be mandated to screen for patterns that link fraud to trafficking, forced labour and organised crime.
At the same time, when supervising financial institutions, the FCA (Financial Conduct Authority) should include in its supervisory expectations recognised patterns that show how these types of crime overlap.
-
Consult global operational practitioners
What’s required is a permanent Government advisory panel comprised of members with real-operational experience; prosecutors, investigators, crypto tracing specialists, compound raid veterans and trafficking survivors’ advocates. These people understand what’s required far better than industry lobbyists or Whitehall officials because they are experts working in the field every day.
-
Publish the real numbers
We need a long-overdue independent assessment of the true costs of fraud in the UK, one that goes beyond reported cases and captures unreported fraud, its wider economic damage and the UK’s exposure to global criminal networks.
Making the data public matters because political will is likely to follow when people understand the true scale of the problem.
The UK Fraud Strategy needs less talk and more action
The 2026-2029 UK Fraud Strategy is better than what came before. But that’s not the bar. The bar is whether it’s proportionate to a threat that its own database describes as the “country’s largest crime type”.
The UK has built a world-class infrastructure for talking about fraud. What it hasn’t built is a system capable of stopping it at the speed it occurs. Every new body, charter, and forum is a political signal that “something is being done.” All this does is add bodies to an already overcrowded system.
The metric that matters most is money stolen versus money recovered and at the moment asset recovery rate is below 1% and prosecution rate is below 0.1%. This tells you everything about whether it’s working.
The new strategy offers no urgency and the scale is wrong. Criminals are not waiting for consultations, calls for evidence or voluntary charters and neither should we.
Share this post
Written by
Silvija Krupena
Director, Financial Intelligence Unit , RedCompass Labs
Resources