How to Report Cybercrime in the UK
To report cyber crime in the UK, report fraud and cyber-enabled crime to Action Fraud (actionfraud.police.uk or 0300 123 2040), report any personal data breach to the ICO within 72 hours under UK GDPR, and escalate serious or ongoing attacks to the NCSC.
Quick answer
To report cyber crime in the UK, report fraud and cyber-enabled crime to Action Fraud (actionfraud.police.uk or 0300 123 2040), report any personal data breach to the ICO within 72 hours under UK GDPR, and escalate serious or ongoing attacks to the NCSC. Report fast — delay raises both regulatory and insurance risk.
Key Points
What you need to know.
The Short Answer
A concise overview of what you need to know.
For UK Businesses
How this applies specifically in the UK context.
Cost Considerations
What to expect in terms of investment and ongoing costs.
Next Steps
What you should do with this information.
Quick Comparison
| Feature | Option A | Option B |
|---|
Knowing exactly who to call, in what order, and inside which deadline is the difference between a contained incident and a six-figure fine. This guide sets out the reporting path UK businesses must follow, what evidence each body needs, and how a managed cybersecurity partner shortens the whole process. It matters: 43% of UK businesses experienced a breach or attack (DSIT 2025), and most of them had no documented reporting plan.
Who do you report cyber crime to in the UK?
There is no single phone number. UK cyber crime reporting splits across three bodies with different jobs: Action Fraud handles fraud and most cyber-enabled crime, the Information Commissioner's Office (ICO) handles personal data breaches, and the National Cyber Security Centre (NCSC) handles nationally significant or ongoing technical attacks. Many incidents require reports to more than one.
The trap businesses fall into is treating these as alternatives. They are not. A ransomware attack that exposes customer records can be an Action Fraud crime report, an ICO data-breach notification, and an NCSC incident report at the same time.
| Body | What it handles | How to report | Deadline |
|---|---|---|---|
| Action Fraud | Fraud, phishing, ransomware, most cyber crime | actionfraud.police.uk or 0300 123 2040 | As soon as possible |
| ICO | Personal data breaches under UK GDPR | ico.org.uk breach reporting | Within 72 hours of awareness |
| NCSC | Significant/ongoing attacks, critical infrastructure | ncsc.gov.uk report tool | As soon as possible |
How do you report cyber crime to Action Fraud?
Report to Action Fraud, the UK's national reporting centre for fraud and cyber crime, online at actionfraud.police.uk or by phone on 0300 123 2040. You will be issued a crime reference number, which your insurer and bank will ask for. Report even if no money was lost — the data feeds national policing intelligence.
Action Fraud will ask for the attack type, the date you discovered it, the affected systems or data, any financial loss, and preserved evidence. Because 85% of businesses that experienced a breach identified phishing as the attack vector (DSIT 2025), keep original phishing emails intact with full headers rather than deleting or forwarding them.
What to have ready before you call: - A short timeline of when the attack was discovered and by whom - Affected systems, accounts, and any data categories involved - Financial losses or attempted fraudulent transactions - Preserved evidence: emails with headers, logs, screenshots, ransom notes
When must you report a data breach to the ICO?
If the cyber crime exposed personal data, you must report it to the ICO within 72 hours of becoming aware, under UK GDPR — unless the breach is unlikely to result in a risk to people's rights and freedoms. The clock starts at awareness, not at full diagnosis. A partial, honest report on time beats a complete report that misses the deadline.
You report to the ICO directly; an Action Fraud report does not satisfy this duty. If the breach poses a high risk to individuals, you must also tell the affected people without undue delay. Document your reasoning even when you decide not to report — the ICO expects to see that judgement recorded.
When should you involve the NCSC?
Involve the NCSC for significant or ongoing attacks — active ransomware, large-scale data compromise, or anything touching critical national infrastructure. The National Cyber Security Centre provides technical incident guidance and tracks attacks at national scale, but it is not a substitute for Action Fraud or the ICO. Use it alongside them.
Scale justifies it: approximately 19,000 UK businesses were hit by ransomware in 2025 (Sophos). For an active ransomware incident, early NCSC contact can shape containment decisions before you pay for — or rule out — recovery options.
What evidence should you preserve before reporting?
Preserve everything in its original state before you start cleaning up. The instinct to delete the malicious email, wipe the infected machine, or "just get back to work" destroys the evidence every reporting body and your cyber insurer will ask for. Isolate, do not erase.
Practical preservation steps: - Disconnect affected devices from the network — power them off only on expert advice, as memory evidence can be lost - Keep phishing emails with full headers; export rather than forward - Screenshot ransom notes, error messages, and unusual account activity - Preserve firewall, VPN, and authentication logs before they rotate - Record names, times, and actions in a running incident log
This is exactly the discipline a professional incident response team brings — evidence handling that survives both an ICO inquiry and an insurance claim.
What happens if you fail to report cyber crime?
Failing to report carries two distinct costs. A missed ICO notification can trigger regulatory enforcement and fines under UK GDPR. Separately, late or incomplete reporting frequently invalidates cyber insurance claims, because policies require prompt notification and preserved evidence. The financial hit often lands harder than the original attack.
There is a slower cost too: unreported crime is invisible to national policing, which weakens the intelligence picture for everyone. Reporting is not just compliance — it is how the UK builds a defence against repeat offenders.
How AMVIA shortens the reporting process
When AMVIA monitors your environment, reporting starts from a position of evidence, not panic. Our in-house 24/7 SOC detects the incident, preserves the logs and artefacts each body requires, and helps you notify Action Fraud, the ICO, and the NCSC within their deadlines. One provider. Security-first. Microsoft-certified — so your defence, detection, and reporting sit under a single accountable team rather than three disconnected suppliers.
The strongest reporting position is the one you never have to use because the attack was stopped first. Strengthening phishing protection removes the vector behind most reportable incidents before it reaches an inbox.
Frequently Asked Questions
For most private businesses, reporting fraud and cyber crime to Action Fraud is strongly encouraged but not a legal duty in itself. However, reporting personal data breaches to the ICO within 72 hours is a legal requirement under UK GDPR. Regulated sectors may face additional mandatory reporting obligations to their own regulators.
Yes. They serve different purposes and one report does not cover the other. Action Fraud records the crime and issues a reference number for police intelligence and insurers. The ICO handles your statutory data-breach notification. A single incident involving personal data typically requires both reports, made independently.
You must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it under UK GDPR. The countdown begins at awareness, not at full investigation. If you cannot provide all details in time, submit an initial report and follow up — a late report is harder to defend than a partial one.
Action Fraud asks for the attack type, the date of discovery, affected systems or data, any financial losses, and preserved evidence. Because phishing is the leading attack vector for UK breaches, keep original phishing emails with full headers intact. A clear timeline of who discovered what, and when, speeds the report significantly.
Yes, directly. Most cyber insurance policies require prompt notification of an incident and preservation of evidence as conditions of cover. Delayed reporting or destroyed evidence can reduce or invalidate a claim. Reporting quickly to Action Fraud and the ICO, and keeping a full incident log, protects both your compliance position and your payout.
Protect your business → Get Cybersecurity Assessment