AEO Answer

How to Report Cybercrime in the UK

To report cyber crime in the UK, report fraud and cyber-enabled crime to Action Fraud (actionfraud.police.uk or 0300 123 2040), report any personal data breach to the ICO within 72 hours under UK GDPR, and escalate serious or ongoing attacks to the NCSC.

Quick answer

To report cyber crime in the UK, report fraud and cyber-enabled crime to Action Fraud (actionfraud.police.uk or 0300 123 2040), report any personal data breach to the ICO within 72 hours under UK GDPR, and escalate serious or ongoing attacks to the NCSC. Report fast — delay raises both regulatory and insurance risk.

Key Points

What you need to know.

The Short Answer

A concise overview of what you need to know.

For UK Businesses

How this applies specifically in the UK context.

Cost Considerations

What to expect in terms of investment and ongoing costs.

Next Steps

What you should do with this information.

Quick Comparison

Feature
Option A
Option B

Knowing exactly who to call, in what order, and inside which deadline is the difference between a contained incident and a six-figure fine. This guide sets out the reporting path UK businesses must follow, what evidence each body needs, and how a managed cybersecurity partner shortens the whole process. It matters: 43% of UK businesses experienced a breach or attack (DSIT 2025), and most of them had no documented reporting plan.

Who do you report cyber crime to in the UK?

There is no single phone number. UK cyber crime reporting splits across three bodies with different jobs: Action Fraud handles fraud and most cyber-enabled crime, the Information Commissioner's Office (ICO) handles personal data breaches, and the National Cyber Security Centre (NCSC) handles nationally significant or ongoing technical attacks. Many incidents require reports to more than one.

The trap businesses fall into is treating these as alternatives. They are not. A ransomware attack that exposes customer records can be an Action Fraud crime report, an ICO data-breach notification, and an NCSC incident report at the same time.

BodyWhat it handlesHow to reportDeadline
Action FraudFraud, phishing, ransomware, most cyber crimeactionfraud.police.uk or 0300 123 2040As soon as possible
ICOPersonal data breaches under UK GDPRico.org.uk breach reportingWithin 72 hours of awareness
NCSCSignificant/ongoing attacks, critical infrastructurencsc.gov.uk report toolAs soon as possible

How do you report cyber crime to Action Fraud?

Report to Action Fraud, the UK's national reporting centre for fraud and cyber crime, online at actionfraud.police.uk or by phone on 0300 123 2040. You will be issued a crime reference number, which your insurer and bank will ask for. Report even if no money was lost — the data feeds national policing intelligence.

Action Fraud will ask for the attack type, the date you discovered it, the affected systems or data, any financial loss, and preserved evidence. Because 85% of businesses that experienced a breach identified phishing as the attack vector (DSIT 2025), keep original phishing emails intact with full headers rather than deleting or forwarding them.

What to have ready before you call: - A short timeline of when the attack was discovered and by whom - Affected systems, accounts, and any data categories involved - Financial losses or attempted fraudulent transactions - Preserved evidence: emails with headers, logs, screenshots, ransom notes

When must you report a data breach to the ICO?

If the cyber crime exposed personal data, you must report it to the ICO within 72 hours of becoming aware, under UK GDPR — unless the breach is unlikely to result in a risk to people's rights and freedoms. The clock starts at awareness, not at full diagnosis. A partial, honest report on time beats a complete report that misses the deadline.

You report to the ICO directly; an Action Fraud report does not satisfy this duty. If the breach poses a high risk to individuals, you must also tell the affected people without undue delay. Document your reasoning even when you decide not to report — the ICO expects to see that judgement recorded.

When should you involve the NCSC?

Involve the NCSC for significant or ongoing attacks — active ransomware, large-scale data compromise, or anything touching critical national infrastructure. The National Cyber Security Centre provides technical incident guidance and tracks attacks at national scale, but it is not a substitute for Action Fraud or the ICO. Use it alongside them.

Scale justifies it: approximately 19,000 UK businesses were hit by ransomware in 2025 (Sophos). For an active ransomware incident, early NCSC contact can shape containment decisions before you pay for — or rule out — recovery options.

What evidence should you preserve before reporting?

Preserve everything in its original state before you start cleaning up. The instinct to delete the malicious email, wipe the infected machine, or "just get back to work" destroys the evidence every reporting body and your cyber insurer will ask for. Isolate, do not erase.

Practical preservation steps: - Disconnect affected devices from the network — power them off only on expert advice, as memory evidence can be lost - Keep phishing emails with full headers; export rather than forward - Screenshot ransom notes, error messages, and unusual account activity - Preserve firewall, VPN, and authentication logs before they rotate - Record names, times, and actions in a running incident log

This is exactly the discipline a professional incident response team brings — evidence handling that survives both an ICO inquiry and an insurance claim.

What happens if you fail to report cyber crime?

Failing to report carries two distinct costs. A missed ICO notification can trigger regulatory enforcement and fines under UK GDPR. Separately, late or incomplete reporting frequently invalidates cyber insurance claims, because policies require prompt notification and preserved evidence. The financial hit often lands harder than the original attack.

There is a slower cost too: unreported crime is invisible to national policing, which weakens the intelligence picture for everyone. Reporting is not just compliance — it is how the UK builds a defence against repeat offenders.

How AMVIA shortens the reporting process

When AMVIA monitors your environment, reporting starts from a position of evidence, not panic. Our in-house 24/7 SOC detects the incident, preserves the logs and artefacts each body requires, and helps you notify Action Fraud, the ICO, and the NCSC within their deadlines. One provider. Security-first. Microsoft-certified — so your defence, detection, and reporting sit under a single accountable team rather than three disconnected suppliers.

The strongest reporting position is the one you never have to use because the attack was stopped first. Strengthening phishing protection removes the vector behind most reportable incidents before it reaches an inbox.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.