You can use the search function to find a range of UK Finance material, from consultation responses to thought leadership to blogs, or to find content on a range of topics from Capital Markets & Wholesale to Payments & Innovation.
08 Jun 2026
The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.
Fraud starts with what data criminals already have
Fraud now represents over 40 per cent of all crime in the UK, and 80 per cent of reported crimes have a cyber element. The identity data fuelling that is already in criminal hands – before an account gets taken over, before a synthetic identity is weaponised, before a fraudulent payment clears.
Criminals do their homework first. They collect stolen access data – credentials, session tokens, PII – from malware-infected devices, phishing attacks, and third-party breaches. The question isn't whether UK banking customers are exposed on the criminal underground. It's the scale, and what criminals are doing with it right now.
SpyCloud ran its Check Your Exposure tool across the 20 largest banks operating in the UK by total assets – spanning high street banks, building societies, challenger banks, and the UK entities of international institutions. Here's what the data reveals.
The scale of employee identity exposure
Across the 20 institutions, SpyCloud identified 1,619 employees infected by malware in the last 6 months – an average of 81 per bank. Sixteen of the 20 had at least one infected employee during this window.
Malware infections aren't just a password problem. When an infostealer lands on a device (66 per cent of infections are present on devices with anti-virus or EDR installed), it exfiltrates everything in reach – saved credentials, session cookies, autofill data, device fingerprints, and PII. That data package gives a criminal everything they need to impersonate that employee across multiple systems, often without triggering red flags.
The average employee password reuse rate across all 20 banks was 75.6 per cent. That means three in every four exposed employee passwords aren't unique – they're being reused across other accounts and platforms, likely even personal accounts. When a credential is exposed in a successful phish, infostealer infection log, or data breach, criminals don't just try it once. They run it systematically across every high-value target they can reach. A single exposed password becomes a skeleton key.
The consumer picture
Behind every consumer credential exposure is a real customer – one whose banking login, personal email, and saved payment details may all sit in the same malware exfiltration package. Across these 20 institutions, SpyCloud found 4.6 million consumer credential exposures and more than 18,000 malware-infected consumer devices. That data feeds synthetic identity fraud, new account fraud, and identity theft – often long before the customer knows anything is wrong, and long before it shows up in a bank's fraud detection stack.
Consumer password reuse averaged 83.5 per cent – meaning most of those stolen credentials will work somewhere else too.
Worth being clear on methodology: these figures reflect data exposed across third-party breaches, malware infections, and successful phishes tied to consumers of these financial institutions. They don't represent breaches of the banks themselves. But again – that's the point. This is exposure that exists entirely outside the bank's visibility, in criminal hands, right now.
What criminals do with this data
Stolen credentials get tested. High reuse rates mean a credential exposed in one breach gets systematically tried across banking, e-commerce, and payment platforms. This is credential stuffing at industrialised scale – automated, fast, and increasingly AI-assisted.
Malware-exfiltrated session cookies are more immediately dangerous. A valid session token has already cleared MFA. It doesn't need a password. AiTM (adversary-in-the-middle) phishing kits take this further – proxying the entire authentication process in real time to capture post-login session tokens and long-lived refresh tokens. A stolen refresh token can remain valid for up to 90 days after a password change. The account looks legitimate to every downstream control.
This is why the industry's push toward passkeys and stronger digital identity controls – while absolutely the right direction – needs a complementary upstream layer. Stronger authentication raises the bar. It doesn't address what criminals already have, and it doesn’t stop session hijacking attacks.
Exposure is consistent across institution size
The malware infection data doesn't cluster at the largest institutions. Building societies, challengers, and mid-tier banks all show up in the findings alongside the major high street names. Size and security budget don't insulate an institution from this – the criminal ecosystem doesn't discriminate.
What does your institution's exposure look like?
The data above reflects six months of recaptured darknet intelligence across 20 UK institutions. Curious what's out there for yours?
SpyCloud's Check Your Exposure tool gives financial institutions a free summary of their darknet exposure in minutes. No commitment required – just your institution’s domain. If what you find raises questions, we're happy to walk through it.
08.06.26
Mandeep Sandhu, Solution Engineering Manager and Investigator, EMEA, Spycloud
Our popular half-day conference returns in 2026 at a pivotal moment for the UK’s fraud and financial crime landscape. Join us on 15 June to examine the challenges, opportunities and strategic shifts shaping the year ahead.
By downloading this document, you understand and agree that any sharing, distribution or republishing of the content, without prior written authorisation from the author or content managers at UK Finance, shall be constituted as a breach of the UK Finance website terms of use.