You’ve just realised your business has been hit — ransomware, a fraudulent bank transfer, compromised email accounts, or a scam that’s cost you money. The immediate priorities are containment and recovery. But alongside that, there’s a reporting step that many small businesses either don’t know about or put off indefinitely: filing a report with Action Fraud.
Action Fraud is the UK’s national reporting centre for fraud and cyber crime. It’s run by the City of London Police and is the single official route for businesses and individuals to report this type of crime. Reporting doesn’t guarantee investigation or recovery of losses, but it matters for several reasons: it creates a formal record, contributes to the intelligence picture that NCSC and law enforcement use to identify and disrupt criminal groups, and it’s often required for cyber insurance claims and regulatory notifications.
This guide walks through exactly how to report, what information you need, and what to expect afterwards.
Before You Report: Contain and Document
Don’t wait until everything is resolved before reporting — but do spend a few minutes on documentation first, because you’ll need it.
Write down:
- When you first noticed the incident (date and approximate time)
- What you noticed (error messages, suspicious transactions, alerts from staff)
- What systems or accounts were affected
- Any communications from the attackers (ransom notes, emails, screenshots)
- Transaction references for any fraudulent payments, including amounts, dates, and destination account details
- IP addresses or email addresses if you have them from logs or emails
Keep originals intact — don’t delete suspicious emails or wipe affected systems before you’ve documented what you can. If you believe a device has malware, isolate it from the network but leave it powered on and connected to a power source so forensics are possible.
How to Make a Report
Online: actionfraud.police.uk
The primary reporting route is the Action Fraud website. Reports can be made 24/7. You’ll create a case via the online reporting tool, which walks you through a structured questionnaire. The process takes 15-30 minutes depending on the complexity of what happened.
You’ll be asked to specify:
- Whether you’re reporting as an individual or on behalf of an organisation
- The type of crime (cyber crime, fraud, both)
- When it occurred
- What losses you’ve suffered (financial and otherwise)
- Details of how the attack happened, as far as you know
At the end you’ll receive a Police Report Number (also called a NFRC — National Fraud and Cyber Crime Reporting Centre — number). Keep this. You’ll need it for insurance claims, for reference if you’re contacted by investigators, and for any follow-up with regulators.
By phone: 0300 123 2040
If you’d prefer to report by phone, Action Fraud’s number is 0300 123 2040, available Monday to Friday 8am to 8pm. This route is particularly useful if you need help navigating the report or if the incident is complex. A member of staff will take you through the same structured questions.
For businesses that have suffered a significant financial loss or are experiencing an active attack, the phone route often gets faster initial attention.
Reporting in Welsh
Action Fraud offers a Welsh-language service by phone. When you call 0300 123 2040, request a Welsh-speaking officer and one will be arranged.
What Counts as a Cyber Crime vs. Fraud
Action Fraud handles both. The distinction matters slightly for how your report is categorised:
Fraud is when you’ve been deceived into handing over money or information — a business email compromise that caused a fraudulent transfer, an invoice scam, a fake supplier email. The criminal element is the deception that led to financial loss.
Cyber crime is when criminal activity targeted your systems or data directly — ransomware, hacking, DDoS attacks, data theft. You don’t need a financial loss to report cyber crime.
Many incidents are both: a phishing attack that compromised email accounts and then led to a fraudulent payment involves both cyber crime and fraud. Report it as both or describe the full chain of events and Action Fraud will categorise it appropriately.
Specific Reporting for Ransomware
If you’ve been hit by ransomware, Action Fraud should be notified, but there’s an additional route worth knowing: the NCSC’s Cyber Incident Reporting form at ncsc.gov.uk/report-an-incident.
NCSC operates separately from Action Fraud and focuses on understanding the threat landscape and helping organisations respond. For significant ransomware attacks — particularly if you’re in a critical sector like healthcare, utilities, or finance — NCSC reporting can result in direct support and access to their Incident Management team.
For most small businesses, report to Action Fraud first, then also file with NCSC. They share intelligence and the reports don’t conflict. If you’re unsure whether NCSC will be interested in your incident, their guidance says any organisation can report; they triage based on impact and sector.
Bank and Payment Fraud
If the attack involved a fraudulent bank transfer — money sent to a criminal account as a result of a scam or compromised communications — contact your bank immediately. Do this before reporting to Action Fraud if the transfer is very recent: UK banks participate in the Faster Payments recall scheme, and rapid notification gives the best chance of stopping the transfer.
Tell your bank:
- The amount and date of the fraudulent transfer
- Your account details
- The destination sort code and account number (from the transfer record)
Under the Contingent Reimbursement Model (CRM) and the new mandatory reimbursement rules that came into force in 2024, banks are required to reimburse victims of certain types of Authorised Push Payment (APP) fraud within 5 business days, up to £85,000. This applies when you were deceived into making the payment — invoice fraud and CEO fraud scams typically qualify. The reimbursement rules don’t cover all types of fraud, so check with your bank about your specific situation.
After notifying your bank, report to Action Fraud. Include the bank reference for the transfer in your report.
ICO Notification for Data Breaches
If the incident involved personal data — customer records, employee information, health data, financial details — you likely have a notification obligation to the Information Commissioner’s Office (ICO) under UK GDPR.
The threshold is a data breach that is “likely to result in a risk to the rights and freedoms of individuals.” This is deliberately broad, and if you’re unsure whether your incident qualifies, the safer approach is to notify. Notification to the ICO must happen within 72 hours of becoming aware of the breach.
ICO notification and Action Fraud reporting are separate processes. ICO notification is about your data protection obligations; Action Fraud reporting is a criminal justice matter. Both can happen in parallel.
Report a data breach to the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
What Happens After You Report
Action Fraud will send you a confirmation email with your Police Report Number. The City of London Police’s National Fraud Intelligence Bureau (NFIB) assesses all reports and decides which cases to pursue. The reality is that most individual reports don’t result in a direct investigation — there are hundreds of thousands of reports per year and finite investigative resources.
What reports do is feed into the intelligence picture. Patterns across many reports can identify criminal infrastructure, flag compromised services, or trigger law enforcement action against specific groups. NCSC and the National Cyber Security Programme both use Action Fraud data to understand emerging threats.
For your insurance claim, the Police Report Number is typically required as part of the claims process. Some policies also require you to report within a certain timeframe, so don’t delay if you have cyber insurance.
If you want to know the status of your report, you can check online at actionfraud.police.uk using your Police Report Number.
After Reporting: Next Steps
Reporting is one part of the response, not the whole of it. Alongside the report:
- Preserve evidence: Don’t wipe affected systems before forensics are done, even if you want the machines back in service. Consider engaging a forensics firm for serious incidents.
- Notify affected parties: If customer or supplier data was compromised, you may need to notify them directly — your legal obligation to notify individuals is separate from ICO notification.
- Review access controls: Change passwords, revoke compromised credentials, and review who has access to what across your systems.
- Update your cyber insurance: If the incident affects your risk profile, notify your insurer — some policies require prompt notification of incidents even before you make a claim.
- Check NCSC guidance: The NCSC small business guide (ncsc.gov.uk/collection/small-business-guide) has specific guidance on recovering from common attack types.
The Cyber Resilience Centre for your region (there are nine regional centres across England and Wales) can also provide post-incident support for small businesses, often at low cost.
Reporting to Action Fraud isn’t going to undo the damage from a cyber attack, and it’s not a substitute for the technical and operational work of recovery. But it’s a step that takes under an hour, contributes to the national response to cyber crime, and is required for insurance and regulatory processes. Do it as part of your incident response, not as an afterthought months later.